- Classes
- Interfaces
- Type Aliases
- Variables
- Functions
- References
Backend that routes every operation through Atlas Agent Engine's secure path. Each
method delegates to SecureToolWrapper.executeTool, which sends the request
to the OE for policy approval and audit logging before it runs in the Tool
Pod.
SandboxBackendProtocolV2
new AgentEngineToolPodBackend(): AgentEngineToolPodBackend;Returns
| Property | Modifier | Type | Default value | Description |
|---|---|---|---|---|
id |
readonly |
"agent-engine-toolpod" |
"agent-engine-toolpod" |
Unique identifier for the sandbox backend instance |
downloadFiles(paths): Promise<FileDownloadResponse[]>;Download files via the audited filesystem_download handler — one call per
path so each is policy-checked and logged independently — then base64-decode
the content_base64 field into raw bytes. Responses preserve input order;
on failure content is null and error carries a classified message.
Native-mode batches fan out on a bounded worker pool so skills loading pays one round-trip of latency instead of a sum. Durable attempts stay sequential: unkeyed activities are exclusive under the attempt gate, and overlapping them raises CONFLICT.
Parameters
| Parameter | Type |
|---|---|
paths |
string[] |
Returns
Promise<FileDownloadResponse[]>
Implementation of
SandboxBackendProtocolV2.downloadFilesedit(
filePath,
oldString,
newString,
replaceAll?
): Promise<EditResult>;Edit a file by replacing string occurrences.
Parameters
| Parameter | Type | Default value | Description |
|---|---|---|---|
filePath |
string |
undefined |
Absolute file path |
oldString |
string |
undefined |
String to find and replace |
newString |
string |
undefined |
Replacement string |
replaceAll |
boolean |
false |
If true, replace all occurrences (default: false) |
Returns
Promise<EditResult>
EditResult with error, path, filesUpdate, and occurrences
Implementation of
SandboxBackendProtocolV2.editexecute(command): Promise<ExecuteResponse>;Execute a command in the sandbox.
Parameters
| Parameter | Type | Description |
|---|---|---|
command |
string |
Full shell command string to execute |
Returns
Promise<ExecuteResponse>
ExecuteResponse with combined output, exit code, and truncation flag
Implementation of
SandboxBackendProtocolV2.executeglob(pattern, path?): Promise<GlobResult>;Structured glob matching returning FileInfo objects.
Parameters
| Parameter | Type | Default value | Description |
|---|---|---|---|
pattern |
string |
undefined |
Glob pattern (e.g., *.py, **/*.ts) |
path |
string |
"/" |
Base path to search from (default: "/") |
Returns
Promise<GlobResult>
GlobResult with list of FileInfo objects matching the pattern on success or error on failure
Implementation of
SandboxBackendProtocolV2.globgrep(
pattern,
path?,
glob?
): Promise<GrepResult>;Search file contents for a literal text pattern.
Binary files (determined by MIME type) are skipped.
Parameters
| Parameter | Type | Description |
|---|---|---|
pattern |
string |
Literal text pattern to search for |
path? |
string | null |
Base path to search from (default: null) |
glob? |
string | null |
Optional glob pattern to filter files (e.g., "*.py") |
Returns
Promise<GrepResult>
GrepResult with matches on success or error on failure
Implementation of
SandboxBackendProtocolV2.grepls(path): Promise<LsResult>;Structured listing with file metadata.
Lists files and directories in the specified directory (non-recursive). Directories have a trailing / in their path and is_dir=true.
Parameters
| Parameter | Type | Description |
|---|---|---|
path |
string |
Absolute path to directory |
Returns
Promise<LsResult>
LsResult with list of FileInfo objects on success or error on failure
Implementation of
SandboxBackendProtocolV2.lsread(
filePath,
offset?,
limit?
): Promise<ReadResult>;Read file content.
For text files, content is paginated by line offset/limit. For binary files, the full raw Uint8Array content is returned.
