github_copilot_sdk/generated/session_events.rs
1//! Auto-generated from session-events.schema.json — do not edit manually.
2
3#![allow(deprecated)]
4
5use std::collections::HashMap;
6
7use serde::{Deserialize, Serialize};
8
9use crate::types::{RequestId, SessionId};
10
11/// Identifies the kind of session event.
12#[derive(Debug, Clone, Default, PartialEq, Eq, Hash, Serialize, Deserialize)]
13pub enum SessionEventType {
14 #[serde(rename = "session.start")]
15 SessionStart,
16 #[serde(rename = "session.resume")]
17 SessionResume,
18 #[serde(rename = "session.remote_steerable_changed")]
19 SessionRemoteSteerableChanged,
20 #[serde(rename = "session.error")]
21 SessionError,
22 #[serde(rename = "session.idle")]
23 SessionIdle,
24 #[serde(rename = "session.title_changed")]
25 SessionTitleChanged,
26 #[serde(rename = "session.schedule_created")]
27 SessionScheduleCreated,
28 #[serde(rename = "session.schedule_cancelled")]
29 SessionScheduleCancelled,
30 #[serde(rename = "session.schedule_rearmed")]
31 SessionScheduleRearmed,
32 #[serde(rename = "session.autopilot_objective_changed")]
33 SessionAutopilotObjectiveChanged,
34 #[serde(rename = "session.info")]
35 SessionInfo,
36 #[serde(rename = "session.indexed_search")]
37 SessionIndexedSearch,
38 #[serde(rename = "session.warning")]
39 SessionWarning,
40 #[serde(rename = "session.model_change")]
41 SessionModelChange,
42 #[serde(rename = "session.model_deselected")]
43 SessionModelDeselected,
44 ///
45 /// <div class="warning">
46 ///
47 /// **Experimental.** This type is part of an experimental wire-protocol surface
48 /// and may change or be removed in future SDK or CLI releases.
49 ///
50 /// </div>
51 #[serde(rename = "session.auto_tier_recommendation")]
52 SessionAutoTierRecommendation,
53 #[serde(rename = "session.auto_tier_switch_failed")]
54 SessionAutoTierSwitchFailed,
55 #[serde(rename = "session.mode_changed")]
56 SessionModeChanged,
57 #[serde(rename = "session.mode_notice_delivered")]
58 SessionModeNoticeDelivered,
59 #[serde(rename = "session.session_limits_changed")]
60 SessionSessionLimitsChanged,
61 ///
62 /// <div class="warning">
63 ///
64 /// **Experimental.** This type is part of an experimental wire-protocol surface
65 /// and may change or be removed in future SDK or CLI releases.
66 ///
67 /// </div>
68 #[serde(rename = "session.permissions_changed")]
69 SessionPermissionsChanged,
70 #[serde(rename = "session.plan_changed")]
71 SessionPlanChanged,
72 #[serde(rename = "session.todos_changed")]
73 SessionTodosChanged,
74 #[serde(rename = "session.workspace_file_changed")]
75 SessionWorkspaceFileChanged,
76 #[serde(rename = "session.handoff")]
77 SessionHandoff,
78 #[serde(rename = "session.truncation")]
79 SessionTruncation,
80 #[serde(rename = "session.snapshot_rewind")]
81 SessionSnapshotRewind,
82 #[serde(rename = "session.shutdown")]
83 SessionShutdown,
84 #[serde(rename = "session.usage_checkpoint")]
85 SessionUsageCheckpoint,
86 #[serde(rename = "session.context_changed")]
87 SessionContextChanged,
88 #[serde(rename = "session.usage_info")]
89 SessionUsageInfo,
90 #[serde(rename = "session.context_cleared")]
91 SessionContextCleared,
92 #[serde(rename = "session.compaction_start")]
93 SessionCompactionStart,
94 #[serde(rename = "session.compaction_complete")]
95 SessionCompactionComplete,
96 #[serde(rename = "session.task_complete")]
97 SessionTaskComplete,
98 ///
99 /// <div class="warning">
100 ///
101 /// **Experimental.** This type is part of an experimental wire-protocol surface
102 /// and may change or be removed in future SDK or CLI releases.
103 ///
104 /// </div>
105 #[serde(rename = "session.completion_receipt")]
106 SessionCompletionReceipt,
107 ///
108 /// <div class="warning">
109 ///
110 /// **Experimental.** This type is part of an experimental wire-protocol surface
111 /// and may change or be removed in future SDK or CLI releases.
112 ///
113 /// </div>
114 #[serde(rename = "session.fusion_route_started")]
115 SessionFusionRouteStarted,
116 ///
117 /// <div class="warning">
118 ///
119 /// **Experimental.** This type is part of an experimental wire-protocol surface
120 /// and may change or be removed in future SDK or CLI releases.
121 ///
122 /// </div>
123 #[serde(rename = "session.fusion_route_failed")]
124 SessionFusionRouteFailed,
125 ///
126 /// <div class="warning">
127 ///
128 /// **Experimental.** This type is part of an experimental wire-protocol surface
129 /// and may change or be removed in future SDK or CLI releases.
130 ///
131 /// </div>
132 #[serde(rename = "session.fusion_resolved")]
133 SessionFusionResolved,
134 ///
135 /// <div class="warning">
136 ///
137 /// **Experimental.** This type is part of an experimental wire-protocol surface
138 /// and may change or be removed in future SDK or CLI releases.
139 ///
140 /// </div>
141 #[serde(rename = "session.fusion_completed")]
142 SessionFusionCompleted,
143 #[serde(rename = "session.permission_recovery")]
144 SessionPermissionRecovery,
145 #[serde(rename = "user.message")]
146 UserMessage,
147 #[serde(rename = "pending_messages.modified")]
148 PendingMessagesModified,
149 #[serde(rename = "assistant.turn_start")]
150 AssistantTurnStart,
151 #[serde(rename = "assistant.turn_retry")]
152 AssistantTurnRetry,
153 #[serde(rename = "agent.interrupted")]
154 AgentInterrupted,
155 #[serde(rename = "assistant.intent")]
156 AssistantIntent,
157 ///
158 /// <div class="warning">
159 ///
160 /// **Experimental.** This type is part of an experimental wire-protocol surface
161 /// and may change or be removed in future SDK or CLI releases.
162 ///
163 /// </div>
164 #[serde(rename = "assistant.fusion_phase_started")]
165 AssistantFusionPhaseStarted,
166 ///
167 /// <div class="warning">
168 ///
169 /// **Experimental.** This type is part of an experimental wire-protocol surface
170 /// and may change or be removed in future SDK or CLI releases.
171 ///
172 /// </div>
173 #[serde(rename = "assistant.fusion_phase_activity")]
174 AssistantFusionPhaseActivity,
175 ///
176 /// <div class="warning">
177 ///
178 /// **Experimental.** This type is part of an experimental wire-protocol surface
179 /// and may change or be removed in future SDK or CLI releases.
180 ///
181 /// </div>
182 #[serde(rename = "assistant.fusion_phase_completed")]
183 AssistantFusionPhaseCompleted,
184 ///
185 /// <div class="warning">
186 ///
187 /// **Experimental.** This type is part of an experimental wire-protocol surface
188 /// and may change or be removed in future SDK or CLI releases.
189 ///
190 /// </div>
191 #[serde(rename = "assistant.fusion_phase_failed")]
192 AssistantFusionPhaseFailed,
193 #[serde(rename = "assistant.server_tool_progress")]
194 AssistantServerToolProgress,
195 #[serde(rename = "assistant.reasoning")]
196 AssistantReasoning,
197 #[serde(rename = "assistant.reasoning_delta")]
198 AssistantReasoningDelta,
199 #[serde(rename = "assistant.tool_call_delta")]
200 AssistantToolCallDelta,
201 #[serde(rename = "assistant.streaming_delta")]
202 AssistantStreamingDelta,
203 #[serde(rename = "assistant.message")]
204 AssistantMessage,
205 #[serde(rename = "assistant.message_start")]
206 AssistantMessageStart,
207 #[serde(rename = "assistant.message_delta")]
208 AssistantMessageDelta,
209 #[serde(rename = "assistant.turn_end")]
210 AssistantTurnEnd,
211 #[serde(rename = "assistant.idle")]
212 AssistantIdle,
213 #[serde(rename = "assistant.usage")]
214 AssistantUsage,
215 #[serde(rename = "prompt_cache_break")]
216 PromptCacheBreak,
217 #[serde(rename = "model.call_failure")]
218 ModelCallFailure,
219 #[serde(rename = "model.call_finished")]
220 ModelCallFinished,
221 #[serde(rename = "model.call_start")]
222 ModelCallStart,
223 #[serde(rename = "abort")]
224 Abort,
225 #[serde(rename = "tool.user_requested")]
226 ToolUserRequested,
227 #[serde(rename = "tool.execution_start")]
228 ToolExecutionStart,
229 #[serde(rename = "tool.execution_partial_result")]
230 ToolExecutionPartialResult,
231 #[serde(rename = "tool.execution_progress")]
232 ToolExecutionProgress,
233 #[serde(rename = "tool.execution_complete")]
234 ToolExecutionComplete,
235 #[serde(rename = "tool_search.activated")]
236 ToolSearchActivated,
237 #[serde(rename = "skill.invoked")]
238 SkillInvoked,
239 ///
240 /// <div class="warning">
241 ///
242 /// **Experimental.** This type is part of an experimental wire-protocol surface
243 /// and may change or be removed in future SDK or CLI releases.
244 ///
245 /// </div>
246 #[serde(rename = "skill.invoked_ref")]
247 SkillInvokedRef,
248 ///
249 /// <div class="warning">
250 ///
251 /// **Experimental.** This type is part of an experimental wire-protocol surface
252 /// and may change or be removed in future SDK or CLI releases.
253 ///
254 /// </div>
255 #[serde(rename = "skill.context_delivered")]
256 SkillContextDelivered,
257 ///
258 /// <div class="warning">
259 ///
260 /// **Experimental.** This type is part of an experimental wire-protocol surface
261 /// and may change or be removed in future SDK or CLI releases.
262 ///
263 /// </div>
264 #[serde(rename = "skill.context_delivered_ref")]
265 SkillContextDeliveredRef,
266 #[serde(rename = "sandbox.decision")]
267 SandboxDecision,
268 #[serde(rename = "subagent.started")]
269 SubagentStarted,
270 #[serde(rename = "subagent.configured")]
271 SubagentConfigured,
272 #[serde(rename = "subagent.completed")]
273 SubagentCompleted,
274 #[serde(rename = "subagent.failed")]
275 SubagentFailed,
276 #[serde(rename = "subagent.selected")]
277 SubagentSelected,
278 #[serde(rename = "subagent.deselected")]
279 SubagentDeselected,
280 #[serde(rename = "hook.start")]
281 HookStart,
282 #[serde(rename = "hook.end")]
283 HookEnd,
284 #[serde(rename = "hook.progress")]
285 HookProgress,
286 ///
287 /// <div class="warning">
288 ///
289 /// **Experimental.** This type is part of an experimental wire-protocol surface
290 /// and may change or be removed in future SDK or CLI releases.
291 ///
292 /// </div>
293 #[serde(rename = "session.binary_asset")]
294 SessionBinaryAsset,
295 #[serde(rename = "system.message")]
296 SystemMessage,
297 #[serde(rename = "system.notification")]
298 SystemNotification,
299 #[serde(rename = "permission.requested")]
300 PermissionRequested,
301 #[serde(rename = "permission.completed")]
302 PermissionCompleted,
303 ///
304 /// <div class="warning">
305 ///
306 /// **Experimental.** This type is part of an experimental wire-protocol surface
307 /// and may change or be removed in future SDK or CLI releases.
308 ///
309 /// </div>
310 #[serde(rename = "permission.carriedForward")]
311 PermissionCarriedForward,
312 ///
313 /// <div class="warning">
314 ///
315 /// **Experimental.** This type is part of an experimental wire-protocol surface
316 /// and may change or be removed in future SDK or CLI releases.
317 ///
318 /// </div>
319 #[serde(rename = "permission.messageAuthorization")]
320 PermissionMessageAuthorization,
321 ///
322 /// <div class="warning">
323 ///
324 /// **Experimental.** This type is part of an experimental wire-protocol surface
325 /// and may change or be removed in future SDK or CLI releases.
326 ///
327 /// </div>
328 #[serde(rename = "permission.messageAuthorizationRead")]
329 PermissionMessageAuthorizationRead,
330 ///
331 /// <div class="warning">
332 ///
333 /// **Experimental.** This type is part of an experimental wire-protocol surface
334 /// and may change or be removed in future SDK or CLI releases.
335 ///
336 /// </div>
337 #[serde(rename = "permission.messageAuthorizationDegraded")]
338 PermissionMessageAuthorizationDegraded,
339 ///
340 /// <div class="warning">
341 ///
342 /// **Experimental.** This type is part of an experimental wire-protocol surface
343 /// and may change or be removed in future SDK or CLI releases.
344 ///
345 /// </div>
346 #[serde(rename = "permission.assentDetected")]
347 PermissionAssentDetected,
348 ///
349 /// <div class="warning">
350 ///
351 /// **Experimental.** This type is part of an experimental wire-protocol surface
352 /// and may change or be removed in future SDK or CLI releases.
353 ///
354 /// </div>
355 #[serde(rename = "permission.contextualAuthorization")]
356 PermissionContextualAuthorization,
357 #[serde(rename = "user_input.requested")]
358 UserInputRequested,
359 #[serde(rename = "user_input.completed")]
360 UserInputCompleted,
361 #[serde(rename = "elicitation.requested")]
362 ElicitationRequested,
363 #[serde(rename = "elicitation.completed")]
364 ElicitationCompleted,
365 #[serde(rename = "sampling.requested")]
366 SamplingRequested,
367 #[serde(rename = "sampling.completed")]
368 SamplingCompleted,
369 #[serde(rename = "mcp.oauth_required")]
370 McpOauthRequired,
371 #[serde(rename = "mcp.oauth_completed")]
372 McpOauthCompleted,
373 #[serde(rename = "mcp.headers_refresh_required")]
374 McpHeadersRefreshRequired,
375 #[serde(rename = "mcp.headers_refresh_completed")]
376 McpHeadersRefreshCompleted,
377 #[serde(rename = "session.custom_notification")]
378 SessionCustomNotification,
379 ///
380 /// <div class="warning">
381 ///
382 /// **Experimental.** This type is part of an experimental wire-protocol surface
383 /// and may change or be removed in future SDK or CLI releases.
384 ///
385 /// </div>
386 #[serde(rename = "ui.ephemeral_query")]
387 UiEphemeralQuery,
388 #[serde(rename = "external_tool.requested")]
389 ExternalToolRequested,
390 #[serde(rename = "external_tool.completed")]
391 ExternalToolCompleted,
392 #[serde(rename = "command.queued")]
393 CommandQueued,
394 #[serde(rename = "command.execute")]
395 CommandExecute,
396 #[serde(rename = "command.completed")]
397 CommandCompleted,
398 #[serde(rename = "auto_mode_switch.requested")]
399 AutoModeSwitchRequested,
400 #[serde(rename = "auto_mode_switch.completed")]
401 AutoModeSwitchCompleted,
402 #[serde(rename = "session_limits_exhausted.requested")]
403 SessionLimitsExhaustedRequested,
404 #[serde(rename = "session_limits_exhausted.completed")]
405 SessionLimitsExhaustedCompleted,
406 ///
407 /// <div class="warning">
408 ///
409 /// **Experimental.** This type is part of an experimental wire-protocol surface
410 /// and may change or be removed in future SDK or CLI releases.
411 ///
412 /// </div>
413 #[serde(rename = "session.auto_mode_resolved")]
414 SessionAutoModeResolved,
415 ///
416 /// <div class="warning">
417 ///
418 /// **Experimental.** This type is part of an experimental wire-protocol surface
419 /// and may change or be removed in future SDK or CLI releases.
420 ///
421 /// </div>
422 #[serde(rename = "session.managed_settings_resolved")]
423 SessionManagedSettingsResolved,
424 ///
425 /// <div class="warning">
426 ///
427 /// **Experimental.** This type is part of an experimental wire-protocol surface
428 /// and may change or be removed in future SDK or CLI releases.
429 ///
430 /// </div>
431 #[serde(rename = "session.managed_settings_enforced")]
432 SessionManagedSettingsEnforced,
433 #[serde(rename = "commands.changed")]
434 CommandsChanged,
435 #[serde(rename = "capabilities.changed")]
436 CapabilitiesChanged,
437 #[serde(rename = "exit_plan_mode.requested")]
438 ExitPlanModeRequested,
439 #[serde(rename = "exit_plan_mode.completed")]
440 ExitPlanModeCompleted,
441 #[serde(rename = "session.tools_updated")]
442 SessionToolsUpdated,
443 #[serde(rename = "session.background_tasks_changed")]
444 SessionBackgroundTasksChanged,
445 ///
446 /// <div class="warning">
447 ///
448 /// **Experimental.** This type is part of an experimental wire-protocol surface
449 /// and may change or be removed in future SDK or CLI releases.
450 ///
451 /// </div>
452 #[serde(rename = "workflow.run_updated")]
453 WorkflowRunUpdated,
454 ///
455 /// <div class="warning">
456 ///
457 /// **Experimental.** This type is part of an experimental wire-protocol surface
458 /// and may change or be removed in future SDK or CLI releases.
459 ///
460 /// </div>
461 #[serde(rename = "workflow.run_started")]
462 WorkflowRunStarted,
463 ///
464 /// <div class="warning">
465 ///
466 /// **Experimental.** This type is part of an experimental wire-protocol surface
467 /// and may change or be removed in future SDK or CLI releases.
468 ///
469 /// </div>
470 #[serde(rename = "workflow.run_settled")]
471 WorkflowRunSettled,
472 #[serde(rename = "session.skills_loaded")]
473 SessionSkillsLoaded,
474 #[serde(rename = "session.custom_agents_updated")]
475 SessionCustomAgentsUpdated,
476 #[serde(rename = "session.mcp_servers_loaded")]
477 SessionMcpServersLoaded,
478 #[serde(rename = "session.mcp_server_status_changed")]
479 SessionMcpServerStatusChanged,
480 #[serde(rename = "session.mcp_server_removed")]
481 SessionMcpServerRemoved,
482 #[serde(rename = "session.mcp_server_needs_reconnect")]
483 SessionMcpServerNeedsReconnect,
484 #[serde(rename = "mcp.tools.list_changed")]
485 McpToolsListChanged,
486 #[serde(rename = "mcp.resources.list_changed")]
487 McpResourcesListChanged,
488 #[serde(rename = "mcp.prompts.list_changed")]
489 McpPromptsListChanged,
490 #[serde(rename = "session.extensions_loaded")]
491 SessionExtensionsLoaded,
492 ///
493 /// <div class="warning">
494 ///
495 /// **Experimental.** This type is part of an experimental wire-protocol surface
496 /// and may change or be removed in future SDK or CLI releases.
497 ///
498 /// </div>
499 #[serde(rename = "session.canvas.opened")]
500 SessionCanvasOpened,
501 ///
502 /// <div class="warning">
503 ///
504 /// **Experimental.** This type is part of an experimental wire-protocol surface
505 /// and may change or be removed in future SDK or CLI releases.
506 ///
507 /// </div>
508 #[serde(rename = "session.canvas.registry_changed")]
509 SessionCanvasRegistryChanged,
510 ///
511 /// <div class="warning">
512 ///
513 /// **Experimental.** This type is part of an experimental wire-protocol surface
514 /// and may change or be removed in future SDK or CLI releases.
515 ///
516 /// </div>
517 #[serde(rename = "session.canvas.closed")]
518 SessionCanvasClosed,
519 ///
520 /// <div class="warning">
521 ///
522 /// **Experimental.** This type is part of an experimental wire-protocol surface
523 /// and may change or be removed in future SDK or CLI releases.
524 ///
525 /// </div>
526 #[serde(rename = "session.canvas.unavailable")]
527 SessionCanvasUnavailable,
528 ///
529 /// <div class="warning">
530 ///
531 /// **Experimental.** This type is part of an experimental wire-protocol surface
532 /// and may change or be removed in future SDK or CLI releases.
533 ///
534 /// </div>
535 #[serde(rename = "session.canvas.recorded")]
536 SessionCanvasRecorded,
537 ///
538 /// <div class="warning">
539 ///
540 /// **Experimental.** This type is part of an experimental wire-protocol surface
541 /// and may change or be removed in future SDK or CLI releases.
542 ///
543 /// </div>
544 #[serde(rename = "session.canvas.removed")]
545 SessionCanvasRemoved,
546 #[serde(rename = "session.extensions.attachments_pushed")]
547 SessionExtensionsAttachmentsPushed,
548 #[serde(rename = "mcp_app.tool_call_complete")]
549 McpAppToolCallComplete,
550 /// Unknown event type for forward compatibility.
551 #[default]
552 #[serde(other)]
553 Unknown,
554}
555
556/// Typed session event data, discriminated by the event `type` field.
557///
558/// Use with [`TypedSessionEvent`] for fully typed event handling.
559#[derive(Debug, Clone, Serialize, Deserialize)]
560#[serde(tag = "type", content = "data")]
561pub enum SessionEventData {
562 #[serde(rename = "session.start")]
563 SessionStart(SessionStartData),
564 #[serde(rename = "session.resume")]
565 SessionResume(SessionResumeData),
566 #[serde(rename = "session.remote_steerable_changed")]
567 SessionRemoteSteerableChanged(SessionRemoteSteerableChangedData),
568 #[serde(rename = "session.error")]
569 SessionError(SessionErrorData),
570 #[serde(rename = "session.idle")]
571 SessionIdle(SessionIdleData),
572 #[serde(rename = "session.title_changed")]
573 SessionTitleChanged(SessionTitleChangedData),
574 #[serde(rename = "session.schedule_created")]
575 SessionScheduleCreated(SessionScheduleCreatedData),
576 #[serde(rename = "session.schedule_cancelled")]
577 SessionScheduleCancelled(SessionScheduleCancelledData),
578 #[serde(rename = "session.schedule_rearmed")]
579 SessionScheduleRearmed(SessionScheduleRearmedData),
580 #[serde(rename = "session.autopilot_objective_changed")]
581 SessionAutopilotObjectiveChanged(SessionAutopilotObjectiveChangedData),
582 #[serde(rename = "session.info")]
583 SessionInfo(SessionInfoData),
584 #[serde(rename = "session.indexed_search")]
585 SessionIndexedSearch(SessionIndexedSearchData),
586 #[serde(rename = "session.warning")]
587 SessionWarning(SessionWarningData),
588 #[serde(rename = "session.model_change")]
589 SessionModelChange(SessionModelChangeData),
590 #[serde(rename = "session.model_deselected")]
591 SessionModelDeselected(SessionModelDeselectedData),
592 ///
593 /// <div class="warning">
594 ///
595 /// **Experimental.** This type is part of an experimental wire-protocol surface
596 /// and may change or be removed in future SDK or CLI releases.
