removedOutput schema / $defs
Removed value: -{
- "Agent": {
- "additionalProperties": true,
- "description": "An agent. GET /v1/agents/{id} returns one of TWO projections by authorization: an ORGANIZATION-MEMBER (owner) caller receives the full agent row (all fields below); a NON-OWNER receives a reduced public projection (id, name, claimed, created_at, last_seen, status, avatar_url). additionalProperties is left open because the owner row is the full DB row and grows as agent-settings columns are added (ADR-053 / proof / DDR); over-constraining it would 500 the endpoint on the next migration under /v1 response enforcement.",
- "properties": {
- "agent_hash": {
- "description": "First 16 hex chars of `SHA256(apiKey + '|' + agentName)` for named agents, or `SHA256(apiKey)` for unnamed singleton agents. The gateway computes the same value on each request and uses it as the lookup key. See [Agent Identity](https://docs.mnemom.ai/concepts/agent-identity#agent_hash--the-canonical-identity-hash).",
- "example": "a1b2c3d4e5f6a7b8",
- "type": "string"
- },
- "agent_proof_captured_at": {
- "format": "date-time",
- "type": [
- "string",
- "null"
- ]
- },
- "agent_proof_hash": {
- "description": "Owner projection: captured hash_proof of the bound key (mig 263).",
- "type": [
- "string",
- "null"
- ]
- },
- "aip_enforcement_mode": {
- "enum": [
- "observe",
- "enforce",
- "nudge"
- ],
- "type": [
- "string",
- "null"
- ]
- },
- "avatar_url": {
- "type": [
- "string",
- "null"
- ]
- },
- "billing_account_id": {
- "type": [
- "string",
- "null"
- ]
- },
- "caller": {
- "description": "Self-describing caller context for THIS response. `org_member` callers receive the full owner record (all fields here); `anonymous`/`authenticated` (non-member) callers receive the reduced public projection (id, name, claimed, created_at, last_seen, status, avatar_url, caller). The differing field set is GOVERNED by this value — read it instead of inferring why a field is absent.",
- "enum": [
- "anonymous",
- "authenticated",
- "org_member"
- ],
- "type": "string"
- },
- "claimed": {
- "description": "Public projection only: whether the agent has been claimed by a user.",
- "type": "boolean"
- },
- "claimed_at": {
- "format": "date-time",
- "type": [
- "string",
- "null"
- ]
- },
- "claimed_by": {
- "description": "Owner projection: user id that claimed the agent.",
- "type": [
- "string",
- "null"
- ]
- },
- "containment_status": {
- "description": "Containment state of the agent (ADR-053).",
- "enum": [
- "active",
- "paused",
- "killed"
- ],
- "type": [
- "string",
- "null"
- ]
- },
- "created_at": {
- "format": "date-time",
- "type": "string"
- },
- "created_by": {
- "description": "Owner projection: user id that created the agent (provenance).",
- "type": [
- "string",
- "null"
- ]
- },
- "deleted_at": {
- "description": "Owner projection: soft-delete timestamp (null when live).",
- "format": "date-time",
- "type": [
- "string",
- "null"
- ]
- },
- "email": {
- "type": [
- "string",
- "null"
- ]
- },
- "groups": {
- "description": "Active groups this agent belongs to, name-ordered; `[]` when none. Present on org-fleet rows (GET /v1/orgs/{org_id}/agents). Archived groups are excluded.",
- "items": {
- "properties": {
- "color": {
- "description": "Group color (hex, e.g. `#0d9488`); `null` when unset.",
- "type": [
- "string",
- "null"
- ]
- },
- "id": {
- "type": "string"
- },
- "name": {
- "type": "string"
- }
- },
- "required": [
- "id",
- "name",
- "color"
- ],
- "type": "object"
- },
- "type": "array"
- },
- "id": {
- "type": "string"
- },
- "key_prefix": {
- "description": "First 8 chars of the bound API key hash — useful for key-rotation debugging.",
- "type": [
- "string",
- "null"
- ]
- },
- "last_seen": {
- "format": "date-time",
- "type": [
- "string",
- "null"
- ]
- },
- "name": {
- "description": "Agent name (2-32 chars, alphanumeric + hyphens). Present on all list and get responses.",
- "type": [
- "string",
- "null"
- ]
- },
- "org_id": {
- "description": "Owner projection: the agent's org binding (ADR-062 authz boundary).",
- "type": [
- "string",
- "null"
- ]
- },
- "public": {
- "description": "Identity-record visibility axis — whether the agent's IDENTITY RECORD is publicly discoverable. This is DISTINCT from reputation visibility: every registered agent's reputation is public by accountability standard (see `ReputationScore.visibility`). `public` here governs only the identity record, never the Trust Rating.",
- "type": "boolean"
- },
- "status": {
- "enum": [
- "active",
- "offline"
- ],
- "type": "string"
- },
- "user_id": {
- "type": [
- "string",
- "null"
- ]
- }
- },
- "type": "object"
- }
-}
changedOutput schema / additionalProperties
Previous value: -trueNew value: +false
changedOutput schema / description
Previous value: -"An agent. GET /v1/agents/{id} returns one of TWO projections by authorization: an ORGANIZATION-MEMBER (owner) caller receives the full agent row (all fields below); a NON-OWNER receives a reduced public projection (id, name, claimed, created_at, last_seen, status, avatar_url). additionalProperties is left open because the owner row is the full DB row and grows as agent-settings columns are added (ADR-053 / proof / DDR); over-constraining it would 500 the endpoint on the next migration under /v1 response enforcement."New value: +"An agent's identity and trust state, reduced to the fields the trust loop needs. Personal data (owner email address, user identifiers), internal commercial identifiers (billing account) and key-material-derived values (bound-key proof hash, key prefix) are REMOVED at the MCP boundary and are never returned to an MCP client — see the Mnemom privacy policy at https://www.mnemom.ai/privacy. Which fields are present depends on authorization: read `caller` to know which projection you received."