Parameters
| Parameter | Type | Default value | Description |
|---|---|---|---|
filePath |
string |
undefined |
Absolute file path |
offset |
number |
0 |
Line offset to start reading from (0-indexed), default 0 |
limit |
number |
2000 |
Maximum number of lines to read, default 500 |
Returns
Promise<ReadResult>
ReadResult with content on success or error on failure
Implementation of
SandboxBackendProtocolV2.readreadRaw(filePath): Promise<ReadRawResult>;Raw read is not backed by a dedicated wire handler; the Tool Pod exposes
only line-oriented filesystem_read. We wrap its text content in a v2
FileData so binary-unaware callers still work. Genuine binary reads should
use downloadFiles, which carries raw bytes base64-encoded.
Parameters
| Parameter | Type |
|---|---|
filePath |
string |
Returns
Promise<ReadRawResult>
Implementation of
SandboxBackendProtocolV2.readRawuploadFiles(files): Promise<FileUploadResponse[]>;Upload multiple files. Optional - backends that don't support file upload can omit this.
Parameters
| Parameter | Type | Description |
|---|---|---|
files |
[string, Uint8Array<ArrayBufferLike>][] |
List of [path, content] tuples to upload |
Returns
Promise<FileUploadResponse[]>
List of FileUploadResponse objects, one per input file
Implementation of
SandboxBackendProtocolV2.uploadFileswrite(filePath, content): Promise<WriteResult>;Create a new file.
Parameters
| Parameter | Type | Description |
|---|---|---|
filePath |
string |
Absolute file path |
content |
string |
File content as string |
Returns
Promise<WriteResult>
WriteResult with error populated on failure
Implementation of
SandboxBackendProtocolV2.writeLangChain SDK for the Atlas Agent Engine.
import { App } from '@mongodb-js/agent-engine-sdk-langgraph';
const app = new App({ appName: 'My Agent' });
app.tool()((args: { query: string }) => 'result');
app.entrypoint(() => {
const llm = app.llm(chatModel);
const checkpointer = app.checkpointer();
const tools = app.getTools();
// Build LangGraph...
return graph;
});BaseApp
new App(options): App;Parameters
| Parameter | Type |
|---|---|
options |
AppOptions |
Returns
Overrides
BaseApp.constructor| Property | Modifier | Type | Inherited from |
|---|---|---|---|
llmWrapper |
public |
unknown |
BaseApp.llmWrapper |
name |
readonly |
string |
BaseApp.name |
toolWrapper |
public |
unknown |
BaseApp.toolWrapper |
Get Signature
get agentConfig(): RuntimeAgentConfig;Returns
RuntimeAgentConfig
Get Signature
get memory(): Memory;Unified memory facade over app-bound adapters.
Lazily constructed on first access and cached (a long-lived singleton over
per-request context). Operations resolve the end-user and session from the
ambient execution context, so agent code calls app.memory.saveSemantic(...)
without threading identity through. Requests route through the OE memory
proxy; memory is reachable only while handling a platform request.
Returns
Memory
checkpointer(): PlatformCheckpointer | null;Get the platform checkpointer for LangGraph.
Lazily constructs and wraps a MongoDBSaver on first call in AER mode.
Native sessions use that saver through the request-scoped platform
wrapper. The underlying MongoClient is closed by App.close().
The database name is read from CHECKPOINT_DB_NAME when set (exact
override, no project scoping). Otherwise the existing
MDB_AGENTIC_STORE_DB / per-project store resolution is used
(default: "mdb_store"). The URI comes from MONGODB_URI — the same
source TenantRuntime uses internally.
Mirrors Python runtime.py:checkpointer().
Returns
PlatformCheckpointer | null
close(): Promise<void>;Release resources held by this App instance.
