On this page

List stored identity entries (no values)

GET/agents/{id}/identities

Operation getAgentIdentitiesAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200EntriesIdentityListResponse
agentIdrequiredstring

Agent id

identitiesrequiredarray<object>
3 fields of identities
purposerequiredstring
encryptedrequiredboolean
code_accessrequiredboolean
Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/identities" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

List identity purposes

GET/agents/{id}/identity

Operation listAgentIdentityPurposesAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Query parameters

NameTypeDescription
prefixstring

Only purposes starting with this

Responses

StatusDescriptionBody
200PurposesIdentityPurposesResponse
agentIdrequiredstring

Agent id

purposesrequiredarray<string>
Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/identity" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

List stored identity entries (alias of …/identities)

GET/agents/{id}/identity/entries

Operation listAgentIdentityEntriesAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200EntriesIdentityListResponse
agentIdrequiredstring

Agent id

identitiesrequiredarray<object>
3 fields of identities
purposerequiredstring
encryptedrequiredboolean
code_accessrequiredboolean
Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/identity/entries" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Whether the identity store has a password and is unlocked

GET/agents/{id}/identity/password

Operation getAgentIdentityPasswordStatusAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200StatusIdentityPasswordStatus
agentIdrequiredstring

Agent id

needsPasswordrequiredboolean
unlockedrequiredboolean
Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/identity/password" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Set an identity password (legacy whole-file encryption)

PUT/agents/{id}/identity/password

Operation setAgentIdentityPasswordAuthBearer token

Always 400 not_supported: whole-file passwords are no longer supported.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Request bodyapplication/json · IdentityPasswordBody · required

FieldTypeDescription
passwordrequiredstring

Responses

StatusDescriptionBody
200SetAgentSuccess
agentIdrequiredstring

Agent id

successrequiredboolean
Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X PUT "http://127.0.0.1:7385/agents/agent-1/identity/password" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"password":"string"}'
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "success": true
}

Remove the identity password

DELETE/agents/{id}/identity/password

Operation removeAgentIdentityPasswordAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200RemovedAgentSuccess
agentIdrequiredstring

Agent id

successrequiredboolean
Errors 401 · 403 · 404 · 409 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
409Bad value (key material cannot be replaced over the API), or the agent's credentials envelope is locked on this daemon (credentials_locked): unlock the owner identity, or retry with replace: true. A legacy agent locked with a whole-file password answers 409 credentials_locked until POST /agents/{id}/identity/password/unlock
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X DELETE "http://127.0.0.1:7385/agents/agent-1/identity/password" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "success": true
}

Unlock a password-protected identity store

POST/agents/{id}/identity/password/unlock

Operation unlockAgentIdentityPasswordAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Request bodyapplication/json · IdentityPasswordBody · required

FieldTypeDescription
passwordrequiredstring

Responses

StatusDescriptionBody
200UnlockedAgentSuccess
agentIdrequiredstring

Agent id

successrequiredboolean
Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/identity/password/unlock" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"password":"string"}'
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "success": true
}

Change the identity password

POST/agents/{id}/identity/password/change

Operation changeAgentIdentityPasswordAuthBearer token

Always 400 not_supported: whole-file passwords are no longer supported.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Request bodyapplication/json · IdentityChangePasswordBody · required

FieldTypeDescription
newPasswordrequiredstring

Alias: new_password

Responses

StatusDescriptionBody
200ChangedAgentSuccess
agentIdrequiredstring

Agent id

successrequiredboolean
Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/identity/password/change" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"newPassword":"string"}'
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "success": true
}

The agent's DID

GET/agents/{id}/identity/did

Operation getAgentDidAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200DID (null when no keys)AgentDidResponse
agentIdrequiredstring

Agent id

didrequiredstring | null
Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/identity/did" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "did": "did:key:z6Mk…"
}

Generate the agent's signing keys

POST/agents/{id}/identity/generate-keys

Operation generateAgentIdentityKeysAuthBearer token

No body.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200GeneratedGenerateKeysResponse
agentIdrequiredstring

Agent id

successrequiredboolean

Value true

didrequiredstring
Errors 401 · 403 · 404 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/identity/generate-keys" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Wipe every identity row

POST/agents/{id}/identity/wipe

Operation wipeAgentIdentityAuthBearer token

Irreversible: keys, DID and every stored credential go. No body.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200WipedAgentSuccess
agentIdrequiredstring

Agent id

successrequiredboolean
Errors 401 · 403 · 404 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/identity/wipe" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "success": true
}

