OptionalallowAllowlist controlling which policy fields an untrusted request body may set.
OptionalallowAllows trusted callers to choose session and fork ids. Server-owned ids are the secure default.
OptionalallowPreserves the legacy restore-or-create behavior for message endpoints.
OptionalbaseOptionalconversationOptionalcontextOptionalexposeWhen true, raw tool_result content parts are included verbatim in public
session projections and SSE streams. Defaults to false: tool results are
treated as server-internal and redacted before reaching clients, so raw
database/RAG rows are not exposed before assistant-level filtering.
OptionalmiddlewareOptionalmaxMaximum UTF-8 request-body size accepted by JSON POST routes.
OptionalsessionOptionaltenantOptionaltoolsOptionalwith
Configuration for
SessionApiandcreateSessionApi().