changedOutput schema / properties / agent_hash / description
Previous value: -"First 16 hex chars of `SHA256(apiKey + '|' + agentName)` for named agents, or `SHA256(apiKey)` for unnamed singleton agents. The gateway computes the same value on each request and uses it as the lookup key. See [Agent Identity](https://docs.mnemom.ai/concepts/agent-identity#agent_hash--the-canonical-identity-hash)."New value: +"The canonical public identity hash (first 16 hex chars) used as the gateway lookup key and as the input to verify_agent_binding. Owner projection only. Not a credential and not reversible to one."
removedOutput schema / properties / agent_hash / example
Removed value: -"a1b2c3d4e5f6a7b8"
removedOutput schema / properties / agent_proof_captured_at
Removed value: -{
- "format": "date-time",
- "type": [
- "string",
- "null"
- ]
-}
removedOutput schema / properties / agent_proof_hash
Removed value: -{
- "description": "Owner projection: captured hash_proof of the bound key (mig 263).",
- "type": [
- "string",
- "null"
- ]
-}
removedOutput schema / properties / billing_account_id
Removed value: -{
- "type": [
- "string",
- "null"
- ]
-}
changedOutput schema / properties / caller / description
Previous value: -"Self-describing caller context for THIS response. `org_member` callers receive the full owner record (all fields here); `anonymous`/`authenticated` (non-member) callers receive the reduced public projection (id, name, claimed, created_at, last_seen, status, avatar_url, caller). The differing field set is GOVERNED by this value — read it instead of inferring why a field is absent."New value: +"Which projection THIS response is. `org_member` receives the owner field set; `anonymous`/`authenticated` receive the reduced public set (id, name, claimed, created_at, last_seen, status, avatar_url, caller). Read this instead of inferring why a field is absent."
changedOutput schema / properties / claimed / description
Previous value: -"Public projection only: whether the agent has been claimed by a user."New value: +"Whether a human or organization has claimed accountability for this agent. On the owner projection this is derived from the ownership column; the owning user's identifier itself is not returned."
removedOutput schema / properties / claimed_by
Removed value: -{
- "description": "Owner projection: user id that claimed the agent.",
- "type": [
- "string",
- "null"
- ]
-}
changedOutput schema / properties / containment_status / description
Previous value: -"Containment state of the agent (ADR-053)."New value: +"Containment state of the agent."
removedOutput schema / properties / created_by
Removed value: -{
- "description": "Owner projection: user id that created the agent (provenance).",
- "type": [
- "string",
- "null"
- ]
-}
removedOutput schema / properties / deleted_at
Removed value: -{
- "description": "Owner projection: soft-delete timestamp (null when live).",
- "format": "date-time",
- "type": [
- "string",
- "null"
- ]
-}
removedOutput schema / properties / email
Removed value: -{
- "type": [
- "string",
- "null"
- ]
-}
changedOutput schema / properties / groups / description
Previous value: -"Active groups this agent belongs to, name-ordered; `[]` when none. Present on org-fleet rows (GET /v1/orgs/{org_id}/agents). Archived groups are excluded."New value: +"Active groups this agent belongs to, name-ordered; `[]` when none. Present on org-fleet rows."
addedOutput schema / properties / id / description
Added value: +"Agent identifier (e.g. smolt-abc123)."
removedOutput schema / properties / key_prefix
Removed value: -{
- "description": "First 8 chars of the bound API key hash — useful for key-rotation debugging.",
- "type": [
- "string",
- "null"
- ]
-}
changedOutput schema / properties / name / description
Previous value: -"Agent name (2-32 chars, alphanumeric + hyphens). Present on all list and get responses."New value: +"Agent name (2-32 chars, alphanumeric + hyphens)."
changedOutput schema / properties / org_id / description
Previous value: -"Owner projection: the agent's org binding (ADR-062 authz boundary)."New value: +"The agent's organization binding. Required as an input by the org-scoped tools (fleet listing, posture assignment). Identifies an organization, not a person."
changedOutput schema / properties / public / description
Previous value: -"Identity-record visibility axis — whether the agent's IDENTITY RECORD is publicly discoverable. This is DISTINCT from reputation visibility: every registered agent's reputation is public by accountability standard (see `ReputationScore.visibility`). `public` here governs only the identity record, never the Trust Rating."New value: +"Whether the agent's identity record is publicly discoverable. Distinct from Trust Rating visibility, which is always public."
addedOutput schema / properties / status / description
Added value: +"Derived from last_seen (active = seen within the last hour)."
removedOutput schema / properties / user_id
Removed value: -{
- "type": [
- "string",
- "null"
- ]
-}
addedOutput schema / required
Added value: +[
+ "id"
+]