createAgentRouter requires an explicit security mode. Choose local for a trusted local application, or authenticated with verified identity and resource ownership for a hosted service.
Installation
Install matching Agentium builds andexpress. Add openai for this example:
Quick start
This local example binds only to loopback:registry: false exposes only the explicit map. Omitting it enables global registry lookup; choose that deliberately. In your host shutdown handler, stop accepting requests, drain active work, and close owned Agents/storage.
Request format
/stream endpoint for SSE. Consume the stream to completion and handle error termination. A model-call finish event does not necessarily end a tool loop.
Authenticated hosting
Configure verified authentication middleware or JWT, then supply both hooks:resolveIdentity(verifiedUser)returns{ userId, tenantId? }from verified credentials.authorizeResource({ identity, operation, resource })checks authoritative ownership and returns true only when access is allowed.
session:create authorization. That operation must atomically persist its owner binding before returning true. A supplied session ID requires session:use; deny unknown or ownerless records. The selected ID is returned in X-Agentium-Session-Id.
Request-body user/tenant values must match verified identity if supplied. Middleware must never copy unverified body claims into req.user.
Resource authorization
RBAC rejects unknown routes until mapped. Public discovery/Swagger routes require an explicit choice. Do not grant collection-wide administration to users who should only access individual resources.
Streaming and cancellation
Ordinary HTTP text runs belong to the connection. Disconnect aborts their signal and closes the iterator. SSE waits for writable drain, bounds frames/buffering to 256 KiB each by default, and uses a 10-second write deadline. ConfiguretextStream limits where needed.
Cancellation is cooperative and does not undo effects. A callback that ignores its signal can delay cleanup. Process-local SSE replay does not persist execution; use durable task routes for a durable lifecycle.