Workers API
List, update, approve and revoke workers, and approve pairing codes. The worker protocol itself is internal.
| Method and path | Purpose | Permission |
|---|---|---|
GET /orgs/:orgId/workers | List workers, with status, tools, agents and providers | member |
GET /orgs/:orgId/workers/:workerId | Get a worker | member |
PATCH /orgs/:orgId/workers/:workerId | Update a worker (name, labels, policy) | worker.manage |
POST /orgs/:orgId/workers/:workerId/approve | Approve a worker when the organization requires approval | worker.approve |
DELETE /orgs/:orgId/workers/:workerId | Revoke the worker's credential | worker.manage |
GET /pairing/:userCode | Describe a pending pairing | signed-in user |
POST /pairing/approve, POST /pairing/deny | Decide a pairing code | signed-in user |
Worker protocol
Workers use HTTP for state changes (claim, transition, events) and a WebSocket (/api/v1/worker/ws) for offers,
control messages and heartbeats, authenticated with their aow_… credential. The protocol is versioned with the
core (packages/contracts/src/worker-protocol.ts) and is not meant for third-party clients.