597 ///
598 /// </div>
599 #[serde(rename = "session.auto_tier_recommendation")]
600 SessionAutoTierRecommendation(SessionAutoTierRecommendationData),
601 #[serde(rename = "session.auto_tier_switch_failed")]
602 SessionAutoTierSwitchFailed(SessionAutoTierSwitchFailedData),
603 #[serde(rename = "session.mode_changed")]
604 SessionModeChanged(SessionModeChangedData),
605 #[serde(rename = "session.mode_notice_delivered")]
606 SessionModeNoticeDelivered(SessionModeNoticeDeliveredData),
607 #[serde(rename = "session.session_limits_changed")]
608 SessionSessionLimitsChanged(SessionSessionLimitsChangedData),
609 ///
610 /// <div class="warning">
611 ///
612 /// **Experimental.** This type is part of an experimental wire-protocol surface
613 /// and may change or be removed in future SDK or CLI releases.
614 ///
615 /// </div>
616 #[serde(rename = "session.permissions_changed")]
617 SessionPermissionsChanged(SessionPermissionsChangedData),
618 #[serde(rename = "session.plan_changed")]
619 SessionPlanChanged(SessionPlanChangedData),
620 #[serde(rename = "session.todos_changed")]
621 SessionTodosChanged(SessionTodosChangedData),
622 #[serde(rename = "session.workspace_file_changed")]
623 SessionWorkspaceFileChanged(SessionWorkspaceFileChangedData),
624 #[serde(rename = "session.handoff")]
625 SessionHandoff(SessionHandoffData),
626 #[serde(rename = "session.truncation")]
627 SessionTruncation(SessionTruncationData),
628 #[serde(rename = "session.snapshot_rewind")]
629 SessionSnapshotRewind(SessionSnapshotRewindData),
630 #[serde(rename = "session.shutdown")]
631 SessionShutdown(SessionShutdownData),
632 #[serde(rename = "session.usage_checkpoint")]
633 SessionUsageCheckpoint(SessionUsageCheckpointData),
634 #[serde(rename = "session.context_changed")]
635 SessionContextChanged(SessionContextChangedData),
636 #[serde(rename = "session.usage_info")]
637 SessionUsageInfo(SessionUsageInfoData),
638 #[serde(rename = "session.context_cleared")]
639 SessionContextCleared(SessionContextClearedData),
640 #[serde(rename = "session.compaction_start")]
641 SessionCompactionStart(SessionCompactionStartData),
642 #[serde(rename = "session.compaction_complete")]
643 SessionCompactionComplete(SessionCompactionCompleteData),
644 #[serde(rename = "session.task_complete")]
645 SessionTaskComplete(SessionTaskCompleteData),
646 ///
647 /// <div class="warning">
648 ///
649 /// **Experimental.** This type is part of an experimental wire-protocol surface
650 /// and may change or be removed in future SDK or CLI releases.
651 ///
652 /// </div>
653 #[serde(rename = "session.completion_receipt")]
654 SessionCompletionReceipt(SessionCompletionReceiptData),
655 ///
656 /// <div class="warning">
657 ///
658 /// **Experimental.** This type is part of an experimental wire-protocol surface
659 /// and may change or be removed in future SDK or CLI releases.
660 ///
661 /// </div>
662 #[serde(rename = "session.fusion_route_started")]
663 SessionFusionRouteStarted(SessionFusionRouteStartedData),
664 ///
665 /// <div class="warning">
666 ///
667 /// **Experimental.** This type is part of an experimental wire-protocol surface
668 /// and may change or be removed in future SDK or CLI releases.
669 ///
670 /// </div>
671 #[serde(rename = "session.fusion_route_failed")]
672 SessionFusionRouteFailed(SessionFusionRouteFailedData),
673 ///
674 /// <div class="warning">
675 ///
676 /// **Experimental.** This type is part of an experimental wire-protocol surface
677 /// and may change or be removed in future SDK or CLI releases.
678 ///
679 /// </div>
680 #[serde(rename = "session.fusion_resolved")]
681 SessionFusionResolved(SessionFusionResolvedData),
682 ///
683 /// <div class="warning">
684 ///
685 /// **Experimental.** This type is part of an experimental wire-protocol surface
686 /// and may change or be removed in future SDK or CLI releases.
687 ///
688 /// </div>
689 #[serde(rename = "session.fusion_completed")]
690 SessionFusionCompleted(SessionFusionCompletedData),
691 #[serde(rename = "session.permission_recovery")]
692 SessionPermissionRecovery(SessionPermissionRecoveryData),
693 #[serde(rename = "user.message")]
694 UserMessage(UserMessageData),
695 #[serde(rename = "pending_messages.modified")]
696 PendingMessagesModified(PendingMessagesModifiedData),
697 #[serde(rename = "assistant.turn_start")]
698 AssistantTurnStart(AssistantTurnStartData),
699 #[serde(rename = "assistant.turn_retry")]
700 AssistantTurnRetry(AssistantTurnRetryData),
701 #[serde(rename = "agent.interrupted")]
702 AgentInterrupted(AgentInterruptedData),
703 #[serde(rename = "assistant.intent")]
704 AssistantIntent(AssistantIntentData),
705 ///
706 /// <div class="warning">
707 ///
708 /// **Experimental.** This type is part of an experimental wire-protocol surface
709 /// and may change or be removed in future SDK or CLI releases.
710 ///
711 /// </div>
712 #[serde(rename = "assistant.fusion_phase_started")]
713 AssistantFusionPhaseStarted(AssistantFusionPhaseStartedData),
714 ///
715 /// <div class="warning">
716 ///
717 /// **Experimental.** This type is part of an experimental wire-protocol surface
718 /// and may change or be removed in future SDK or CLI releases.
719 ///
720 /// </div>
721 #[serde(rename = "assistant.fusion_phase_activity")]
722 AssistantFusionPhaseActivity(AssistantFusionPhaseActivityData),
723 ///
724 /// <div class="warning">
725 ///
726 /// **Experimental.** This type is part of an experimental wire-protocol surface
727 /// and may change or be removed in future SDK or CLI releases.
728 ///
729 /// </div>
730 #[serde(rename = "assistant.fusion_phase_completed")]
731 AssistantFusionPhaseCompleted(AssistantFusionPhaseCompletedData),
732 ///
733 /// <div class="warning">
734 ///
735 /// **Experimental.** This type is part of an experimental wire-protocol surface
736 /// and may change or be removed in future SDK or CLI releases.
737 ///
738 /// </div>
739 #[serde(rename = "assistant.fusion_phase_failed")]
740 AssistantFusionPhaseFailed(AssistantFusionPhaseFailedData),
741 #[serde(rename = "assistant.server_tool_progress")]
742 AssistantServerToolProgress(AssistantServerToolProgressData),
743 #[serde(rename = "assistant.reasoning")]
744 AssistantReasoning(AssistantReasoningData),
745 #[serde(rename = "assistant.reasoning_delta")]
746 AssistantReasoningDelta(AssistantReasoningDeltaData),
747 #[serde(rename = "assistant.tool_call_delta")]
748 AssistantToolCallDelta(AssistantToolCallDeltaData),
749 #[serde(rename = "assistant.streaming_delta")]
750 AssistantStreamingDelta(AssistantStreamingDeltaData),
751 #[serde(rename = "assistant.message")]
752 AssistantMessage(AssistantMessageData),
753 #[serde(rename = "assistant.message_start")]
754 AssistantMessageStart(AssistantMessageStartData),
755 #[serde(rename = "assistant.message_delta")]
756 AssistantMessageDelta(AssistantMessageDeltaData),
757 #[serde(rename = "assistant.turn_end")]
758 AssistantTurnEnd(AssistantTurnEndData),
759 #[serde(rename = "assistant.idle")]
760 AssistantIdle(AssistantIdleData),
761 #[serde(rename = "assistant.usage")]
762 AssistantUsage(AssistantUsageData),
763 #[serde(rename = "prompt_cache_break")]
764 PromptCacheBreak(PromptCacheBreakData),
765 #[serde(rename = "model.call_failure")]
766 ModelCallFailure(ModelCallFailureData),
767 #[serde(rename = "model.call_finished")]
768 ModelCallFinished(ModelCallFinishedData),
769 #[serde(rename = "model.call_start")]
770 ModelCallStart(ModelCallStartData),
771 #[serde(rename = "abort")]
772 Abort(AbortData),
773 #[serde(rename = "tool.user_requested")]
774 ToolUserRequested(ToolUserRequestedData),
775 #[serde(rename = "tool.execution_start")]
776 ToolExecutionStart(ToolExecutionStartData),
777 #[serde(rename = "tool.execution_partial_result")]
778 ToolExecutionPartialResult(ToolExecutionPartialResultData),
779 #[serde(rename = "tool.execution_progress")]
780 ToolExecutionProgress(ToolExecutionProgressData),
781 #[serde(rename = "tool.execution_complete")]
782 ToolExecutionComplete(ToolExecutionCompleteData),
783 #[serde(rename = "tool_search.activated")]
784 ToolSearchActivated(ToolSearchActivatedData),
785 #[serde(rename = "skill.invoked")]
786 SkillInvoked(SkillInvokedData),
787 #[serde(rename = "skill.invoked_ref")]
788 SkillInvokedRef(SkillInvokedRefData),
789 #[serde(rename = "skill.context_delivered")]
790 SkillContextDelivered(SkillContextDeliveredData),
791 #[serde(rename = "skill.context_delivered_ref")]
792 SkillContextDeliveredRef(SkillContextDeliveredRefData),
793 #[serde(rename = "sandbox.decision")]
794 SandboxDecision(SandboxDecisionData),
795 #[serde(rename = "subagent.started")]
796 SubagentStarted(SubagentStartedData),
797 #[serde(rename = "subagent.configured")]
798 SubagentConfigured(SubagentConfiguredData),
799 #[serde(rename = "subagent.completed")]
800 SubagentCompleted(SubagentCompletedData),
801 #[serde(rename = "subagent.failed")]
802 SubagentFailed(SubagentFailedData),
803 #[serde(rename = "subagent.selected")]
804 SubagentSelected(SubagentSelectedData),
805 #[serde(rename = "subagent.deselected")]
806 SubagentDeselected(SubagentDeselectedData),
807 #[serde(rename = "hook.start")]
808 HookStart(HookStartData),
809 #[serde(rename = "hook.end")]
810 HookEnd(HookEndData),
811 #[serde(rename = "hook.progress")]
812 HookProgress(HookProgressData),
813 #[serde(rename = "session.binary_asset")]
814 SessionBinaryAsset(SessionBinaryAssetData),
815 #[serde(rename = "system.message")]
816 SystemMessage(SystemMessageData),
817 #[serde(rename = "system.notification")]
818 SystemNotification(SystemNotificationData),
819 #[serde(rename = "permission.requested")]
820 PermissionRequested(PermissionRequestedData),
821 #[serde(rename = "permission.completed")]
822 PermissionCompleted(PermissionCompletedData),
823 ///
824 /// <div class="warning">
825 ///
826 /// **Experimental.** This type is part of an experimental wire-protocol surface
827 /// and may change or be removed in future SDK or CLI releases.
828 ///
829 /// </div>
830 #[serde(rename = "permission.carriedForward")]
831 PermissionCarriedForward(PermissionCarriedForwardData),
832 ///
833 /// <div class="warning">
834 ///
835 /// **Experimental.** This type is part of an experimental wire-protocol surface
836 /// and may change or be removed in future SDK or CLI releases.
837 ///
838 /// </div>
839 #[serde(rename = "permission.messageAuthorization")]
840 PermissionMessageAuthorization(PermissionMessageAuthorizationData),
841 ///
842 /// <div class="warning">
843 ///
844 /// **Experimental.** This type is part of an experimental wire-protocol surface
845 /// and may change or be removed in future SDK or CLI releases.
846 ///
847 /// </div>
848 #[serde(rename = "permission.messageAuthorizationRead")]
849 PermissionMessageAuthorizationRead(PermissionMessageAuthorizationReadData),
850 ///
851 /// <div class="warning">
852 ///
853 /// **Experimental.** This type is part of an experimental wire-protocol surface
854 /// and may change or be removed in future SDK or CLI releases.
855 ///
856 /// </div>
857 #[serde(rename = "permission.messageAuthorizationDegraded")]
858 PermissionMessageAuthorizationDegraded(PermissionMessageAuthorizationDegradedData),
859 ///
860 /// <div class="warning">
861 ///
862 /// **Experimental.** This type is part of an experimental wire-protocol surface
863 /// and may change or be removed in future SDK or CLI releases.
864 ///
865 /// </div>
866 #[serde(rename = "permission.assentDetected")]
867 PermissionAssentDetected(PermissionAssentDetectedData),
868 ///
869 /// <div class="warning">
870 ///
871 /// **Experimental.** This type is part of an experimental wire-protocol surface
872 /// and may change or be removed in future SDK or CLI releases.
873 ///
874 /// </div>
875 #[serde(rename = "permission.contextualAuthorization")]
876 PermissionContextualAuthorization(PermissionContextualAuthorizationData),
877 #[serde(rename = "user_input.requested")]
878 UserInputRequested(UserInputRequestedData),
879 #[serde(rename = "user_input.completed")]
880 UserInputCompleted(UserInputCompletedData),
881 #[serde(rename = "elicitation.requested")]
882 ElicitationRequested(ElicitationRequestedData),
883 #[serde(rename = "elicitation.completed")]
884 ElicitationCompleted(ElicitationCompletedData),
885 #[serde(rename = "sampling.requested")]
886 SamplingRequested(SamplingRequestedData),
887 #[serde(rename = "sampling.completed")]
888 SamplingCompleted(SamplingCompletedData),
889 #[serde(rename = "mcp.oauth_required")]
890 McpOauthRequired(McpOauthRequiredData),
891 #[serde(rename = "mcp.oauth_completed")]
892 McpOauthCompleted(McpOauthCompletedData),
893 #[serde(rename = "mcp.headers_refresh_required")]
894 McpHeadersRefreshRequired(McpHeadersRefreshRequiredData),
895 #[serde(rename = "mcp.headers_refresh_completed")]
896 McpHeadersRefreshCompleted(McpHeadersRefreshCompletedData),
897 #[serde(rename = "session.custom_notification")]
898 SessionCustomNotification(SessionCustomNotificationData),
899 ///
900 /// <div class="warning">
901 ///
902 /// **Experimental.** This type is part of an experimental wire-protocol surface
903 /// and may change or be removed in future SDK or CLI releases.
904 ///
905 /// </div>
906 #[serde(rename = "ui.ephemeral_query")]
907 UiEphemeralQuery(UiEphemeralQueryData),
908 #[serde(rename = "external_tool.requested")]
909 ExternalToolRequested(ExternalToolRequestedData),
910 #[serde(rename = "external_tool.completed")]
911 ExternalToolCompleted(ExternalToolCompletedData),
912 #[serde(rename = "command.queued")]
913 CommandQueued(CommandQueuedData),
914 #[serde(rename = "command.execute")]
915 CommandExecute(CommandExecuteData),
916 #[serde(rename = "command.completed")]
917 CommandCompleted(CommandCompletedData),
918 #[serde(rename = "auto_mode_switch.requested")]
919 AutoModeSwitchRequested(AutoModeSwitchRequestedData),
920 #[serde(rename = "auto_mode_switch.completed")]
921 AutoModeSwitchCompleted(AutoModeSwitchCompletedData),
922 #[serde(rename = "session_limits_exhausted.requested")]
923 SessionLimitsExhaustedRequested(SessionLimitsExhaustedRequestedData),
924 #[serde(rename = "session_limits_exhausted.completed")]
925 SessionLimitsExhaustedCompleted(SessionLimitsExhaustedCompletedData),
926 ///
927 /// <div class="warning">
928 ///
929 /// **Experimental.** This type is part of an experimental wire-protocol surface
930 /// and may change or be removed in future SDK or CLI releases.
931 ///
932 /// </div>
933 #[serde(rename = "session.auto_mode_resolved")]
934 SessionAutoModeResolved(SessionAutoModeResolvedData),
935 ///
936 /// <div class="warning">
937 ///
938 /// **Experimental.** This type is part of an experimental wire-protocol surface
939 /// and may change or be removed in future SDK or CLI releases.
940 ///
941 /// </div>
942 #[serde(rename = "session.managed_settings_resolved")]
943 SessionManagedSettingsResolved(SessionManagedSettingsResolvedData),
944 ///
945 /// <div class="warning">
946 ///
947 /// **Experimental.** This type is part of an experimental wire-protocol surface
948 /// and may change or be removed in future SDK or CLI releases.
949 ///
950 /// </div>
951 #[serde(rename = "session.managed_settings_enforced")]
952 SessionManagedSettingsEnforced(SessionManagedSettingsEnforcedData),
953 #[serde(rename = "commands.changed")]
954 CommandsChanged(CommandsChangedData),
955 #[serde(rename = "capabilities.changed")]
956 CapabilitiesChanged(CapabilitiesChangedData),
957 #[serde(rename = "exit_plan_mode.requested")]
958 ExitPlanModeRequested(ExitPlanModeRequestedData),
959 #[serde(rename = "exit_plan_mode.completed")]
960 ExitPlanModeCompleted(ExitPlanModeCompletedData),
961 #[serde(rename = "session.tools_updated")]
962 SessionToolsUpdated(SessionToolsUpdatedData),
963 #[serde(rename = "session.background_tasks_changed")]
964 SessionBackgroundTasksChanged(SessionBackgroundTasksChangedData),
965 ///
966 /// <div class="warning">
967 ///
968 /// **Experimental.** This type is part of an experimental wire-protocol surface
969 /// and may change or be removed in future SDK or CLI releases.
970 ///
971 /// </div>
972 #[serde(rename = "workflow.run_updated")]
973 WorkflowRunUpdated(WorkflowRunUpdatedData),
974 ///
975 /// <div class="warning">
976 ///
977 /// **Experimental.** This type is part of an experimental wire-protocol surface
978 /// and may change or be removed in future SDK or CLI releases.
979 ///
980 /// </div>
981 #[serde(rename = "workflow.run_started")]
982 WorkflowRunStarted(WorkflowRunStartedData),
983 ///
984 /// <div class="warning">
985 ///
986 /// **Experimental.** This type is part of an experimental wire-protocol surface
987 /// and may change or be removed in future SDK or CLI releases.
988 ///
989 /// </div>
990 #[serde(rename = "workflow.run_settled")]
991 WorkflowRunSettled(WorkflowRunSettledData),
992 #[serde(rename = "session.skills_loaded")]
993 SessionSkillsLoaded(SessionSkillsLoadedData),
994 #[serde(rename = "session.custom_agents_updated")]
995 SessionCustomAgentsUpdated(SessionCustomAgentsUpdatedData),
996 #[serde(rename = "session.mcp_servers_loaded")]
997 SessionMcpServersLoaded(SessionMcpServersLoadedData),
998 #[serde(rename = "session.mcp_server_status_changed")]
999 SessionMcpServerStatusChanged(SessionMcpServerStatusChangedData),
1000 #[serde(rename = "session.mcp_server_removed")]
1001 SessionMcpServerRemoved(SessionMcpServerRemovedData),
1002 #[serde(rename = "session.mcp_server_needs_reconnect")]
1003 SessionMcpServerNeedsReconnect(SessionMcpServerNeedsReconnectData),
1004 #[serde(rename = "mcp.tools.list_changed")]
1005 McpToolsListChanged(McpToolsListChangedData),
1006 #[serde(rename = "mcp.resources.list_changed")]
1007 McpResourcesListChanged(McpResourcesListChangedData),
1008 #[serde(rename = "mcp.prompts.list_changed")]
1009 McpPromptsListChanged(McpPromptsListChangedData),
1010 #[serde(rename = "session.extensions_loaded")]
1011 SessionExtensionsLoaded(SessionExtensionsLoadedData),
1012 ///
1013 /// <div class="warning">
1014 ///
1015 /// **Experimental.** This type is part of an experimental wire-protocol surface
1016 /// and may change or be removed in future SDK or CLI releases.
1017 ///
1018 /// </div>
1019 #[serde(rename = "session.canvas.opened")]
1020 SessionCanvasOpened(SessionCanvasOpenedData),
1021 ///
1022 /// <div class="warning">
1023 ///
1024 /// **Experimental.** This type is part of an experimental wire-protocol surface
1025 /// and may change or be removed in future SDK or CLI releases.
1026 ///
1027 /// </div>
1028 #[serde(rename = "session.canvas.registry_changed")]
1029 SessionCanvasRegistryChanged(SessionCanvasRegistryChangedData),
1030 ///
1031 /// <div class="warning">
1032 ///
1033 /// **Experimental.** This type is part of an experimental wire-protocol surface
1034 /// and may change or be removed in future SDK or CLI releases.
1035 ///
1036 /// </div>
1037 #[serde(rename = "session.canvas.closed")]
1038 SessionCanvasClosed(SessionCanvasClosedData),
1039 ///
1040 /// <div class="warning">
1041 ///
1042 /// **Experimental.** This type is part of an experimental wire-protocol surface
1043 /// and may change or be removed in future SDK or CLI releases.
1044 ///
1045 /// </div>
1046 #[serde(rename = "session.canvas.unavailable")]
1047 SessionCanvasUnavailable(SessionCanvasUnavailableData),
1048 ///
1049 /// <div class="warning">
1050 ///
1051 /// **Experimental.** This type is part of an experimental wire-protocol surface
1052 /// and may change or be removed in future SDK or CLI releases.
1053 ///
1054 /// </div>
1055 #[serde(rename = "session.canvas.recorded")]
1056 SessionCanvasRecorded(SessionCanvasRecordedData),
1057 ///
1058 /// <div class="warning">
1059 ///
1060 /// **Experimental.** This type is part of an experimental wire-protocol surface
1061 /// and may change or be removed in future SDK or CLI releases.
