curl --request GET \
--url https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/orgs/{orgSlug}/agents \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/orgs/{orgSlug}/agents', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/orgs/{orgSlug}/agents"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"items": [
{
"id": "<string>",
"name": "<string>",
"description": "<string>",
"instructions": "<string>",
"model": "<string>",
"fallback_models": [
"<string>"
],
"temperature": 123,
"icon_url": "<string>",
"skills": [
{}
],
"attachments": {
"upload": {
"workspaceId": "<string>",
"url": "<string>",
"method": "POST"
}
},
"tools": [
{
"id": "<string>",
"type": "file_search",
"name": "<string>",
"display_name": "<string>",
"description": "<string>",
"catalog_id": "<string>",
"auth": {},
"icon_url": "<string>",
"vector_store_id": "<string>",
"server": "<string>",
"headers": {},
"scope": "<string>",
"url": "<string>",
"parameters": {}
}
],
"tool_permissions": {
"default": "auto",
"tools": [
{
"tool": "<string>",
"policy": "auto",
"conditions": {},
"approvers": [
{
"type": "owner",
"id": "<string>"
}
]
}
]
},
"tool_activation": {
"default": "auto",
"tools": [
{
"tool": "<string>",
"activation": "auto"
}
]
},
"guardrails": {},
"sub_agents": [
{
"agent_id": "<string>",
"name": "<string>",
"description": "<string>"
}
],
"starters": [
{}
],
"allowed_models": [
"<string>"
],
"max_tokens": 123,
"max_turns": 123,
"token_budget": 123,
"tool_call_budget": 123,
"effective_defaults": {
"temperature": 123,
"temperature_ignored": true,
"max_tokens": 123,
"max_turns": 123,
"token_budget": 123,
"tool_call_budget": 123
},
"canvas_enabled": true,
"visibility": "public",
"category": "<string>",
"tags": [
"<string>"
],
"status": "draft",
"profile": "simple",
"owner_id": "<string>",
"orgSlug": "<string>",
"subscription_id": "<string>",
"serviceAccountId": "<string>",
"published_config": {},
"published_at": "2023-11-07T05:31:56Z",
"has_draft_changes": true,
"rating": 123,
"ratings_count": 123,
"messages_count": 123,
"conversations_count": 123,
"access_status": "granted",
"role": "owner",
"access_reason": "<string>",
"is_owner": true,
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z"
}
],
"total": 123,
"page": 123,
"limit": 123
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}List all agents of an organization (admin)
Org-wide agent listing for administrators (agent-factory admin or
platform admin), whatever the owner or visibility. The caller must
belong to orgSlug. Rows expose the published snapshot when one
exists and never carry published_config. Sorted descending.
curl --request GET \
--url https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/orgs/{orgSlug}/agents \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/orgs/{orgSlug}/agents', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/orgs/{orgSlug}/agents"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"items": [
{
"id": "<string>",
"name": "<string>",
"description": "<string>",
"instructions": "<string>",
"model": "<string>",
"fallback_models": [
"<string>"
],
"temperature": 123,
"icon_url": "<string>",
"skills": [
{}
],
"attachments": {
"upload": {
"workspaceId": "<string>",
"url": "<string>",
"method": "POST"
}
},
"tools": [
{
"id": "<string>",
"type": "file_search",
"name": "<string>",
"display_name": "<string>",
"description": "<string>",
"catalog_id": "<string>",
"auth": {},
"icon_url": "<string>",
"vector_store_id": "<string>",
"server": "<string>",
"headers": {},
"scope": "<string>",
"url": "<string>",
"parameters": {}
}
],
"tool_permissions": {
"default": "auto",
"tools": [
{
"tool": "<string>",
"policy": "auto",
"conditions": {},
"approvers": [
{
"type": "owner",
"id": "<string>"
}
]
}
]
},
"tool_activation": {
"default": "auto",
"tools": [
{
"tool": "<string>",
"activation": "auto"
}
]
},
"guardrails": {},
"sub_agents": [
{
"agent_id": "<string>",
"name": "<string>",
"description": "<string>"
}
],
"starters": [
{}
],
"allowed_models": [
"<string>"
],
"max_tokens": 123,
"max_turns": 123,
"token_budget": 123,
"tool_call_budget": 123,
"effective_defaults": {
"temperature": 123,
"temperature_ignored": true,
"max_tokens": 123,
"max_turns": 123,
"token_budget": 123,
"tool_call_budget": 123
},
"canvas_enabled": true,
"visibility": "public",
"category": "<string>",
"tags": [
"<string>"
],
"status": "draft",
"profile": "simple",
"owner_id": "<string>",
"orgSlug": "<string>",
"subscription_id": "<string>",
"serviceAccountId": "<string>",
"published_config": {},
"published_at": "2023-11-07T05:31:56Z",
"has_draft_changes": true,
"rating": 123,
"ratings_count": 123,
"messages_count": 123,
"conversations_count": 123,
"access_status": "granted",
"role": "owner",
"access_reason": "<string>",
"is_owner": true,
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z"
}
],
"total": 123,
"page": 123,
"limit": 123
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}Authorizations
User-bound credential carrying an identity: either a session JWT
or a user access token (at:*) generated from the user settings UI.