Returns
Promise<void>
deepAgent(llm, options?): DeepAgent<DeepAgentTypeConfig<ResponseFormatUndefined, undefined, InteropZodObject, readonly [AgentMiddleware<ZodObject<{
}, "strip", ZodTypeAny, {
}, {
}>, undefined, unknown, readonly [DynamicStructuredTool<ZodObject<{
}, "strip", ZodTypeAny, {
}, {
}>, {
}, {
}, Command<unknown, {
}, string>, unknown, "write_todos">]>, AgentMiddleware<StateSchema<{
}>, undefined, unknown, (
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "ls">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, object[] | object[], unknown, "read_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| ToolMessage<MessageStructure<MessageToolSet>>
| Command<unknown, {
}, string>, unknown, "write_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| ToolMessage<MessageStructure<MessageToolSet>>
| Command<unknown, {
}, string>, unknown, "edit_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "glob">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "grep">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "execute">)[]>, AgentMiddleware<undefined, undefined, unknown, readonly [DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| Command<unknown, Record<string, unknown>, string>, unknown, "task">]>, AgentMiddleware<ZodObject<{
}, $strip>, undefined, unknown, readonly (ClientTool | ServerTool)[]>, AgentMiddleware<undefined, undefined, unknown, readonly (ClientTool | ServerTool)[]>, AgentMiddleware<any, any, any, readonly (ClientTool | ServerTool)[]>], readonly (ClientTool | ServerTool)[], readonly AnySubAgent[], readonly () => StreamTransformer<any>[]>>;Build a deepagents graph pre-wired for Atlas Agent Engine AER.
Wraps llm in SecureWrappedLLM, resolves relative skill paths, validates
the subagent tree (string models are rejected — they would bypass OE
routing), then delegates to deepagents' createDeepAgent.
Each skills entry is a parent source directory. At runtime, deepagents
lists it through the configured backend and treats each immediate child
directory containing SKILL.md as one skill; discovery is not recursive.
deepagents skips unreadable or unparsable frontmatter and skills missing
name or description; it warns but may still load Agent Skills naming or
directory-name violations.
Mirrors Python runtime.py:App.deep_agent().
Parameters
| Parameter | Type |
|---|---|
llm |
BaseChatModel |
options |
DeepAgentOptions |
Returns
DeepAgent<DeepAgentTypeConfig<ResponseFormatUndefined, undefined, InteropZodObject, readonly [AgentMiddleware<ZodObject<{
}, "strip", ZodTypeAny, {
}, {
}>, undefined, unknown, readonly [DynamicStructuredTool<ZodObject<{
}, "strip", ZodTypeAny, {
}, {
}>, {
}, {
}, Command<unknown, {
}, string>, unknown, "write_todos">]>, AgentMiddleware<StateSchema<{
}>, undefined, unknown, (
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "ls">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, object[] | object[], unknown, "read_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| ToolMessage<MessageStructure<MessageToolSet>>
| Command<unknown, {
}, string>, unknown, "write_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| ToolMessage<MessageStructure<MessageToolSet>>
| Command<unknown, {
}, string>, unknown, "edit_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "glob">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "grep">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "execute">)[]>, AgentMiddleware<undefined, undefined, unknown, readonly [DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| Command<unknown, Record<string, unknown>, string>, unknown, "task">]>, AgentMiddleware<ZodObject<{
}, $strip>, undefined, unknown, readonly (ClientTool | ServerTool)[]>, AgentMiddleware<undefined, undefined, unknown, readonly (ClientTool | ServerTool)[]>, AgentMiddleware<any, any, any, readonly (ClientTool | ServerTool)[]>], readonly (ClientTool | ServerTool)[], readonly AnySubAgent[], readonly () => StreamTransformer<any>[]>>
Throws
features.deep_agent is not enabled, or a subagent spec
uses a string model, or nesting exceeds the recursion cap.
entrypoint<F>(fn): F;Mark the graph builder function.
Type Parameters
| Type Parameter |
|---|
F extends () => unknown |
Parameters
| Parameter | Type |
|---|---|
fn |
F |
Returns
F
Overrides
BaseApp.entrypointfinishSession(): SessionFinishStatus;Mark this session finished so the platform frees its compute now.
Call it when the agent is done with the session. The current turn keeps running and returns its result normally; once it completes, the platform cancels any live sub-agent runs and releases the session's AER and tool pods instead of holding them until the idle timeout expires.
