@agentium/transport and verify who can use a session. The default model is a local fixture. The example demonstrates the host hooks with two known demonstration credentials and binds only to 127.0.0.1.
Get the project
Download the complete project, extract it, and runnpm install, npm run check, then npm start.
For manual setup in an empty directory:
Create the service
The middleware recognizes the demo credentials.resolveIdentity receives only those host-verified claims. authorizeResource atomically creates an owner record for a new session and checks that record on reuse. Unrecognized resource operations are denied.
Save as authenticated-api.ts:
authenticated-api.ts
Exercise the boundary
1. Missing credentials. Expect HTTP 401:Please share your order ID. in the response’s text. Copy the X-Agentium-Session-Id response header:
Bearer docs-bob with the same session ID. Expect HTTP 403. A request authenticated as Alice with "userId":"bob" in the body also fails with HTTP 403. The host does not trust a body field to select an identity.
The fixture always returns the same response. The Agent retains conversation history in its fallback in-memory session manager, so Alice’s second run receives the first turn. History and ownership records disappear on restart. Add persistent session storage when they must survive a process restart; long-term memory is a separate choice.
Connect and deploy your application
To try a real model explicitly:owners with an authoritative store that binds session creation atomically, and apply application authorization to tools. Provider keys belong to the host.
The router serves core Agents, Teams, and Workflows. It does not automatically host a HarnessRuntime; a harness application needs a host adapter that maps verified requests into its runtime contract. See harness runtime.
Failures and shutdown
Ctrl-C stops new connections, drains active requests, and closes the Agent. A production host should also enforce a bounded shutdown deadline. Continue with streaming, quality gates, and hosted authentication.