Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ OAC_WEB_DEV_PROXY_TARGET=http://127.0.0.1:8091

# Legacy development proxy only. The console never calls /v1; the Vite server
# still forwards /v1 with this Project API key for older tooling such as
# scripts/core-doctor.mjs (see docs/web/roadmap.md). Plaintext bearer file read
# scripts/core-doctor.mjs. Plaintext bearer file read
# only by the local Vite server; if unset, it checks this conventional path.
OAC_WEB_DEV_PROXY_TOKEN_FILE=~/.oac/dev/web-token

Expand Down
4 changes: 2 additions & 2 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,8 @@ This guide owns how to work in the repository: documentation ownership, the repo
| MiniMax Code and Claude Runtime adapter rules | [MiniMax Code Runtime](services/agents-api/deploy/mcode/README.md), [Claude Runtime](services/agents-api/deploy/claude/README.md) |
| CI, distribution builds, installer lifecycle and managed HTTPS, release publication | [Maintainer guide](docs/maintainers.md) |
| Operator installation, installation layout and configuration | [Installation](docs/getting-started/install.md), [installation options](docs/getting-started/install-options.md), [configuration](docs/configuration.md), [operations](docs/getting-started/operations.md) |
| Core Web console server and sign-in | [Web README](apps/web/README.md) |
| Web components, interaction and visual rules | [Web design](apps/web/DESIGN.md) and [Web architecture](docs/web/architecture.md) |
| Core Web console server and sign-in | [Console server](docs/web/console-server.md) |
| Web components, interaction and visual rules | [Web design](apps/web/DESIGN.md) and [Web product](apps/web/PRODUCT.md) |
| Documentation website generation | [Docs app](apps/docs/README.md) |

## Repository boundary
Expand Down
225 changes: 139 additions & 86 deletions apps/docs/content/docs/bootstrap-projects-keys.mdx

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion apps/docs/content/docs/configure.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -158,6 +158,6 @@ Core reads only its environment. The installer renders `generated/core.env` from

Core logs the file paths it loads, never environment values or file contents.

A Web you run without the installer reads the variables in [Connecting the administrator console to Core](/bootstrap-projects-keys#server-configuration-and-login), plus `OAC_WEB_NODE_PAYLOAD_DIR`: the absolute path of the matched distribution's node payload (the installer's `node-payload/`). Without it, Add node is unavailable.
A Web you run without the installer reads the variables in [Console server settings](/bootstrap-projects-keys#settings), plus `OAC_WEB_NODE_PAYLOAD_DIR`: the absolute path of the matched distribution's node payload (the installer's `node-payload/`). Without it, Add node is unavailable.

[Repository source](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/docs/configuration.md)
88 changes: 40 additions & 48 deletions apps/docs/content/docs/console.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -3,64 +3,56 @@ title: "Administrator console"
description: "Monitor Core, inspect resources and manage deployment settings through Web."
---

Core Web is the administrator console for a Core deployment. Its Go service
provides Core key login and forwards signed-in, same-origin `/core/v1` requests to
Core. Applications use Core's public Agents API directly with their own Project API
keys.
Web is the administrator console of one OpenAgentCore deployment. Administrators use it to watch health, capacity, usage and failures, inspect each Project's resources and execution history, and manage Projects, keys, nodes and deployment settings. Applications do not use Web; they call Core's Agents API (`/v1`) with their own Project API keys.

The React console (`apps/web`) uses this contract: every browser request goes through
the console's same-origin management routes with `AdminClient` and the sandbox
management client, and it sends nothing to `/v1`.
![OpenAgentCore Web overview](/images/source/docs/assets/console-overview-en.webp)

![Core Web overview](/images/source/apps/web/public/onboarding/monitor-en.webp)
## Sign in

[Sign in](/install#sign-in-to-web) with the deployment's [Core key](/troubleshooting#core-key); the console has no user accounts. The browser keeps only a session cookie, and the [console server](/bootstrap-projects-keys) sends the Core key to Core on its behalf; [sign-in](/bootstrap-projects-keys#sign-in) describes how long a session lasts.