Safe to call more than once: the first call returns "requested", later ones "already_requested". Outside an agent run (local scripts, tool pods) there is no session to finish and the call returns "unavailable" without throwing. Calling it after the turn has already ended - e.g. from a setTimeout or a floating promise scheduled during the turn but resolving after it - also returns "unavailable": by then nothing is listening for the request anymore, so reporting "requested" would promise a release that will never happen.
A turn that suspends for human review, or that fails, keeps its resources so it stays resumable and diagnosable; the session then falls back to the idle timeout.
Returns
getAgent(opts?): LangGraphBaseAgent;Build and return a LangGraphBaseAgent instance.
Matches GraphBuilderLike.getAgent({ callbacks? }) — agent-engine-runner-shared's
TenantRuntime.registerAndRun introspects this method to compile the graph.
Accepts an options object with an optional callbacks array, each wrapped
in LangGraphCallbackAdapter before being passed to the graph.
Parameters
| Parameter | Type |
|---|---|
opts? |
{ callbacks?: readonly unknown[]; } |
opts.callbacks? |
readonly unknown[] |
Returns
getCurrentSessionId(): string | null;Returns
string | null
getCurrentUserId(): string | null;Returns
string | null
getToolDefinitions(): object[];Returns all registered tool definitions. Used by the OE to obtain tool execution information.
Returns
object[]
Overrides
BaseApp.getToolDefinitionsgetTools(): readonly StructuredTool<ToolInputSchemaBase, any, any, any, unknown>[];Get wrapped tools for LangGraph's ToolNode.
In AER mode, every tool is wrapped with SecureToolWrapper (via
createSecureToolFunction) so executions route through OE for logging
and policy enforcement. In other modes, the raw LangChain tools are
returned unchanged.
Returns
readonly StructuredTool<ToolInputSchemaBase, any, any, any, unknown>[]
getToolSchemas(): readonly unknown[];Get tool schemas for llm.bindTools(). Always the unwrapped LangChain tools.
Returns
readonly unknown[]
llm(llm, llmId?): BaseChatModel;Wrap a LangChain LLM for audited I/O through the Orchestration Engine.
In AER mode the LLM is wrapped in SecureWrappedLLM. In TOOL mode the raw
LLM is returned unwrapped (the tool pod is the execution end of the chain).
For agents with a single LLM, call without llmId. For agents with
multiple LLMs every call must supply a unique llmId:
const fast = app.llm(ChatOpenAI("gpt-5.4-mini"), "fast")
const primary = app.llm(ChatOpenAI("gpt-5.4"), "primary")
Unnamed calls register under the sentinel id "__default__"; a second
unnamed call therefore raises the same duplicate-id error as a second
named call with the same id.
Parameters
| Parameter | Type |
|---|---|
llm |
BaseChatModel |
llmId? |
string |
Returns
BaseChatModel
prepareAgentInput<F>(fn): F;Register a hook that builds the graph's starting input from the caller's
AgentInput and RequestContext for a fresh execution. Resume stays
platform-managed. Returns the function unchanged so it can be used as a
decorator. Equivalent to the Python SDK's @app.prepare_agent_input.
Type Parameters
| Type Parameter |
|---|
F extends PrepareAgentInput |
Parameters
| Parameter | Type |
|---|---|
fn |
F |
Returns
F
ready(): Promise<void>;Resolved once configured MCP servers have been discovered and registered
as tools. TenantRuntime.runAsync() awaits this (via GraphBuilderLike.ready())
before starting the server.
Returns
Promise<void>
resolveThreadId<F>(fn): F;Register a hook that builds the LangGraph checkpoint thread_id.
Callers manage Atlas Agent Engine session_id (and authenticated user_id). The
agent owns how those map to the LangGraph checkpoint key. When registered,
the hook's return value is used verbatim on every invocation — fresh and
resume — with no workspace suffix appended. When no hook is registered,
the adapter derives session_id:workspace_id as today.
Custom keys are invisible to Atlas Agent Engine session-history queries
(/query/sessions*), which still look up only the default
session/workspace-derived keys. Agents that bypass workspace scoping also
own collision isolation within the checkpoint database.
