Skip to main content

Store and rotate keys

  • Keep the organization API key in your secret manager and load it only on the server. Never ship it in a browser bundle, a Skill, a prompt, or modelContext.
  • Use a workspace API key instead for a component that should reach only one workspace, and a read-only organization key for reporting.
  • Rotate by creating a new key, deploying it, and deleting the old one with deleteOrganizationApiKey. Keys can also carry an expiry.
See Authentication.

Receive events and supply credentials

To hear when work finishes without polling, or to hand each run short-lived credentials from your backend, register one webhook and one credential provider for all your customers’ workspaces. See Webhooks and credentials.

Understand costs

On app.opengeni.ai, agent usage is paid with prepaid OpenGeni credits, or billed by the provider when your organization connects its own model subscription or gateway key. When credits run out, the current turn ends gracefully and the session stays intact, so it continues after a top-up.
  • A single turn can include several model responses and tool calls. Long goals and large tool schemas cost more.
  • getBillingUsage returns usage for accounting and requires billing permission. Chat replies do not carry a per-request price.
  • Distinguish OpenGeni credit charges from what your model provider bills you directly.
For per-seat included usage, administrator splits, top-ups, team budgets, or browser progress meters, see Usage allowances. Use the session proxy’s own-usage read and render fraction, or the usage components, for browser meters. Responses still include amounts; hiding them requires your own authenticated server projection. Keep organization-budget writes on your backend; the conversation proxy exposes only the user’s own usage. Allowances are post-call ceilings, not prepaid reservations.

Keep SDK and server compatible

Published SDKs and servers are compatible within the same major version. Within a major, changes are additive: servers ignore unknown request fields, and clients ignore unknown response fields and event types. Install @opengeni/sdk and @opengeni/react from the same release, and read the server version from /healthz or /v1/config/client. See the API compatibility policy.

Keep the tool surface minimal

Every tool the agent can see costs prompt tokens and widens what it can do. For a product agent that should use only your tools, close every optional surface explicitly:
Omitting tools or firstPartyMcpTools inherits workspace and deployment defaults, including tools that reach other sessions. Always pass explicit lists. Organization owners can also restrict which integrations may be set up at all in Organization settings → Integrations, or through @opengeni/sdk/organization-integration-policy.

Test isolation before launch

Beyond a working conversation, verify that:
  • user A cannot open, stream, message, or attach files to user B’s session through your routes;
  • a request carrying another workspace or session id is rejected;
  • your tools refuse another tenant’s records even when the model asks for them;
  • concurrent onboarding for the same tenant converges on one workspace.

Clean up

A workspace cannot be deleted while a session is running. Organization owners can also set a retention policy in organization settings.
Using a coding agent? The opengeni-client skill covers this.