custom_jwt (the same user pool). There is no shared API key — the user’s identity flows end-to-end.
First, follow Authentication and login to configure AK/SK credentials or complete SSO login. In Agent Identity, prepare a user pool and a WEB client, noting
user_pool_id and client_id (the client secret is fetched automatically by the CLI). To sign in with Feishu, configure Feishu as an identity source (third-party federation) on the user pool.1
Scaffold a project
2
Declare the frontend (edit .agentkit/agentkit.yaml)
Add a
frontend block. Declare the user pool here only — the runtime’s custom_jwt gateway auth is derived from it automatically, so you don’t repeat auth, and the client secret is fetched automatically, so you don’t declare it. Values use ${VAR} and stay out of the repo:.agentkit/agentkit.yaml
3
Fill in the environment variables
Put the values in
.env — the CLI loads it automatically on deploy:.env
4
Deploy
5
Open and use it
Open the frontend URL from the output; the browser redirects to the user pool login, and after signing in you land in the frontend and chat with the agent. The frontend shows the signed-in user’s identity (name and email).
- No shared secret: the client secret lives only on the frontend BFF’s server side; the browser only holds a session cookie, and the BFF injects the user’s JWT when calling the runtime.
- Callback auto-registered:
<frontend-url>/oauth2/callbackis added to the user pool client’s callback list automatically (the URL is known only after deploy; the CLI fills it back in). - Gateway: the frontend runs on a serverless gateway; by default an existing one is reused so it doesn’t consume gateway quota. Pin a specific one with
frontend.gateway. - Python only: the frontend UI is served by the VeADK Frontend (
veadk frontend), so this flow currently supports Python projects. An agent scaffolded with thebasictemplate is already in a layout the frontend can discover (the agent is defined in a package exposingroot_agent).