Equivalent to the Python SDK's @app.resolve_thread_id.
Type Parameters
| Type Parameter |
|---|
F extends ResolveThreadId |
Parameters
| Parameter | Type |
|---|---|
fn |
F |
Returns
F
Example
app.resolveThreadId((ctx) => `${ctx.sessionId}__${actorFrom(ctx.userId)}`);run(options?): Promise<void>;Start the agent service.
Async because the per-project store-DB name is resolved against the live
cluster (an async listDatabases round trip in the Node driver) before the
query plugin and checkpointer are wired, so AER writes land in the same
database the OE reads. The synchronous framework hooks are still registered
before the first await, preserving their ordering relative to startup.
Parameters
| Parameter | Type |
|---|---|
options |
Record<string, unknown> |
Returns
Promise<void>
suspend(reason, context): string;Generate a suspend command. If a tool should suspend, return the result of this method instead of completing normally.
Parameters
| Parameter | Type |
|---|---|
reason |
string |
context |
Record<string, unknown> |
Returns
string
tool(options?): <F>(fn) => F;Register a tool function.
Returns a function that, when applied to a tool function, registers it
and returns the function unchanged. Mirrors Python's @app.tool() shape.
Parameters
| Parameter | Type |
|---|---|
options |
ToolDecoratorOptions |
Returns
<F>(fn) => F
Overrides
BaseApp.tooltools(): unknown[];Returns a list of wrapped, framework-specific tools.
Returns
unknown[]
Overrides
BaseApp.toolswarmUp(): void;Build and cache the graph when explicitly requested. The TypeScript AER
intentionally leaves construction on the existing lazy /execute path:
this synchronous builder cannot run during standby warming without
blocking the Node event loop and server health.
Returns
void
LangGraph adapter implementing the BaseAgent protocol.
BaseAgent
new LangGraphBaseAgent(
graph,
callbacks?,
prepareInput?,
resolveThreadId?
): LangGraphBaseAgent;Parameters
| Parameter | Type |
|---|---|
graph |
CompiledStateGraph<unknown, unknown> |
callbacks? |
readonly unknown[] |
prepareInput? |
PrepareAgentInput | null |
resolveThreadId? |
ResolveThreadId | null |
Returns
Get Signature
get compiledGraph(): CompiledStateGraph<unknown, unknown>;The wrapped compiled graph (Python compiled_graph parity).
Returns
CompiledStateGraph<unknown, unknown>
Get Signature
get resolveThreadId(): ResolveThreadId | null;The tenant thread-id hook, or null (Python _resolve_thread_id parity).
Returns
ResolveThreadId | null
execute(ctx, input): ExecutionResult;Parameters
| Parameter | Type |
|---|---|
ctx |
RequestContext |
input |
AgentInput |
Returns
ExecutionResult
Implementation of
BaseAgent.executeinvoke(ctx, input): Promise<AgentOutput>;Parameters
| Parameter | Type |
|---|---|
ctx |
RequestContext |
input |
AgentInput |
Returns
Promise<AgentOutput>
resume(
ctx,
input,
decision
): Promise<AgentOutput>;Parameters
| Parameter | Type |
|---|---|
ctx |
RequestContext |
input |
AgentInput |
decision |
string |
Returns
Promise<AgentOutput>
stream(ctx, input): AsyncIterable<StreamEvent>;Parameters
| Parameter | Type |
|---|---|
ctx |
RequestContext |
input |
AgentInput |
Returns
AsyncIterable<StreamEvent>
AERQueryPlugin backed by LangGraph's MongoDBSaver.
new LangGraphQueryPlugin(params): LangGraphQueryPlugin;Parameters
| Parameter | Type |
|---|---|
params |
LangGraphQueryPluginParams |
Returns
getMessagesForSession(sessionId): Promise<{
messages: object[];
}>;Parameters
| Parameter | Type |
|---|---|
sessionId |
string |
Returns
Promise<{
messages: object[];
}>
getSummariesForSessions(sessionIds): Promise<{
sessions: object[];
}>;Parameters
| Parameter | Type |
|---|---|
sessionIds |
string[] |
Returns
Promise<{
sessions: object[];
}>
Options for App.deepAgent.
