Overview
Publish a profile to make it available through an authenticated chat endpoint. This guide covers publishing, issuing keys, calling your agent, and revoking access. See Publishing for the conceptual model.Prerequisites
- An Orca account with the owner or admin role
- A profile that runs successfully
- Publishing enabled for your deployment
publicUrl for chat requests. The agents.example.com host below is a placeholder.
Step 1: Publish a Profile
Publishing is a conductor API call against the public port. The dashboard “Publish” surface wraps the same endpoint; the curl examples below match it byte-for-byte.pub_... row plus the publicUrl derived from CHAT_GATEWAY_PUBLIC_HOST:
Slugs are immutable. To change a slug, unpublish and republish.
monthlyCostCapUsdCents spend cap, defaulting to 5000 ($50/month) if not set at publish time. The conductor enforces this fail-closed: once month-to-date spend for the published agent reaches the cap, chat requests are rejected with 402 Payment Required and {"error": "published_agent_cap_reached", "scope": "published_agent", ...}. Set it explicitly in the publish body, or raise it later with the PATCH call in Step 4.
Step 2: Mint an API Key
API keys are HMAC-hashed with the pepper; the plaintext token is returned exactly once and never recoverable. See API Keys for the auth model.token immediately. Re-fetching the keys list returns metadata only.
Step 3: Call the Public Endpoint
Sync Chat
Streaming Chat
Continuing a Conversation
Thread theconversation_id from any prior response back in the body. The gateway reuses the same runtime session under the hood.
Resume an In-Flight Run
/stream endpoint always responds 200 OK with Content-Type: text/event-stream. If the run is still in flight, it forwards live SSE frames as they arrive; if the run already finished, it replays a single reconstructed terminal frame (event: done or event: error) instead.
There is also a plain JSON variant without the /stream suffix, GET /v1/chat/default/general/runs/prun_abcd1234, for polling instead of streaming. It returns 202 Accepted with {"public_run_id": ..., "status": ...} while the run is still dispatching or running, 200 OK with the message once it succeeds, 502 Bad Gateway on an upstream error, and 410 Gone if the run was lost.
Step 4: Update or Disable a Published Agent
PATCH /api/profiles/{name}/published accepts any subset of the published knobs plus enabled. Operators can toggle tool-event streaming on an already-published agent with exposeToolEvents, or raise the spend cap (or set monthlyCostCapUsdCents to 0 for uncapped) once it starts blocking traffic. Setting enabled: false is a fast kill switch that survives without losing history.
DELETE /api/profiles/{name}/published. The row is soft-deleted with unpublished_at so the slug becomes immediately reusable for a different profile.
Step 5: Revoke or Rotate Keys
Revoke One Key
401 unauthorized on the very next request that uses the revoked bearer.
Rotate the Bearer Without Downtime
- Issue a new key
- Roll the new token out to every client
- Revoke the old key