Skip to main content
createAgentRouter requires an explicit security mode. Choose local for a trusted local application, or authenticated with verified identity and resource ownership for a hosted service.

Installation

Install matching Agentium builds and express. Add openai for this example:

Quick start

This local example binds only to loopback:
registry: false exposes only the explicit map. Omitting it enables global registry lookup; choose that deliberately. In your host shutdown handler, stop accepting requests, drain active work, and close owned Agents/storage.

Request format

Use the corresponding /stream endpoint for SSE. Consume the stream to completion and handle error termination. A model-call finish event does not necessarily end a tool loop.

Authenticated hosting

Configure verified authentication middleware or JWT, then supply both hooks:
  • resolveIdentity(verifiedUser) returns { userId, tenantId? } from verified credentials.
  • authorizeResource({ identity, operation, resource }) checks authoritative ownership and returns true only when access is allowed.
These hooks are application dependencies. JWT/RBAC scope checks alone do not establish ownership. Local mode cannot be combined with JWT/RBAC, and missing authenticated hooks fail at router construction. For new runs, the router creates a UUID and awaits session:create authorization. That operation must atomically persist its owner binding before returning true. A supplied session ID requires session:use; deny unknown or ownerless records. The selected ID is returned in X-Agentium-Session-Id. Request-body user/tenant values must match verified identity if supplied. Middleware must never copy unverified body claims into req.user.

Resource authorization

RBAC rejects unknown routes until mapped. Public discovery/Swagger routes require an explicit choice. Do not grant collection-wide administration to users who should only access individual resources.

Streaming and cancellation

Ordinary HTTP text runs belong to the connection. Disconnect aborts their signal and closes the iterator. SSE waits for writable drain, bounds frames/buffering to 256 KiB each by default, and uses a 10-second write deadline. Configure textStream limits where needed. Cancellation is cooperative and does not undo effects. A callback that ignores its signal can delay cleanup. Process-local SSE replay does not persist execution; use durable task routes for a durable lifecycle. Multipart uploads bound file and text-field count/size; identity and ownership checks happen before Agent execution. See file uploads, JWT/RBAC, and Socket.IO.