On this page

List tasks and approvals

GET/agents/{id}/tasks

Operation getAgentTasksAuthBearer token

limit default 200 (clamped 1–1000). pending_approval rows carry the live Always-approve affordance (canAlwaysApprove, alwaysApproveBlockedReason), derived from the executor holding the request and never persisted.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Query parameters

NameTypeDescription
statusstring

Only this status

One of pending, pending_approval, running, completed, failed, denied, cancelled

limitinteger

Maximum rows to return

Responses

StatusDescriptionBody
200TasksTasksResponse
agentIdrequiredstring

Agent id

tasksrequiredarray<Task>
14 fields of tasks
idrequiredstring
toolrequiredstring
argsrequiredstring

JSON text of the tool arguments

statusrequiredstring

One of pending, pending_approval, running, completed, failed, denied, cancelled

resultstring
errorstring
created_atrequiredinteger
completed_atinteger
originstring
requires_authorizationboolean
executor_managedboolean
approval_metaobject
2 fields of approval_meta
reasonrequiredstring

One of restricted, protection

protectionobject
4 fields of protection
kindrequiredstring
targetrequiredstring
levelrequiredstring
descriptionstring
canAlwaysApproveboolean

pending_approval rows: whether POST …/always-approve would be accepted

alwaysApproveBlockedReasonstring

Why canAlwaysApprove is false

Errors 400 · 401 · 403 · 404
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/tasks" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Read one task

GET/agents/{id}/tasks/{taskId}

Operation getAgentTaskAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

taskIdrequiredstring

Task id (GET …/tasks)

Responses

StatusDescriptionBody
200TaskTaskResponse
agentIdrequiredstring

Agent id

taskrequiredobject
14 fields of task · Task
idrequiredstring
toolrequiredstring
argsrequiredstring

JSON text of the tool arguments

statusrequiredstring

One of pending, pending_approval, running, completed, failed, denied, cancelled

resultstring
errorstring
created_atrequiredinteger
completed_atinteger
originstring
requires_authorizationboolean
executor_managedboolean
approval_metaobject
2 fields of approval_meta
reasonrequiredstring

One of restricted, protection

protectionobject
4 fields of protection
kindrequiredstring
targetrequiredstring
levelrequiredstring
descriptionstring
canAlwaysApproveboolean

pending_approval rows: whether POST …/always-approve would be accepted

alwaysApproveBlockedReasonstring

Why canAlwaysApprove is false

Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/tasks/TASK_ID" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Approve or deny a pending task

POST/agents/{id}/tasks/{taskId}/resolve

Operation resolveAgentTaskAuthBearer token

approve lets it run (optionally with modifiedArgs); deny refuses it: reason is stored as the task's error and handed back to the agent as the owner's feedback (a blocking call's tool result reads Tool call "<tool>" was rejected by authorizer. Feedback: <reason>); pending_approval marks a pending task as awaiting approval. Only pending / pending_approval tasks resolve; others answer 409. At load the runtime sweeps orphans from a crash: running tasks become failed and the executor's own pending_approval tasks cancelled, so resolving one of those is a 409. Requests parked by an inner loop are answered on that loop's executor.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

taskIdrequiredstring

Task id (GET …/tasks)

Request bodyapplication/json · TaskResolveBody · required

FieldTypeDescription
actionrequiredstring

One of approve, deny, pending_approval

reasonstring

On deny: stored as the task error and handed back to the agent as the owner's feedback

modifiedArgsobject

Approve with these arguments instead (alias: modified_args)

modified_argsobject

Responses

StatusDescriptionBody
200ResolvedTaskResolutionResponse
agentIdrequiredstring

Agent id

taskIdrequiredstring
resolutionrequiredany

What the executor or task store returned

taskrequiredTask | null
14 fields of task
idrequiredstring
toolrequiredstring
argsrequiredstring

JSON text of the tool arguments

statusrequiredstring

One of pending, pending_approval, running, completed, failed, denied, cancelled

resultstring
errorstring
created_atrequiredinteger
completed_atinteger
originstring
requires_authorizationboolean
executor_managedboolean
approval_metaobject
2 fields of approval_meta
reasonrequiredstring

One of restricted, protection

protectionobject
4 fields of protection
kindrequiredstring
targetrequiredstring
levelrequiredstring
descriptionstring
canAlwaysApproveboolean

pending_approval rows: whether POST …/always-approve would be accepted

alwaysApproveBlockedReasonstring

Why canAlwaysApprove is false

Errors 400 · 401 · 403 · 404 · 409 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
409The resource is in a state that does not allow this now
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/tasks/TASK_ID/resolve" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"action":"approve"}'