1062 ///
1063 /// </div>
1064 #[serde(rename = "session.canvas.removed")]
1065 SessionCanvasRemoved(SessionCanvasRemovedData),
1066 #[serde(rename = "session.extensions.attachments_pushed")]
1067 SessionExtensionsAttachmentsPushed(SessionExtensionsAttachmentsPushedData),
1068 #[serde(rename = "mcp_app.tool_call_complete")]
1069 McpAppToolCallComplete(McpAppToolCallCompleteData),
1070}
1071
1072/// A session event with typed data payload.
1073///
1074/// The common event fields (id, timestamp, parentId, ephemeral, agentId)
1075/// are available directly. The event-specific data is in the `payload`
1076/// field as a [`SessionEventData`] enum.
1077#[derive(Debug, Clone, Serialize, Deserialize)]
1078#[serde(rename_all = "camelCase")]
1079pub struct TypedSessionEvent {
1080 /// Unique event identifier (UUID v4).
1081 pub id: String,
1082 /// ISO 8601 timestamp when the event was created.
1083 pub timestamp: String,
1084 /// ID of the preceding event in the chain.
1085 #[serde(skip_serializing_if = "Option::is_none")]
1086 pub parent_id: Option<String>,
1087 /// When true, the event is transient and not persisted.
1088 #[serde(skip_serializing_if = "Option::is_none")]
1089 pub ephemeral: Option<bool>,
1090 /// Sub-agent instance identifier. Absent for events from the root /
1091 /// main agent and session-level events.
1092 #[serde(skip_serializing_if = "Option::is_none")]
1093 pub agent_id: Option<String>,
1094 /// The typed event payload (discriminated by event type).
1095 #[serde(flatten)]
1096 pub payload: SessionEventData,
1097}
1098
1099/// Working directory and git context at session start
1100#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1101#[serde(rename_all = "camelCase")]
1102pub struct WorkingDirectoryContext {
1103 /// Base commit of current git branch at session start time
1104 #[serde(skip_serializing_if = "Option::is_none")]
1105 pub base_commit: Option<String>,
1106 /// Current git branch name
1107 #[serde(skip_serializing_if = "Option::is_none")]
1108 pub branch: Option<String>,
1109 /// Current working directory path
1110 pub cwd: String,
1111 /// Root directory of the git repository, resolved via git rev-parse
1112 #[serde(skip_serializing_if = "Option::is_none")]
1113 pub git_root: Option<String>,
1114 /// Head commit of current git branch at session start time
1115 #[serde(skip_serializing_if = "Option::is_none")]
1116 pub head_commit: Option<String>,
1117 /// Hosting platform type of the repository (github or ado)
1118 #[serde(skip_serializing_if = "Option::is_none")]
1119 pub host_type: Option<WorkingDirectoryContextHostType>,
1120 /// Set on the immediate preliminary event of a working-directory change, before the git context is resolved. A settled follow-up event (enriched with git context, or cwd-only for a non-repository) is always emitted afterward, so observers may defer to it. Absent on standalone/final events (e.g. relay context changes).
1121 #[serde(skip_serializing_if = "Option::is_none")]
1122 pub pending_git_context: Option<bool>,
1123 /// Repository identifier derived from the git remote URL ("owner/name" for GitHub, "org/project/repo" for Azure DevOps)
1124 #[serde(skip_serializing_if = "Option::is_none")]
1125 pub repository: Option<String>,
1126 /// Raw host string from the git remote URL (e.g. "github.com", "mycompany.ghe.com", "dev.azure.com")
1127 #[serde(skip_serializing_if = "Option::is_none")]
1128 pub repository_host: Option<String>,
1129}
1130
1131/// Per-session configuration for the built-in GitHub MCP server
1132#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1133#[serde(rename_all = "camelCase")]
1134pub struct GitHubMcpToolConfig {
1135 /// Additional GitHub MCP tools requested by the session
1136 #[serde(skip_serializing_if = "Option::is_none")]
1137 pub additional_tools: Option<Vec<String>>,
1138 /// Additional GitHub MCP toolsets requested by the session
1139 #[serde(skip_serializing_if = "Option::is_none")]
1140 pub additional_toolsets: Option<Vec<String>>,
1141 /// Whether to use the read-write endpoint and request all toolsets
1142 #[serde(skip_serializing_if = "Option::is_none")]
1143 pub enable_all_tools: Option<bool>,
1144 /// Whether to request the GitHub MCP insiders build
1145 #[serde(skip_serializing_if = "Option::is_none")]
1146 pub enable_insiders_mode: Option<bool>,
1147}
1148
1149/// Optional session limits.
1150#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1151#[serde(rename_all = "camelCase")]
1152pub struct SessionLimitsConfig {
1153 /// Maximum AI Credits allowed across the session's current accounting window.
1154 #[serde(skip_serializing_if = "Option::is_none")]
1155 pub max_ai_credits: Option<f64>,
1156}
1157
1158/// Session event "session.start". Session initialization metadata including context and configuration
1159#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1160#[serde(rename_all = "camelCase")]
1161pub struct SessionStartData {
1162 /// Whether the session was already in use by another client at start time
1163 #[serde(skip_serializing_if = "Option::is_none")]
1164 pub already_in_use: Option<bool>,
1165 /// Auto routing preference selected at session creation time
1166 #[serde(skip_serializing_if = "Option::is_none")]
1167 pub auto_tier: Option<AutoTier>,
1168 /// Working directory and git context at session start
1169 #[serde(skip_serializing_if = "Option::is_none")]
1170 pub context: Option<WorkingDirectoryContext>,
1171 /// Context tier selected at session creation time for models with tiered context pricing; null when no tier is selected (e.g., non-tiered model)
1172 #[serde(skip_serializing_if = "Option::is_none")]
1173 pub context_tier: Option<ContextTier>,
1174 /// Version string of the Copilot application
1175 pub copilot_version: String,
1176 /// When set, identifies a parent session whose context this session continues — e.g., a detached headless rem-agent run launched on the parent's interactive shutdown. Telemetry from this session is reported under the parent's session_id.
1177 #[serde(skip_serializing_if = "Option::is_none")]
1178 pub detached_from_spawning_parent_session_id: Option<String>,
1179 /// Per-session GitHub MCP override persisted for cold resume
1180 #[serde(skip_serializing_if = "Option::is_none")]
1181 pub github_mcp_tool_config: Option<GitHubMcpToolConfig>,
1182 /// Identifier of the software producing the events (e.g., "copilot-agent")
1183 pub producer: String,
1184 /// Reasoning effort level used for model calls, if applicable (e.g. "none", "low", "medium", "high", "xhigh", "max")
1185 #[serde(skip_serializing_if = "Option::is_none")]
1186 pub reasoning_effort: Option<String>,
1187 /// Reasoning summary mode used for model calls, if applicable (e.g. "none", "concise", "detailed")
1188 #[serde(skip_serializing_if = "Option::is_none")]
1189 pub reasoning_summary: Option<ReasoningSummary>,
1190 /// Whether this session supports remote steering via GitHub
1191 #[serde(skip_serializing_if = "Option::is_none")]
1192 pub remote_steerable: Option<bool>,
1193 /// Model selected at session creation time, if any
1194 #[serde(skip_serializing_if = "Option::is_none")]
1195 pub selected_model: Option<String>,
1196 /// Unique identifier for the session
1197 pub session_id: SessionId,
1198 /// Session limits configured at session creation time, if any
1199 #[serde(skip_serializing_if = "Option::is_none")]
1200 pub session_limits: Option<SessionLimitsConfig>,
1201 /// ISO 8601 timestamp when the session was created
1202 pub start_time: String,
1203 /// Output verbosity level used for model calls, if applicable (e.g. "low", "medium", "high")
1204 #[serde(skip_serializing_if = "Option::is_none")]
1205 pub verbosity: Option<Verbosity>,
1206 /// Schema version number for the session event format
1207 pub version: i64,
1208}
1209
1210/// Session event "session.resume". Session resume metadata including current context and event count
1211#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1212#[serde(rename_all = "camelCase")]
1213pub struct SessionResumeData {
1214 /// Whether the session was already in use by another client at resume time
1215 #[serde(skip_serializing_if = "Option::is_none")]
1216 pub already_in_use: Option<bool>,
1217 /// Auto routing preference active at resume time
1218 #[serde(skip_serializing_if = "Option::is_none")]
1219 pub auto_tier: Option<AutoTier>,
1220 /// Updated working directory and git context at resume time
1221 #[serde(skip_serializing_if = "Option::is_none")]
1222 pub context: Option<WorkingDirectoryContext>,
1223 /// Context tier currently selected at resume time; null when no tier is active
1224 #[serde(skip_serializing_if = "Option::is_none")]
1225 pub context_tier: Option<ContextTier>,
1226 /// When true, tool calls and permission requests left in flight by the previous session lifetime remain pending after resume and the agentic loop awaits their results. User sends are queued behind the pending work until all such requests reach a terminal state. When false or omitted, pending work is normally marked as interrupted unless the resume passively joined live work owned by another client; sessionWasActive distinguishes that case.
1227 #[serde(skip_serializing_if = "Option::is_none")]
1228 pub continue_pending_work: Option<bool>,
1229 /// Total number of persisted events in the session at the time of resume
1230 pub event_count: i64,
1231 /// On-disk byte size of the session's persisted events.jsonl file at resume time; omitted when the file does not exist or cannot be stat'd
1232 #[serde(skip_serializing_if = "Option::is_none")]
1233 pub events_file_size_bytes: Option<i64>,
1234 /// Reasoning effort level used for model calls, if applicable (e.g. "none", "low", "medium", "high", "xhigh", "max")
1235 #[serde(skip_serializing_if = "Option::is_none")]
1236 pub reasoning_effort: Option<String>,
1237 /// Reasoning summary mode used for model calls, if applicable (e.g. "none", "concise", "detailed")
1238 #[serde(skip_serializing_if = "Option::is_none")]
1239 pub reasoning_summary: Option<ReasoningSummary>,
1240 /// Whether this session supports remote steering via GitHub
1241 #[serde(skip_serializing_if = "Option::is_none")]
1242 pub remote_steerable: Option<bool>,
1243 /// ISO 8601 timestamp when the session was resumed
1244 pub resume_time: String,
1245 /// Model currently selected at resume time
1246 #[serde(skip_serializing_if = "Option::is_none")]
1247 pub selected_model: Option<String>,
1248 /// Session limits currently configured at resume time; null when no limits are active
1249 #[serde(skip_serializing_if = "Option::is_none")]
1250 pub session_limits: Option<SessionLimitsConfig>,
1251 /// True when this resume passively joined a session that already had live work running in the runtime - an agent turn, a native queue run, a queued resume continuation, or an in-flight send (for example, an extension joining a session another client was actively driving). False (or omitted) when the session had no live work or when the resume explicitly abandoned pending work, including cold resumes and suspended sessions that remain resident in memory.
1252 #[serde(skip_serializing_if = "Option::is_none")]
1253 pub session_was_active: Option<bool>,
1254 /// Output verbosity level used for model calls, if applicable (e.g. "low", "medium", "high")
1255 #[serde(skip_serializing_if = "Option::is_none")]
1256 pub verbosity: Option<Verbosity>,
1257}
1258
1259/// Session event "session.remote_steerable_changed". Notifies that the session's remote steering capability has changed
1260#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1261#[serde(rename_all = "camelCase")]
1262pub struct SessionRemoteSteerableChangedData {
1263 /// Whether this session now supports remote steering via GitHub
1264 pub remote_steerable: bool,
1265}
1266
1267/// Session event "session.error". Error details for timeline display including message and optional diagnostic information
1268#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1269#[serde(rename_all = "camelCase")]
1270pub struct SessionErrorData {
1271 /// Only set on `errorType: "rate_limit"`. When `true`, the runtime will follow this error with an `auto_mode_switch.requested` event (or silently switch if `continueOnAutoMode` is enabled). UI clients can use this flag to suppress duplicate rendering of the rate-limit error when they show their own auto-mode-switch prompt.
1272 #[serde(skip_serializing_if = "Option::is_none")]
1273 pub eligible_for_auto_switch: Option<bool>,
1274 /// Fine-grained error code from the upstream provider, when available. For `errorType: "rate_limit"`, this is one of the `RateLimitErrorCode` values (e.g., `"user_weekly_rate_limited"`, `"user_global_rate_limited"`, `"rate_limited"`, `"user_model_rate_limited"`, `"integration_rate_limited"`). For `errorType: "quota"`, this is the CAPI quota error code (e.g., `"quota_exceeded"`, `"session_quota_exceeded"`, `"billing_not_configured"`).
1275 #[serde(skip_serializing_if = "Option::is_none")]
1276 pub error_code: Option<String>,
1277 /// Category of error (e.g., "authentication", "authorization", "quota", "rate_limit", "context_limit", "query")
1278 pub error_type: String,
1279 /// Human-readable error message
1280 pub message: String,
1281 /// GitHub request tracing ID (x-github-request-id header) for correlating with server-side logs
1282 #[serde(skip_serializing_if = "Option::is_none")]
1283 pub provider_call_id: Option<String>,
1284 /// What the user must do to recover, when the runtime knows of an action. The `message` never names a client affordance, so a client that offers one — a slash command, a settings pane, a link — renders it from this value.
1285 #[serde(skip_serializing_if = "Option::is_none")]
1286 pub remediation: Option<RemediationAction>,
1287 /// Copilot service request ID (x-copilot-service-request-id header) for CAPI log correlation
1288 #[serde(skip_serializing_if = "Option::is_none")]
1289 pub service_request_id: Option<String>,
1290 /// Error stack trace, when available
1291 #[serde(skip_serializing_if = "Option::is_none")]
1292 pub stack: Option<String>,
1293 /// HTTP status code from the upstream request, if applicable
1294 #[serde(skip_serializing_if = "Option::is_none")]
1295 pub status_code: Option<i32>,
1296 /// Optional URL associated with this error that the user can open in a browser
1297 #[serde(skip_serializing_if = "Option::is_none")]
1298 pub url: Option<String>,
1299}
1300
1301/// Session event "session.idle". Payload indicating the session is idle with no background agents or attached shell commands in flight
1302#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1303#[serde(rename_all = "camelCase")]
1304pub struct SessionIdleData {
1305 /// True when the preceding agentic loop was cancelled via abort signal
1306 #[serde(skip_serializing_if = "Option::is_none")]
1307 pub aborted: Option<bool>,
1308 /// The session mode the agent was operating in when it went idle, when the mode is known. Lets turn-scoped consumers distinguish an autopilot continuation boundary (where the agent keeps working after this idle) from a genuine turn completion.
1309 #[serde(skip_serializing_if = "Option::is_none")]
1310 pub mode: Option<SessionMode>,
1311}
1312
1313/// Session event "session.title_changed". Session title change payload containing the new display title
1314#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1315#[serde(rename_all = "camelCase")]
1316pub struct SessionTitleChangedData {
1317 /// The new display title for the session
1318 pub title: String,
1319}
1320
1321/// Session event "session.schedule_created". Scheduled prompt registered via /every or /after
1322#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1323#[serde(rename_all = "camelCase")]
1324pub struct SessionScheduleCreatedData {
1325 /// Absolute fire time (epoch milliseconds) for a one-shot calendar schedule
1326 #[serde(skip_serializing_if = "Option::is_none")]
1327 pub at: Option<i64>,
1328 /// 5-field cron expression for a recurring calendar schedule, evaluated in `tz`
1329 #[serde(skip_serializing_if = "Option::is_none")]
1330 pub cron: Option<String>,
1331 /// Optional user-facing label shown in the timeline instead of the actual prompt (e.g. `/skill-name args` when the prompt is a skill invocation expansion)
1332 #[serde(skip_serializing_if = "Option::is_none")]
1333 pub display_prompt: Option<String>,
1334 /// Sequential id assigned to the scheduled prompt within the session
1335 pub id: i64,
1336 /// Interval between ticks in milliseconds (relative-interval schedules)
1337 #[serde(skip_serializing_if = "Option::is_none")]
1338 pub interval_ms: Option<i64>,
1339 /// Who created the schedule (`user` or `model`). Persisted so a resumed session keeps gating non-user schedules from firing skills that opted out of model invocation. Absent on entries created before this field existed; a missing origin fails closed (treated the same as a non-user origin), so such a schedule may not resolve a `disable-model-invocation` skill.
1340 #[serde(skip_serializing_if = "Option::is_none")]
1341 pub origin: Option<ScheduleOrigin>,
1342 /// Prompt text that gets enqueued on every tick
1343 pub prompt: String,
1344 /// Whether the schedule re-arms after each tick (`/every`) or fires once (`/after`)
1345 #[serde(skip_serializing_if = "Option::is_none")]
1346 pub recurring: Option<bool>,
1347 /// True for a self-paced (`dynamic`) schedule: no fixed cadence; the model arms each next run via the `manage_schedule` `wakeup` action. `nextRunAt` is model-controlled rather than auto-computed.
1348 #[serde(skip_serializing_if = "Option::is_none")]
1349 pub self_paced: Option<bool>,
1350 /// IANA timezone the `cron` expression is evaluated in
1351 #[serde(skip_serializing_if = "Option::is_none")]
1352 pub tz: Option<String>,
1353}
1354
1355/// Session event "session.schedule_cancelled". Scheduled prompt cancelled from the schedule manager dialog
1356#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1357#[serde(rename_all = "camelCase")]
1358pub struct SessionScheduleCancelledData {
1359 /// Id of the scheduled prompt that was cancelled
1360 pub id: i64,
1361}
1362
1363/// Session event "session.schedule_rearmed". Self-paced schedule re-armed for its next run
1364#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1365#[serde(rename_all = "camelCase")]
1366pub struct SessionScheduleRearmedData {
1367 /// Id of the self-paced schedule that was re-armed
1368 pub id: i64,
1369 /// Absolute time (epoch milliseconds) the model armed the next run to fire
1370 pub next_run_at: i64,
1371}
1372
1373/// Session event "session.autopilot_objective_changed". Autopilot objective state file operation details indicating what changed
1374#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1375#[serde(rename_all = "camelCase")]
1376pub struct SessionAutopilotObjectiveChangedData {
1377 /// Current autopilot objective id, if one exists
1378 #[serde(skip_serializing_if = "Option::is_none")]
1379 pub id: Option<i64>,
1380 /// The type of operation performed on the autopilot objective state file
1381 pub operation: AutopilotObjectiveChangedOperation,
1382 /// Current autopilot objective status, if one exists
1383 #[serde(skip_serializing_if = "Option::is_none")]
1384 pub status: Option<AutopilotObjectiveChangedStatus>,
1385}
1386
1387/// Session event "session.info". Informational message for timeline display with categorization
1388#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1389#[serde(rename_all = "camelCase")]
1390pub struct SessionInfoData {
1391 /// Category of informational message (e.g., "notification", "timing", "context_window", "mcp", "snapshot", "configuration", "authentication", "model")
1392 pub info_type: String,
1393 /// Human-readable informational message for display in the timeline
1394 pub message: String,
1395 /// Optional actionable tip displayed with this message
1396 #[serde(skip_serializing_if = "Option::is_none")]
1397 pub tip: Option<String>,
1398 /// Optional URL associated with this message that the user can open in a browser
1399 #[serde(skip_serializing_if = "Option::is_none")]
1400 pub url: Option<String>,
1401}
1402
1403#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1404#[serde(rename_all = "camelCase")]
1405pub struct IndexedSearchDataStatus {
1406 /// Indexed-search event variant discriminator.
1407 pub kind: IndexedSearchDataStatusKind,
1408 /// Current indexed-search state for this session activation.
1409 pub state: IndexedSearchState,
1410}
1411
1412#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1413#[serde(rename_all = "camelCase")]
1414pub struct IndexedSearchDataStartup {
1415 /// Why indexed search was disabled, when applicable.
1416 #[serde(skip_serializing_if = "Option::is_none")]
1417 pub disabled_reason: Option<IndexedSearchDisabledReason>,
1418 /// Whether the repository meets the automatic indexing file-count threshold, when known.
1419 #[serde(skip_serializing_if = "Option::is_none")]
1420 pub eligible: Option<bool>,
1421 /// Startup failure details. May contain sensitive user data; restricted telemetry only.
1422 #[serde(skip_serializing_if = "Option::is_none")]
1423 pub error_message: Option<String>,
1424 /// Number of text files counted in the repository.
1425 #[serde(skip_serializing_if = "Option::is_none")]
1426 pub file_count: Option<f64>,
1427 /// Whether indexed search was explicitly enabled through the environment.
1428 pub forced_by_env: bool,
1429 /// Indexed-search event variant discriminator.
1430 pub kind: IndexedSearchDataStartupKind,
1431 /// Outcome of this startup attempt.
1432 pub outcome: IndexedSearchOutcome,
1433 /// Wall-clock duration of startup in milliseconds.
1434 pub startup_duration_ms: f64,
1435 /// Whether waiting for index readiness was requested, including skipped attempts.
1436 pub warm_start: bool,
1437}
1438
1439#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1440#[serde(rename_all = "camelCase")]
1441pub struct IndexedSearchDataServerError {
1442 /// Server failure details. May contain sensitive user data; restricted telemetry only.
1443 #[serde(skip_serializing_if = "Option::is_none")]
1444 pub error_message: Option<String>,
1445 /// Category of the server failure.
1446 pub error_type: IndexedSearchErrorType,
1447 /// Process exit code, when available.
1448 #[serde(skip_serializing_if = "Option::is_none")]
1449 pub exit_code: Option<f64>,
1450 /// Indexed-search event variant discriminator.
1451 pub kind: IndexedSearchDataServerErrorKind,
1452}
1453
1454#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1455#[serde(rename_all = "camelCase")]
1456pub struct IndexedSearchDataIncremental {
1457 /// Number of added files.
1458 #[serde(skip_serializing_if = "Option::is_none")]
1459 pub added_file_count: Option<f64>,
1460 /// Number of modified files.
1461 #[serde(skip_serializing_if = "Option::is_none")]
1462 pub changed_file_count: Option<f64>,
1463 /// Number of deleted files.
1464 #[serde(skip_serializing_if = "Option::is_none")]
1465 pub deleted_file_count: Option<f64>,
1466 /// Indexed-search event variant discriminator.
1467 pub kind: IndexedSearchDataIncrementalKind,
1468 /// Phase of the incremental index update.
1469 pub phase: IndexedSearchIncrementalPhase,
1470 /// Total number of detected changes.
1471 #[serde(skip_serializing_if = "Option::is_none")]
1472 pub total_change_count: Option<f64>,
1473 /// Total incremental indexing duration in milliseconds.