Signing in opens the Overview. While any step is still to do, its **Getting started** checklist leads through four steps in any order: sandboxes ready, a default model provider, a Project with an active key, and a first Session. An optional tour of the console opens from it.

## Console pages

| Group | Page | Purpose |
| --- | --- | --- |
| Monitor | Overview | Service status, running Sessions, sandbox slots and work needing attention; 24-hour Session activity; Core and its nodes as a topology, each with a popover glance; Sessions needing attention; usage by Project |
| Monitor | Core metrics | The Core process: execution slots, the Turn queue, connected daemons, database latency and pool, background jobs |
| Monitor | Core metrics | The Core process: CPU and resident memory against their limits, execution slots and the Turn queue, connected daemons, database latency and pool, background jobs |
| Monitor | Agent metrics | Requests, errors, duration, tokens, models, tools, Agents and API keys over 1 h, 6 h, 24 h or 7 d |
| Monitor | Sandbox metrics | Node capacity and hosted Runtime CPU and memory across Projects |
| Monitor | Session log | Every Session, opening one Session's read-only conversation, trace and Turns; a self-hosted Session's page also manages its executor credentials and gives the command that connects a host |
| Resources | Agents, Environment templates, Skills, Files, Vaults | Inspection and permitted deletion |
| Platform | Projects and keys, Nodes, System | Project and key lifecycle; sandbox deployment and nodes; System: the installation's public address, API base URL, ID and source commit (read-only), each harness's default model provider (write-only key) beside its read-only startup state, the sandbox configuration every Project shares: provider, sandbox size, Runtime or E2B template build, idle suspension and reset, and Core's config.json startup settings with where to change them |

Missing data is shown as missing (—), never as zero. How each figure is read and
bounded is recorded in [management interface coverage](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/docs/web/protocol-coverage.md).

## Management scope

Administrators can create, rename and archive Projects; issue and revoke their
keys; inspect resources and execution history; delete supported resources; and
issue, rotate and revoke the executor credentials of a self-hosted Session's
environment on its Session page.
They can also read summaries, Runtime observations and audit history, and manage
deployment sandbox nodes. Deployment sandbox management selects E2B, Docker or
microsandbox; caller-managed `self_hosted` Runtimes remain a separate application
path.

How Projects and keys behave, and what administrators can and cannot do, is in
the [design principles](/concepts#projects-own-assets).

## Connect and develop

Follow the [installation guide](/install) for Core, Web and
PostgreSQL with zero execution nodes. Installation creates no Project or application
key; an administrator creates them on the console's **Projects and keys** page or
through the management API. The browser signs in to the console with the Core key;
only the console server sends it to Core.

- [Connection and authentication](/bootstrap-projects-keys)
- [Architecture and ownership](/execution-model)
- [Management interface coverage](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/docs/web/protocol-coverage.md)
- [Frontend handoff and acceptance](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/docs/web/roadmap.md)
- [React application](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/apps/web/README.md)

The [administrator API contract](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/contracts/agents-api/admin-api.md) defines
management routes and resource behavior. The [public API contracts](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/contracts/agents-api/README.md)
define the separate application interface. See the [design principles](/concepts)
for ownership and [contributor guide](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/CONTRIBUTING.md) for required checks.
| Monitor | Session log | Every Session, and each Session's read-only conversation, trace and Turns with the classified reason of a failure; a self-hosted Session's page also manages its executor credentials and gives the command that connects a host |
| Resources | Agents, Environment templates, Skills, Files, Vaults | Inspection and permitted deletion, with the Project and the creating key of each resource |
| Platform | Projects and keys | Create, rename and archive Projects; issue and revoke keys; each Project's usage, write history and how to call the API |
| Platform | Nodes | Add, edit and remove Docker or microsandbox nodes; each node's readiness, capacity and allocations |
| Platform | System | The installation's public address, API base URL, ID and source commit; **Domain and HTTPS**; each harness's default model; **Sandbox configuration**; Core's `config.json` startup settings, read-only, with where to change them |

Missing data is shown as missing (—), never as zero. [Console API usage](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/docs/web/console-api-usage.md) lists what each page reads and how its figures are bounded.

