Update Agent Connections
Bulk save the tenant’s agent connections. Secrets are encrypted at rest.
Service-layer ValueError (external MCP URL validation, intra-document
duplicate id guard) surfaces as 422 with the message so the FE can point
at the offending row. Unhandled, these would land as 500.
/agents/connectionsAuthorizationBearer token · headerrequiredapplication/jsonllmConnectionsAgentLlmConnection[]Saved LLM connections - credentials + default tuning. Reusable across many agents.
Show propertiesHide properties
AgentLlmConnectionidstring | nullServer-generated UUID — stable across renames. Null on first create, BE assigns.
Show propertiesHide properties
stringnullnamestringrequiredUser-facing name; unique per tenant by FE convention
providerAgentLlmProviderEnumrequiredUnified LLM provider enum.
A single AgentLlmConnection row carries one provider and a set of
capabilities (chat / embedding). PROVIDER_CAPABILITIES below pins
which capabilities each provider can serve — picked by the FE Connections
drawer and re-validated server-side on every write.
anthropicopenaiopenai-responsesollamaazureazure-openaibedrockqwenopenai-compatibleapiKeystringAPI key — KMS-wrapped at rest, masked on GET
baseUrlstring | nullBase URL for Ollama / Azure / self-deployed OpenAI- or Anthropic-compatible servers (vLLM, LocalAI, TGI, LM Studio, LiteLLM gateways)
Show propertiesHide properties
stringnullcapabilitiesConnectionCapability[]requiredNon-empty list of capabilities this connection powers. Each entry must be allowed by the provider per PROVIDER_CAPABILITIES, and each listed capability must have its defaults block populated.
chatChatDefaults | nullChat-capability defaults. Required iff 'chat' in capabilities.
Show propertiesHide properties
modelstringDefault chat model, e.g. claude-sonnet-4-20250514. Empty = fill at agent creation.
temperaturenumber | nullDefault sampling temperature (null = matrix-skipped)
Show propertiesHide properties
numbernullmaxTokensinteger | nullDefault max output tokens (null = matrix-skipped)
Show propertiesHide properties
integernulltimeoutinteger | nullDefault request timeout (seconds, null = matrix-skipped)
Show propertiesHide properties
integernullreasoningEffortstring | nullDefault reasoning effort. Accepted set is per-model — the matrix in app/utils/llm_capabilities.py rejects values not in caps.reasoning_effort_values for the picked (provider, model).
Show propertiesHide properties
stringnullthinkingBudgetTokensinteger | nullDefault Anthropic Claude 4 extended-thinking budget (tokens). Non-null enables thinking.
Show propertiesHide properties
integernullollamaThinkboolean | nullDefault Ollama 'think' toggle for reasoning models
Show propertiesHide properties
booleannullmaxRetriesinteger | nullUniversal — max retry attempts on LLM call. Accepted by every provider.
Show propertiesHide properties
integernullregionstring | nullBedrock chat: AWS region (e.g. us-east-1). Ignored for non-bedrock providers.
Show propertiesHide properties
stringnullstrictboolean | nullopenai-responses: enable JSON-schema strict mode. Ignored for other providers.
Show propertiesHide properties
booleannullstoreboolean | nullopenai-responses: server-side response storage flag. Ignored for other providers.
Show propertiesHide properties
booleannullinstructionsstring | nullopenai-responses: system-level instructions passed as a top-level Responses param.
Show propertiesHide properties
stringnulladditionalKwargsobject | nullopenai-responses / azure-openai: free-form extra request params forwarded verbatim by the runtime. Use for provider-specific fields not modelled above.
Show propertiesHide properties
objectnullapiVersionstring | nullazure-openai: Azure OpenAI API version (e.g. '2024-02-01'). Required for azure-openai.
Show propertiesHide properties
stringnullazureEndpointstring | nullazure-openai: Azure resource endpoint (e.g. https://<resource>.openai.azure.com). Required.
Show propertiesHide properties
stringnullazureUrlPathModestring | nullazure-openai: URL path resolution — AUTO / LEGACY / UNIFIED. Optional.
Show propertiesHide properties
stringnullnullembeddingEmbeddingDefaults | nullEmbedding-capability defaults. Required iff 'embedding' in capabilities.
Show propertiesHide properties
modelstringDefault embedding model, e.g. text-embedding-3-small. Empty = fill at KB creation.
dimensionsinteger | nullOutput embedding dimensions override (provider-dependent)
Show propertiesHide properties
integernullbatchSizeintegerRecords per embedding batch call
regionstring | nullAWS region for bedrock embedding provider (e.g. us-east-1). Ignored for non-bedrock rows.
Show propertiesHide properties
stringnullmaxRetriesinteger | nullBedrock retry cap. Ignored for non-bedrock rows.
