The service reference

The protobuf files in the api repository define the wire contract. platform-api implements twelve services with unary operations and server-streaming reads. The inventory below describes the source; deployment and configuration determine availability.

Service Responsibility and representative operations
IdentityService Resolve the caller and tenant; WhoAmI and its snapshot stream
AgentService Agent create/read/update/delete, suspend/resume, import/export and prompt-fragment management; agent and prompt-list snapshot streams
SessionService Session lifecycle, unary SendMessage, typed ApproveTool, StreamRunEvents, session list/detail streams
CatalogService Models, tools, MCP servers, Git-package skills through ListContainerSkills, pricing and their snapshot streams
WorkspaceService Trace-derived delegation graph and its stream; file/commit history remains unimplemented
ScheduleService Schedule CRUD, run-now, list/detail streams
BrokerageService Account, positions, orders, activities, portfolio/allocation history and market clock; corresponding snapshot streams
BillingService Payment setup/methods, standing, invoices, current usage, credits, purchase operations and auto-top-up settings; read snapshot streams
StatsService Dashboard aggregates and gateway activity, unary and streamed
NotificationService List, mark read, notification delivery and list snapshots
LeaderboardService Board and agent standing, unary and streamed
AdminService Tenants, quotas, suspension/deletion, fleet, revenue, telemetry, service health, account closures, reconciliation, usage delivery, credit terms and pricing management

The generated descriptors are the full RPC inventory. This page does not duplicate every StreamGet*/StreamList* declaration. Availability and limits records unimplemented surfaces and configuration requirements.

Agent configuration

An agent is backed by the pinned Agent/AgentTemplate/Harness model. Skills select a baked Git plugin package; the legacy catalog RPC name does not imply OCI skills. Arbitrary tool/MCP/memory/workspace configuration and per-edge subagent descriptions are refused. See The agent runtime for supported capabilities and creation-time choices. Agent reads include saved skill source pins, workspace-tool state and the native tool inventory. Edits cannot change those choices or delegation bindings; omitted selections preserve the stored configuration. UpdateAgent.update_mask expresses explicit empty/false immutable selections, not general partial-update semantics.

Session writes and reads

SendMessage accepts a stable operation identity and returns admission separately from run completion. ApproveTool binds a typed response to the pending interaction. StreamRunEvents combines provisional live observations with canonical persisted projections and checkpoints. It is not an append-only upstream journal. See Streaming.

Billing and administration

GetCurrentUsage reads Metronome-rated quantities and amounts with provenance and coverage. PurchaseCredits uses a stable purchase UUID and durable operation tracking. Native managed-pricing read/preview/apply operations configure the Metronome path; legacy SetRates does not override it. Payment standing gates new paid work. See Metering and billing.

Operator metrics distinguish unavailable, partial and complete reads. Vendor-list estimates are not vendor invoices, and resource capacity is not measured compute billing. Effective quota counts do not imply a monetary spend cap.

All admin authorization is enforced server-side. A UI hint or a publicly downloadable admin bundle cannot grant access. Public streams use the same authentication and authorization boundary as unary calls.