1474 #[serde(skip_serializing_if = "Option::is_none")]
1475 pub total_duration_ms: Option<f64>,
1476 /// Index update duration in milliseconds.
1477 #[serde(skip_serializing_if = "Option::is_none")]
1478 pub update_duration_ms: Option<f64>,
1479 /// Workspace scan duration in milliseconds.
1480 #[serde(skip_serializing_if = "Option::is_none")]
1481 pub walk_duration_ms: Option<f64>,
1482}
1483
1484/// Session event "session.warning". Warning message for timeline display with categorization
1485#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1486#[serde(rename_all = "camelCase")]
1487pub struct SessionWarningData {
1488 /// Human-readable warning message for display in the timeline
1489 pub message: String,
1490 /// What the user must do to recover, when the runtime knows of an action. The `message` never names a client affordance, so a client that offers one — a slash command, a settings pane, a link — renders it from this value.
1491 #[serde(skip_serializing_if = "Option::is_none")]
1492 pub remediation: Option<RemediationAction>,
1493 /// Optional URL associated with this warning that the user can open in a browser
1494 #[serde(skip_serializing_if = "Option::is_none")]
1495 pub url: Option<String>,
1496 /// Category of warning (e.g., "subscription", "policy", "mcp")
1497 pub warning_type: String,
1498}
1499
1500/// Session event "session.model_change". Model change details including previous and new model identifiers
1501#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1502#[serde(rename_all = "camelCase")]
1503pub struct SessionModelChangeData {
1504 /// Committed Auto preference after the model configuration change, when applicable.
1505 #[serde(skip_serializing_if = "Option::is_none")]
1506 pub auto_tier: Option<AutoTier>,
1507 /// Reason the change happened, when not user-initiated. `"rate_limit_auto_switch"` for changes triggered by the auto-mode-switch rate-limit recovery path, or `"refusal_fallback"` when the active model declined a request (content refusal) and the runtime switched to the configured refusal-fallback model. UI clients can use this to render contextual copy.
1508 #[serde(skip_serializing_if = "Option::is_none")]
1509 pub cause: Option<String>,
1510 /// Context tier after the model change; null explicitly clears a previously selected tier
1511 #[serde(skip_serializing_if = "Option::is_none")]
1512 pub context_tier: Option<ContextTier>,
1513 /// Newly selected model identifier
1514 pub new_model: String,
1515 /// Previously committed Auto preference, when one was explicitly selected.
1516 #[serde(skip_serializing_if = "Option::is_none")]
1517 pub previous_auto_tier: Option<AutoTier>,
1518 /// Model that was previously selected, if any
1519 #[serde(skip_serializing_if = "Option::is_none")]
1520 pub previous_model: Option<String>,
1521 /// Reasoning effort level before the model change, if applicable
1522 #[serde(skip_serializing_if = "Option::is_none")]
1523 pub previous_reasoning_effort: Option<String>,
1524 /// Reasoning summary mode before the model change, if applicable
1525 #[serde(skip_serializing_if = "Option::is_none")]
1526 pub previous_reasoning_summary: Option<ReasoningSummary>,
1527 /// Output verbosity level before the model change, if applicable
1528 #[serde(skip_serializing_if = "Option::is_none")]
1529 pub previous_verbosity: Option<Verbosity>,
1530 /// Reasoning effort level after the model change, if applicable
1531 #[serde(skip_serializing_if = "Option::is_none")]
1532 pub reasoning_effort: Option<String>,
1533 /// Reasoning summary mode after the model change, if applicable
1534 #[serde(skip_serializing_if = "Option::is_none")]
1535 pub reasoning_summary: Option<ReasoningSummary>,
1536 /// Origin of the effective model change, when known.
1537 #[serde(skip_serializing_if = "Option::is_none")]
1538 pub source: Option<ModelChangeSource>,
1539 /// Output verbosity level after the model change, if applicable
1540 #[serde(skip_serializing_if = "Option::is_none")]
1541 pub verbosity: Option<Verbosity>,
1542}
1543
1544/// Session event "session.model_deselected". The model the user had explicitly selected is no longer available, because the host that published it withdrew it, so the session no longer has an explicit selection. The next turn resolves a default as though the user had never chosen a model. Clients should stop presenting the previous model as selected. This event is durable because resume rebuilds the selected model from the event log; without it a resumed session would restore a model its provider no longer serves. Reasoning effort, verbosity, and other session-level preferences are deliberately unchanged, because they belong to the session rather than to the model.
1545#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1546#[serde(rename_all = "camelCase")]
1547pub struct SessionModelDeselectedData {
1548 /// Model that was selected before the host withdrew it.
1549 pub previous_model: String,
1550 /// Low-cardinality reason the selection was cleared.
1551 pub reason: ModelDeselectedReason,
1552}
1553
1554/// Session event "session.auto_tier_recommendation". Live-only Auto preference recommendation from Copilot API after a successful Auto model call.
1555///
1556/// <div class="warning">
1557///
1558/// **Experimental.** This type is part of an experimental wire-protocol surface
1559/// and may change or be removed in future SDK or CLI releases.
1560///
1561/// </div>
1562#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1563#[serde(rename_all = "camelCase")]
1564pub struct SessionAutoTierRecommendationData {
1565 /// Recommended Auto preference.
1566 pub recommended_auto_tier: RecommendedAutoTier,
1567}
1568
1569/// Session event "session.auto_tier_switch_failed". A transient Auto preference failure emitted when the runtime cannot mint or accept a usable model and token pair. The previously effective preference remains active, so SDK clients can surface a non-blocking failure without changing their committed-tier state. This event is ephemeral and is not persisted or replayed on resume.
1570#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1571#[serde(rename_all = "camelCase")]
1572pub struct SessionAutoTierSwitchFailedData {
1573 /// Auto preference that remains effective after the failed request.
1574 #[serde(skip_serializing_if = "Option::is_none")]
1575 pub effective_auto_tier: Option<AutoTier>,
1576 /// Low-cardinality failure outcome reported by Auto resolution.
1577 pub reason: AutoTierSwitchFailureReason,
1578 /// Auto preference that failed to activate, or null when returning to provider-default routing failed.
1579 pub requested_auto_tier: Option<AutoTier>,
1580}
1581
1582/// Session event "session.mode_changed". Agent mode change details including previous and new modes
1583#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1584#[serde(rename_all = "camelCase")]
1585pub struct SessionModeChangedData {
1586 /// The session mode the agent is operating in
1587 pub new_mode: SessionMode,
1588 /// The session mode the agent is operating in
1589 pub previous_mode: SessionMode,
1590}
1591
1592/// Session event "session.mode_notice_delivered". Records that a mode transition notice reached the model so cache-stable mode tools can remain offered across resume.
1593#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1594#[serde(rename_all = "camelCase")]
1595pub struct SessionModeNoticeDeliveredData {
1596 /// Model-visible transition notice persisted for a mid-turn delivery
1597 #[serde(skip_serializing_if = "Option::is_none")]
1598 pub content: Option<String>,
1599 /// Mode established by the delivered transition notice
1600 pub mode: SessionMode,
1601}
1602
1603/// Session event "session.session_limits_changed". Session limits update details. Null clears the limits.
1604#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1605#[serde(rename_all = "camelCase")]
1606pub struct SessionSessionLimitsChangedData {
1607 /// Current session limits, or null when no limits are active
1608 pub session_limits: Option<SessionLimitsConfig>,
1609}
1610
1611/// Session event "session.permissions_changed". Permission-mode transition details.
1612///
1613/// <div class="warning">
1614///
1615/// **Experimental.** This type is part of an experimental wire-protocol surface
1616/// and may change or be removed in future SDK or CLI releases.
1617///
1618/// </div>
1619#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1620#[serde(rename_all = "camelCase")]
1621pub struct SessionPermissionsChangedData {
1622 /// Explicit LLM judge model override used by assisted mode; omitted when the provider default applies
1623 ///
1624 /// <div class="warning">
1625 ///
1626 /// **Experimental.** This type is part of an experimental wire-protocol surface
1627 /// and may change or be removed in future SDK or CLI releases.
1628 ///
1629 /// </div>
1630 #[serde(skip_serializing_if = "Option::is_none")]
1631 pub assisted_approval_model: Option<String>,
1632 /// Permission mode after the change
1633 ///
1634 /// <div class="warning">
1635 ///
1636 /// **Experimental.** This type is part of an experimental wire-protocol surface
1637 /// and may change or be removed in future SDK or CLI releases.
1638 ///
1639 /// </div>
1640 #[serde(skip_serializing_if = "Option::is_none")]
1641 pub mode: Option<PermissionMode>,
1642 /// Permission mode before the change
1643 ///
1644 /// <div class="warning">
1645 ///
1646 /// **Experimental.** This type is part of an experimental wire-protocol surface
1647 /// and may change or be removed in future SDK or CLI releases.
1648 ///
1649 /// </div>
1650 #[serde(skip_serializing_if = "Option::is_none")]
1651 pub previous_mode: Option<PermissionMode>,
1652}
1653
1654/// Session event "session.plan_changed". Plan file operation details indicating what changed
1655#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1656#[serde(rename_all = "camelCase")]
1657pub struct SessionPlanChangedData {
1658 /// The type of operation performed on the plan file
1659 pub operation: PlanChangedOperation,
1660}
1661
1662/// Session event "session.todos_changed". Signal-only event: the agent's todos or todo_deps table was written to. No payload — clients should call session.plan.readSqlTodosWithDependencies() to fetch the current state. Events arrive in order; clients can debounce on arrival if needed.
1663#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1664#[serde(rename_all = "camelCase")]
1665pub struct SessionTodosChangedData {}
1666
1667/// Session event "session.workspace_file_changed". Workspace file change details including path and operation type
1668#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1669#[serde(rename_all = "camelCase")]
1670pub struct SessionWorkspaceFileChangedData {
1671 /// Whether the file was newly created or updated
1672 pub operation: WorkspaceFileChangedOperation,
1673 /// Relative path within the session workspace files directory
1674 pub path: String,
1675}
1676
1677/// Repository context for the handed-off session
1678#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1679#[serde(rename_all = "camelCase")]
1680pub struct HandoffRepository {
1681 /// Git branch name, if applicable
1682 #[serde(skip_serializing_if = "Option::is_none")]
1683 pub branch: Option<String>,
1684 /// Repository name
1685 pub name: String,
1686 /// Repository owner (user or organization)
1687 pub owner: String,
1688}
1689
1690/// Session event "session.handoff". Session handoff metadata including source, context, and repository information
1691#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1692#[serde(rename_all = "camelCase")]
1693pub struct SessionHandoffData {
1694 /// Additional context information for the handoff
1695 #[serde(skip_serializing_if = "Option::is_none")]
1696 pub context: Option<String>,
1697 /// ISO 8601 timestamp when the handoff occurred
1698 pub handoff_time: String,
1699 /// GitHub host URL for the source session (e.g., https://github.com or https://tenant.ghe.com)
1700 #[serde(skip_serializing_if = "Option::is_none")]
1701 pub host: Option<String>,
1702 /// Session ID of the remote session being handed off
1703 #[serde(skip_serializing_if = "Option::is_none")]
1704 pub remote_session_id: Option<SessionId>,
1705 /// Repository context for the handed-off session
1706 #[serde(skip_serializing_if = "Option::is_none")]
1707 pub repository: Option<HandoffRepository>,
1708 /// Origin type of the session being handed off
1709 pub source_type: HandoffSourceType,
1710 /// Summary of the work done in the source session
1711 #[serde(skip_serializing_if = "Option::is_none")]
1712 pub summary: Option<String>,
1713}
1714
1715/// Session event "session.truncation". Conversation truncation statistics including token counts and removed content metrics
1716#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1717#[serde(rename_all = "camelCase")]
1718pub struct SessionTruncationData {
1719 /// Number of messages removed by truncation
1720 pub messages_removed_during_truncation: i64,
1721 /// Identifier of the component that performed truncation (e.g., "BasicTruncator")
1722 pub performed_by: String,
1723 /// Number of conversation messages after truncation
1724 pub post_truncation_messages_length: i64,
1725 /// Total tokens in conversation messages after truncation
1726 pub post_truncation_tokens_in_messages: i64,
1727 /// Number of conversation messages before truncation
1728 pub pre_truncation_messages_length: i64,
1729 /// Total tokens in conversation messages before truncation
1730 pub pre_truncation_tokens_in_messages: i64,
1731 /// Maximum token count for the model's context window
1732 pub token_limit: i64,
1733 /// Number of tokens removed by truncation
1734 pub tokens_removed_during_truncation: i64,
1735}
1736
1737/// Session event "session.snapshot_rewind". Session rewind details including target event and count of removed events
1738#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1739#[serde(rename_all = "camelCase")]
1740pub struct SessionSnapshotRewindData {
1741 /// The removed events, starting with `upToEventId`. Later events not listed were kept, such as a background agent's events that interleaved with a withdrawn turn
1742 #[serde(skip_serializing_if = "Option::is_none")]
1743 pub event_ids: Option<Vec<String>>,
1744 /// Number of events that were removed by the rewind
1745 pub events_removed: i64,
1746 /// First removed event. Without `eventIds`, it and every event after it were removed
1747 pub up_to_event_id: String,
1748}
1749
1750/// Request count and cost metrics
1751#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1752#[serde(rename_all = "camelCase")]
1753pub struct ShutdownModelMetricRequests {
1754 /// Cumulative cost multiplier for requests to this model
1755 ///
1756 /// <div class="warning">
1757 ///
1758 /// **Experimental.** This type is part of an experimental wire-protocol surface
1759 /// and may change or be removed in future SDK or CLI releases.
1760 ///
1761 /// </div>
1762 #[serde(skip_serializing_if = "Option::is_none")]
1763 pub cost: Option<f64>,
1764 /// Total number of API requests made to this model
1765 ///
1766 /// <div class="warning">
1767 ///
1768 /// **Experimental.** This type is part of an experimental wire-protocol surface
1769 /// and may change or be removed in future SDK or CLI releases.
1770 ///
1771 /// </div>
1772 #[serde(skip_serializing_if = "Option::is_none")]
1773 pub count: Option<i64>,
1774}
1775
1776/// A token-type entry in a shutdown model metric, storing the accumulated token count.
1777#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1778#[serde(rename_all = "camelCase")]
1779pub struct ShutdownModelMetricTokenDetail {
1780 /// Accumulated token count for this token type
1781 pub token_count: i64,
1782}
1783
1784/// Token usage breakdown
1785#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1786#[serde(rename_all = "camelCase")]
1787pub struct ShutdownModelMetricUsage {
1788 /// Total tokens read from prompt cache across all requests
1789 pub cache_read_tokens: i64,
1790 /// Total tokens written to prompt cache across all requests
1791 pub cache_write_tokens: i64,
1792 /// Total input tokens consumed across all requests to this model
1793 pub input_tokens: i64,
1794 /// Total output tokens produced across all requests to this model
1795 pub output_tokens: i64,
1796 /// Total reasoning tokens produced across all requests to this model
1797 #[serde(skip_serializing_if = "Option::is_none")]
1798 pub reasoning_tokens: Option<i64>,
1799}
1800
1801/// Per-model shutdown metrics with request counts, token usage, nano-AI units, and token details.
1802#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1803#[serde(rename_all = "camelCase")]
1804pub struct ShutdownModelMetric {
1805 /// Request count and cost metrics
1806 pub requests: ShutdownModelMetricRequests,
1807 /// Token count details per type
1808 #[serde(skip_serializing_if = "Option::is_none")]
1809 pub token_details: Option<HashMap<String, ShutdownModelMetricTokenDetail>>,
1810 /// Accumulated nano-AI units cost for this model
1811 ///
1812 /// <div class="warning">
1813 ///
1814 /// **Experimental.** This type is part of an experimental wire-protocol surface
1815 /// and may change or be removed in future SDK or CLI releases.
1816 ///
1817 /// </div>
1818 #[serde(skip_serializing_if = "Option::is_none")]
1819 pub total_nano_aiu: Option<f64>,
1820 /// Token usage breakdown
1821 pub usage: ShutdownModelMetricUsage,
1822}
1823
1824/// Usage attributed to one agent instance at session shutdown.
1825#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1826#[serde(rename_all = "camelCase")]
1827pub struct ShutdownAgentMetric {
1828 /// Human-readable label for this subagent invocation, copied from the originating `subagent.started` event. For task-tool subagents this is the invocation's task description rather than the agent's configured display name, so group by `agentName` for stable per-agent labels.
1829 #[serde(skip_serializing_if = "Option::is_none")]
1830 pub agent_display_name: Option<String>,
1831 /// Configured agent name, when this is a subagent
1832 #[serde(skip_serializing_if = "Option::is_none")]
1833 pub agent_name: Option<String>,
1834 /// Per-model usage for this agent, keyed by model identifier
1835 pub model_metrics: HashMap<String, ShutdownModelMetric>,
1836 /// Time spent in model API calls by this agent, in milliseconds
1837 pub total_api_duration_ms: i64,
1838 /// Accumulated nano-AI units cost for this agent
1839 pub total_nano_aiu: f64,
1840}
1841
1842/// Aggregate code change metrics for the session
1843#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1844#[serde(rename_all = "camelCase")]
1845pub struct ShutdownCodeChanges {
1846 /// List of file paths that were modified during the session
1847 pub files_modified: Vec<String>,
1848 /// Total number of lines added during the session
1849 pub lines_added: i64,
1850 /// Total number of lines removed during the session
1851 pub lines_removed: i64,
1852}
1853
1854/// A session-wide shutdown token-type entry storing the accumulated token count.
1855#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1856#[serde(rename_all = "camelCase")]
1857pub struct ShutdownTokenDetail {
1858 /// Accumulated token count for this token type
1859 pub token_count: i64,
1860}
1861
1862/// Session event "session.shutdown". Session termination metrics including usage statistics, code changes, and shutdown reason
1863#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1864#[serde(rename_all = "camelCase")]
1865pub struct SessionShutdownData {
1866 /// Per-agent usage breakdown, keyed by agent instance identifier. The main conversation uses the stable key `main`.
1867 #[serde(skip_serializing_if = "Option::is_none")]
1868 pub agent_metrics: Option<HashMap<String, ShutdownAgentMetric>>,
1869 /// Aggregate code change metrics for the session
1870 pub code_changes: ShutdownCodeChanges,
1871 /// Non-system message token count at shutdown
1872 #[serde(skip_serializing_if = "Option::is_none")]
1873 pub conversation_tokens: Option<i64>,
1874 /// Model that was selected at the time of shutdown
1875 #[serde(skip_serializing_if = "Option::is_none")]
1876 pub current_model: Option<String>,
1877 /// Total tokens in context window at shutdown
1878 #[serde(skip_serializing_if = "Option::is_none")]
1879 pub current_tokens: Option<i64>,
1880 /// Error description when shutdownType is "error"
1881 #[serde(skip_serializing_if = "Option::is_none")]
1882 pub error_reason: Option<String>,
1883 /// On-disk byte size of the session's persisted events.jsonl file at shutdown time; omitted when the file does not exist or cannot be stat'd
1884 #[serde(skip_serializing_if = "Option::is_none")]
1885 pub events_file_size_bytes: Option<i64>,
1886 /// Per-model usage breakdown, keyed by model identifier
1887 pub model_metrics: HashMap<String, ShutdownModelMetric>,
1888 /// Unix timestamp (milliseconds) when the session started
1889 pub session_start_time: i64,
1890 /// Whether the session ended normally ("routine") or due to a crash/fatal error ("error")
1891 pub shutdown_type: ShutdownType,
1892 /// System message token count at shutdown
1893 #[serde(skip_serializing_if = "Option::is_none")]
1894 pub system_tokens: Option<i64>,
1895 /// Session-wide per-token-type accumulated token counts
1896 #[serde(skip_serializing_if = "Option::is_none")]
1897 pub token_details: Option<HashMap<String, ShutdownTokenDetail>>,
1898 /// Tool definitions token count at shutdown
1899 #[serde(skip_serializing_if = "Option::is_none")]
1900 pub tool_definitions_tokens: Option<i64>,
1901 /// Cumulative time spent in API calls during the session, in milliseconds
1902 pub total_api_duration_ms: i64,
1903 /// Session-wide accumulated nano-AI units cost
1904 ///
1905 /// <div class="warning">
1906 ///
1907 /// **Experimental.** This type is part of an experimental wire-protocol surface
1908 /// and may change or be removed in future SDK or CLI releases.
1909 ///
1910 /// </div>
1911 #[serde(skip_serializing_if = "Option::is_none")]
1912 pub total_nano_aiu: Option<f64>,
1913 /// Total number of premium API requests used during the session
1914 #[doc(hidden)]
1915 #[serde(skip_serializing_if = "Option::is_none")]
1916 pub(crate) total_premium_requests: Option<f64>,
1917}
1918
1919/// Internal prompt-cache expiration state for one model
1920#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1921#[serde(rename_all = "camelCase")]
1922pub(crate) struct UsageCheckpointModelCacheState {
1923 /// Latest known prompt-cache expiration
1924 pub cache_expires_at: String,
1925 /// Retained cache lifetime in seconds, used to refresh expiration after a cache read
1926 #[doc(hidden)]
1927 pub(crate) cache_ttl_seconds: i64,
1928 /// Model identifier associated with this cache state
1929 pub model_id: String,
1930}
1931
1932/// Session event "session.usage_checkpoint". Durable session usage checkpoint for reconstructing aggregate accounting on resume
1933#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1934#[serde(rename_all = "camelCase")]
1935pub struct SessionUsageCheckpointData {
1936 /// Internal per-model prompt-cache state used to restore expiration tracking on resume
1937 #[doc(hidden)]
1938 #[serde(skip_serializing_if = "Option::is_none")]
1939 pub(crate) model_cache_state: Option<Vec<UsageCheckpointModelCacheState>>,
1940 /// Internal per-conversation prompt-cache-break detector baselines restored on resume
1941 #[doc(hidden)]
1942 #[serde(skip_serializing_if = "Option::is_none")]
1943 pub(crate) prompt_cache_break_state: Option<Vec<serde_json::Value>>,
1944 /// Session-wide accumulated nano-AI units cost at checkpoint time
1945 pub total_nano_aiu: f64,
1946 /// Total number of premium API requests used at checkpoint time
1947 #[doc(hidden)]
1948 #[serde(skip_serializing_if = "Option::is_none")]
1949 pub(crate) total_premium_requests: Option<f64>,
1950}
1951
1952/// Session event "session.context_changed". Updated working directory and git context after the change
1953#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1954#[serde(rename_all = "camelCase")]
1955pub struct SessionContextChangedData {
1956 /// Base commit of current git branch at session start time
1957 #[serde(skip_serializing_if = "Option::is_none")]
1958 pub base_commit: Option<String>,
1959 /// Current git branch name
1960 #[serde(skip_serializing_if = "Option::is_none")]
1961 pub branch: Option<String>,
1962 /// Current working directory path
1963 pub cwd: String,
1964 /// Root directory of the git repository, resolved via git rev-parse
1965 #[serde(skip_serializing_if = "Option::is_none")]
1966 pub git_root: Option<String>,
1967 /// Head commit of current git branch at session start time
1968 #[serde(skip_serializing_if = "Option::is_none")]
1969 pub head_commit: Option<String>,
1970 /// Hosting platform type of the repository (github or ado)
1971 #[serde(skip_serializing_if = "Option::is_none")]
1972 pub host_type: Option<WorkingDirectoryContextHostType>,
1973 /// Set on the immediate preliminary event of a working-directory change, before the git context is resolved. A settled follow-up event (enriched with git context, or cwd-only for a non-repository) is always emitted afterward, so observers may defer to it. Absent on standalone/final events (e.g. relay context changes).
