Skip to main content
createAgentGateway requires explicit local or authenticated security. The text gateway and voice gateway have separate configuration contracts.

Local setup

Install socket.io, @agentium/core, @agentium/transport, and openai. Stop the server and close owned Agents in your host shutdown lifecycle.

With authentication

authMiddleware verifies credentials and stores trusted state in socket.data; it requires authenticated mode. Middleware must call next. Synchronous exceptions and returned promise rejections deny admission. If middleware returns a promise, the gateway waits for it to settle. Provide security: { mode: "authenticated", resolveIdentity, authorizeResource }:
  • Resolve identity from host-verified socket state.
  • Authorize execute for the selected Agent, Team, or Workflow.
  • Atomically bind new IDs for session:create; reject unknown or foreign IDs for session:use.
  • Authorize discover per listed entity/tool.
  • Authorize run:cancel after checking socket and actor ownership.
The authorizer must return exactly true. Authenticated run payloads reject userId, tenantId, runId, room, and apiKey. Provider credentials stay on host-configured providers. A client sessionId is an ownership-checked reference.

Events

Correlate all concurrent events by runId. Cancellation acknowledgement means cancellation_requested; terminal error follows after cleanup settles.

Bounds and disconnects

maxConcurrentRuns, maxOutputBytes, and textStream control active work and output. Encoded frames and queued bytes default to 256 KiB; the default write timeout is 10 seconds. Final collected Agent text has its own cap. Configure Socket.IO inbound and deployment limits separately. Disconnect aborts connection-owned text runs and suppresses late success. Slow or oversized output cancels production. Arbitrary callbacks remain cooperative; a disconnected socket does not undo an external action. Durable task watchers have a separate persisted lifetime. For audio clients, use the voice acknowledgement contract.