Always approve: un-restrict the tool and approve the request

POST/agents/{id}/tasks/{taskId}/always-approve

Operation alwaysApproveAgentTaskAuthBearer token

Studio's Approve ▸ Always approve. The host tool declaration (taken from the pending request, never the client) becomes enabled and unrestricted, persisted like PUT …/config; then the request is approved. 409 for protection overrides, one-shot approvals, locked declarations or a request no executor holds. No body.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

taskIdrequiredstring

Task id (GET …/tasks)

Responses

StatusDescriptionBody
200ApprovedTaskAlwaysApproveResponse
agentIdrequiredstring

Agent id

taskIdrequiredstring
looprequiredstring

Loop whose executor held the request

toolrequiredstring

Tool whose host declaration was un-restricted

resolutionrequiredany
taskrequiredTask | null
14 fields of task
idrequiredstring
toolrequiredstring
argsrequiredstring

JSON text of the tool arguments

statusrequiredstring

One of pending, pending_approval, running, completed, failed, denied, cancelled

resultstring
errorstring
created_atrequiredinteger
completed_atinteger
originstring
requires_authorizationboolean
executor_managedboolean
approval_metaobject
2 fields of approval_meta
reasonrequiredstring

One of restricted, protection

protectionobject
4 fields of protection
kindrequiredstring
targetrequiredstring
levelrequiredstring
descriptionstring
canAlwaysApproveboolean

pending_approval rows: whether POST …/always-approve would be accepted

alwaysApproveBlockedReasonstring

Why canAlwaysApprove is false

Errors 401 · 403 · 404 · 409 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
409The resource is in a state that does not allow this now
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/tasks/TASK_ID/always-approve" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Approve every pending gated approval

POST/agents/{id}/tasks/approve-all

Operation approveAllAgentTasksAuthBearer token

Studio's Approve all: main and every running inner loop (or only loop, from the body or query). Protection overrides are never approved; they are counted in skippedProtection.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Query parameters

NameTypeDescription
loopstring

Cognition loop to address. Absent = main. Unknown loops answer 404.

Request bodyapplication/json · ApproveAllBody · optional

FieldTypeDescription
loopstring

Only this loop's approvals

Responses

StatusDescriptionBody
200CountsApproveAllResponse
agentIdrequiredstring

Agent id

loopstring
approvedrequiredinteger
skippedProtectionrequiredinteger
Errors 400 · 401 · 403 · 404 · 409 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
409The resource is in a state that does not allow this now
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/tasks/approve-all" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "approved": 2,
  "skippedProtection": 1
}

List pending ask requests

GET/agents/{id}/asks

Operation getAgentAsksAuthBearer token

Every loop's (main and each running inner loop); loop names the loop whose turn is waiting.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200AsksAsksResponse
agentIdrequiredstring

Agent id

asksrequiredarray<object>
3 fields of asks
requestIdrequiredstring
questionrequiredstring
looprequiredstring

The loop waiting on the answer

Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/asks" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Answer an ask request

POST/agents/{id}/asks/{requestId}/respond

Operation answerAgentAskAuthBearer token

Request ids are numbered per loop: pass the loop from GET …/asks when two loops ask at once; without it the first loop holding the id is answered. An id no loop holds (already answered, or never asked) answers 404 ask_not_found.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

requestIdrequiredstring

Ask request id (GET …/asks)

Request bodyapplication/json · AskRespondBody · required

FieldTypeDescription
answerrequiredstring
loopstring

The loop that asked (GET …/asks lists it); absent = the first loop holding the id

Responses

StatusDescriptionBody
200answered is false when no loop held the requestAskRespondResponse
agentIdrequiredstring

Agent id

requestIdrequiredstring
looprequiredstring
answeredrequiredboolean
Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (not_found), or no loop holds this ask (ask_not_found)ask_not_foundnot_found
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/asks/REQUEST_ID/respond" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"answer":"Yes, go ahead."}'

Resume or stop after a suspend prompt

POST/agents/{id}/suspend/respond

Operation respondAgentSuspendAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Request bodyapplication/json · SuspendRespondBody · required

FieldTypeDescription
resumerequiredboolean

Responses

StatusDescriptionBody
200ResolvedSuspendRespondResponse
agentIdrequiredstring

Agent id

resumerequiredboolean
resolvedrequiredboolean
Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/suspend/respond" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"resume":true}'