1974 #[serde(skip_serializing_if = "Option::is_none")]
1975 pub pending_git_context: Option<bool>,
1976 /// Repository identifier derived from the git remote URL ("owner/name" for GitHub, "org/project/repo" for Azure DevOps)
1977 #[serde(skip_serializing_if = "Option::is_none")]
1978 pub repository: Option<String>,
1979 /// Raw host string from the git remote URL (e.g. "github.com", "mycompany.ghe.com", "dev.azure.com")
1980 #[serde(skip_serializing_if = "Option::is_none")]
1981 pub repository_host: Option<String>,
1982}
1983
1984/// Session event "session.usage_info". Current context window usage statistics including token and message counts
1985#[derive(Debug, Clone, Default, Serialize, Deserialize)]
1986#[serde(rename_all = "camelCase")]
1987pub struct SessionUsageInfoData {
1988 /// Token count from non-system messages (user, assistant, tool)
1989 #[serde(skip_serializing_if = "Option::is_none")]
1990 pub conversation_tokens: Option<i64>,
1991 /// Current number of tokens in the context window
1992 pub current_tokens: i64,
1993 /// Whether this is the first usage_info event emitted in this session
1994 #[serde(skip_serializing_if = "Option::is_none")]
1995 pub is_initial: Option<bool>,
1996 /// Current number of messages in the conversation
1997 pub messages_length: i64,
1998 /// Token count from system message(s)
1999 #[serde(skip_serializing_if = "Option::is_none")]
2000 pub system_tokens: Option<i64>,
2001 /// Maximum token count for the model's context window
2002 pub token_limit: i64,
2003 /// Token count from tool definitions
2004 #[serde(skip_serializing_if = "Option::is_none")]
2005 pub tool_definitions_tokens: Option<i64>,
2006}
2007
2008/// Session event "session.context_cleared". Context-cleared details emitted when the host clears the conversation (the session.history.clearContext RPC / Session.clearContextMessages)
2009#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2010#[serde(rename_all = "camelCase")]
2011pub struct SessionContextClearedData {
2012 /// Optional initial message set after clearing
2013 #[serde(skip_serializing_if = "Option::is_none")]
2014 pub initial_message: Option<String>,
2015 /// Number of conversation messages that were cleared
2016 pub messages_cleared: i64,
2017}
2018
2019/// Session event "session.compaction_start". Context window breakdown at the start of LLM-powered conversation compaction
2020#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2021#[serde(rename_all = "camelCase")]
2022pub struct SessionCompactionStartData {
2023 /// Token count from non-system messages (user, assistant, tool) at compaction start
2024 #[serde(skip_serializing_if = "Option::is_none")]
2025 pub conversation_tokens: Option<i64>,
2026 /// Total context tokens (system + conversation + tool definitions) at compaction start, when known
2027 #[serde(skip_serializing_if = "Option::is_none")]
2028 pub current_tokens: Option<i64>,
2029 /// Model identifier used for compaction, when known
2030 #[serde(skip_serializing_if = "Option::is_none")]
2031 pub model: Option<String>,
2032 /// Token count from system message(s) at compaction start
2033 #[serde(skip_serializing_if = "Option::is_none")]
2034 pub system_tokens: Option<i64>,
2035 /// Model context window token limit the compaction is targeting, when known
2036 #[serde(skip_serializing_if = "Option::is_none")]
2037 pub token_limit: Option<i64>,
2038 /// Token count from tool definitions at compaction start
2039 #[serde(skip_serializing_if = "Option::is_none")]
2040 pub tool_definitions_tokens: Option<i64>,
2041 /// What initiated this compaction, when known
2042 #[serde(skip_serializing_if = "Option::is_none")]
2043 pub trigger: Option<CompactionTrigger>,
2044}
2045
2046/// Token usage detail for a single billing category
2047#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2048#[serde(rename_all = "camelCase")]
2049pub struct CompactionCompleteCompactionTokensUsedCopilotUsageTokenDetail {
2050 /// Number of tokens in this billing batch
2051 pub batch_size: i64,
2052 /// Cost per batch of tokens
2053 pub cost_per_batch: i64,
2054 /// Model responsible for this billing entry
2055 #[serde(skip_serializing_if = "Option::is_none")]
2056 pub model: Option<String>,
2057 /// Total token count for this entry
2058 pub token_count: i64,
2059 /// Token category (e.g., "input", "output")
2060 pub token_type: String,
2061}
2062
2063/// Per-request cost and usage data from the CAPI copilot_usage response field
2064#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2065#[serde(rename_all = "camelCase")]
2066pub(crate) struct CompactionCompleteCompactionTokensUsedCopilotUsage {
2067 /// Default billing model for token details that do not identify their own model
2068 #[doc(hidden)]
2069 #[serde(skip_serializing_if = "Option::is_none")]
2070 pub(crate) model: Option<String>,
2071 /// Itemized token usage breakdown
2072 #[doc(hidden)]
2073 #[serde(skip_serializing_if = "Option::is_none")]
2074 pub(crate) token_details:
2075 Option<Vec<CompactionCompleteCompactionTokensUsedCopilotUsageTokenDetail>>,
2076 /// Total cost in nano-AI units for this request
2077 pub total_nano_aiu: f64,
2078}
2079
2080/// Token usage breakdown for the compaction LLM call (aligned with assistant.usage format)
2081#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2082#[serde(rename_all = "camelCase")]
2083pub struct CompactionCompleteCompactionTokensUsed {
2084 /// Cached input tokens reused in the compaction LLM call
2085 #[serde(skip_serializing_if = "Option::is_none")]
2086 pub cache_read_tokens: Option<i64>,
2087 /// Tokens written to prompt cache in the compaction LLM call
2088 #[serde(skip_serializing_if = "Option::is_none")]
2089 pub cache_write_tokens: Option<i64>,
2090 /// Per-request cost and usage data from the CAPI copilot_usage response field
2091 #[doc(hidden)]
2092 #[serde(skip_serializing_if = "Option::is_none")]
2093 pub(crate) copilot_usage: Option<CompactionCompleteCompactionTokensUsedCopilotUsage>,
2094 /// Duration of the compaction LLM call in milliseconds
2095 #[serde(skip_serializing_if = "Option::is_none")]
2096 pub duration: Option<i64>,
2097 /// Input tokens consumed by the compaction LLM call
2098 #[serde(skip_serializing_if = "Option::is_none")]
2099 pub input_tokens: Option<i64>,
2100 /// Model identifier used for the compaction LLM call
2101 #[serde(skip_serializing_if = "Option::is_none")]
2102 pub model: Option<String>,
2103 /// Output tokens produced by the compaction LLM call
2104 #[serde(skip_serializing_if = "Option::is_none")]
2105 pub output_tokens: Option<i64>,
2106}
2107
2108/// Original request-level and effective conversation reasoning effort for a provider history boundary; the historical type name is retained for compatibility
2109#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2110#[serde(rename_all = "camelCase")]
2111pub struct ResponsesReasoning {
2112 /// Effective effort selected before this message, independent of the response-level reasoning field
2113 pub effort: String,
2114 /// Original request-level effort, retained while replaying this conversation prefix
2115 pub initial_effort: String,
2116 /// Provider model whose reasoning settings this boundary records
2117 pub model: String,
2118}
2119
2120/// Session event "session.compaction_complete". Conversation compaction results including success status, metrics, and optional error details
2121#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2122#[serde(rename_all = "camelCase")]
2123pub struct SessionCompactionCompleteData {
2124 /// Legacy active-workflow reminder retained for replay compatibility
2125 #[doc(hidden)]
2126 #[serde(skip_serializing_if = "Option::is_none")]
2127 pub(crate) active_factory_summary: Option<String>,
2128 /// Authoritative active-workflow reminder appended to the compacted context
2129 #[doc(hidden)]
2130 #[serde(skip_serializing_if = "Option::is_none")]
2131 pub(crate) active_workflow_summary: Option<String>,
2132 /// Canonical model identifier used for model-specific behavior when replaying compaction
2133 #[serde(skip_serializing_if = "Option::is_none")]
2134 pub behavior_model_id: Option<String>,
2135 /// Checkpoint snapshot number created for recovery
2136 #[serde(skip_serializing_if = "Option::is_none")]
2137 pub checkpoint_number: Option<i64>,
2138 /// File path where the checkpoint was stored
2139 #[serde(skip_serializing_if = "Option::is_none")]
2140 pub checkpoint_path: Option<String>,
2141 /// Token usage breakdown for the compaction LLM call (aligned with assistant.usage format)
2142 #[serde(skip_serializing_if = "Option::is_none")]
2143 pub compaction_tokens_used: Option<CompactionCompleteCompactionTokensUsed>,
2144 /// Token count from non-system messages (user, assistant, tool) after compaction
2145 #[serde(skip_serializing_if = "Option::is_none")]
2146 pub conversation_tokens: Option<i64>,
2147 /// User-supplied focus instructions provided to a manual `/compact` invocation. Omitted for automatic compaction and for manual compaction with no focus text.
2148 #[serde(skip_serializing_if = "Option::is_none")]
2149 pub custom_instructions: Option<String>,
2150 /// Error message if compaction failed
2151 #[serde(skip_serializing_if = "Option::is_none")]
2152 pub error: Option<String>,
2153 /// Number of messages removed during compaction
2154 #[serde(skip_serializing_if = "Option::is_none")]
2155 pub messages_removed: Option<i64>,
2156 /// Total tokens in conversation after compaction
2157 #[serde(skip_serializing_if = "Option::is_none")]
2158 pub post_compaction_tokens: Option<i64>,
2159 /// Number of messages before compaction
2160 #[serde(skip_serializing_if = "Option::is_none")]
2161 pub pre_compaction_messages_length: Option<i64>,
2162 /// Total tokens in conversation before compaction
2163 #[serde(skip_serializing_if = "Option::is_none")]
2164 pub pre_compaction_tokens: Option<i64>,
2165 /// GitHub request tracing ID (x-github-request-id header) for the compaction LLM call
2166 #[serde(skip_serializing_if = "Option::is_none")]
2167 pub request_id: Option<RequestId>,
2168 /// Reasoning baseline on the replacement summary, preserved when replay skips the compacted history
2169 #[serde(skip_serializing_if = "Option::is_none")]
2170 pub responses_reasoning: Option<ResponsesReasoning>,
2171 /// Copilot service request ID (x-copilot-service-request-id header) for the compaction LLM call
2172 #[serde(skip_serializing_if = "Option::is_none")]
2173 pub service_request_id: Option<String>,
2174 /// For failed compaction only: the HTTP status code of the compaction LLM call failure, when it carried one. Absent for successful compaction and for failures without an HTTP status (e.g. an empty model response or a transport error).
2175 #[serde(skip_serializing_if = "Option::is_none")]
2176 pub status_code: Option<i64>,
2177 /// Whether compaction completed successfully
2178 pub success: bool,
2179 /// LLM-generated summary of the compacted conversation history
2180 #[serde(skip_serializing_if = "Option::is_none")]
2181 pub summary_content: Option<String>,
2182 /// Token count from system message(s) after compaction
2183 #[serde(skip_serializing_if = "Option::is_none")]
2184 pub system_tokens: Option<i64>,
2185 /// Model context window token limit the compaction was targeting, when known
2186 #[serde(skip_serializing_if = "Option::is_none")]
2187 pub token_limit: Option<i64>,
2188 /// Number of tokens removed during compaction
2189 #[serde(skip_serializing_if = "Option::is_none")]
2190 pub tokens_removed: Option<i64>,
2191 /// Token count from tool definitions after compaction
2192 #[serde(skip_serializing_if = "Option::is_none")]
2193 pub tool_definitions_tokens: Option<i64>,
2194 /// What initiated this compaction, when known
2195 #[serde(skip_serializing_if = "Option::is_none")]
2196 pub trigger: Option<CompactionTrigger>,
2197}
2198
2199#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2200#[serde(rename_all = "camelCase")]
2201pub struct PermissionRecoveryAttempt {
2202 /// Unique identifier for this attempt record
2203 pub attempt_id: String,
2204 /// How the runtime handled this attempt
2205 pub disposition: PermissionRecoveryAttemptDisposition,
2206 /// One-based position of this attempt in the episode
2207 pub ordinal: i64,
2208 /// Controlled permission request kind, such as shell, path, URL, or tool
2209 pub permission_kind: String,
2210 /// Controlled reason for the attempt disposition
2211 pub reason: PermissionRecoveryAttemptReason,
2212 /// Relationship between this attempt and earlier attempts in the episode
2213 pub relation: PermissionRecoveryAttemptRelation,
2214 /// SHA-256 fingerprint of normalized request data; raw permission arguments are not included
2215 pub request_fingerprint: String,
2216 /// Tool-call identifier associated with this attempt, when available
2217 #[serde(skip_serializing_if = "Option::is_none")]
2218 pub tool_call_id: Option<String>,
2219}
2220
2221/// Authoritative snapshot of an Autopilot permission-recovery episode
2222#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2223#[serde(rename_all = "camelCase")]
2224pub struct PermissionRecoveryData {
2225 /// Ordered privacy-safe record of permission attempts and the successful alternative, when any
2226 pub attempts: Vec<PermissionRecoveryAttempt>,
2227 /// Stable identifier shared by every transition in this recovery episode
2228 pub episode_id: String,
2229 /// Maximum number of distinct autonomous permission attempts allowed before escalation
2230 pub max_attempts: i64,
2231 /// Policy selected from the current client's response capability; mode or client changes may update it during recovery
2232 pub on_blocked: PermissionRecoveryOnBlocked,
2233 /// Controlled reason for the latest episode transition
2234 pub reason: PermissionRecoveryReason,
2235 /// Current lifecycle state of the recovery episode
2236 pub status: PermissionRecoveryStatus,
2237}
2238
2239/// Structured reason that the task cannot continue without intervention
2240///
2241/// <div class="warning">
2242///
2243/// **Experimental.** This type is part of an experimental wire-protocol surface
2244/// and may change or be removed in future SDK or CLI releases.
2245///
2246/// </div>
2247#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2248#[serde(rename_all = "camelCase")]
2249pub struct TaskBlocker {
2250 /// Category of intervention that blocked the task
2251 pub kind: TaskBlockerKind,
2252 /// Permission-recovery episode that produced this blocker
2253 pub permission_recovery: PermissionRecoveryData,
2254 /// Controlled reason for the current blocked state
2255 pub reason: PermissionRecoveryReason,
2256 /// Whether a later user response or steering message can resume the task
2257 pub resumable: bool,
2258}
2259
2260/// Session event "session.task_complete". Task completion notification with summary from the agent
2261#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2262#[serde(rename_all = "camelCase")]
2263pub struct SessionTaskCompleteData {
2264 /// Structured blocker details when outcome is blocked
2265 #[serde(skip_serializing_if = "Option::is_none")]
2266 pub blocker: Option<TaskBlocker>,
2267 /// Active autopilot objective ID evaluated by the completion reviewer
2268 #[serde(skip_serializing_if = "Option::is_none")]
2269 pub objective_id: Option<i64>,
2270 /// Semantic completion decision. Absent on legacy events and invalid tool calls
2271 #[serde(skip_serializing_if = "Option::is_none")]
2272 pub outcome: Option<TaskCompletionOutcome>,
2273 /// Label-safe runtime rationale for the completion decision (e.g. a cancellation or pause/resume downgrade), when one applies. Reviewer-authored rationale is intentionally omitted here because this event has no IFC label channel; the reviewer's findings remain available through its own labeled sub-agent events
2274 #[serde(skip_serializing_if = "Option::is_none")]
2275 pub reason: Option<String>,
2276 /// Whether the task was accepted as complete. False when validation failed or completion was rejected or blocked by the reviewer
2277 #[serde(skip_serializing_if = "Option::is_none")]
2278 pub success: Option<bool>,
2279 /// Summary of the completed task, provided by the agent
2280 #[serde(skip_serializing_if = "Option::is_none")]
2281 pub summary: Option<String>,
2282}
2283
2284/// Inclusive durable event range summarized by a completion receipt.
2285#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2286#[serde(rename_all = "camelCase")]
2287pub struct CompletionReceiptEventRange {
2288 /// Identifier of the assistant turn-end event that ends the covered exchange. Always equals the receipt's sourceEventId, so either field is a valid join key.
2289 pub end_event_id: String,
2290 /// Identifier of the user message that starts the covered exchange.
2291 pub start_event_id: String,
2292}
2293
2294/// Final structured tool completion in the covered event range.
2295#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2296#[serde(rename_all = "camelCase")]
2297pub struct CompletionReceiptFinalTool {
2298 /// Process exit code from a structured shell result, when available.
2299 #[serde(skip_serializing_if = "Option::is_none")]
2300 pub exit_code: Option<i64>,
2301 /// Structured success or failure status from the tool completion event.
2302 pub status: CompletionReceiptToolStatus,
2303 /// Unique identifier of the completed tool call.
2304 pub tool_call_id: String,
2305 /// Tool name from the matching tool execution start event, when available.
2306 #[serde(skip_serializing_if = "Option::is_none")]
2307 pub tool_name: Option<String>,
2308}
2309
2310/// Session event "session.completion_receipt". Behavior-neutral record of structured runtime facts present when an agent completion decision is accepted.
2311///
2312/// <div class="warning">
2313///
2314/// **Experimental.** This type is part of an experimental wire-protocol surface
2315/// and may change or be removed in future SDK or CLI releases.
2316///
2317/// </div>
2318#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2319#[serde(rename_all = "camelCase")]
2320pub struct SessionCompletionReceiptData {
2321 /// One-based accepted completion receipt ordinal in the durable session history.
2322 pub attempt: i64,
2323 /// Inclusive durable event range summarized by this receipt.
2324 pub event_range: CompletionReceiptEventRange,
2325 /// Number of failed structured tool completions in the covered range.
2326 pub failed_tool_count: i64,
2327 /// Final structured tool completion in the covered range, when one exists.
2328 #[serde(skip_serializing_if = "Option::is_none")]
2329 pub final_tool: Option<CompletionReceiptFinalTool>,
2330 /// Version of the completion receipt payload.
2331 pub schema_version: i64,
2332 /// Identifier of the assistant turn-end event that supplied the accepted completion boundary. This is the receipt's idempotency key, and always equals eventRange.endEventId.
2333 pub source_event_id: String,
2334 /// Runtime reason the completion decision was accepted.
2335 pub stop_reason: CompletionReceiptStopReason,
2336 /// Number of successful structured tool completions in the covered range.
2337 pub successful_tool_count: i64,
2338}
2339
2340/// Session event "session.fusion_route_started". Experimental transient signal that HydraFusion routing has started for an eligible turn.
2341///
2342/// <div class="warning">
2343///
2344/// **Experimental.** This type is part of an experimental wire-protocol surface
2345/// and may change or be removed in future SDK or CLI releases.
2346///
2347/// </div>
2348#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2349#[serde(rename_all = "camelCase")]
2350pub struct SessionFusionRouteStartedData {
2351 /// Identifier for this routing attempt before a durable Fusion turn exists.
2352 pub attempt_id: String,
2353 /// HydraFusion routing policy requested for the turn.
2354 #[serde(skip_serializing_if = "Option::is_none")]
2355 pub policy: Option<String>,
2356 /// Synthetic HydraFusion model selected for the session.
2357 #[serde(skip_serializing_if = "Option::is_none")]
2358 pub synthetic_model: Option<String>,
2359 /// Kind of turn being routed.
2360 pub turn_kind: FusionTurnKind,
2361}
2362
2363/// Session event "session.fusion_route_failed". Experimental durable HydraFusion routing failure and the deterministic concrete fallback selected for the turn.
2364///
2365/// <div class="warning">
2366///
2367/// **Experimental.** This type is part of an experimental wire-protocol surface
2368/// and may change or be removed in future SDK or CLI releases.
2369///
2370/// </div>
2371#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2372#[serde(rename_all = "camelCase")]
2373pub struct SessionFusionRouteFailedData {
2374 /// Identifier of the routing attempt that failed.
2375 pub attempt_id: String,
2376 /// Provider or validation error detail, when available.
2377 #[serde(skip_serializing_if = "Option::is_none")]
2378 pub error_message: Option<String>,
2379 /// Concrete model selected as the deterministic fallback.
2380 pub fallback_model: String,
2381 /// HydraFusion routing policy requested for the turn.
2382 pub policy: String,
2383 /// Stable machine-readable reason for the routing failure.
2384 pub reason: String,
2385 /// Elapsed routing time in milliseconds before the failure.
2386 #[serde(skip_serializing_if = "Option::is_none")]
2387 pub routing_latency_ms: Option<f64>,
2388 /// Synthetic HydraFusion model selected for the session.
2389 pub synthetic_model: String,
2390}
2391
2392///
2393/// <div class="warning">
2394///
2395/// **Experimental.** This type is part of an experimental wire-protocol surface
2396/// and may change or be removed in future SDK or CLI releases.
2397///
2398/// </div>
2399#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2400#[serde(rename_all = "camelCase")]
2401pub struct FusionCritic {
2402 /// Concrete model selected for this critic.
2403 ///
2404 /// <div class="warning">
2405 ///
2406 /// **Experimental.** This type is part of an experimental wire-protocol surface
2407 /// and may change or be removed in future SDK or CLI releases.
