- The browser runs the stock SDK client against your own origin,
/api/opengeni. - Your proxy authenticates each request with your existing session check, resolves the user’s workspace, and forwards only the routes the conversation needs, acting as that user.
- OpenGeni runs the agent. When it needs product data, it calls your MCP server or OpenAPI Integration with a credential you issued for that user.
Mapping your product onto OpenGeni
A workspace is the sharing boundary for sessions, files, knowledge, connections, and integrations. Use one per customer when their users share those; see Users, tenants & privacy for other choices.
Who does what
Link records by opaque ids. Keep your business data in your product and let the agent fetch it through tools.