You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 664c9a7
Browse filesBrowse the repository at this point in the historyBrowse files
description: 'Headers the CLI copies onto the daemon request so the sidecar can verify who is asking.'
28651
+
example:
28652
+
x-ori-invoke-signature: 'MEUCIQ...'
28653
+
x-ori-invoke-timestamp: '1789000000'
28654
+
x-ori-invoke-user: 'user_2abc'
28655
+
properties:
28656
+
x-ori-invoke-signature:
28657
+
description: 'Base64 Ed25519 signature over the intern id, timestamp, user and body digest.'
28658
+
type: 'string'
28659
+
x-ori-invoke-timestamp:
28660
+
description: 'Unix seconds at signing; the daemon refuses proofs older than its window.'
28661
+
type: 'string'
28662
+
x-ori-invoke-user:
28663
+
description: 'The verified OAuth subject the proof names. Never taken from the request.'
28664
+
type: 'string'
28665
+
required:
28666
+
- 'x-ori-invoke-signature'
28667
+
- 'x-ori-invoke-timestamp'
28668
+
- 'x-ori-invoke-user'
28669
+
type: 'object'
28637
28670
SpeechInput:
28638
28671
anyOf:
28639
28672
- type: 'string'
@@ -41944,6 +41977,315 @@ paths:
41944
41977
summary: 'Get an intern''s daemon access (deprecated alias)'
41945
41978
tags:
41946
41979
- 'Interns'
41980
+
/interns/{internId}/daemon-access/sign:
41981
+
post:
41982
+
deprecated: true
41983
+
description: 'Deprecated alias of `POST /interns/{internId}/daemon/sign` with the same request, response, and errors. The API key selects the caller, workspace and visible interns. An intern''s own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.'
41984
+
operationId: 'signInternDaemonAccessRequest'
41985
+
parameters:
41986
+
- description: 'ID of an intern visible to the authenticated API key.'
41987
+
in: 'path'
41988
+
name: 'internId'
41989
+
required: true
41990
+
schema:
41991
+
description: 'ID of an intern visible to the authenticated API key.'
description: 'Missing, unknown or provisioning API key.'
42031
+
'403':
42032
+
content:
42033
+
application/json:
42034
+
example:
42035
+
error:
42036
+
code: 403
42037
+
message: 'Personal connections require ori login --oidc.'
42038
+
metadata:
42039
+
reason: 'personal_identity_required'
42040
+
retryable: false
42041
+
schema:
42042
+
$ref: '#/components/schemas/InternLifecycleError'
42043
+
description: 'The caller is an API key, which names no person (`personal_identity_required`), or an OAuth grant without `vault:read` (`insufficient_scope`). Also returned when the key owner no longer has access or the request used a regional hostname.'
42044
+
'404':
42045
+
content:
42046
+
application/json:
42047
+
example:
42048
+
error:
42049
+
code: 404
42050
+
message: 'Intern not found'
42051
+
metadata:
42052
+
reason: 'not_found'
42053
+
retryable: false
42054
+
schema:
42055
+
$ref: '#/components/schemas/InternLifecycleError'
42056
+
description: 'The caller is outside the Intern API programme, the intern is hidden, or lifecycle writes are disabled.'
42057
+
'408':
42058
+
content:
42059
+
application/json:
42060
+
example:
42061
+
error:
42062
+
code: 408
42063
+
message: 'Operation timed out after 10s. Please try again later.'
42064
+
metadata:
42065
+
reason: 'timeout'
42066
+
retryable: true
42067
+
schema:
42068
+
$ref: '#/components/schemas/InternLifecycleError'
42069
+
description: 'The request exceeded its route deadline. The deadline quoted in the message is the route''s own, so it differs between operations.'
42070
+
'413':
42071
+
content:
42072
+
application/json:
42073
+
example:
42074
+
error:
42075
+
code: 413
42076
+
message: 'Request body exceeds 1048576 bytes'
42077
+
metadata:
42078
+
reason: 'payload_too_large'
42079
+
retryable: false
42080
+
schema:
42081
+
$ref: '#/components/schemas/InternLifecycleError'
42082
+
description: 'The request body is larger than 1048576 bytes.'