Omit<CreateAgentEngineDeepAgentOptions,"checkpointer"|"skillsBaseDir">
| Property | Type | Description | Inherited from |
|---|---|---|---|
backend? |
AnyBackendProtocol |
Backend for filesystem/shell ops. Defaults to AgentEngineToolPodBackend, so every op is OE-audited and sandboxed in the Tool Pod. Pass a custom backend (e.g. deepagents' in-memory StateBackend) to override — note that doing so bypasses the OE audit path. |
- |
checkpointer? |
boolean | BaseCheckpointSaver<number> |
Checkpointer selection. Omitted (undefined) resolves to app.checkpointer() (MongoDB when configured, else none). false disables checkpointing. A BaseCheckpointSaver instance is used directly. Note the mapping differs from Python (None disables there): in TS, "disable" is false, and "use the default" is simply leaving it out. |
- |
middleware? |
readonly AgentMiddleware<any, any, any, readonly (ClientTool | ServerTool)[]>[] |
Additional middleware, appended after the default durable middleware. | CreateAgentEngineDeepAgentOptions.middleware |
skills? |
string[] |
Parent directories for deepagents' one-level skill discovery. | CreateAgentEngineDeepAgentOptions.skills |
store? |
BaseStore |
LangGraph store for skills and shared data. | CreateAgentEngineDeepAgentOptions.store |
subagents? |
readonly AnySubAgent[] |
SubAgent specs. Plain specs with a model field must use a model instance, not a string — string models bypass OE routing. |
CreateAgentEngineDeepAgentOptions.subagents |
systemPrompt? |
string |
Custom system instructions. | CreateAgentEngineDeepAgentOptions.systemPrompt |
tools? |
StructuredTool<ToolInputSchemaBase, any, any, any, unknown>[] |
Additional tools for the deep agent. | CreateAgentEngineDeepAgentOptions.tools |
| Property | Type |
|---|---|
client |
MongoClient |
dbName |
string |
saver |
MongoDBSaver |
workspaceId? |
string |
workspaceIdResolver? |
() => string | null | undefined |
type PrepareAgentInput = (input, ctx) => unknown;| Parameter | Type |
|---|---|
input |
AgentInput |
ctx |
RequestContext |
unknown
type ResolveThreadId = (ctx) => string;| Parameter | Type |
|---|---|
ctx |
RequestContext |
string
type SessionFinishStatus = "requested" | "already_requested" | "unavailable";const MAX_SUBAGENT_NESTING_DEPTH: 10 = 10;Recursion is bounded so an adversarial spec (or an accidental cycle) can't blow the stack at agent-construction time.
function createAgentEngineDeepAgent(
secureLlm,
backend,
options?
): DeepAgent<DeepAgentTypeConfig<ResponseFormatUndefined, undefined, InteropZodObject, readonly [AgentMiddleware<ZodObject<{
}, "strip", ZodTypeAny, {
}, {
}>, undefined, unknown, readonly [DynamicStructuredTool<ZodObject<{
}, "strip", ZodTypeAny, {
}, {
}>, {
}, {
}, Command<unknown, {
}, string>, unknown, "write_todos">]>, AgentMiddleware<StateSchema<{
}>, undefined, unknown, (
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "ls">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, object[] | object[], unknown, "read_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| ToolMessage<MessageStructure<MessageToolSet>>
| Command<unknown, {
}, string>, unknown, "write_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| ToolMessage<MessageStructure<MessageToolSet>>
| Command<unknown, {
}, string>, unknown, "edit_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "glob">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "grep">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "execute">)[]>, AgentMiddleware<undefined, undefined, unknown, readonly [DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| Command<unknown, Record<string, unknown>, string>, unknown, "task">]>, AgentMiddleware<ZodObject<{
}, $strip>, undefined, unknown, readonly (ClientTool | ServerTool)[]>, AgentMiddleware<undefined, undefined, unknown, readonly (ClientTool | ServerTool)[]>, AgentMiddleware<any, any, any, readonly (ClientTool | ServerTool)[]>], readonly (ClientTool | ServerTool)[], readonly AnySubAgent[], readonly () => StreamTransformer<any>[]>>;Create a deep-agent graph pre-configured for Atlas Agent Engine AER. Resolves relative
skill paths, validates the subagent tree, then delegates to deepagents'
createDeepAgent.
