Skip to main content
Three different things in Orca hold file content. They are easy to mix up, so here is how they differ: Files and artifacts need a sandbox. Sessions with environment: {"type": "none"} have nowhere to put files.

Upload a file

Examples on this page assume client is an OpenAI client configured as in the quickstart. client.files.create stores a file in Orca and returns an ID. Upload once and stage it into as many sessions as you like.

Put files in the sandbox

When you create a session, list files under environment.files. Each needs a path inside /workspace and a source:
  • {"type": "file_id", "file_id": ..., "path": ...} copies an uploaded file.
  • {"type": "inline", "data": <base64>, "path": ...} sends small content directly.
You can also add files to a running sandbox later; see execution environments. Size limits:

Get results back as artifacts

Tell the agent to save its results under /workspace/outputs. When a turn completes, Orca copies every regular file in that folder (including subfolders) into an artifact. Then list and download them:
It assumes an agent created as in the quickstart. It uploads a file, stages it, asks the agent for a summary, then saves every artifact to the current folder.

How capture works

  • Only /workspace/outputs is captured. A file elsewhere in the workspace is not, even if the agent mentions it. For self-hosted environments the folder is outputs inside your workspace_directory.
  • Only completed turns are captured. A failed or cancelled turn produces no artifacts.
  • Artifacts never change. If the agent edits a file in a later turn, that turn gets a new artifact, and the old one keeps the old content.
  • Symbolic links are skipped.
  • Size limits apply: 64 MiB per file, 256 MiB and 4,096 entries per capture. If the outputs folder exceeds them, nothing from that turn is captured. The turn itself still completes, so an empty artifact list after a big job can mean this.

Tips

  • Be explicit in your instructions. “Write the report to /workspace/outputs/report.md” works much better than “create a report”.
  • Save bytes, not text. Artifacts can be images, PDFs, or archives. Write the raw content to disk rather than decoding it as UTF-8.
  • Download before you delete. Deleting a session deletes its artifacts.
  • Treat outputs as untrusted. The agent produced them, possibly from untrusted input. Check them before opening or executing them.
  • Keep secrets out of staged files. Anything in the workspace is visible to the agent and to commands it runs. Use vaults for credentials.

Common mistakes

See also: execution environments, skills and templates for reusable bundles, runnable examples, and the files reference.