| scope | No | spawn: role@location, repeatable; role is viewer, editor or manager (reader, writer and approver are deprecated aliases), e.g. editor@specs/api.md or viewer@* | |
| action | Yes | what to do; each action takes the arguments its line names | |
| reason | No | why you are doing this, in one line (at most 200 characters); recorded with the event and exported with the log | |
| target | No | update: an identity id; defaults to you | |
| vendor | No | spawn, set_card: who makes the agent, e.g. anthropic | |
| display | No | spawn: the child's name | |
| purpose | No | spawn, set_card: what it is for | |
| lifecycle | No | spawn: persistent, intermittent (default) or ephemeral | |
| risk_tier | No | spawn, set_card: low, standard (default) or high | |
| expires_at | No | spawn: ISO time the child ends; never later than yours | |
| environment | No | spawn, set_card: where it runs, e.g. ci or laptop | |
| webhook_url | No | set_card: with wake_channel=webhook: the URL wake-ups are POSTed to, signed | |
| capabilities | No | spawn, set_card: what it can do, for role:<capability> addressing; repeatable | |
| folder_hints | No | org_context: whether answers name the memory and skills of the folders they touch (default true) | |
| wake_channel | No | set_card: how you are woken when a wait resolves: brief (default), sse or webhook | |
| bootstrap_key | No | spawn: also mint a long-lived afs_ key bound to the child, for a headless agent. Lives until the child's expires_at, at most 365 days; 90 days when the child has no expiry | |
| idempotency_key | No | Any unique string you choose for this write, e.g. a UUID. If you retry the call with the same key and the same arguments, the first answer is returned and nothing is done twice. Reusing a key for a different request is refused. Keys are kept 24 hours. | |
| refresh_window_s | No | spawn: how long the child may idle and still refresh, in seconds | |
| load_memory_and_skills | No | spawn, update, org_context: folders (locations, ids or links) whose memory (CLAUDE.md, AGENTS.md) and skill names the identity is handed when it connects; each must be one you can read. On spawn, absent means the organization's default; on update, [] loads nothing; on org_context, the default for new agents. A console link (`/d/<Name-Slug>-<32 hex>`, whole or just its id) is accepted too. | |