Send as Authorization: Bearer <token>.
Org API keys (iak_*) are not accepted here - they carry
no user identity. Use the x-prismeai-api-key header instead
(see OrgApiKeyAuth).
Path Parameters
64Query Parameters
32Case-insensitive match on name or description.
200ISO date - only agents with a message at or after this date.
40ISO date - agents with no message since this date (never-used agents included).
40Minimum messages_count.
ISO date - only agents created before this date.
40Sort field, always descending (default created).
created, last_message, messages Page size (max 100, default 20).
1-indexed page number.
Response
Page of the org's agents.
Page of agents (with published_config stripped on list rows).
Hide child attributes
Hide child attributes
Where to upload an attachment before referencing it in
message.parts[].url: POST {url} in multipart, then put the
returned file url in the part. This is the storage workspace,
the one the web chat uploads to; clients should read it here
rather than hardcode a workspace.
Hide child attributes
Hide child attributes
Hide child attributes
Hide child attributes
file_search, mcp, function ^[a-zA-Z0-9_-]+$Required for file_search.
MCP server URL (for mcp).
Required for function.
JSON Schema describing the function tool's parameters.
Human-in-the-Loop configuration. Sets a default policy plus optional per-tool overrides. Policies:
auto- run immediately (default).always_ask- halt every call on approval.ask_external- halt only on MCP tool calls.ask_first- halt the first time a tool runs in a session, then auto-approve that tool for the rest of the session. The approval is cached per tool (the namespaced<parent>__<child>name for an MCP child) whatever level the rule is written at: under an MCP server rule, approving one child does not approve its siblings. When the matched rule carriesconditions, the approval is also scoped to those conditions (e.g.recordswithaction: deleteis approved apart fromrecordsitself).
Hide child attributes
Hide child attributes
auto, always_ask, ask_external, ask_first Hide child attributes
Hide child attributes
auto, always_ask, ask_external, ask_first Optional jsonmatch pattern compared against the tool call's
arguments. The rule's policy only fires when the pattern matches.
A matching conditional rule beats a rule without conditions on
the same tool, whatever their order in the array; when no
conditional rule matches, the call falls through to the tool's
rule without conditions, then to a legacy rule on the bare tool
name, then to the server's rule, then to default.
Controls whether the model can use a given tool on a given turn.
user_first tools are replaced by a same-named, schema-less stub with
a "disabled" description on each turn, unless the user explicitly
summons the tool from the chat input via metadata.tool_choice.
Eligible tool types: function and mcp. file_search, skill,
guardrail, and system types are exempt and always behave as auto.
Hide child attributes
Hide child attributes
Editor view only (x-draft-mode, caller with edit rights). The values the runtime applies when an advanced field is left empty: profile limits first, then the workspace defaults (max_turns has no profile default: the workspace default applies, 50 when unset); max_tokens is the model's declared response limit, or null when the provider drops max_tokens (its own default applies). temperature_ignored is true when the model's provider drops the temperature parameter.
Hide child attributes
Hide child attributes
public, private, restricted draft, published simple, workflow, agent_light, agent_full, orchestrator Snapshot of runtime fields at last publish (owners only).
Only present on restricted-agent rows in list/discovery views.
granted, none The CALLER's effective rights on this agent, computed at read time.
It has the same shape as role on knowledge bases. Returned by
GET /v1/agents/{agent_id} and by the list endpoint.
owner- owns the agent.admin- platform admin, agent-factory admin in the agent's org, or a share carrying the owner/admin role. Implies publish rights.editor- may write but NOT publish. A surface rendering a publish button must check foradmin, not merely "not reader".reader- a decision was taken and it grants no write.null- UNDETERMINED, not a refusal: for a caller who is neither owner nor admin, the write decision is only taken when the request asks for it -x-draft-modeon the detail endpoint,x-draft-modeor?action=writeon the list. A consumer read (chat, embed, A2A, MCP) pays for no probe and gets null. Render no access screen on null - re-ask with the header, or show the consumer view.
Reading an agent is much wider than editing it (a published+public
agent is readable org-wide), which is why Agent Creator gates its UI
on this rather than on the global agent-factory:agents:write
scope. Informational - write endpoints still authorize on their own.
owner, admin, editor, reader, null Which access path granted the read: owner, admin, public, published, trusted-source:<workspace>, binding:<principal>[:<role>], wildcard-scope, scope or permission. Diagnostic companion to role, and internal authorization topology - so it rides with the editor surface only: GET /v1/agents/{agent_id} returns it when the request carries x-draft-mode, and never on a consumer read or in the list.
The binding: prefix carries a second job: it is what lets an agent with no published version be served to someone it was explicitly shared with - never published or withdrawn alike, since withdrawing empties the catalogue and not the shares. A public consumer (public), an admin (admin) and an RBAC scope (wildcard-scope, scope) do not match it and keep the refusal.
Whether the caller owns this agent. Redundant with role = owner, kept for surfaces that only need that one bit.
Was this page helpful?