This is an advanced tier. Most products only need the default embed and
per-session tools. Use these primitives when agents run sandbox work that
needs credentials your product owns, or when your product must react to agent events without a
user watching.
@opengeni/sdk and require workspace:admin. Agents can never change them. OpenGeni generates each signing secret and returns it once, at creation.
One signature scheme
Every request OpenGeni sends to your endpoints carries:Credential provider
One optional HTTPS endpoint per workspace that supplies short-lived credentials for sandbox work: environment variables, files, and Git credentials. OpenGeni calls it before a turn’s sandbox work and again before the returned material expires.ok with the material and an optional expiresAt, not_applicable, or auth_needed with a reconnect message that OpenGeni shows to the user. Credentials never enter the sandbox manifest, and renewals replace files in place.
Webhooks
Up to ten endpoints per workspace, each subscribed to a subset of:id and order by sequence within a session. Failed deliveries retry with backoff; listWorkspaceWebhookDeliveries and redeliverWorkspaceWebhookDelivery let you inspect and replay them.
Turn identity on MCP calls
Every tool call the agent makes to an MCP server includes_meta.opengeni with the workspace, session, turn, attempt, and initiating user. Use it to attribute a call to the exact turn and person in your logs. It is informational: authorize with the connection’s own credential.