custom_jwt (the same user pool). There is no shared API key — the user’s identity flows end-to-end.
First, follow Authentication and login to configure AK/SK credentials or complete SSO login. In Agent Identity, prepare a user pool and a WEB client, noting
user_pool_id and client_id (the client secret is fetched automatically by the CLI). To sign in with Feishu, configure Feishu as an identity source (third-party federation) on the user pool.Prerequisites and version scope
Prepare a deployed target Runtime that the frontend can discover and the signed-in user is authorized to invoke. The current frontend displays cloud Runtimes by default; this flow does not automatically add the local agent from thebasic template. For local agent-directory development, use development mode in VeADK Frontend
The CLI 0.54.0 frontend build uses the VeADK main branch, so behavior depends on the version available at build time rather than a fixed VeADK release. Verify target Runtime discovery, login, and invocation permissions before production use
1
Scaffold a project
2
Declare the frontend (edit .agentkit/agentkit.yaml)
Add a
frontend block with the user pool region and project explicitly selected to avoid matching another environment. The frontend Runtime derives custom_jwt authentication from this pool, so do not repeat auth. The client secret is fetched by default; if it is not returned, reference the actual value with frontend.oauth2.client_secret: ${USERPOOL_CLIENT_SECRET}:.agentkit/agentkit.yaml
3
Fill in the environment variables
Put actual values in
.env, which the CLI loads during release; exclude .env from version control and Docker build input with .gitignore and .dockerignore. This example uses Volcengine. For BytePlus, use its own user pool and client and update the provider, regions, and model service in release configuration:.env
4
Deploy
5
Open and use it
Open the frontend URL and complete user-pool login. Verify the displayed identity, confirm that the target cloud Runtime appears in the list, and then send a message. Login success only verifies authentication. If the list is empty, check Runtime discovery permissions; if a call fails, check target Runtime authentication and model settings. After signing out, accessing the page again should return to login
- No shared secret: the client secret lives only on the frontend BFF’s server side; the browser only holds a session cookie, and the BFF injects the user’s JWT when calling the runtime.
- Callback auto-registered:
<frontend-url>/oauth2/callbackis added to the user pool client’s callback list automatically (the URL is known only after deploy; the CLI fills it back in). - Gateway: the frontend runs on a serverless gateway; by default an existing one is reused so it doesn’t consume gateway quota. Pin a specific one with
frontend.gateway. - Python project:
veadk frontendserves the UI, and the build requires a Python project withrequirements.txt. This flow uses cloud Runtime browsing and does not load localroot_agentdirectories