Delete identity values by purpose prefix

DELETE/agents/{id}/identity-prefix

Operation deleteAgentIdentityPrefixAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Query parameters

NameTypeDescription
prefixrequiredstring

Purpose prefix, e.g. mcp:@acme/server:

Responses

StatusDescriptionBody
200Deleted countIdentityPrefixDeleteResponse
agentIdrequiredstring

Agent id

prefixrequiredstring
deletedrequiredinteger
Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X DELETE "http://127.0.0.1:7385/agents/agent-1/identity-prefix?prefix=PREFIX" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Metadata of one stored value (never the value)

GET/agents/{id}/identity/{purpose}

Operation getAgentIdentityValueAuthBearer token

Values and key material (crypto:signing:*, crypto:envelope:*, owner/runtime keys) never leave the daemon by any route. storage: sealed (envelope-encrypted), plain, password (legacy whole-file password) or null (absent); locked: stored but unreadable in this process; length is null for crypto:* and locked values.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

purposerequiredstring

Identity purpose, e.g. provider:anthropic:apiKey

Responses

StatusDescriptionBody
200MetadataAgentIdentityMetaResponse
purposerequiredstring
presentrequiredboolean
storagerequiredstring | null

One of sealed, plain, password, null

sealedrequiredboolean
lockedrequiredboolean

Stored but not readable in this process

lengthrequiredinteger | null

null for crypto:* purposes and locked values

code_accessrequiredboolean
agentIdrequiredstring
Errors 401 · 403 · 404 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/identity/PURPOSE" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Store one identity value

PUT/agents/{id}/identity/{purpose}

Operation setAgentIdentityValueAuthBearer token

Values go in, never out. While the agent's credentials envelope is locked (or foreign) on this daemon the write is refused with 409 credentials_locked: a plain write would destroy a sealed value it cannot read, or store a new one unsealed. Unlock the owner identity first, or send replace: true (the owner's override: a locked sealed value is discarded unread, the new value stored plain and sealed once the envelope unlocks, logged as credential_replaced; the response then has replaced: true). replace is refused for key material (crypto:*, 400). A write to an agent locked by a legacy whole-file identity password answers 500 (unlock it with POST …/identity/password/unlock).

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

purposerequiredstring

Identity purpose, e.g. provider:anthropic:apiKey

Request bodyapplication/json · IdentityValueBody · required

FieldTypeDescription
valuerequiredstring
replaceboolean

Owner override while the agent's credentials envelope is locked on this daemon: a locked sealed value is discarded unread and the new value is stored plain, sealed again on unlock; logged to adf_logs (credential_replaced). Without it such a write answers 409 credentials_locked.

Responses

StatusDescriptionBody
200StoredIdentityWriteResponse
agentIdrequiredstring

Agent id

purposerequiredstring
successrequiredboolean

Value true

replacedboolean

A locked sealed value was discarded (replace: true)

Errors 400 · 401 · 403 · 404 · 409 · 500
400Missing value, or replace on key material
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
409Bad value (key material cannot be replaced over the API), or the agent's credentials envelope is locked on this daemon (credentials_locked): unlock the owner identity, or retry with replace: true. A legacy agent locked with a whole-file password answers 409 credentials_locked until POST /agents/{id}/identity/password/unlock
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X PUT "http://127.0.0.1:7385/agents/agent-1/identity/PURPOSE" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"value":"sk-…"}'

Delete one identity value

DELETE/agents/{id}/identity/{purpose}

Operation deleteAgentIdentityValueAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

purposerequiredstring

Identity purpose, e.g. provider:anthropic:apiKey

Responses

StatusDescriptionBody
200success is false when nothing was deletedIdentityDeleteResponse
agentIdrequiredstring

Agent id

purposerequiredstring
successrequiredboolean
Errors 401 · 403 · 404 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X DELETE "http://127.0.0.1:7385/agents/agent-1/identity/PURPOSE" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Allow or deny code (sys_code / lambdas) reading a value

PATCH/agents/{id}/identity/{purpose}/code-access

Operation setAgentIdentityCodeAccessAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

purposerequiredstring

Identity purpose, e.g. provider:anthropic:apiKey

Request bodyapplication/json · IdentityCodeAccessBody · required

FieldTypeDescription
codeAccessrequiredboolean

Alias: code_access

Responses

StatusDescriptionBody
200SavedIdentityDeleteResponse
agentIdrequiredstring

Agent id

purposerequiredstring
successrequiredboolean
Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X PATCH "http://127.0.0.1:7385/agents/agent-1/identity/PURPOSE/code-access" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"codeAccess":true}'