Skip to main content
An Agent is the entity within your project that OTAS monitors. Each agent maps to a distinct AI system or component in your architecture—for example, a customer-support LLM, a document processing pipeline, or a code generation service. Agents have their own API keys and sessions, which lets OTAS attribute every logged event to the right system.

Agent fields

Creating an agent

Only project Admins can create agents. A single API call creates both the Agent record and an initial AgentKey, so you have a working key immediately.
The response contains both the agent object and the agent_key object—including the full key value, which is shown only once.

Agent keys

An AgentKey is a credential issued to a specific agent. It is distinct from a Backend SDK Key: while an SDK key authenticates your server-side middleware on behalf of any agent, an agent key authenticates the agent itself. Key format: agent_<prefix>_<secret>
Rotating a key via POST /api/agent/v1/agents/key/create/ immediately revokes all existing active keys for that agent before issuing the new one. Update your agent’s configuration before the old key expires to avoid downtime.

Key lifecycle

1

Key is issued at agent creation

The initial key is returned in the agent_key.api_key field of the create response. Store it securely—it will not be shown again.
2

Pass the key in API calls

Your agent sends X-OTAS-AGENT-KEY: agent_<prefix>_<secret> to authenticate when creating sessions or logging events.
3

Rotate the key before expiry

Call POST /api/agent/v1/agents/key/create/ with { "agent_id": "<uuid>" }. This revokes the current key and issues a fresh one expiring 30 days from now.
4

Revoke if compromised

Call POST /api/agent/v1/agents/key/revoke/ with { "agent_key_id": "<uuid>" }. The key is immediately invalidated.

Agent sessions

An AgentSession scopes a group of events to a single task or run. Every time your agent starts a new task, it should create a session. All events logged during that task are then linked to the session, making it easy to replay or debug the entire interaction.

Creating a session

The response contains a short-lived JWT in the jwt_token field. Pass this as X-OTAS-AGENT-SESSION-TOKEN when logging events so OTAS associates them with this session.

End-to-end flow

1. Create agent

Call POST /api/agent/v1/create/ as a project Admin. Receive the agent UUID and initial AgentKey.

2. Store the key

Save agent_<prefix>_<secret> in your agent’s environment. The plain-text key is never stored by OTAS.

3. Create a session

Before each task, call POST /api/agent/v1/session/create/ with X-OTAS-AGENT-KEY. Receive a session JWT.

4. Log events

Send X-OTAS-AGENT-SESSION-TOKEN with each event so OTAS groups all calls under the correct session.