createAgentGateway requires explicit local or authenticated security. The text gateway and voice gateway have separate configuration contracts.
Local setup
socket.io, @agentium/core, @agentium/transport, and openai. Stop the server and close owned Agents in your host shutdown lifecycle.
With authentication
authMiddleware verifies credentials and stores trusted state in socket.data; it requires authenticated mode. Middleware must call next. Synchronous exceptions and returned promise rejections deny admission. If middleware returns a promise, the gateway waits for it to settle.
Provide security: { mode: "authenticated", resolveIdentity, authorizeResource }:
- Resolve identity from host-verified socket state.
- Authorize
executefor the selected Agent, Team, or Workflow. - Atomically bind new IDs for
session:create; reject unknown or foreign IDs forsession:use. - Authorize
discoverper listed entity/tool. - Authorize
run:cancelafter checking socket and actor ownership.
userId, tenantId, runId, room, and apiKey. Provider credentials stay on host-configured providers. A client sessionId is an ownership-checked reference.
Events
Correlate all concurrent events by
runId. Cancellation acknowledgement means cancellation_requested; terminal error follows after cleanup settles.
Bounds and disconnects
maxConcurrentRuns, maxOutputBytes, and textStream control active work and output. Encoded frames and queued bytes default to 256 KiB; the default write timeout is 10 seconds. Final collected Agent text has its own cap. Configure Socket.IO inbound and deployment limits separately.
Disconnect aborts connection-owned text runs and suppresses late success. Slow or oversized output cancels production. Arbitrary callbacks remain cooperative; a disconnected socket does not undo an external action. Durable task watchers have a separate persisted lifetime.
For audio clients, use the voice acknowledgement contract.