API и сервер

Запуск без интерфейса.
Наблюдение вживую.

HTTP-сервер на Axum с аутентификацией, rate limiting, SSE-стримингом событий, управлением в процессе выполнения и встроенным веб-дашбордом — всё в одном бинарнике.

Аутентификация

API-ключи + rate limiting

Установите FATHOM_API_KEYS (через запятую) — и каждый запрос /api/v1/* требует ключ: Bearer-токен или заголовок X-Api-Key. Скользящее окно rate limiting возвращает 429 при превышении. Не задано = открытый доступ для разработки.

curl -H "Authorization: Bearer $KEY" \
  http://localhost:8080/api/v1/sessions

curl -H "X-Api-Key: $KEY" \
  http://localhost:8080/api/v1/memories/stats

Эндпоинты

Всё — это эндпоинт

Сессии

POST/api/v1/sessionsЗапустить сессию (запрос, профиль, модель, бюджет)
GET/api/v1/sessionsСписок сессий со статусом и прогрессом
GET/api/v1/sessions/:idСостояние сессии, дерево агентов, расход токенов
GET/api/v1/sessions/:id/resultsРезультаты, контакты, экспорты
DELETE/api/v1/sessions/:idОтменить выполняемую сессию

Агенты

GET/api/v1/agentsВсе агенты по сессиям (дерево)
GET/api/v1/agents/:idДетали агента, сообщения, tool-call

Контрольная панель

POST/api/v1/sessions/:id/steerУправление mid-run — перенаправить сессию
POST/api/v1/sessions/:id/answerОтветить на `question` tool-call агента
POST/api/v1/sessions/:id/approveОдобрить/отклонить сайд-эффект инструмент (approval)

События

GET/api/v1/eventsГлобальный SSE-поток событий агентов
GET/api/v1/sessions/:id/eventsSSE-поток по сессии (дельты, tool-call, результаты)

Память

GET/api/v1/memoriesПоиск по семантической памяти
POST/api/v1/memories/absorbПоглотить факт (дедуп + supersedes)
GET/api/v1/memories/statsРазмер хранилища, области, статистика графа
POST/api/v1/memories/distillПерегнать run-факты в долгосрочные знания
POST/api/v1/memories/gcАрхивировать устаревшие факты, уплотнить области
GET / DELETE/api/v1/memories/:idПросмотр/удаление записи памяти

Задачи

POST/api/v1/jobsОтправить долгосрочную фоновую задачу (task, attempts)
GET/api/v1/jobsСписок задач
GET/api/v1/jobs/:idСтатус задачи
GET/api/v1/jobs/:id/logstdout + stderr всех попыток
DELETE/api/v1/jobs/:idОтменить активную задачу
POST/api/v1/jobs/:id/rerunПерезапустить завершённую/застрявшую задачу

Управление и совместная работа

GET / PUT/api/v1/governance/policyRead or replace the governance policy
POST/api/v1/governance/decideEvaluate a governed action
GET/api/v1/governance/auditRead governance audit events
GET / POST/api/v1/coworkersList or create persistent coworker profiles
GET / PUT / PATCH / DELETE/api/v1/coworkers/:idInspect or update a coworker profile
GET / POST/api/v1/channelsList or create collaboration channels
PUT / PATCH / DELETE/api/v1/channels/:idUpdate or remove a channel
GET / POST/api/v1/schedulesList or create cron-like coworker schedules
GET / PUT / PATCH / DELETE/api/v1/schedules/:idInspect, update, or remove a schedule
POST/api/v1/schedules/claimAtomically claim due schedules for a scheduler tick
GET/api/v1/ag-ui/eventsStream the Fathom AG-UI-compatible event subset over SSE
GET/api/v1/ag-ui/healthProbe AG-UI bridge and advertised event-only capabilities

Секреты и аудит

GET / POST/api/v1/credentialsList redacted credential metadata or store a secret
DELETE/api/v1/credentials/:idDelete a stored credential
GET/api/v1/replayList redacted governed actions; filter by session or agent
GET/api/v1/observability/summaryRead bounded live metrics and audit counts
POST/api/v1/notifications/testOperator-triggered bounded test through one configured webhook, email or Telegram channel

Опциональный компьютерный ретранслятор

POST/api/v1/computers/sessionStart a session on a configured computer relay
GET/api/v1/computers/healthCheck whether the configured computer relay is reachable
GET/api/v1/computers/snapshotRead the current snapshot from a configured relay
POST/api/v1/computers/navigateNavigate the configured computer relay
POST/api/v1/computers/clickClick through the configured computer relay
POST/api/v1/computers/typeType through the configured computer relay
POST/api/v1/computers/keySend a keyboard action through a configured relay
POST/api/v1/computers/secretEnter a secret through a configured relay without returning or logging its value
GET/api/v1/computers/screenshotCapture a screenshot from a configured relay
GET / POST/api/v1/computers/tabs*List, open, activate, or close tabs on a configured browser relay
POST/api/v1/computers/control/take|releaseTake or release operator control of the configured relay
GET / PUT / DELETE/api/v1/computers/files*List, read, write, or delete confined workspace files on the relay
GET/api/v1/computersList configured computers; supervisor lifecycle requires COMPUTER_TOKEN

Система

GET/healthПроверка живости
GET/metricsМетрики Prometheus
GET/dashboardWeb-дашборд в одном файле: сессии, дерево агентов, память, задачи, живой SSE

Пример

Запустите сессию и управляйте mid-run

Сессии стартуют асинхронно. Следите за прогрессом в SSE-потоке, затем управляйте или отвечайте на вопросы, пока агенты ещё работают.

curl -X POST localhost:8080/api/v1/sessions \
  -H "Content-Type: application/json" \
  -d '{"query":"Find VPs of Engineering
       at Series B fintech startups in SF"}'

# follow the live event stream
curl -N localhost:8080/api/v1/sessions/abc/events

# redirect mid-run
curl -X POST localhost:8080/api/v1/sessions/abc/steer \
  -d '{"message":"Focus on Berlin instead"}'

Наблюдаемость

Метрики Prometheus

Собирайте /metrics с вашего селф-хостед рантайма для телеметрии запросов, сессий и инструментов. Аутентифицированный API также предоставляет /api/v1/observability/summary для живых счетчиков и аудита безопасности.

МетрикаТипЧто считает
pr_http_requests_totalcounterrequests by route and status
pr_request_duration_secondshistogramlatency distribution
pr_sessions_totalcountersessions started
pr_sessions_activegaugesessions running right now
pr_agents_spawned_totalcountersub-agents across all trees
pr_tool_calls_totalcountertool executions by name
pr_tokens_used_totalcounterLLM tokens consumed
Prometheus

/metrics отдаёт счётчики запросов, задержки, метрики сессий и инструментов для дашбордов Grafana.

SSE-стриминг

Дельта-токены, вызовы инструментов, запуск/завершение агентов и находки приходят как server-sent events — без поллинга.

Веб-дашборд

GET /dashboard отдаёт одностраничный HTML-дашборд: сессии, дерево агентов, память, джобы, живая лента событий.

CORS

Доступ между origin настраивается через [server]-конфиг — ограничьте origin в продакшене.