Surfaces

ReferenceWhat it covers
Surface referenceTop-level AgentSurface panel fields, protocol options, gateway DID injection settings, and the canvas element index.
Access PointInbound listener: panel settings (listen address, channel prefix, custom path) and canvas elements (policy, rate limit, caller context, identity, trust check, extension validation, metadata).
Managed AgentUpstream destination: endpoint routing and authentication.
Transit PointsAgent-initiated outbound routes: transit point panel settings and canvas elements for per-destination policy, rate limiting, and payment.
VariantsNamed surface snapshots: alias grammar, canvas configuration, and default variant promotion.
Caller ContextAuthentication method selection and per-method credential extraction configuration.
IdentityAgent DID extraction at inbound, protected, external, or outbound pipeline edges.
NetworkingRequest control: timeouts, automatic retry, circuit breaking, traffic mirroring, and the Rate Limit canvas element.
MCP ToolsPer-tool RBAC policy bindings for MCP surfaces.
Paymentx402 paywall configuration for MCP and A2A surfaces.
Trust elementsTrust Check and Trust Recorder elements: TRQP queries, template syntax, result wire shape, error codes, and trust registry writes.
OPA policiesThe Policy element and the complete input field reference for gateway, surface, and MCP tool policy scopes.
Protocol extensionsExtension Validation and Extension Rules elements for A2A and AP2 surfaces.
Metadata elementsMetadata Injection and Metadata Extraction elements: header manipulation and protocol metadata normalisation.
Outbound bindingCredential Delegation and Workload Binding elements: outbound credential injection and VP binding.