Show propertiesHide properties
integernullnulldescriptionstring | nullOptional human-readable context for the connection
Show propertiesHide properties
stringnullmcpConnectionsStreamkapMcpConnection | ExternalMcpNoneConnection | ExternalMcpBearerConnection | ExternalMcpHeaderConnection[]Saved MCP connections (external-source only)
Show propertiesHide properties
StreamkapMcpConnection | ExternalMcpNoneConnection | ExternalMcpBearerConnection | ExternalMcpHeaderConnectionsourcestringDiscriminator - must be 'streamkap' for this variant
namestringrequiredConnection name (e.g. 'Production Streamkap MCP')
serverUrlstringheadersobjectAuth headers. Set 'X-Streamkap-Project-Key' to the base64-encoded credential file downloaded when the Project Key was created.
sourcestringDiscriminator - must be 'external'
namestringrequiredConnection name (e.g. 'AWS Knowledge', 'Zapier Personal')
serverUrlstringrequiredauthModestringrequiredsourcestringDiscriminator - must be 'external'
namestringrequiredConnection name (e.g. 'AWS Knowledge', 'Zapier Personal')
serverUrlstringrequiredauthModestringrequiredbearerTokenstringrequiredBearer token - encrypted at rest, masked on GET
sourcestringDiscriminator - must be 'external'
namestringrequiredConnection name (e.g. 'AWS Knowledge', 'Zapier Personal')
serverUrlstringrequiredauthModestringrequiredheaderNamestringrequiredHTTP header name (RFC 7230 token alphabet, narrowed)
headerValuestringrequiredHeader value - encrypted at rest, masked on GET
httpConnectionsAgentHttpConnection[]Saved HTTP API connections. Referenced by HTTP tool rows via connectionId to inherit baseUrl + headers without duplicating them per tool.
Show propertiesHide properties
AgentHttpConnectionidstring | nullServer-generated UUID - stable across renames. Null on first create, BE assigns.
Show propertiesHide properties
stringnullnamestringrequiredUser-facing name; unique per tenant by FE convention (e.g. 'Stripe API')
baseUrlstring | nullBase URL prepended to a referencing tool's relative URL. Tools with an absolute URL ignore this. Optional - a connection can be header-only (e.g. shared auth across hosts).
Show propertiesHide properties
stringnullheadersobjectHTTP headers merged into every referencing tool's request. Values are KMS-encrypted at rest and full-masked on GET.
descriptionstring | nullOptional human-readable context for the connection
Show propertiesHide properties
stringnullvectorStoreConnectionsAgentVectorStoreConnection[]Lightweight vector store credentials (apiKey + endpoint). Used by KBs and agent long-term memory.
Show propertiesHide properties
AgentVectorStoreConnectionidstring | nullServer-generated UUID. Null on first create, BE assigns.
Show propertiesHide properties
stringnullnamestringrequiredUser-facing name
providerVectorStoreProviderEnumrequiredVector-store providers supported by the Flink runtime (integration guide §3b.4).
Two shape families:
- Typed-field providers —
pgvectorandpinecone. Each has a fixed set of named fields onAgentVectorStoreConnection. - Pass-through providers —
milvus,opensearch,elasticsearch,s3vectors. Each carries a free-formpropertiesmap that gets copied straight into the framework'sResourceDescriptor.addInitialArgument(key, value)pairs at deploy time. Framework validates required keys at open-time.
redis is retained for legacy saved connections but is not accepted by
the current runtime.
pgvectorpineconemilvusopensearchelasticsearchs3vectorsredisapiKeystringPinecone API key — KMS-wrapped at rest, masked on GET
endpointstring | nullPinecone index host URL
Show propertiesHide properties
stringnulldefaultNamespacestring | nullDefault namespace / collection (overridable per KB or agent)
Show propertiesHide properties
stringnullallowHashFallbackbooleanOpt in to the non-semantic hash-embedding fallback when the vector index lacks integrated inference. Default False = fail-hard (throws instead of silently degrading recall).
jdbcUrlstring | nullpgvector: jdbc:postgresql://host:port/db. Never embed userinfo here; put credentials in username / password.
Show propertiesHide properties
stringnullusernamestring | nullpgvector username. Supports ${SECRET:...} template.
Show propertiesHide properties
stringnullpasswordstring | nullpgvector password. Supports ${SECRET:...} template.
Show propertiesHide properties
stringnulltablestring | nullpgvector table name used as the vector collection.
Show propertiesHide properties
stringnulldimsinteger | nullpgvector: embedding output dimensions. 0/unset inherits from the embedding model. Must match the embedding model's output.
Show propertiesHide properties
integernullmetricstring | nullpgvector distance metric. Only cosine is currently supported.
Show propertiesHide properties
stringnullpropertiesobject | nullFree-form Map<String, Object> for pass-through providers. Copied straight into the framework's ResourceDescriptor.addInitialArgument pairs at deploy time. Framework validates required keys at open-time. Not used for pinecone or pgvector (they have named typed fields).
Show propertiesHide properties
objectnulldescriptionstring | nullOptional human-readable context
Show propertiesHide properties
stringnullSuccessful Response
objectValidation Error
detailValidationError[]Show propertiesHide properties
ValidationErrorlocstring | integer[]requiredShow propertiesHide properties
string | integerstringintegermsgstringrequiredtypestringrequiredinputanyctxobject