2408 ///
2409 /// </div>
2410 pub model: String,
2411 /// Unique execution phase identifier for this critic.
2412 ///
2413 /// <div class="warning">
2414 ///
2415 /// **Experimental.** This type is part of an experimental wire-protocol surface
2416 /// and may change or be removed in future SDK or CLI releases.
2417 ///
2418 /// </div>
2419 pub phase_id: String,
2420 /// Explicit reasoning effort selected for this critic, if supplied.
2421 ///
2422 /// <div class="warning">
2423 ///
2424 /// **Experimental.** This type is part of an experimental wire-protocol surface
2425 /// and may change or be removed in future SDK or CLI releases.
2426 ///
2427 /// </div>
2428 #[serde(skip_serializing_if = "Option::is_none")]
2429 pub reasoning_effort: Option<String>,
2430}
2431
2432/// Durable server recommendation for subsequent HydraFusion turns.
2433///
2434/// <div class="warning">
2435///
2436/// **Experimental.** This type is part of an experimental wire-protocol surface
2437/// and may change or be removed in future SDK or CLI releases.
2438///
2439/// </div>
2440#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2441#[serde(rename_all = "camelCase")]
2442pub struct FusionFollowUpRecommendation {
2443 /// Recommended routing action for the next compaction turn.
2444 pub compaction_turn: FusionFollowUpAction,
2445 /// Recommended routing action for the next user-message turn.
2446 pub user_turn: FusionFollowUpAction,
2447}
2448
2449/// Presentation-neutral phase planned for a HydraFusion turn.
2450///
2451/// <div class="warning">
2452///
2453/// **Experimental.** This type is part of an experimental wire-protocol surface
2454/// and may change or be removed in future SDK or CLI releases.
2455///
2456/// </div>
2457#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2458#[serde(rename_all = "camelCase")]
2459pub struct FusionPhasePlanStep {
2460 /// Whether the phase executes only when an earlier phase requests it.
2461 pub conditional: bool,
2462 /// Kind of phase that may execute.
2463 pub kind: FusionPhaseKind,
2464 /// Semantic role assigned to the phase.
2465 pub role: String,
2466 /// Conversation scope in which the phase executes.
2467 pub scope: FusionConversationScope,
2468}
2469
2470/// Validated HydraFusion routing capability scores.
2471///
2472/// <div class="warning">
2473///
2474/// **Experimental.** This type is part of an experimental wire-protocol surface
2475/// and may change or be removed in future SDK or CLI releases.
2476///
2477/// </div>
2478#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2479#[serde(rename_all = "camelCase")]
2480pub struct FusionScores {
2481 /// Code-generation capability score returned by the authenticated router.
2482 pub code_gen: f64,
2483 /// Debugging capability score returned by the authenticated router.
2484 pub debugging: f64,
2485 /// Reasoning capability score returned by the authenticated router.
2486 pub reasoning: f64,
2487 /// Tool-use capability score returned by the authenticated router.
2488 pub tool_use: f64,
2489}
2490
2491/// Session event "session.fusion_resolved". Experimental durable validated HydraFusion route and turn policy.
2492///
2493/// <div class="warning">
2494///
2495/// **Experimental.** This type is part of an experimental wire-protocol surface
2496/// and may change or be removed in future SDK or CLI releases.
2497///
2498/// </div>
2499#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2500#[serde(rename_all = "camelCase")]
2501pub struct SessionFusionResolvedData {
2502 /// Version of the validated HydraFusion event contract.
2503 pub contract_version: i64,
2504 /// Planned Critique phase identities, including independent critics with repeated model IDs. May be absent in older events; consumers then use secondaryModel for the legacy critic.
2505 ///
2506 /// <div class="warning">
2507 ///
2508 /// **Experimental.** This type is part of an experimental wire-protocol surface
2509 /// and may change or be removed in future SDK or CLI releases.
2510 ///
2511 /// </div>
2512 #[serde(skip_serializing_if = "Option::is_none")]
2513 pub critics: Option<Vec<FusionCritic>>,
2514 /// Concrete model used when the planned primary model cannot execute.
2515 pub fallback_model: String,
2516 /// Router recommendation controlling reuse or rerouting on later turns.
2517 #[serde(skip_serializing_if = "Option::is_none")]
2518 pub follow_up: Option<FusionFollowUpRecommendation>,
2519 /// Concrete model recommended for eligible follow-up turns.
2520 pub follow_up_model: String,
2521 /// Stable identifier for the resolved HydraFusion turn.
2522 pub fusion_id: String,
2523 /// Short human-readable summary of the selected workflow, suitable for immediate client display after routing. May be absent in older durable events; omit the explanation or derive one from pattern and phasePlan. Display text, not a stable machine-readable value.
2524 ///
2525 /// <div class="warning">
2526 ///
2527 /// **Experimental.** This type is part of an experimental wire-protocol surface
2528 /// and may change or be removed in future SDK or CLI releases.
2529 ///
2530 /// </div>
2531 #[serde(skip_serializing_if = "Option::is_none")]
2532 pub hint: Option<String>,
2533 /// Concrete model selected for Cascade escalation-gate calls, when required.
2534 ///
2535 /// <div class="warning">
2536 ///
2537 /// **Experimental.** This type is part of an experimental wire-protocol surface
2538 /// and may change or be removed in future SDK or CLI releases.
2539 ///
2540 /// </div>
2541 #[serde(skip_serializing_if = "Option::is_none")]
2542 pub judge_model: Option<String>,
2543 /// Version of the executable model universe used for selection.
2544 #[serde(skip_serializing_if = "Option::is_none")]
2545 pub model_universe_version: Option<String>,
2546 /// Validated orchestration pattern selected for the turn.
2547 pub pattern: FusionPattern,
2548 /// Presentation-neutral phase plan for clients that render workflow progress.
2549 ///
2550 /// <div class="warning">
2551 ///
2552 /// **Experimental.** This type is part of an experimental wire-protocol surface
2553 /// and may change or be removed in future SDK or CLI releases.
2554 ///
2555 /// </div>
2556 #[serde(skip_serializing_if = "Option::is_none")]
2557 pub phase_plan: Option<Vec<FusionPhasePlanStep>>,
2558 /// Version of the validated execution-plan format.
2559 #[serde(skip_serializing_if = "Option::is_none")]
2560 pub plan_version: Option<String>,
2561 /// HydraFusion routing policy used to resolve the plan.
2562 pub policy: String,
2563 /// Version of the local routing policy.
2564 #[serde(skip_serializing_if = "Option::is_none")]
2565 pub policy_version: Option<String>,
2566 /// Concrete model selected for the primary solver phase.
2567 pub primary_model: String,
2568 /// Concrete model selected for Cascade repair, when required.
2569 ///
2570 /// <div class="warning">
2571 ///
2572 /// **Experimental.** This type is part of an experimental wire-protocol surface
2573 /// and may change or be removed in future SDK or CLI releases.
2574 ///
2575 /// </div>
2576 #[serde(skip_serializing_if = "Option::is_none")]
2577 pub repair_model: Option<String>,
2578 /// Router implementation that supplied the plan.
2579 #[serde(skip_serializing_if = "Option::is_none")]
2580 pub route_source: Option<String>,
2581 /// Elapsed time in milliseconds required to resolve and validate the route.
2582 #[serde(skip_serializing_if = "Option::is_none")]
2583 pub routing_latency_ms: Option<f64>,
2584 /// Identifier of the local policy rule that matched.
2585 #[serde(skip_serializing_if = "Option::is_none")]
2586 pub rule_id: Option<String>,
2587 /// Zero-based index of the local policy rule that matched.
2588 #[serde(skip_serializing_if = "Option::is_none")]
2589 pub rule_index: Option<i64>,
2590 /// Human-readable name of the local policy rule that matched.
2591 #[serde(skip_serializing_if = "Option::is_none")]
2592 pub rule_name: Option<String>,
2593 /// Validated capability scores used to select the route.
2594 #[serde(skip_serializing_if = "Option::is_none")]
2595 pub scores: Option<FusionScores>,
2596 /// Concrete model selected for Critique review, or the legacy Cascade judge/repair model when role-specific fields are absent.
2597 pub secondary_model: Option<String>,
2598 /// Synthetic HydraFusion model selected for the session.
2599 pub synthetic_model: String,
2600 /// Identifier of the session turn associated with the route.
2601 pub turn_id: String,
2602}
2603
2604/// Session event "session.fusion_completed". Experimental durable aggregate outcome of a HydraFusion turn.
2605///
2606/// <div class="warning">
2607///
2608/// **Experimental.** This type is part of an experimental wire-protocol surface
2609/// and may change or be removed in future SDK or CLI releases.
2610///
2611/// </div>
2612#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2613#[serde(rename_all = "camelCase")]
2614pub struct SessionFusionCompletedData {
2615 /// Total cached input tokens reported across all phases.
2616 pub cached_tokens: i64,
2617 /// Total tokens written to prompt cache across all phases.
2618 #[serde(skip_serializing_if = "Option::is_none")]
2619 pub cache_write_tokens: Option<i64>,
2620 /// Idempotency identifier for the authoritative final commit.
2621 pub commit_id: String,
2622 /// Reason the turn used a degraded route, when applicable.
2623 pub degraded_reason: Option<String>,
2624 /// Total elapsed execution time for the HydraFusion turn in milliseconds.
2625 pub duration_ms: f64,
2626 /// Concrete model that supplied the authoritative final content.
2627 pub final_source_model: Option<String>,
2628 /// Phase whose output supplied the authoritative final content.
2629 pub final_source_phase_id: Option<String>,
2630 /// Concrete model recommended for eligible follow-up turns.
2631 pub follow_up_model: String,
2632 /// Stable identifier for the completed HydraFusion turn.
2633 pub fusion_id: String,
2634 /// Total input tokens consumed across all phases.
2635 pub input_tokens: i64,
2636 /// Stable aggregate outcome of the HydraFusion turn.
2637 pub outcome: String,
2638 /// Total output tokens produced across all phases.
2639 pub output_tokens: i64,
2640 /// HydraFusion orchestration pattern executed for the turn.
2641 pub pattern: FusionPattern,
2642 /// Number of concrete phases attempted by the turn.
2643 pub phase_count: i64,
2644 /// Total concrete model requests made across all phases.
2645 pub request_count: i64,
2646 /// Synthetic HydraFusion model selected for the session.
2647 pub synthetic_model: String,
2648 /// Total normalized AI-unit cost reported across all phases, in nano-AIU.
2649 pub total_nano_aiu: f64,
2650 /// Identifier of the session turn associated with the completion.
2651 pub turn_id: String,
2652}
2653
2654/// Session event "session.permission_recovery". Authoritative snapshot of an Autopilot permission-recovery episode
2655#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2656#[serde(rename_all = "camelCase")]
2657pub struct SessionPermissionRecoveryData {
2658 /// Ordered privacy-safe record of permission attempts and the successful alternative, when any
2659 pub attempts: Vec<PermissionRecoveryAttempt>,
2660 /// Stable identifier shared by every transition in this recovery episode
2661 pub episode_id: String,
2662 /// Maximum number of distinct autonomous permission attempts allowed before escalation
2663 pub max_attempts: i64,
2664 /// Policy selected from the current client's response capability; mode or client changes may update it during recovery
2665 pub on_blocked: PermissionRecoveryOnBlocked,
2666 /// Controlled reason for the latest episode transition
2667 pub reason: PermissionRecoveryReason,
2668 /// Current lifecycle state of the recovery episode
2669 pub status: PermissionRecoveryStatus,
2670}
2671
2672/// Session event "user.message". Payload of `user.message` with displayed and model-transformed content, attachments, source/delivery metadata, mode, and telemetry IDs.
2673#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2674#[serde(rename_all = "camelCase")]
2675pub struct UserMessageData {
2676 /// The agent mode that was active when this message was sent
2677 #[serde(skip_serializing_if = "Option::is_none")]
2678 pub agent_mode: Option<UserMessageAgentMode>,
2679 /// Files, selections, or GitHub references attached to the message
2680 #[serde(skip_serializing_if = "Option::is_none")]
2681 pub attachments: Option<Vec<serde_json::Value>>,
2682 /// The user's message text as displayed in the timeline
2683 pub content: String,
2684 /// How this message was delivered to the agentic loop relative to loop state (idle-start vs. steering/queued while busy). The timing axis; combine with `source` (origin) for the full picture. Used for telemetry attribution.
2685 #[serde(skip_serializing_if = "Option::is_none")]
2686 pub delivery: Option<UserMessageDelivery>,
2687 /// CAPI interaction ID for correlating this user message with its turn
2688 #[serde(skip_serializing_if = "Option::is_none")]
2689 pub interaction_id: Option<String>,
2690 /// True when this user message was auto-injected by autopilot's continuation loop rather than typed by the user; used to distinguish autopilot-driven turns in telemetry.
2691 #[serde(skip_serializing_if = "Option::is_none")]
2692 pub is_autopilot_continuation: Option<bool>,
2693 /// Stable identity of the logical user message, matching the ID returned by send and retained by pending queue snapshots
2694 #[serde(skip_serializing_if = "Option::is_none")]
2695 pub message_id: Option<String>,
2696 /// Path-backed native document attachments that stayed on the tagged_files path flow because native upload could not read them or would exceed the request size limit
2697 #[serde(skip_serializing_if = "Option::is_none")]
2698 pub native_document_path_fallback_paths: Option<Vec<String>>,
2699 /// Parent agent task ID for background telemetry correlated to this user turn
2700 #[serde(skip_serializing_if = "Option::is_none")]
2701 pub parent_agent_task_id: Option<String>,
2702 /// Provider reasoning settings anchored before this model-facing message for cache-stable replay; the historical responsesReasoning name is retained for compatibility
2703 #[serde(skip_serializing_if = "Option::is_none")]
2704 pub responses_reasoning: Option<ResponsesReasoning>,
2705 /// Origin of this message, used for timeline filtering and attribution (e.g., `skill-pdf` for hidden skill injection or `agent-<agent-id>` for an inter-agent prompt)
2706 #[serde(skip_serializing_if = "Option::is_none")]
2707 pub source: Option<String>,
2708 /// Normalized document MIME types that were sent natively instead of through tagged_files XML
2709 #[serde(skip_serializing_if = "Option::is_none")]
2710 pub supported_native_document_mime_types: Option<Vec<String>>,
2711 /// Transformed version of the message sent to the model, with XML wrapping, timestamps, and other augmentations for prompt caching
2712 #[serde(skip_serializing_if = "Option::is_none")]
2713 pub transformed_content: Option<String>,
2714 /// The agent-loop turn ID that consumed this message; absent when no agent-loop turn consumed it
2715 #[serde(skip_serializing_if = "Option::is_none")]
2716 pub turn_id: Option<String>,
2717}
2718
2719/// Session event "pending_messages.modified". Empty payload; the event signals that the pending message queue has changed
2720#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2721#[serde(rename_all = "camelCase")]
2722pub struct PendingMessagesModifiedData {}
2723
2724/// Session event "assistant.turn_start". Turn initialization metadata including identifier and interaction tracking
2725#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2726#[serde(rename_all = "camelCase")]
2727pub struct AssistantTurnStartData {
2728 /// CAPI interaction ID for correlating this turn with upstream telemetry
2729 #[serde(skip_serializing_if = "Option::is_none")]
2730 pub interaction_id: Option<String>,
2731 /// Model identifier used for this turn, when known
2732 #[serde(skip_serializing_if = "Option::is_none")]
2733 pub model: Option<String>,
2734 /// Parent task tool call ID when this turn belongs to a sub-agent
2735 #[serde(skip_serializing_if = "Option::is_none")]
2736 pub parent_tool_call_id: Option<String>,
2737 /// Identifier for this turn within the agentic loop, typically a stringified turn number
2738 pub turn_id: String,
2739}
2740
2741/// Session event "assistant.turn_retry". Metadata for an additional model inference attempt within an existing assistant turn
2742#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2743#[serde(rename_all = "camelCase")]
2744pub struct AssistantTurnRetryData {
2745 /// Model identifier used for this retry, when known
2746 #[serde(skip_serializing_if = "Option::is_none")]
2747 pub model: Option<String>,
2748 /// Provider or runtime classification that caused the retry, when known
2749 #[serde(skip_serializing_if = "Option::is_none")]
2750 pub reason: Option<String>,
2751 /// Identifier of the turn whose model inference is being retried
2752 pub turn_id: String,
2753}
2754
2755/// Session event "agent.interrupted". Metadata for work the user interrupted while the agent was running
2756#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2757#[serde(rename_all = "camelCase")]
2758pub struct AgentInterruptedData {
2759 /// What the agent was doing when the user interrupted it
2760 pub activity: AgentInterruptedActivity,
2761 /// For an interrupted model call: the provider endpoint the request targeted
2762 #[serde(skip_serializing_if = "Option::is_none")]
2763 pub api_endpoint: Option<String>,
2764 /// For an interrupted model call: whether the user interrupted before any token arrived or while the response was streaming
2765 #[serde(skip_serializing_if = "Option::is_none")]
2766 pub cancel_phase: Option<AgentInterruptedCancelPhase>,
2767 /// How long the interrupted work had been running, in milliseconds
2768 pub elapsed_ms: f64,
2769 /// For an interrupted background-agent batch: how many background sub-agents the stop swept. Counts accepted cancellations, so an agent cancelled as a cascade of its interrupted parent is covered by that parent rather than counted again.
2770 #[serde(skip_serializing_if = "Option::is_none")]
2771 pub interrupted_agent_count: Option<i64>,
2772 /// For an interrupted model call: the model the request targeted
2773 #[serde(skip_serializing_if = "Option::is_none")]
2774 pub model: Option<String>,
2775 /// For a mid-stream interrupt: the observed time to first observable output, in milliseconds. Deliberately distinct from the `ttftMs` reported on a successful model call, which measures time to first stream event.
2776 #[serde(skip_serializing_if = "Option::is_none")]
2777 pub output_ttft_ms: Option<f64>,
2778 /// For an interrupted model call: the reasoning effort the request asked for
2779 #[serde(skip_serializing_if = "Option::is_none")]
2780 pub reasoning_effort: Option<String>,
2781 /// Subset of `toolNames` whose tool metadata marks the tool name as safe to record unhashed in telemetry.
2782 #[serde(skip_serializing_if = "Option::is_none")]
2783 pub safe_tool_names: Option<Vec<String>>,
2784 /// Tool call identifiers that were still running
2785 #[serde(skip_serializing_if = "Option::is_none")]
2786 pub tool_call_ids: Option<Vec<String>>,
2787 /// Names of the tools that were still running. More than one when the model requested a parallel fan-out.
2788 #[serde(skip_serializing_if = "Option::is_none")]
2789 pub tool_names: Option<Vec<String>>,
2790 /// For an interrupted model call: the transport the request used
2791 #[serde(skip_serializing_if = "Option::is_none")]
2792 pub transport: Option<ModelCallFailureTransport>,
2793 /// Zero-based agentic-loop iteration the interrupt landed in
2794 pub turn: i64,
2795}
2796
2797/// Session event "assistant.intent". Agent intent description for current activity or plan
2798#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2799#[serde(rename_all = "camelCase")]
2800pub struct AssistantIntentData {
2801 /// Short description of what the agent is currently doing or planning to do
2802 pub intent: String,
2803}
2804
2805/// Session event "assistant.fusion_phase_started". Experimental transient HydraFusion phase/model/role signal.
2806///
2807/// <div class="warning">
2808///
2809/// **Experimental.** This type is part of an experimental wire-protocol surface
2810/// and may change or be removed in future SDK or CLI releases.
2811///
2812/// </div>
2813#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2814#[serde(rename_all = "camelCase")]
2815pub struct AssistantFusionPhaseStartedData {
2816 /// Conversation scope in which the phase executes.
2817 pub conversation_scope: FusionConversationScope,
2818 /// Identifier of the HydraFusion turn containing the phase.
2819 pub fusion_id: String,
2820 /// Concrete model executing the phase.
2821 pub model: String,
2822 /// HydraFusion orchestration pattern containing the phase.
2823 pub pattern: FusionPattern,
2824 /// Stable identifier for the concrete phase.
2825 pub phase_id: String,
2826 /// Kind of phase being executed.
2827 pub phase_kind: FusionPhaseKind,
2828 /// Explicit reasoning effort selected for this phase, if supplied.
2829 ///
2830 /// <div class="warning">
2831 ///
2832 /// **Experimental.** This type is part of an experimental wire-protocol surface
2833 /// and may change or be removed in future SDK or CLI releases.
2834 ///
2835 /// </div>
2836 #[serde(skip_serializing_if = "Option::is_none")]
2837 pub reasoning_effort: Option<String>,
2838 /// Semantic role assigned to the phase.
2839 pub role: String,
2840}
2841
2842/// Session event "assistant.fusion_phase_activity". Experimental content-safe activity signal for a running HydraFusion phase.
2843///
2844/// <div class="warning">
2845///
2846/// **Experimental.** This type is part of an experimental wire-protocol surface
2847/// and may change or be removed in future SDK or CLI releases.
2848///
2849/// </div>
2850#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2851#[serde(rename_all = "camelCase")]
2852pub struct AssistantFusionPhaseActivityData {
2853 /// Kind of real activity observed.
2854 pub activity: FusionPhaseActivityKind,
2855 /// Conversation scope in which the phase executes.
2856 pub conversation_scope: FusionConversationScope,
2857 /// Identifier of the HydraFusion turn containing the phase.
2858 pub fusion_id: String,
2859 /// HydraFusion orchestration pattern containing the phase.
2860 pub pattern: FusionPattern,
2861 /// Stable identifier for the concrete phase.
2862 pub phase_id: String,
2863 /// Kind of phase currently executing.
2864 pub phase_kind: FusionPhaseKind,
2865 /// Semantic role assigned to the phase.
2866 pub role: String,
2867 /// Opaque hashed correlation token for matching tool-started and tool-completed activity within this Fusion activity stream. It is not the tool call identifier exposed by tool lifecycle events.
2868 #[serde(skip_serializing_if = "Option::is_none")]
2869 pub tool_call_id: Option<String>,
2870 /// Cumulative private response bytes observed for this model call. The event never includes response text.
2871 #[serde(skip_serializing_if = "Option::is_none")]
2872 pub total_response_size_bytes: Option<i64>,
2873}
2874
2875/// Internal durable terminal request staged by a HydraFusion phase until an idempotent final commit selects it.
2876///
2877/// <div class="warning">
2878///
2879/// **Experimental.** This type is part of an experimental wire-protocol surface
2880/// and may change or be removed in future SDK or CLI releases.
