Skip to content
Warrantv0.1

Agents

One read-back endpoint, session-only. There is no agent CRUD API.

GET /v1/console/agents is the only agent endpoint that exists — a session-authenticated read-back. Agents are created and edited in the console, not over the API.

GET /v1/console/agents
Cookie: warrant_session=…

No create, update or delete

There is no POST /v1/agents, no PATCH, and no DELETE. Those endpoints are not built, and this page does not describe them as though they were. Agents are managed in the console at console.gowarrant.xyz/agents.

An API key cannot call this endpoint at all: it requires a signed-in person with at least the viewer role. A key gets 403 user_session_required.

What it returns

Each agent comes back with its configuration, its live spend session if it has one, its attached policy, and a count of the warrants it has opened by state.

FieldMeaning
statusactive, paused or killed.
failure_budget / failure_countConsecutive failures tolerated, and spent.
policyThe agent's own policy, else the org default, else null.
sessionThe current unrevoked session, or null.
warrants.by_stateCounts keyed by lifecycle state.

failure_count counts consecutive failures and resets to zero on a clean settlement. When it reaches failure_budget the agent's status moves to paused — a circuit breaker against an autonomous system spending in a loop nobody is watching.

GET /v1/console/agents HTTP/1.1
Host: api.gowarrant.xyz
Cookie: warrant_session=…

200

{
"object": "list",
"data": [
  {
    "id": "agt_01J8Z3M4YQ7K2V9XABCDEFGHJK",
    "name": "invoice-reconciler",
    "identity": "did:key:z6Mk…",
    "status": "active",
    "failure_budget": 3,
    "failure_count": 0,
    "created_at": "2026-08-01T09:14:22.000Z",
    "policy": { "agentId": "agt_01J8Z3M4YQ7K2V9XABCDEFGHJK", "name": "strict", "version": 2 },
    "session": {
      "id": "ses_01J8Z3M4YQ7K2V9XABCDEFGHJK",
      "amount_ceiling": "50000000",
      "amount_spent": "8400000",
      "warrant_limit": 20,
      "warrant_count": 3,
      "failure_budget": 3,
      "failure_count": 0,
      "expires_at": "2026-08-16T12:00:00.000Z"
    },
    "warrants": {
      "total": 12,
      "by_state": { "released": 9, "escalated": 2, "refunded": 1 }
    }
  }
]
}
curl -sS https://api.gowarrant.xyz/v1/console/agents \
-b "warrant_session=$WARRANT_SESSION"

Using an agent when opening a warrant

Pass agent_id to POST /v1/warrants. That is what attaches the spend session, the failure budget and the agent's policy to the warrant.

Omitting it is legal, and it means the warrant runs under the organisation default policy with no session ceiling applied.

Amounts

amount_ceiling and amount_spent are integer strings of the asset's smallest unit, matching ^[0-9]+$.

"50000000"   50.00 USDC
50000000     rejected — a JSON number
"50.00"      rejected — not the smallest unit