Setup
This is a host integration factory, not a standalone server. Your host supplies a Node HTTP server, initialized storage ownership, and a verifier that returns true only for authorized operators. Install@agentium/admin@4.0.0, @agentium/core@4.0.0, and socket.io@4 alongside the storage adapter’s dependency.
io and its connections, finish owned Agent work, and close the host-owned storage. io.close() also closes the underlying HTTP server: coordinate this with any Express routes sharing that server. If the host already has a Socket.IO server, call createAdminGateway() with that instance instead of constructing another.
A missing/rejected token should produce connect_error before any admin handlers run. The restored.workflows count is stored metadata, not reconstructed workflows.
AdminGatewayOptions
Server
required
Socket.IO server instance.
StorageDriver
required
Storage backend for persisting blueprints.
Record<string, ToolDef>
Named tools available for agent creation. Explicit entries override toolkit tools.
Toolkit[]
Toolkit instances whose tools are automatically collected into the tool library.
string
default:"/agentium-admin"
Socket.IO namespace for admin events.
(socket, next) => void
Socket.IO middleware for authentication.
Events
Agent Events
Team Events
Workflow events
Tools
Toolkit Catalog
Toolkit Configs (Credentials)
Registry
Broadcast events
When entities are created, updated, or deleted, the gateway broadcasts to all connected clients on the admin namespace:
Use these events to refresh an operator UI. Provider configuration is omitted from public Agent/Team payloads; toolkit settings use catalog-driven secret masking. A broadcast is not a durable audit record.
Client example
Installsocket.io-client@4 in the operator client. This runnable client connects to a host that has mounted the factory above; set its URL and operator token in the environment. It only lists configuration.
{ "ok": true, "data": [...] }. A rejected connection means operator authentication failed; an acknowledgement with ok: false means the operation failed. An acknowledgement timeout does not prove a create/update did not happen: list or get the target before retrying.
Full flow: create agents, build team, run
- Connect to the protected namespace and inspect
admin.tools.listfor available tool names. - Send
admin.agent.createfor each member. Each body includesname,provider,model, and optional tools/instructions. Check every acknowledgement before continuing. - Send
admin.team.createwith a new name, provider/model, mode, and the successfully created member names. - Invoke the Team through your separately configured application transport. The admin namespace stores configuration; it is not a run gateway.
- Stop or drain active work before changing its configuration. Disconnect the operator client when its UI closes.