## What administrators do here

| Task | Where |
| --- | --- |
| Give the installation an HTTPS address | **System → Domain and HTTPS**, on an installation with managed ingress; see [Make Core reachable](/install#configure-the-domain-and-https) |
| Choose the sandbox backend (Docker, microsandbox or E2B), the sandbox size and Runtime, or reset the backend | **System → Sandbox configuration**; see [change the sandbox configuration](/hosted-providers#change-the-sandbox-configuration) |
| Add or remove execution nodes | **Nodes**; see the [nodes guide](/hosted-providers) |
| Set the default model of a harness | **System → Default model configuration**; see [default models](/configure#default-models) |
| Create a Project and issue its API keys | **Projects and keys**; see [Projects and API keys](/troubleshooting#projects-and-api-keys) |
| Issue, rotate or revoke a self-hosted executor's credential, or copy its install command | The Session's page in the **Session log**; see [self-hosted executors](/self-hosted-execution) |
| Delete a resource, for example a leaked Credential | The resource's row in its list, or its page; Files are deleted from the Files list. The public deletion rules apply |

Installation creates no Project or key. Opening the console neither allocates compute nor calls a model, and an installation may have zero nodes. Web never starts a Session, sends input or cancels work; the [design principles](/concepts#what-administrators-can-and-cannot-do) state what administrators can and cannot do.

The deployment's sandbox backend serves hosted Sessions. An application's `self_hosted` Runtime, including one in its own E2B account, is a separate path that the sandbox configuration does not change.

A loopback public address (`local_only`) keeps nodes and remote applications from reaching Core. The console stays reachable at its own address and [warns about it](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/docs/web/console-api-usage.md#provenance-and-monitoring).

## More

- [Console server](/bootstrap-projects-keys): request boundary, sign-in, settings and verification.
- [Console API usage](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/docs/web/console-api-usage.md): the Core routes each page uses.
- [Web package](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/apps/web/README.md): developing the console.
- [Administrator API](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/contracts/agents-api/admin-api.md): the `/core/v1` routes behind the console.

OpenAgentCore Web is available under the [MIT License](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/LICENSE).

Expand Down
2 changes: 1 addition & 1 deletion apps/docs/content/docs/development.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -93,7 +93,7 @@ site; `pnpm dev:docs` starts its development server.
| `apps/parsar-daemon/internal/dispatch` | Runtime preparation, Executor reuse, Turn and cleanup ownership | [Harness lifecycle](/harness-onboarding#required-adapter-interfaces) |
| `apps/parsar-daemon/internal/agent` | Native harness adapters | [Native references](/harness-onboarding#native-references) |
| `services/agents-api/internal/sandbox` | Provider interfaces and managed compute lifecycle | [Provider onboarding](/sandbox-provider) |
| `services/core-console` | Console login and the server-side management proxy | [Web architecture](/execution-model) |
| `services/core-console` | Console login and the server-side management proxy | [Console server](/bootstrap-projects-keys) |
| `apps/web` and `packages/agents-client` | Console UI and typed clients | [Web guide](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/apps/web/README.md) |
| `deploy/install` and `scripts` | Distribution, installation and validation tools | [Maintainers](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/docs/maintainers.md) |
| `contracts/agents-api` | Pinned schema, local semantic contracts and qualification evidence | [Coverage ledger](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/contracts/agents-api/README.md) |
Expand Down
Loading