Skip to main content
Use Socket.IO for an operator interface that needs configuration acknowledgements and change notifications. It manages Agents, Teams, toolkit configuration, and workflow metadata. Workflow steps and executable instances remain application code. Every authenticated connection can use the admin namespace, and mutation broadcasts go to that entire namespace. Authenticate trusted operators before admission. The namespace does not inherit authorization from a separate Agent run gateway and does not provide per-tenant filtering.

Setup

This is a host integration factory, not a standalone server. Your host supplies a Node HTTP server, initialized storage ownership, and a verifier that returns true only for authorized operators. Install @agentium/admin@4.0.0, @agentium/core@4.0.0, and socket.io@4 alongside the storage adapter’s dependency.
Register custom model providers before calling the factory; start listening only after it returns. On shutdown, close io and its connections, finish owned Agent work, and close the host-owned storage. io.close() also closes the underlying HTTP server: coordinate this with any Express routes sharing that server. If the host already has a Socket.IO server, call createAdminGateway() with that instance instead of constructing another. A missing/rejected token should produce connect_error before any admin handlers run. The restored.workflows count is stored metadata, not reconstructed workflows.

AdminGatewayOptions

Server
required
Socket.IO server instance.
StorageDriver
required
Storage backend for persisting blueprints.
Record<string, ToolDef>
Named tools available for agent creation. Explicit entries override toolkit tools.
Toolkit[]
Toolkit instances whose tools are automatically collected into the tool library.
string
default:"/agentium-admin"
Socket.IO namespace for admin events.
(socket, next) => void
Socket.IO middleware for authentication.

Events

Agent Events

Team Events

Workflow events

Tools

Toolkit Catalog

Toolkit Configs (Credentials)

Registry


Broadcast events

When entities are created, updated, or deleted, the gateway broadcasts to all connected clients on the admin namespace: Use these events to refresh an operator UI. Provider configuration is omitted from public Agent/Team payloads; toolkit settings use catalog-driven secret masking. A broadcast is not a durable audit record.

Client example

Install socket.io-client@4 in the operator client. This runnable client connects to a host that has mounted the factory above; set its URL and operator token in the environment. It only lists configuration.
Expect { "ok": true, "data": [...] }. A rejected connection means operator authentication failed; an acknowledgement with ok: false means the operation failed. An acknowledgement timeout does not prove a create/update did not happen: list or get the target before retrying.

Full flow: create agents, build team, run

  1. Connect to the protected namespace and inspect admin.tools.list for available tool names.
  2. Send admin.agent.create for each member. Each body includes name, provider, model, and optional tools/instructions. Check every acknowledgement before continuing.
  3. Send admin.team.create with a new name, provider/model, mode, and the successfully created member names.
  4. Invoke the Team through your separately configured application transport. The admin namespace stores configuration; it is not a run gateway.
  5. Stop or drain active work before changing its configuration. Disconnect the operator client when its UI closes.
For a complete configuration → execution → restart walkthrough, use the local REST application. The same provider registry, named-tool resolution, persistence, and workflow limitations apply here.