42083
+
'415':
42084
+
content:
42085
+
application/json:
42086
+
example:
42087
+
error:
42088
+
code: 415
42089
+
message: 'Request body must be sent as application/json'
42090
+
metadata:
42091
+
reason: 'unsupported_media_type'
42092
+
retryable: false
42093
+
schema:
42094
+
$ref: '#/components/schemas/InternLifecycleError'
42095
+
description: 'The request body is non-empty and its Content-Type is not application/json.'
42096
+
'429':
42097
+
content:
42098
+
application/json:
42099
+
example:
42100
+
error:
42101
+
code: 429
42102
+
message: 'Too many intern turns. Please wait a moment.'
42103
+
metadata:
42104
+
reason: 'rate_limited'
42105
+
retryable: true
42106
+
schema:
42107
+
$ref: '#/components/schemas/InternLifecycleError'
42108
+
description: 'Too many turns for the user or organization this credential acts as (`rate_limited`). Shares the chat turn limiter, reports `retryable: true` and carries `Retry-After`.'
42109
+
headers:
42110
+
Retry-After:
42111
+
description: 'Seconds to wait before retrying this request.'
42112
+
required: true
42113
+
schema:
42114
+
description: 'Seconds to wait before retrying this request.'
42115
+
example: '60'
42116
+
type: 'string'
42117
+
'500':
42118
+
content:
42119
+
application/json:
42120
+
example:
42121
+
error:
42122
+
code: 500
42123
+
message: 'The request could not be completed'
42124
+
metadata:
42125
+
reason: 'internal_error'
42126
+
retryable: true
42127
+
schema:
42128
+
$ref: '#/components/schemas/InternLifecycleError'
42129
+
description: 'The request could not be completed. `metadata.reason` says whether to try again: `internal_error` is a transient failure and carries `metadata.retryable: true`, so the same request may be sent again, while `configuration_error` carries `retryable: false` because the next attempt reads the same missing binding or unusable stored credential.'
42130
+
security:
42131
+
- apiKey: []
42132
+
summary: 'Sign a daemon request with the caller''s identity (deprecated alias)'
42133
+
tags:
42134
+
- 'Interns'
42135
+
/interns/{internId}/daemon/sign:
42136
+
post:
42137
+
description: 'Signs the SHA-256 digest of one request the CLI is about to send to the intern daemon, binding it to the intern and to the signed-in member so personal connections resolve. Only an OAuth session from `ori login --oidc` whose grant carries `vault:read` can sign: an API key is refused with 403 because it names no person, and an `interns`-only grant is refused with 403 because a proof releases that user''s personal connections. The route is behind the same gate as chat and counts against the chat turn limiter. The response is sent with `Cache-Control: no-store`. The API key selects the caller, workspace and visible interns. An intern''s own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.'
42138
+
operationId: 'signInternDaemonRequest'
42139
+
parameters:
42140
+
- description: 'ID of an intern visible to the authenticated API key.'
42141
+
in: 'path'
42142
+
name: 'internId'
42143
+
required: true
42144
+
schema:
42145
+
description: 'ID of an intern visible to the authenticated API key.'
description: 'Missing, unknown or provisioning API key.'
42185
+
'403':
42186
+
content:
42187
+
application/json:
42188
+
example:
42189
+
error:
42190
+
code: 403
42191
+
message: 'Personal connections require ori login --oidc.'
42192
+
metadata:
42193
+
reason: 'personal_identity_required'
42194
+
retryable: false
42195
+
schema:
42196
+
$ref: '#/components/schemas/InternLifecycleError'
42197
+
description: 'The caller is an API key, which names no person (`personal_identity_required`), or an OAuth grant without `vault:read` (`insufficient_scope`). Also returned when the key owner no longer has access or the request used a regional hostname.'
42198
+
'404':
42199
+
content:
42200
+
application/json:
42201
+
example:
42202
+
error:
42203
+
code: 404
42204
+
message: 'Intern not found'
42205
+
metadata:
42206
+
reason: 'not_found'
42207
+
retryable: false
42208
+
schema:
42209
+
$ref: '#/components/schemas/InternLifecycleError'
42210
+
description: 'The caller is outside the Intern API programme, the intern is hidden, or lifecycle writes are disabled.'