2881///
2882/// </div>
2883#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2884#[serde(rename_all = "camelCase")]
2885pub(crate) struct FusionStagedTerminal {
2886 pub arguments: String,
2887 pub assistant_message: serde_json::Value,
2888 pub phase_id: String,
2889 pub tool_call_id: String,
2890 pub tool_name: String,
2891}
2892
2893/// Aggregate concrete-model usage for one HydraFusion phase.
2894///
2895/// <div class="warning">
2896///
2897/// **Experimental.** This type is part of an experimental wire-protocol surface
2898/// and may change or be removed in future SDK or CLI releases.
2899///
2900/// </div>
2901#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2902#[serde(rename_all = "camelCase")]
2903pub struct FusionPhaseUsage {
2904 /// Total cached input tokens reported for the phase.
2905 pub cached_tokens: i64,
2906 /// Total tokens written to prompt cache during the phase.
2907 #[serde(skip_serializing_if = "Option::is_none")]
2908 pub cache_write_tokens: Option<i64>,
2909 /// Total input tokens consumed by the phase.
2910 pub input_tokens: i64,
2911 /// Total output tokens produced by the phase.
2912 pub output_tokens: i64,
2913 /// Number of concrete model requests made by the phase.
2914 pub request_count: i64,
2915 /// Total normalized AI-unit cost reported for the phase, in nano-AIU.
2916 pub total_nano_aiu: f64,
2917}
2918
2919/// Session event "assistant.fusion_phase_completed". Experimental durable HydraFusion phase output and lossless replay checkpoint.
2920///
2921/// <div class="warning">
2922///
2923/// **Experimental.** This type is part of an experimental wire-protocol surface
2924/// and may change or be removed in future SDK or CLI releases.
2925///
2926/// </div>
2927#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2928#[serde(rename_all = "camelCase")]
2929pub struct AssistantFusionPhaseCompletedData {
2930 /// Provider-normalized textual output produced by the phase.
2931 pub content: String,
2932 /// Conversation scope in which the phase executed.
2933 pub conversation_scope: FusionConversationScope,
2934 /// Elapsed execution time for the phase in milliseconds.
2935 pub duration_ms: f64,
2936 /// Identifier of the HydraFusion turn containing the phase.
2937 pub fusion_id: String,
2938 /// Concrete model that executed the phase.
2939 pub model: String,
2940 /// Stable identifier for the completed phase.
2941 pub phase_id: String,
2942 /// Kind of phase that completed.
2943 pub phase_kind: FusionPhaseKind,
2944 /// Exact provider-normalized message used to reconstruct canonical model history.
2945 #[doc(hidden)]
2946 #[serde(skip_serializing_if = "Option::is_none")]
2947 pub(crate) projection_message: Option<serde_json::Value>,
2948 /// Projection action for the exact internal message.
2949 #[doc(hidden)]
2950 #[serde(skip_serializing_if = "Option::is_none")]
2951 pub(crate) projection_mode: Option<FusionProjectionMode>,
2952 /// Explicit reasoning effort selected for this phase, if supplied.
2953 ///
2954 /// <div class="warning">
2955 ///
2956 /// **Experimental.** This type is part of an experimental wire-protocol surface
2957 /// and may change or be removed in future SDK or CLI releases.
2958 ///
2959 /// </div>
2960 #[serde(skip_serializing_if = "Option::is_none")]
2961 pub reasoning_effort: Option<String>,
2962 /// Semantic role assigned to the completed phase.
2963 pub role: String,
2964 /// Terminal request held outside canonical state until selected by the final commit.
2965 #[doc(hidden)]
2966 #[serde(skip_serializing_if = "Option::is_none")]
2967 pub(crate) staged_terminal: Option<FusionStagedTerminal>,
2968 /// Durable outcome status of the phase.
2969 pub status: FusionPhaseStatus,
2970 /// Aggregate concrete-model usage consumed by the phase.
2971 pub usage: FusionPhaseUsage,
2972 /// Structured judge or critic verdict, when the phase produces one.
2973 pub verdict: Option<String>,
2974}
2975
2976/// Session event "assistant.fusion_phase_failed". Experimental durable typed HydraFusion phase failure and degradation transition.
2977///
2978/// <div class="warning">
2979///
2980/// **Experimental.** This type is part of an experimental wire-protocol surface
2981/// and may change or be removed in future SDK or CLI releases.
2982///
2983/// </div>
2984#[derive(Debug, Clone, Default, Serialize, Deserialize)]
2985#[serde(rename_all = "camelCase")]
2986pub struct AssistantFusionPhaseFailedData {
2987 /// Conversation scope in which the phase executed.
2988 pub conversation_scope: FusionConversationScope,
2989 /// Identifier of the fallback phase used to continue the turn after degradation.
2990 #[serde(skip_serializing_if = "Option::is_none")]
2991 pub degraded_to_phase_id: Option<String>,
2992 /// Elapsed execution time before the phase failed, in milliseconds.
2993 pub duration_ms: f64,
2994 /// Provider or execution error detail, when available.
2995 #[serde(skip_serializing_if = "Option::is_none")]
2996 pub error_message: Option<String>,
2997 /// Identifier of the HydraFusion turn containing the phase.
2998 pub fusion_id: String,
2999 /// Concrete model that attempted the phase.
3000 pub model: String,
3001 /// Stable identifier for the failed phase.
3002 pub phase_id: String,
3003 /// Kind of phase that failed.
3004 pub phase_kind: FusionPhaseKind,
3005 /// Stable machine-readable reason for the phase failure.
3006 pub reason: String,
3007 /// Explicit reasoning effort selected for this phase, if supplied.
3008 ///
3009 /// <div class="warning">
3010 ///
3011 /// **Experimental.** This type is part of an experimental wire-protocol surface
3012 /// and may change or be removed in future SDK or CLI releases.
3013 ///
3014 /// </div>
3015 #[serde(skip_serializing_if = "Option::is_none")]
3016 pub reasoning_effort: Option<String>,
3017 /// Semantic role assigned to the failed phase.
3018 pub role: String,
3019 /// Durable outcome status of the phase.
3020 pub status: FusionPhaseStatus,
3021 /// Aggregate concrete-model usage consumed before the failure.
3022 pub usage: FusionPhaseUsage,
3023}
3024
3025/// Session event "assistant.server_tool_progress". Live progress signal for a provider-hosted server tool (e.g. hosted web search) while it runs, before the finalized serverTools envelope lands on the terminal assistant.message
3026#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3027#[serde(rename_all = "camelCase")]
3028pub struct AssistantServerToolProgressData {
3029 /// Kind of hosted server tool that is running. Only `web_search` is emitted today.
3030 pub kind: String,
3031 /// Position of the hosted tool call in the response output. Stable across the call's lifecycle events (unlike the provider's per-event item id, which CAPI rotates), so the host keys the live in-progress row on it.
3032 pub output_index: i64,
3033 /// Lifecycle status of the hosted call: `in_progress`, `searching`, or `completed`.
3034 pub status: String,
3035}
3036
3037/// Session event "assistant.reasoning". Assistant reasoning content for timeline display with complete thinking text
3038#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3039#[serde(rename_all = "camelCase")]
3040pub struct AssistantReasoningData {
3041 /// The complete extended thinking text from the model
3042 pub content: String,
3043 /// Unique identifier for this reasoning block
3044 pub reasoning_id: String,
3045 /// Per-request treatment/eligibility signal returned by the Copilot API in the `X-GitHub-Copilot-Request-TE` response header for the associated model call; `false` when the header was absent or unparseable.
3046 #[serde(skip_serializing_if = "Option::is_none")]
3047 pub rte: Option<bool>,
3048}
3049
3050/// Session event "assistant.reasoning_delta". Streaming reasoning delta for incremental extended thinking updates
3051#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3052#[serde(rename_all = "camelCase")]
3053pub struct AssistantReasoningDeltaData {
3054 /// Incremental text chunk to append to the reasoning content
3055 pub delta_content: String,
3056 /// Reasoning block ID this delta belongs to, matching the corresponding assistant.reasoning event
3057 pub reasoning_id: String,
3058}
3059
3060/// Session event "assistant.tool_call_delta". Streaming tool-call input delta for incremental tool-call updates
3061#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3062#[serde(rename_all = "camelCase")]
3063pub struct AssistantToolCallDeltaData {
3064 /// Raw provider tool input fragment to append for this tool call. Function/tool-use providers stream serialized JSON argument text (so newlines inside JSON string values may appear as escaped `\n` until the accumulated JSON is parsed); custom tool calls stream raw custom input.
3065 pub input_delta: String,
3066 /// Tool call ID this delta belongs to, matching the corresponding assistant.message tool request
3067 pub tool_call_id: String,
3068 /// Name of the tool being invoked, when known from the stream
3069 #[serde(skip_serializing_if = "Option::is_none")]
3070 pub tool_name: Option<String>,
3071 /// Tool call type, when known from the stream
3072 #[serde(skip_serializing_if = "Option::is_none")]
3073 pub tool_type: Option<AssistantMessageToolRequestType>,
3074}
3075
3076/// Session event "assistant.streaming_delta". Streaming response progress with cumulative byte count
3077#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3078#[serde(rename_all = "camelCase")]
3079pub struct AssistantStreamingDeltaData {
3080 /// Cumulative total bytes received from the streaming response so far
3081 pub total_response_size_bytes: i64,
3082}
3083
3084/// A source that backs one or more cited spans in the assistant's response.
3085///
3086/// <div class="warning">
3087///
3088/// **Experimental.** This type is part of an experimental wire-protocol surface
3089/// and may change or be removed in future SDK or CLI releases.
3090///
3091/// </div>
3092#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3093#[serde(rename_all = "camelCase")]
3094pub struct CitationSource {
3095 /// Stable, turn-scoped identifier for this source, referenced by CitationReference.sourceId.
3096 pub id: String,
3097 /// File path relative to the agent's workspace root, when the source is a file.
3098 #[serde(skip_serializing_if = "Option::is_none")]
3099 pub path: Option<String>,
3100 /// The system that produced this citation.
3101 pub provider: CitationProvider,
3102 /// Human-readable title of the source.
3103 #[serde(skip_serializing_if = "Option::is_none")]
3104 pub title: Option<String>,
3105 /// URL of the source, when it is a web resource.
3106 #[serde(skip_serializing_if = "Option::is_none")]
3107 pub url: Option<String>,
3108}
3109
3110/// A single citation occurrence linking a span of generated text to a supporting source.
3111///
3112/// <div class="warning">
3113///
3114/// **Experimental.** This type is part of an experimental wire-protocol surface
3115/// and may change or be removed in future SDK or CLI releases.
3116///
3117/// </div>
3118#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3119#[serde(rename_all = "camelCase")]
3120pub struct CitationReference {
3121 /// The exact text from the source that supports the cited span, when provided by the model.
3122 #[serde(skip_serializing_if = "Option::is_none")]
3123 pub cited_text: Option<String>,
3124 /// Location within the source that supports the cited span, when the provider reports one.
3125 #[serde(skip_serializing_if = "Option::is_none")]
3126 pub location: Option<serde_json::Value>,
3127 /// Provider-native citation correlation data (e.g. Anthropic search_result_index / document_index), passed through opaquely for debugging and forward compatibility.
3128 #[serde(skip_serializing_if = "Option::is_none")]
3129 pub provider_metadata: Option<serde_json::Value>,
3130 /// Identifier of the CitationSource this reference points to (CitationSource.id).
3131 pub source_id: String,
3132}
3133
3134/// A contiguous span of generated assistant text and the source references that support it.
3135///
3136/// <div class="warning">
3137///
3138/// **Experimental.** This type is part of an experimental wire-protocol surface
3139/// and may change or be removed in future SDK or CLI releases.
3140///
3141/// </div>
3142#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3143#[serde(rename_all = "camelCase")]
3144pub struct CitationSpan {
3145 /// End offset of the cited span within the final assistant message content (UTF-16 code units, zero-based, exclusive).
3146 pub end_index: i64,
3147 /// The sources that support this span of generated text.
3148 pub references: Vec<CitationReference>,
3149 /// Start offset of the cited span within the final assistant message content (UTF-16 code units, zero-based, inclusive).
3150 pub start_index: i64,
3151}
3152
3153/// Provider-agnostic citations linking spans of the assistant's response to their supporting sources.
3154///
3155/// <div class="warning">
3156///
3157/// **Experimental.** This type is part of an experimental wire-protocol surface
3158/// and may change or be removed in future SDK or CLI releases.
3159///
3160/// </div>
3161#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3162#[serde(rename_all = "camelCase")]
3163pub struct Citations {
3164 /// Deduplicated set of sources referenced by the citation spans.
3165 pub sources: Vec<CitationSource>,
3166 /// Spans of generated text annotated with the sources that support them.
3167 pub spans: Vec<CitationSpan>,
3168}
3169
3170/// Experimental attribution linking an ordinary event to the HydraFusion turn, phase, and concrete source that produced it.
3171///
3172/// <div class="warning">
3173///
3174/// **Experimental.** This type is part of an experimental wire-protocol surface
3175/// and may change or be removed in future SDK or CLI releases.
3176///
3177/// </div>
3178#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3179#[serde(rename_all = "camelCase")]
3180pub struct FusionAttribution {
3181 /// Idempotency identifier for the authoritative commit, when the event belongs to the selected output.
3182 #[serde(skip_serializing_if = "Option::is_none")]
3183 pub commit_id: Option<String>,
3184 /// Conversation scope in which the concrete phase executed.
3185 #[serde(skip_serializing_if = "Option::is_none")]
3186 pub conversation_scope: Option<String>,
3187 /// Stable identifier for the HydraFusion turn that produced the event.
3188 pub fusion_id: String,
3189 /// Whether this model request consumed a user steering message rather than only internal Fusion work.
3190 #[serde(skip_serializing_if = "Option::is_none")]
3191 pub has_user_steering: Option<bool>,
3192 /// HydraFusion orchestration pattern selected for the turn.
3193 pub pattern: String,
3194 /// Identifier of the concrete phase that produced the event.
3195 #[serde(skip_serializing_if = "Option::is_none")]
3196 pub phase_id: Option<String>,
3197 /// Kind of concrete phase that produced the event.
3198 #[serde(skip_serializing_if = "Option::is_none")]
3199 pub phase_kind: Option<String>,
3200 /// HydraFusion routing policy used for the turn.
3201 pub policy: String,
3202 /// Semantic role assigned to the concrete phase.
3203 #[serde(skip_serializing_if = "Option::is_none")]
3204 pub role: Option<String>,
3205 /// Concrete model that produced the attributed event.
3206 #[serde(skip_serializing_if = "Option::is_none")]
3207 pub source_model: Option<String>,
3208 /// Phase whose output supplied the authoritative content, when different from the executing phase.
3209 #[serde(skip_serializing_if = "Option::is_none")]
3210 pub source_phase_id: Option<String>,
3211 /// Synthetic HydraFusion model selected for the session.
3212 pub synthetic_model: String,
3213}
3214
3215/// Neutral provider-tagged reasoning content blocks preserved verbatim for round-tripping
3216///
3217/// <div class="warning">
3218///
3219/// **Experimental.** This type is part of an experimental wire-protocol surface
3220/// and may change or be removed in future SDK or CLI releases.
3221///
3222/// </div>
3223#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3224#[serde(rename_all = "camelCase")]
3225pub struct AssistantMessageReasoningBlocks {
3226 /// Provider-native reasoning items or content blocks preserved verbatim, in order. A single response can carry several, and provider signatures or identifiers may depend on their exact content and ordering.
3227 #[serde(skip_serializing_if = "Option::is_none")]
3228 pub blocks: Option<Vec<serde_json::Value>>,
3229 /// Model provider that produced these reasoning blocks.
3230 pub provider: String,
3231}
3232
3233/// Neutral provider-tagged server-side tool-use payload (tool search, advisor) for verbatim round-tripping
3234///
3235/// <div class="warning">
3236///
3237/// **Experimental.** This type is part of an experimental wire-protocol surface
3238/// and may change or be removed in future SDK or CLI releases.
3239///
3240/// </div>
3241#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3242#[serde(rename_all = "camelCase")]
3243pub struct AssistantMessageServerTools {
3244 /// Advisor model identifier associated with the server-tool payload.
3245 #[serde(skip_serializing_if = "Option::is_none")]
3246 pub advisor_model: Option<String>,
3247 /// Provider function-call namespaces keyed by function-call identifier.
3248 #[serde(skip_serializing_if = "Option::is_none")]
3249 pub function_call_namespaces: Option<HashMap<String, String>>,
3250 /// Provider-native server-tool call and output items preserved verbatim for replay.
3251 #[serde(skip_serializing_if = "Option::is_none")]
3252 pub items: Option<Vec<serde_json::Value>>,
3253 /// Model provider that produced this server-tool payload.
3254 pub provider: String,
3255 /// Raw provider content blocks retained for verbatim round-tripping.
3256 #[serde(skip_serializing_if = "Option::is_none")]
3257 pub raw_content_blocks: Option<Vec<serde_json::Value>>,
3258}
3259
3260/// Hosted program that requested this client tool call
3261#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3262#[serde(rename_all = "camelCase")]
3263pub struct AssistantMessageToolRequestCaller {
3264 /// Provider-assigned identifier for the hosted caller.
3265 pub caller_id: String,
3266 /// Kind of hosted caller that requested the client tool call.
3267 pub r#type: AssistantMessageToolRequestCallerType,
3268}
3269
3270/// A tool invocation request from the assistant
3271#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3272#[serde(rename_all = "camelCase")]
3273pub struct AssistantMessageToolRequest {
3274 /// Arguments to pass to the tool, format depends on the tool
3275 #[serde(skip_serializing_if = "Option::is_none")]
3276 pub arguments: Option<serde_json::Value>,
3277 /// Hosted program that requested this client tool call
3278 #[serde(skip_serializing_if = "Option::is_none")]
3279 pub caller: Option<AssistantMessageToolRequestCaller>,
3280 /// Resolved intention summary describing what this specific call does
3281 #[serde(skip_serializing_if = "Option::is_none")]
3282 pub intention_summary: Option<String>,
3283 /// Name of the MCP server hosting this tool, when the tool is an MCP tool
3284 #[serde(skip_serializing_if = "Option::is_none")]
3285 pub mcp_server_name: Option<String>,
3286 /// Original tool name on the MCP server, when the tool is an MCP tool
3287 #[serde(skip_serializing_if = "Option::is_none")]
3288 pub mcp_tool_name: Option<String>,
3289 /// Name of the tool being invoked
3290 pub name: String,
3291 /// Unique identifier for this tool call
3292 pub tool_call_id: String,
3293 /// Human-readable display title for the tool
3294 #[serde(skip_serializing_if = "Option::is_none")]
3295 pub tool_title: Option<String>,
3296 /// Tool call type: "function" for standard tool calls, "custom" for grammar-based tool calls. Defaults to "function" when absent.
3297 #[serde(skip_serializing_if = "Option::is_none")]
3298 pub r#type: Option<AssistantMessageToolRequestType>,
3299}
3300
3301/// Session event "assistant.message". Assistant response containing text content, optional tool requests, and interaction metadata
3302#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3303#[serde(rename_all = "camelCase")]
3304pub struct AssistantMessageData {
3305 /// Provider's completion / response identifier; shared across all chunks of a single API call. Used to group multi-chunk assistant utterances.
3306 #[serde(skip_serializing_if = "Option::is_none")]
3307 pub api_call_id: Option<String>,
3308 /// Total messages the model call's response was split into, one per reasoning boundary. Absent for a single-message response; the last chunk is the one where chunkIndex is chunkCount - 1.
3309 #[serde(skip_serializing_if = "Option::is_none")]
3310 pub chunk_count: Option<i64>,
3311 /// Zero-based position of this message within its model call's response. Absent when the response was not split into chunks.
3312 #[serde(skip_serializing_if = "Option::is_none")]
3313 pub chunk_index: Option<i64>,
3314 /// Provider-agnostic citations linking spans of this message's content to the sources that support them. Experimental; only populated when citation emission is enabled.
3315 ///
3316 /// <div class="warning">
3317 ///
3318 /// **Experimental.** This type is part of an experimental wire-protocol surface
3319 /// and may change or be removed in future SDK or CLI releases.
3320 ///
3321 /// </div>
3322 #[serde(skip_serializing_if = "Option::is_none")]
3323 pub citations: Option<Citations>,
3324 /// Client-minted request id (x-request-id header) echoed by the server. Distinct from requestId (x-github-request-id) and serviceRequestId (x-copilot-service-request-id).
3325 #[serde(skip_serializing_if = "Option::is_none")]
3326 pub client_request_id: Option<String>,
3327 /// The assistant's text response content
3328 pub content: String,
3329 /// Encrypted reasoning content from OpenAI models. Session-bound and stripped on resume.
3330 #[serde(skip_serializing_if = "Option::is_none")]
3331 pub encrypted_content: Option<String>,
3332 /// Experimental HydraFusion source attribution for this ordinary authoritative assistant message.
3333 ///
3334 /// <div class="warning">
3335 ///
3336 /// **Experimental.** This type is part of an experimental wire-protocol surface
3337 /// and may change or be removed in future SDK or CLI releases.
3338 ///
3339 /// </div>
3340 #[serde(skip_serializing_if = "Option::is_none")]
3341 pub fusion: Option<FusionAttribution>,
3342 /// CAPI interaction ID for correlating this message with upstream telemetry
3343 #[serde(skip_serializing_if = "Option::is_none")]
3344 pub interaction_id: Option<String>,
3345 /// Unique identifier for this assistant message
3346 pub message_id: String,
3347 /// Model that produced this assistant message, if known
3348 #[serde(skip_serializing_if = "Option::is_none")]
3349 pub model: Option<String>,
3350 /// Logical ID of the primary user message that initiated this run, matching the messageId returned by session.send (or the last messageId of session.sendMessages). Stable across model/tool iterations, steering messages, and stop-hook corrections. Subagent runs use their own initiating message ID, not the parent's. Absent for runs without an associated initiating message, such as empty batches.
