Documentation

Agent protocol (datanivra.agent/v1)

The outbound lease protocol between agent and control plane, for security and network reviewers.

Shape of the conversation

The agent initiates every exchange over HTTPS. Requests are wrapped in an agent envelope and responses in a control-plane envelope; both carry the protocol version, a unique message id used for de-duplication, identity, a timestamp and a correlation id.

EndpointPurpose
POST /v1/agent/enrollFirst registration with a one-time token
POST /v1/agent/tokenExchange a signed assertion for a short-lived access token
POST /v1/agent/heartbeatLiveness and capability report; learns if it has been revoked
POST /v1/agent/leasesLong-poll for a command lease
POST /v1/agent/leases/{id}/ack and /renewAccept or reject a lease; keep it alive while working
POST /v1/agent/reportsJob events, discovery findings, manifests, certification results, evidence references

Commands are declarative

A command names what to do — discover metadata, validate a source, build or refresh a dataset, cancel, revoke — and references policies by version and checksum. The agent re-verifies the checksum and that the policy is approved and not revoked, and rejects stale, duplicate or cross-tenant commands.

What a report may contain

Only classified fields: control metadata, aggregate metrics, evidence metadata and secret references. Values, rows, samples and credentials are prohibited by the contract itself and by the agent's egress guard, and the control plane validates again on arrival without logging rejected content.

The authoritative reference is docs/contracts/PROTOCOL.md in the repository.

← All documentation