Get a runtime operation
Authorizations
Pass a user JWT or a oag_ User API Key on the
Authorization: Bearer <token> header. Both are validated by
openapi-gateway against the Auth service.
Both credential types are user-scoped: every key (and every JWT) is bound to exactly one owner, and every route grants the caller full access to that owner's own resources. Cross-tenant access is denied by owner-ACL inside the handlers — there is no per-route scope vocabulary on this API.
Removed in v1.1.0: the legacy
agents:*/tasks:*/files:*/instances:*scope set has been dropped together with the403 insufficient_scopeerror. Existingoag_keys automatically gain full owner-level access and do not need to be re-issued. SDK calls that previously passedscopestocreateAPIKeyshould drop the argument. See the changelog at the bottom of this spec for the full migration note.
Response
Reduced durable operation snapshot
- Option 1
- Option 2
- Option 3
session/set_mode, agent/create, agent/update, agent/delete, agent/applyTemplate, skills/list, skills/install, skills/uninstall, skills/update, models/list, cron/list, cron/status, cron/add, cron/update, cron/remove, cron/run, cron/runs, mcp/list, mcp/prepare, mcp/set, mcp/unset, session/clear, session/set_model, session/cancel agents.lifecycle, skills, models, cron, mcp, conversation.control service ^(0|[1-9][0-9]*)$queued, running, runtime_committed, projection_pending, projection_blocked, succeeded, failed, cancelled, expired, outcome_unknown queued, running, committed, failed, cancelled, expired, outcome_unknown ^(0|[1-9][0-9]*)$