Surfaces

ReferenceWhat it covers
Surface referenceTop-level AgentSurface fields: name, status, tags, identity slots, and outbound credentials.
Access PointInbound configuration: listen address, route, protocol, caller authentication, policies, and rate limiting.
TargetUpstream destination: endpoint, authentication, OPA policies, networking, MCP tool policies, and identity injection.
Transit PointsAgent-initiated outbound routes: transit point fields, shared transit config, and credential injection.
VariantsNamed surface variations: alias grammar, override model, and default variant promotion.
Trust Check elementPer-leg TRQP verification element: fields, query parameters, template syntax, error codes, and TrustCheckResult wire shape.
OPA policy inputComplete input field reference for gateway, surface, and MCP tool policy scopes: field tables, source_auth variants, availability by evaluation path, and the McpPolicyContext schema.