Agents API

Agents API

Run LatentCode agents in the cloud from your own code.

The Agents API gives your application the LatentCode agent as a hosted service. LatentStack runs each agent in its own sandbox, keeps its conversation, pauses it when it's idle and brings it back when you write to it again. Your application sends tasks and reads what the agent does.

An agent can read and edit code, run commands and tests, and use git in a workspace of its own. That workspace can be empty or hold one or more of your GitHub repositories. When the agent is done, you get back a patch.

Pricing

The agent's model calls are billed at the selected model's rates, against your organization and tier, like any other LatentStack request. They appear in My Usage.

Try an example

Core concepts

The Agents API is built around four concepts:

  • Agent: the model, instructions and permissions the agent works with.
  • Environment: where the agent works. Either an empty workspace, or up to six GitHub repositories on the branch, tag or commit you choose.
  • Session: a durable instance of an agent. It works on tasks, responds to your input, and survives pauses.
  • Events: everything the agent does, as a numbered stream you can follow live and resume from.

A session from start to finish

  1. 1
    Create a session.
    Configure the agent and its environment. LatentStack starts a sandbox and clones your repositories.
  2. 2
    Give it a task.
    Your first message starts a run as soon as the sandbox is ready, usually within seconds.
  3. 3
    Follow progress.
    Stream events, or wait until the session settles. Answer approvals when the agent asks.
  4. 4
    Continue or steer.
    Send another message to the same session, or guide the agent while it is working.
  5. 5
    Collect the result.
    Read the agent's reply and download its patch, then delete the session.
A complete session
import { LatentStack } from "@latentcode/sandbox-agents"

const client = new LatentStack({ apiKey: process.env.LS_API_KEY! })
const sessions = client.agents.sessions

const session = await sessions.create({
  agent: {
    model: "bedrock/us.anthropic.claude-sonnet-5",
    instructions: "Answer briefly.",
    // An empty sandbox has nothing to protect, so let the agent run commands without asking.
    permissions: [{ action: "bash", effect: "allow" }],
  },
  input: "Write a Python script that prints the first 10 prime numbers, run it, and show me the output.",
})

for await (const event of sessions.events(session.id)) {
  if (event.type === "tool.called") console.log("tool:", event.data?.tool)
  if (event.type === "text.ended") console.log(event.data?.text)
  if (event.type === "run.completed" || event.type === "run.failed") break
}

const { last_seq } = await sessions.get(session.id)
await sessions.message(session.id, "Now make it print the first 20.")

for await (const event of sessions.events(session.id, { after: last_seq })) {
  if (event.type === "text.ended") console.log(event.data?.text)
  if (event.type === "run.completed" || event.type === "run.failed") break
}

await sessions.delete(session.id)

What the hosted agent provides

  • Reading, searching and editing code in its own workspace.
  • Running commands and tests in a sandbox.
  • Working across several repositories at once, with one patch per repository.
  • Asking before risky actions, under permission rules you set.
  • Steering while it works, and queueing follow-up tasks.
  • Summarizing earlier work to keep long sessions within the model's context window.
  • Pausing when idle and resuming later with its conversation and files intact.

Agents use the models, tiers and guardrails your organization already has. Official clients are available for TypeScript and Python.

Data and access

  • A session is visible only to the person who created it, in the organization it was created in.
  • Repository access uses the GitHub token saved on your Agent Settings page. The token stays with LatentStack and is never placed in the sandbox, and agents can't push. You decide what to do with the patch.
  • Authenticate with your personal ls- API key. Keep it on your server; never ship it to a browser.