42211
+
'408':
42212
+
content:
42213
+
application/json:
42214
+
example:
42215
+
error:
42216
+
code: 408
42217
+
message: 'Operation timed out after 10s. Please try again later.'
42218
+
metadata:
42219
+
reason: 'timeout'
42220
+
retryable: true
42221
+
schema:
42222
+
$ref: '#/components/schemas/InternLifecycleError'
42223
+
description: 'The request exceeded its route deadline. The deadline quoted in the message is the route''s own, so it differs between operations.'
42224
+
'413':
42225
+
content:
42226
+
application/json:
42227
+
example:
42228
+
error:
42229
+
code: 413
42230
+
message: 'Request body exceeds 1048576 bytes'
42231
+
metadata:
42232
+
reason: 'payload_too_large'
42233
+
retryable: false
42234
+
schema:
42235
+
$ref: '#/components/schemas/InternLifecycleError'
42236
+
description: 'The request body is larger than 1048576 bytes.'
42237
+
'415':
42238
+
content:
42239
+
application/json:
42240
+
example:
42241
+
error:
42242
+
code: 415
42243
+
message: 'Request body must be sent as application/json'
42244
+
metadata:
42245
+
reason: 'unsupported_media_type'
42246
+
retryable: false
42247
+
schema:
42248
+
$ref: '#/components/schemas/InternLifecycleError'
42249
+
description: 'The request body is non-empty and its Content-Type is not application/json.'
42250
+
'429':
42251
+
content:
42252
+
application/json:
42253
+
example:
42254
+
error:
42255
+
code: 429
42256
+
message: 'Too many intern turns. Please wait a moment.'
42257
+
metadata:
42258
+
reason: 'rate_limited'
42259
+
retryable: true
42260
+
schema:
42261
+
$ref: '#/components/schemas/InternLifecycleError'
42262
+
description: 'Too many turns for the user or organization this credential acts as (`rate_limited`). Shares the chat turn limiter, reports `retryable: true` and carries `Retry-After`.'
42263
+
headers:
42264
+
Retry-After:
42265
+
description: 'Seconds to wait before retrying this request.'
42266
+
required: true
42267
+
schema:
42268
+
description: 'Seconds to wait before retrying this request.'
42269
+
example: '60'
42270
+
type: 'string'
42271
+
'500':
42272
+
content:
42273
+
application/json:
42274
+
example:
42275
+
error:
42276
+
code: 500
42277
+
message: 'The request could not be completed'
42278
+
metadata:
42279
+
reason: 'internal_error'
42280
+
retryable: true
42281
+
schema:
42282
+
$ref: '#/components/schemas/InternLifecycleError'
42283
+
description: 'The request could not be completed. `metadata.reason` says whether to try again: `internal_error` is a transient failure and carries `metadata.retryable: true`, so the same request may be sent again, while `configuration_error` carries `retryable: false` because the next attempt reads the same missing binding or unusable stored credential.'
42284
+
security:
42285
+
- apiKey: []
42286
+
summary: 'Sign a daemon request with the caller''s identity'
42287
+
tags:
42288
+
- 'Interns'
41947
42289
/interns/{internId}/invoke:
41948
42290
post:
41949
42291
description: "Starts a run on one of your interns and answers `202` with the `session_id` as soon as the intern accepts it. The run keeps going on the intern after the response. Nothing about its progress comes back on this request; the intern reports through its own tools, such as Slack.\n\nSend the same `session_id` later to continue the conversation, for example to hand the intern a decision on work it started. If that session already has a run going, the prompt is delivered into it and the status is `steered`. A `session_id` is accepted only from the caller it was issued to, on the same intern; any other, including sessions started from Slack or the chat endpoint, is refused with `404`.\n\nRuns started here self-drive: the intern consents to its own tool approvals, and a question it asks is answered by its own fallback. A run ends when the intern finishes it or after its execution deadline (1 hour by default).\n\nAvailable to interns programme members. Callers outside the programme receive `404` for every path under `/api/v1/interns`."
0 commit comments