Prerequisites
- Install
veadk-python==1.0.8. - Sign in or configure Volcengine access credentials.
- Export an importable
root_agentfrom the project. - Do not commit
.env, API keys, or access credentials to source control.
Create the application
Studio-generated projects callcreate_agentkit_app. Manually created projects can use the same entry point:
app.py
Runtime identity binding
create_agentkit_app accepts an optional identity parameter that passes an AgentKit Runtime identity boundary to the application. When supplied, AgentKit verifies and binds the inbound user identity before VeADK Agent or Tool code runs. Omitting identity preserves the previous behavior.
VeADK excludes the /ping health-check endpoint from identity binding; that endpoint always returns {"status": "ok"}. All other business and introspection endpoints are identity-bound.
app.py
Dynamic A2A run endpoints
Applications built withcreate_agentkit_app override the standard AgentKit run endpoints (/run, /run_sse, /invoke) to support dynamic A2A agent discovery. When the agent is configured with an AgentKit agent center via environment variables such as REGISTRY_SPACE_ID, the run endpoints dynamically discover matching remote agents from the center and attach them as callable tools for the current turn. Without an agent center configured, the run endpoints behave identically to the standard AgentKit run endpoints.
The run endpoints create a session automatically when the specified session does not exist, instead of returning 404.
Session-scoped capability overlays
Starting with VeADK 1.0.9, applications built withcreate_agentkit_app mount session-scoped capability-overlay endpoints under the /harness prefix. A caller can temporarily mount a built-in tool or a remote skill for a session, then run the agent with the overlay applied through /harness/run_sse. Overlays apply only to the specified session: they do not modify the root agent definition and are not written to other sessions.
Capabilities fall into two categories:
- Built-in tools: from the VeADK built-in tool catalog, referenced by tool name.
- Remote skills: from the public Skill Hub or an AgentKit Skill Space, referenced by skill name and skill-source identifier.
custom is false) and cannot be removed; capabilities mounted through the overlay API are session capabilities (custom is true) and can be removed individually.
When to use
- When you need to enable an additional tool or skill for a single session without redeploying the Runtime.
- When you need to isolate different capability sets by session so they do not affect each other.
Dependencies
- The agent must expose a
toolsattribute; mounting fails when the overlay is non-empty but the root agent has notools. - Listing and mounting remote skills requires Volcengine credentials. Provide them locally with
VOLCENGINE_ACCESS_KEYandVOLCENGINE_SECRET_KEY; on VeFaaS, use the bound IAM Role.
Endpoints
Examples
Mount a built-in tool for a session:/harness/run_sse returns the same event format as the standard /run_sse endpoint; each event is sent as a data: -prefixed JSON line.
Parameters
POST /capabilities request body:
GET /harness/skills/spaces and GET /harness/skills/spaces/{space_id}/skills accept a region query parameter: spaces defaults to all (combining Beijing and Shanghai), and the skill list defaults to cn-beijing.
GET /harness/skills/findskill accepts these query parameters:
Limitations
- Base capabilities cannot be removed; a
capability_idstarting withbase:returns 409. - A tool or skill with a duplicate name cannot be mounted; a name that collides with a root-agent capability returns 409.
- An
expected_revisionthat does not match the currentrevisionreturns 409; the caller should re-query and retry. - Session capabilities take effect only for runs of the session they were mounted to; they are not persisted to the root agent after the run.
- The public Skill Hub search URL defaults to
https://skills.volces.com/v1/skillsand can be overridden with theFINDSKILL_SEARCH_URLenvironment variable.
Initialize and deploy
Run these commands in the project directory:veadk agentkit uses the same project configuration and workflows as AgentKit CLI. See the AgentKit CLI documentation for complete commands, flags, and destructive-operation guidance.