Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Path Parameters

runId
string
required

The run to put on hold. A runId: an agentRunId here answers 404.

Response

The run, on hold, and the lease it acts under.

What putting a run on hold hands back: the run as it now stands, and the lease it acts under.

run
object
required

The public projection of a run, and who started it. The run token is deliberately absent: it is returned once, when the run is started, and never again.

leaseId
string
required

The lease the run acts under, kept here for compatibility. You do not need it to act on the device: POST /v1/devices/{deviceId}/actions resolves your organisation's lease for any caller. It is still a CAPABILITY rather than a detail (release takes it), which is why GET /v1/leases never publishes it.

manualControlUntil
string
required

When the hold ends, ISO 8601. Resume the run before then to let it continue; a run nobody resumes by then is canceled. Renewing the lease extends the hold.