Availability and limits
A method in the protobuf contract is not proof of an enabled deployment. This page separates unimplemented APIs, configuration requirements and the remaining limits of the source-verified implementation.
Not implemented
| Surface | Limit |
|---|---|
WorkspaceService.ListFiles, ReadFile, ListCommits, GetWorkspaceAt | No commit recorder and per-agent historical workspace view; these answer Unimplemented |
AgentSpec.tools, mcp_servers, memory, workspace | Unsupported request configuration is refused |
SubagentRef.description | Per-edge descriptions are refused; routing uses the child agent’s description |
| Storage usage billing | No measured storage-usage producer |
| Prepaid-balance hard stop at the gateway | The designed money limit, to land on the gateway’s admission path: model calls are refused once the prepaid balance reaches zero. It is not built or served yet; the console describes the limits that apply to an account today |
Implemented in the reviewed source
SessionService.ApproveTool, typed tool-approval replies and SendMessage idempotency are implemented.
The runtime removes ask_user; there is no typed human-question reply in the current contract. A
tool approval arises only from an imported MCP tool binding with requireApproval; agents created
in the console never pause. Brokerage positions, orders, activities, portfolio history, allocation history and market-clock
reads are implemented.
Compute is billed from Substrate’s actor lifecycle records: platform-api folds the stdout and OTLP
copies into running intervals, attributes them through immutable session bindings and writes
hour-sliced agent_compute ledger rows from the pinned bill-from, 2026-09-30 05:00 UTC. A lost
record is bounded and alerted rather than guessed; see Compute running seconds for the measurement limits.
Creation-time skill, workspace-tool and delegation choices are enforced by the API. Edits retain saved source pins and tool selections, and Agent reads expose the effective selection and native tool inventory. Import overwrite cannot replace the saved capability configuration.
Streaming reconciles mutable task projections and reports coverage; it cannot replay every transient live frame. Billing gates new paid work based on verified payment standing. Credit purchase and invoice-projection repairs preserve ambiguous operations for reconciliation. New session writes and platform scheduling tools enforce immutable agent identity: retained sessions cannot address a replacement agent, legacy unbound sessions cannot admit new work, and name-only agent tokens are refused. Retained session reads remain available to their authorized owner.
Check the deployed image and contract versions before relying on a newly added field or method. See Streaming and Metering and billing.
Configuration requirements
| Surface | Required backing integration |
|---|---|
| Tenant administration | Tenant directory and its stores |
| Billing and credits | Stripe payment configuration, Metronome configuration and required durable stores |
| Compute usage | Substrate actor lifecycle logging (stdout and OTLP copies), the compute-usage Cloud Logging sink, topic and subscription, Firestore evidence collections, immutable session bindings, the pinned bill-from and the Metronome compute metric |
| Native managed pricing | Metronome pricing management; legacy markup RPCs are not its authority |
| Brokerage | Broker integration, gateway routes and agent/account credentials |
| Leaderboard | Redis index and brokerage data |
| Telemetry and uptime | Configured Cloud Monitoring reader |
| Delegation graph | Configured trace reader |
| Account closure operations | Durable account-closure queue |
A deployment can refuse an otherwise implemented operation when its dependencies are absent. Errors, unavailable data, stale data and partial coverage must remain visible. A missing amount or count must not become a plausible zero, and fixtures are not evidence that a live service works.