run
Launch instructed Codex, Claude, or OpenCode agents as sessions or one-shot tasks, with sandbox, permission, model, project, and timeout controls.
Instructions
Launch an instructed agent. Sessions return only when reachable; tasks return a non-messageable run handle.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| cwd | No | ||
| mcp | No | Configured MCP server names. Omit for session defaults; [] disables all. Tasks have no defaults. | |
| ttl | No | Stop this tmux session the given duration after launch regardless of activity, as 90s/30m/4h, or 'off'. Off by default. | |
| args | No | ||
| host | No | ||
| kind | No | session | |
| open | No | Open the tmux session in a terminal viewer (macOS only). | |
| level | No | A spelling of a legal permissions/sandbox pair: read is deny + read-only, work is auto + workspace-write, open is bypass + full-access. Naming a level and either flag is an error. | |
| model | No | Model for the launch. A bare model id for claude and codex; PROVIDER/MODEL for opencode, where it overrides the configured [opencode] model. Recorded on the run and reported by `list`. | |
| title | No | Terminal title for this tmux session, shown by any terminal attached to it. Defaults to the session's name and runtime once it is reachable; the agent's own title is shown instead only with [session] title_from_agent. Control characters are stripped and it is capped at 100 characters. Refused for tasks and for pty or macos-terminal hosts. | |
| plugin | No | Configured OpenCode plugin names. Omit for session defaults; [] disables all. OpenCode only. | |
| prompt | Yes | ||
| options | No | Muster-side launch options. auto-approve-path records the launch directory as trusted in the profile the agent will use, so its one-time dialog does not block the launch; refused for a runtime with no trust gate, and refused if the directory ships hooks or MCP servers. accept-bypass-warning accepts Claude's one-time Bypass Permissions warning for a bypass launch (level open); refused for other runtimes and without bypass permissions. Not expressible remotely. | |
| project | No | A project named in config.toml, used instead of cwd. Naming both is an error. | |
| runtime | Yes | ||
| sandbox | No | Defaults to config (read-only). Full access requires config authorization. | |
| identity | No | A named identity created by `muster setup-identity`; the agent runs as that account instead of inheriting the ambient environment. A non-local requester is bounded by its profile's identities. | |
| terminal | No | Viewer app; requires open. Auto uses Terminal.app. | |
| requestKey | No | Caller-owned identity for this launch. Repeating it returns the launch it already produced instead of starting another; repeating it with different parameters is refused. | |
| idleTimeout | No | Stop this tmux session after the given inactivity, as 90s/30m/4h, or 'off'. Off by default. Refused for tasks and for pty or macos-terminal hosts, which do not outlive their parent. | |
| permissions | No | Defaults to config (deny). Auto requires workspace-write; bypass requires authorized full-access. |