| Parameter | Type | Description |
|---|---|---|
secureLlm |
BaseChatModel |
A SecureWrappedLLM instance — every LLM call is OE-audited. |
backend |
AnyBackendProtocol | undefined |
Backend for filesystem/shell ops; resolved by App.deepAgent(). |
options |
CreateAgentEngineDeepAgentOptions |
- |
DeepAgent<DeepAgentTypeConfig<ResponseFormatUndefined, undefined, InteropZodObject, readonly [AgentMiddleware<ZodObject<{
}, "strip", ZodTypeAny, {
}, {
}>, undefined, unknown, readonly [DynamicStructuredTool<ZodObject<{
}, "strip", ZodTypeAny, {
}, {
}>, {
}, {
}, Command<unknown, {
}, string>, unknown, "write_todos">]>, AgentMiddleware<StateSchema<{
}>, undefined, unknown, (
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "ls">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, object[] | object[], unknown, "read_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| ToolMessage<MessageStructure<MessageToolSet>>
| Command<unknown, {
}, string>, unknown, "write_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| ToolMessage<MessageStructure<MessageToolSet>>
| Command<unknown, {
}, string>, unknown, "edit_file">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "glob">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "grep">
| DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
}, string, unknown, "execute">)[]>, AgentMiddleware<undefined, undefined, unknown, readonly [DynamicStructuredTool<ZodObject<{
}, $strip>, {
}, {
},
| string
| Command<unknown, Record<string, unknown>, string>, unknown, "task">]>, AgentMiddleware<ZodObject<{
}, $strip>, undefined, unknown, readonly (ClientTool | ServerTool)[]>, AgentMiddleware<undefined, undefined, unknown, readonly (ClientTool | ServerTool)[]>, AgentMiddleware<any, any, any, readonly (ClientTool | ServerTool)[]>], readonly (ClientTool | ServerTool)[], readonly AnySubAgent[], readonly () => StreamTransformer<any>[]>>
A subagent spec uses a string model, or nesting exceeds the cap.
function getCallAbortSignal(): AbortSignal | undefined;The per-call stop signal for the in-flight callback-routed tool call.
Defined only inside a tool body that declared call-interrupt support; a
cooperative body checks it (or forwards it to fetch etc.) to stop at its
next checkpoint. Undefined everywhere else.
AbortSignal | undefined
function validateSubagentTree(subagents): void;Walk the subagent tree, throwing on any string-model spec.
String model specs would bypass OE routing because deepagents' resolveModel
instantiates a raw provider client with no SecureToolWrapper. Only model
instances (e.g. SecureWrappedLLM) are accepted.
Spec kinds handled:
CompiledSubAgent(runnableset) — pre-built graph; the model is already bound and unreadable here. Skipped.AsyncSubAgent(graphIdset) — remote graph we can't validate in-process. Logged at WARNING and skipped — the receiving end must route through the OE.- Plain
SubAgent— validated; a stringmodelthrows.
The depth counter is held in a closure rather than a public parameter so callers cannot start recursion mid-tree and bypass the cap.
| Parameter | Type |
|---|---|
subagents |
readonly AnySubAgent[] | undefined |
void
A subagent spec uses a string model, or nesting exceeds
MAX_SUBAGENT_NESTING_DEPTH.
function withCallInterruptSupport<T>(tool): T;Brand a tool as supporting per-call interrupt. The body must honor the
signal from getCallAbortSignal() — check signal.aborted between steps
or pass the signal to APIs that accept one (fetch, streams).
Returns the same tool for chaining at definition time.
| Type Parameter |
|---|
T |
| Parameter | Type |
|---|---|
tool |
T |
T
Renames and re-exports AgentEngineToolPodBackend