Agents
One read-back endpoint, session-only. There is no agent CRUD API.
GET /v1/console/agents is the only agent endpoint that exists — a session-authenticated read-back. Agents are created and edited in the console, not over the API.
GET /v1/console/agents
Cookie: warrant_session=…No create, update or delete
There is no POST /v1/agents, no PATCH, and no DELETE. Those endpoints are
not built, and this page does not describe them as though they were. Agents are
managed in the console at console.gowarrant.xyz/agents.
An API key cannot call this endpoint at all: it requires a signed-in person with
at least the viewer role. A key gets 403 user_session_required.
What it returns
Each agent comes back with its configuration, its live spend session if it has one, its attached policy, and a count of the warrants it has opened by state.
| Field | Meaning |
|---|---|
status | active, paused or killed. |
failure_budget / failure_count | Consecutive failures tolerated, and spent. |
policy | The agent's own policy, else the org default, else null. |
session | The current unrevoked session, or null. |
warrants.by_state | Counts keyed by lifecycle state. |
failure_count counts consecutive failures and resets to zero on a clean
settlement. When it reaches failure_budget the agent's status moves to
paused — a circuit breaker against an autonomous system spending in a loop
nobody is watching.
GET /v1/console/agents HTTP/1.1
Host: api.gowarrant.xyz
Cookie: warrant_session=…200
{
"object": "list",
"data": [
{
"id": "agt_01J8Z3M4YQ7K2V9XABCDEFGHJK",
"name": "invoice-reconciler",
"identity": "did:key:z6Mk…",
"status": "active",
"failure_budget": 3,
"failure_count": 0,
"created_at": "2026-08-01T09:14:22.000Z",
"policy": { "agentId": "agt_01J8Z3M4YQ7K2V9XABCDEFGHJK", "name": "strict", "version": 2 },
"session": {
"id": "ses_01J8Z3M4YQ7K2V9XABCDEFGHJK",
"amount_ceiling": "50000000",
"amount_spent": "8400000",
"warrant_limit": 20,
"warrant_count": 3,
"failure_budget": 3,
"failure_count": 0,
"expires_at": "2026-08-16T12:00:00.000Z"
},
"warrants": {
"total": 12,
"by_state": { "released": 9, "escalated": 2, "refunded": 1 }
}
}
]
}curl -sS https://api.gowarrant.xyz/v1/console/agents \
-b "warrant_session=$WARRANT_SESSION"Using an agent when opening a warrant
Pass agent_id to POST /v1/warrants. That is what
attaches the spend session, the failure budget and the agent's policy to the
warrant.
Omitting it is legal, and it means the warrant runs under the organisation default policy with no session ceiling applied.
Amounts
amount_ceiling and amount_spent are integer strings of the asset's smallest
unit, matching ^[0-9]+$.
"50000000" 50.00 USDC
50000000 rejected — a JSON number
"50.00" rejected — not the smallest unit