3351 #[serde(skip_serializing_if = "Option::is_none")]
3352 pub originating_message_id: Option<String>,
3353 /// Actual output token count from the API response (completion_tokens), used for accurate token accounting
3354 #[serde(skip_serializing_if = "Option::is_none")]
3355 pub output_tokens: Option<i64>,
3356 /// Tool call ID of the parent tool invocation when this event originates from a sub-agent
3357 #[doc(hidden)]
3358 #[deprecated]
3359 #[serde(skip_serializing_if = "Option::is_none")]
3360 pub parent_tool_call_id: Option<String>,
3361 /// Generation phase for phased-output models (e.g., thinking vs. response phases)
3362 #[serde(skip_serializing_if = "Option::is_none")]
3363 pub phase: Option<String>,
3364 /// Neutral provider-tagged reasoning content blocks preserved verbatim for round-tripping. `reasoningText` and `reasoningOpaque` are a lossy derived view of these blocks, retained for display.
3365 #[serde(skip_serializing_if = "Option::is_none")]
3366 pub reasoning_blocks: Option<AssistantMessageReasoningBlocks>,
3367 /// Opaque/encrypted extended thinking data from Anthropic models. Session-bound and stripped on resume.
3368 #[serde(skip_serializing_if = "Option::is_none")]
3369 pub reasoning_opaque: Option<String>,
3370 /// Readable reasoning text from the model's extended thinking
3371 #[serde(skip_serializing_if = "Option::is_none")]
3372 pub reasoning_text: Option<String>,
3373 /// OpenAI-compatible wire field the provider used for reasoning (e.g. reasoning_content/reasoning). Populated only when non-canonical, so the dialect round-trips across turns.
3374 #[serde(skip_serializing_if = "Option::is_none")]
3375 pub reasoning_wire_field: Option<String>,
3376 /// GitHub request tracing ID (x-github-request-id header) for correlating with server-side logs
3377 #[serde(skip_serializing_if = "Option::is_none")]
3378 pub request_id: Option<RequestId>,
3379 /// Per-request treatment/eligibility signal returned by the Copilot API in the `X-GitHub-Copilot-Request-TE` response header for the associated model call; `false` when the header was absent or unparseable.
3380 #[serde(skip_serializing_if = "Option::is_none")]
3381 pub rte: Option<bool>,
3382 /// Neutral provider-tagged server-side tool-use payload (tool search, advisor) for verbatim round-tripping
3383 #[serde(skip_serializing_if = "Option::is_none")]
3384 pub server_tools: Option<AssistantMessageServerTools>,
3385 /// Copilot service request ID (x-copilot-service-request-id header) for CAPI log correlation
3386 #[serde(skip_serializing_if = "Option::is_none")]
3387 pub service_request_id: Option<String>,
3388 /// Tool invocations requested by the assistant in this message
3389 #[serde(skip_serializing_if = "Option::is_none")]
3390 pub tool_requests: Option<Vec<AssistantMessageToolRequest>>,
3391 /// Identifier for the agent loop turn that produced this message, matching the corresponding assistant.turn_start event
3392 #[serde(skip_serializing_if = "Option::is_none")]
3393 pub turn_id: Option<String>,
3394}
3395
3396/// Session event "assistant.message_start". Streaming assistant message start metadata
3397#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3398#[serde(rename_all = "camelCase")]
3399pub struct AssistantMessageStartData {
3400 /// Message ID this start event belongs to, matching subsequent deltas and assistant.message
3401 pub message_id: String,
3402 /// Generation phase this message belongs to for phased-output models
3403 #[serde(skip_serializing_if = "Option::is_none")]
3404 pub phase: Option<String>,
3405}
3406
3407/// Session event "assistant.message_delta". Streaming assistant message delta for incremental response updates
3408#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3409#[serde(rename_all = "camelCase")]
3410pub struct AssistantMessageDeltaData {
3411 /// Incremental text chunk to append to the message content
3412 pub delta_content: String,
3413 /// Message ID this delta belongs to, matching the corresponding assistant.message event
3414 pub message_id: String,
3415 /// Tool call ID of the parent tool invocation when this event originates from a sub-agent
3416 #[doc(hidden)]
3417 #[deprecated]
3418 #[serde(skip_serializing_if = "Option::is_none")]
3419 pub parent_tool_call_id: Option<String>,
3420}
3421
3422/// Session event "assistant.turn_end". Turn completion metadata including the turn identifier
3423#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3424#[serde(rename_all = "camelCase")]
3425pub struct AssistantTurnEndData {
3426 /// Model identifier used for this turn, when known
3427 #[serde(skip_serializing_if = "Option::is_none")]
3428 pub model: Option<String>,
3429 /// Parent task tool call ID when this turn belongs to a sub-agent
3430 #[serde(skip_serializing_if = "Option::is_none")]
3431 pub parent_tool_call_id: Option<String>,
3432 /// Identifier of the turn that has ended, matching the corresponding assistant.turn_start event
3433 pub turn_id: String,
3434}
3435
3436/// Session event "assistant.idle". Payload emitted whenever the main agent's processing loop goes idle, including while related background work (running agents or in-flight attached shell commands) is still pending and the session-level idle event is therefore deferred
3437#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3438#[serde(rename_all = "camelCase")]
3439pub struct AssistantIdleData {
3440 /// True when the preceding agentic loop was cancelled via abort signal
3441 #[serde(skip_serializing_if = "Option::is_none")]
3442 pub aborted: Option<bool>,
3443}
3444
3445/// Token usage detail for a single billing category
3446#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3447#[serde(rename_all = "camelCase")]
3448pub struct AssistantUsageCopilotUsageTokenDetail {
3449 /// Number of tokens in this billing batch
3450 pub batch_size: i64,
3451 /// Cost per batch of tokens
3452 pub cost_per_batch: i64,
3453 /// Model responsible for this billing entry
3454 #[serde(skip_serializing_if = "Option::is_none")]
3455 pub model: Option<String>,
3456 /// Total token count for this entry
3457 pub token_count: i64,
3458 /// Token category (e.g., "input", "output")
3459 pub token_type: String,
3460}
3461
3462/// Per-request cost and usage data from the CAPI copilot_usage response field
3463#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3464#[serde(rename_all = "camelCase")]
3465pub struct AssistantUsageCopilotUsage {
3466 /// Default billing model for token details that do not identify their own model
3467 #[serde(skip_serializing_if = "Option::is_none")]
3468 pub model: Option<String>,
3469 /// Itemized token usage breakdown
3470 #[doc(hidden)]
3471 #[serde(skip_serializing_if = "Option::is_none")]
3472 pub(crate) token_details: Option<Vec<AssistantUsageCopilotUsageTokenDetail>>,
3473 /// Total cost in nano-AI units for this request
3474 pub total_nano_aiu: f64,
3475}
3476
3477/// Internal per-quota snapshot for assistant usage, including entitlement, consumed requests, overage, reset date, and remaining quota.
3478#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3479#[serde(rename_all = "camelCase")]
3480pub(crate) struct AssistantUsageQuotaSnapshot {
3481 /// Total requests allowed by the entitlement
3482 #[doc(hidden)]
3483 pub(crate) entitlement_requests: i64,
3484 /// Whether the user currently has quota available for use
3485 #[doc(hidden)]
3486 #[serde(skip_serializing_if = "Option::is_none")]
3487 pub(crate) has_quota: Option<bool>,
3488 /// Whether the user has an unlimited usage entitlement
3489 #[doc(hidden)]
3490 pub(crate) is_unlimited_entitlement: bool,
3491 /// Number of additional usage requests made this period
3492 #[doc(hidden)]
3493 pub(crate) overage: f64,
3494 /// Whether additional usage is allowed when quota is exhausted
3495 #[doc(hidden)]
3496 pub(crate) overage_allowed_with_exhausted_quota: bool,
3497 /// Pay-as-you-go additional-usage budget cap in AI credits (1 credit = $0.01); present only when CAPI emits a finite value
3498 #[doc(hidden)]
3499 #[serde(skip_serializing_if = "Option::is_none")]
3500 pub(crate) overage_entitlement: Option<f64>,
3501 /// Percentage of quota remaining (0 to 100)
3502 #[doc(hidden)]
3503 pub(crate) remaining_percentage: f64,
3504 /// Date when the quota resets
3505 #[doc(hidden)]
3506 #[serde(skip_serializing_if = "Option::is_none")]
3507 pub(crate) reset_date: Option<String>,
3508 /// Whether this snapshot uses token-based billing (AI-credits allocation)
3509 #[doc(hidden)]
3510 #[serde(skip_serializing_if = "Option::is_none")]
3511 pub(crate) token_based_billing: Option<bool>,
3512 /// Whether usage is still permitted after quota exhaustion
3513 #[doc(hidden)]
3514 pub(crate) usage_allowed_with_exhausted_quota: bool,
3515 /// Number of requests already consumed
3516 #[doc(hidden)]
3517 pub(crate) used_requests: i64,
3518}
3519
3520/// Session event "assistant.usage". LLM API call usage metrics including tokens, costs, quotas, and billing information
3521#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3522#[serde(rename_all = "camelCase")]
3523pub struct AssistantUsageData {
3524 /// Number of accepted speculative prediction tokens
3525 #[serde(skip_serializing_if = "Option::is_none")]
3526 pub accepted_prediction_tokens: Option<i64>,
3527 /// Completion ID from the model provider (e.g., chatcmpl-abc123)
3528 #[serde(skip_serializing_if = "Option::is_none")]
3529 pub api_call_id: Option<String>,
3530 /// API endpoint used for this model call, matching CAPI supported_endpoints vocabulary
3531 #[serde(skip_serializing_if = "Option::is_none")]
3532 pub api_endpoint: Option<AssistantUsageApiEndpoint>,
3533 /// Number of tools available to the model for this call
3534 #[doc(hidden)]
3535 #[serde(skip_serializing_if = "Option::is_none")]
3536 pub(crate) available_tool_count: Option<i64>,
3537 /// Whether the provider reported prompt-cache usage details for this call
3538 #[doc(hidden)]
3539 #[serde(skip_serializing_if = "Option::is_none")]
3540 pub(crate) cache_details_reported: Option<bool>,
3541 /// Updated prompt-cache expiration for this model call. Present only when the call establishes or refreshes known cache state.
3542 #[serde(skip_serializing_if = "Option::is_none")]
3543 pub cache_expires_at: Option<String>,
3544 /// Number of tokens read from prompt cache
3545 #[serde(skip_serializing_if = "Option::is_none")]
3546 pub cache_read_tokens: Option<i64>,
3547 /// Effective prompt-cache lifetime in seconds for this call
3548 #[doc(hidden)]
3549 #[serde(skip_serializing_if = "Option::is_none")]
3550 pub(crate) cache_ttl_seconds: Option<i64>,
3551 /// Number of tokens written to prompt cache
3552 #[serde(skip_serializing_if = "Option::is_none")]
3553 pub cache_write_tokens: Option<i64>,
3554 /// Whether the model response was blocked or truncated by content filtering (finish_reason === 'content_filter'). For Anthropic models this corresponds to a 'refusal' stop reason.
3555 #[serde(skip_serializing_if = "Option::is_none")]
3556 pub content_filter_triggered: Option<bool>,
3557 /// Per-request cost and usage data from the CAPI copilot_usage response field
3558 #[serde(skip_serializing_if = "Option::is_none")]
3559 pub copilot_usage: Option<AssistantUsageCopilotUsage>,
3560 /// Model multiplier cost for billing purposes
3561 ///
3562 /// <div class="warning">
3563 ///
3564 /// **Experimental.** This type is part of an experimental wire-protocol surface
3565 /// and may change or be removed in future SDK or CLI releases.
3566 ///
3567 /// </div>
3568 #[serde(skip_serializing_if = "Option::is_none")]
3569 pub cost: Option<f64>,
3570 /// Duration of the API call in milliseconds
3571 #[serde(skip_serializing_if = "Option::is_none")]
3572 pub duration: Option<i64>,
3573 /// Finish reason reported by the model for this API call (e.g. "stop", "length", "tool_calls", "content_filter"). Normalized to OpenAI vocabulary; for Anthropic models a "refusal" stop reason maps to "content_filter".
3574 #[serde(skip_serializing_if = "Option::is_none")]
3575 pub finish_reason: Option<String>,
3576 /// How the prompt-cache frontier was determined for this call
3577 #[doc(hidden)]
3578 #[serde(skip_serializing_if = "Option::is_none")]
3579 pub(crate) frontier_source: Option<String>,
3580 /// Experimental HydraFusion attribution for this concrete model call's usage.
3581 ///
3582 /// <div class="warning">
3583 ///
3584 /// **Experimental.** This type is part of an experimental wire-protocol surface
3585 /// and may change or be removed in future SDK or CLI releases.
3586 ///
3587 /// </div>
3588 #[serde(skip_serializing_if = "Option::is_none")]
3589 pub fusion: Option<FusionAttribution>,
3590 /// What initiated this API call (e.g., "sub-agent", "mcp-sampling"); absent for user-initiated calls
3591 #[serde(skip_serializing_if = "Option::is_none")]
3592 pub initiator: Option<String>,
3593 /// Number of input tokens consumed
3594 #[serde(skip_serializing_if = "Option::is_none")]
3595 pub input_tokens: Option<i64>,
3596 /// Coarse classification of the interaction that produced this call, mirroring the session's per-request agent context (e.g. `conversation-agent`, `conversation-subagent`, `conversation-sampling`, `conversation-background`, `conversation-compaction`, `conversation-user`). Non-billing; lets consumers attribute a model call to a call class (e.g. sub-agent/sidekick) independently of the billing initiator. Absent when the runtime did not classify the request.
3597 #[serde(skip_serializing_if = "Option::is_none")]
3598 pub interaction_type: Option<String>,
3599 /// Average inter-token latency in milliseconds. Only available for streaming requests
3600 #[serde(skip_serializing_if = "Option::is_none")]
3601 pub inter_token_latency_ms: Option<f64>,
3602 /// Whether Auto mode was selected for this model call
3603 #[serde(skip_serializing_if = "Option::is_none")]
3604 pub is_auto: Option<bool>,
3605 /// Whether this model call used a bring-your-own-key provider
3606 #[serde(skip_serializing_if = "Option::is_none")]
3607 pub is_byok: Option<bool>,
3608 /// Requested maximum output tokens used for this model call
3609 #[serde(skip_serializing_if = "Option::is_none")]
3610 pub max_output_tokens: Option<i64>,
3611 /// Effective maximum prompt-token limit used for this model call
3612 #[serde(skip_serializing_if = "Option::is_none")]
3613 pub max_prompt_tokens: Option<i64>,
3614 /// Model identifier used for this API call
3615 pub model: String,
3616 /// Number of tool calls returned by the model
3617 #[doc(hidden)]
3618 #[serde(skip_serializing_if = "Option::is_none")]
3619 pub(crate) num_tool_calls: Option<i64>,
3620 /// Number of output tokens produced
3621 #[serde(skip_serializing_if = "Option::is_none")]
3622 pub output_tokens: Option<i64>,
3623 /// Time to first observable model output in milliseconds. Includes text, reasoning, and tool-call output; only available for streaming requests that produce observable output.
3624 #[serde(skip_serializing_if = "Option::is_none")]
3625 pub output_ttft_ms: Option<f64>,
3626 /// Parent tool call ID when this usage originates from a sub-agent
3627 #[doc(hidden)]
3628 #[deprecated]
3629 #[serde(skip_serializing_if = "Option::is_none")]
3630 pub parent_tool_call_id: Option<String>,
3631 /// GitHub request tracing ID (x-github-request-id header) for server-side log correlation
3632 #[serde(skip_serializing_if = "Option::is_none")]
3633 pub provider_call_id: Option<String>,
3634 /// Per-quota resource usage snapshots, keyed by quota identifier
3635 #[doc(hidden)]
3636 #[serde(skip_serializing_if = "Option::is_none")]
3637 pub(crate) quota_snapshots: Option<HashMap<String, AssistantUsageQuotaSnapshot>>,
3638 /// Reasoning effort level used for model calls, if applicable (e.g. "none", "low", "medium", "high", "xhigh", "max")
3639 #[serde(skip_serializing_if = "Option::is_none")]
3640 pub reasoning_effort: Option<String>,
3641 /// Reasoning summary mode used for this model call, if applicable
3642 #[serde(skip_serializing_if = "Option::is_none")]
3643 pub reasoning_summary: Option<ReasoningSummary>,
3644 /// Number of output tokens used for reasoning (e.g., chain-of-thought)
3645 #[serde(skip_serializing_if = "Option::is_none")]
3646 pub reasoning_tokens: Option<i64>,
3647 /// Number of rejected speculative prediction tokens
3648 #[serde(skip_serializing_if = "Option::is_none")]
3649 pub rejected_prediction_tokens: Option<i64>,
3650 /// Per-request treatment/eligibility signal returned by the Copilot API in the `X-GitHub-Copilot-Request-TE` response header for the associated model call; `false` when the header was absent or unparseable.
3651 #[serde(skip_serializing_if = "Option::is_none")]
3652 pub rte: Option<bool>,
3653 /// Copilot service request ID (x-copilot-service-request-id header) for CAPI log correlation
3654 #[serde(skip_serializing_if = "Option::is_none")]
3655 pub service_request_id: Option<String>,
3656 /// Number of prior thinking blocks the provider dropped while transforming the request
3657 #[doc(hidden)]
3658 #[serde(skip_serializing_if = "Option::is_none")]
3659 pub(crate) thinking_dropped_blocks: Option<i64>,
3660 /// Recognized provider-reported reasons for dropped thinking blocks, in response order
3661 #[doc(hidden)]
3662 #[serde(skip_serializing_if = "Option::is_none")]
3663 pub(crate) thinking_dropped_reasons: Option<Vec<String>>,
3664 /// Time to first token in milliseconds. Only available for streaming requests
3665 #[serde(skip_serializing_if = "Option::is_none")]
3666 pub time_to_first_token_ms: Option<f64>,
3667 /// Tool-call counts keyed by tool name
3668 #[doc(hidden)]
3669 #[serde(skip_serializing_if = "Option::is_none")]
3670 pub(crate) tool_counts: Option<HashMap<String, i64>>,
3671 /// Number of tokens used by tool definitions for this call
3672 #[doc(hidden)]
3673 #[serde(skip_serializing_if = "Option::is_none")]
3674 pub(crate) tool_token_count: Option<i64>,
3675 /// Transport used for this model call (http or websocket)
3676 #[serde(skip_serializing_if = "Option::is_none")]
3677 pub transport: Option<AssistantUsageTransport>,
3678}
3679
3680/// Session event "prompt_cache_break". A detected loss of a previously cached prompt prefix
3681#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3682#[serde(rename_all = "camelCase")]
3683pub struct PromptCacheBreakData {
3684 /// Request state whose cached prefix fell short
3685 #[doc(hidden)]
3686 #[serde(skip_serializing_if = "Option::is_none")]
3687 pub(crate) after_request: Option<serde_json::Value>,
3688 /// Name of the sub-agent whose conversation broke, stamped by the parent bridge
3689 #[doc(hidden)]
3690 #[serde(skip_serializing_if = "Option::is_none")]
3691 pub(crate) agent_name: Option<String>,
3692 /// Request state that established the prior cache frontier
3693 #[doc(hidden)]
3694 #[serde(skip_serializing_if = "Option::is_none")]
3695 pub(crate) before_request: Option<serde_json::Value>,
3696 /// Names of the cache-configuration fields that changed
3697 #[doc(hidden)]
3698 #[serde(skip_serializing_if = "Option::is_none")]
3699 pub(crate) cache_config_changed_fields: Option<Vec<String>>,
3700 /// All reasons that contributed to the cache break, ordered by precedence
3701 pub contributing_reasons: Vec<String>,
3702 /// Prior cached prompt frontier in tokens
3703 pub frontier_tokens: i64,
3704 /// Model that held the prior cache frontier, when the call changed models
3705 #[doc(hidden)]
3706 #[serde(skip_serializing_if = "Option::is_none")]
3707 pub(crate) model_from: Option<String>,
3708 /// Model this call targeted, when the call changed models
3709 #[doc(hidden)]
3710 #[serde(skip_serializing_if = "Option::is_none")]
3711 pub(crate) model_to: Option<String>,
3712 /// The highest-precedence reason for the cache break
3713 pub primary_reason: String,
3714 /// Fraction of the prior cache frontier that survived
3715 pub retention_ratio: f64,
3716 /// Index of the first conversation message whose content changed
3717 #[doc(hidden)]
3718 #[serde(skip_serializing_if = "Option::is_none")]
3719 pub(crate) rewrite_message_index: Option<i64>,
3720 /// Shape of the history rewrite, for example whether the history grew or shrank
3721 #[doc(hidden)]
3722 #[serde(skip_serializing_if = "Option::is_none")]
3723 pub(crate) rewrite_shape: Option<String>,
3724 /// Subsystems that announced a history rewrite before this call, for example compaction or truncation
3725 #[doc(hidden)]
3726 #[serde(skip_serializing_if = "Option::is_none")]
3727 pub(crate) rewrite_source: Option<Vec<String>>,
3728 /// Cached prefix tokens lost since the prior call
3729 pub shortfall_tokens: i64,
3730 /// Number of cached prefix tokens that survived
3731 pub survived_tokens: i64,
3732 /// Names of the system-prompt segments whose content changed
3733 #[doc(hidden)]
3734 #[serde(skip_serializing_if = "Option::is_none")]
3735 pub(crate) system_segments_changed: Option<Vec<String>>,
3736 /// Telemetry-safe names of tools added since the prior call
3737 #[doc(hidden)]
3738 #[serde(skip_serializing_if = "Option::is_none")]
3739 pub(crate) tools_added: Option<Vec<String>>,
3740 /// Raw names of tools added since the prior call, restricted because a tool name can be user-authored
3741 #[doc(hidden)]
3742 #[serde(skip_serializing_if = "Option::is_none")]
3743 pub(crate) tools_added_raw: Option<Vec<String>>,
3744 /// Telemetry-safe names of tools whose definition changed since the prior call
3745 #[doc(hidden)]
3746 #[serde(skip_serializing_if = "Option::is_none")]
3747 pub(crate) tools_redefined: Option<Vec<String>>,
3748 /// Raw names of tools redefined since the prior call, restricted because a tool name can be user-authored
3749 #[doc(hidden)]
3750 #[serde(skip_serializing_if = "Option::is_none")]
3751 pub(crate) tools_redefined_raw: Option<Vec<String>>,
3752 /// Telemetry-safe names of tools removed since the prior call
3753 #[doc(hidden)]
3754 #[serde(skip_serializing_if = "Option::is_none")]
3755 pub(crate) tools_removed: Option<Vec<String>>,
3756 /// Raw names of tools removed since the prior call, restricted because a tool name can be user-authored
3757 #[doc(hidden)]
3758 #[serde(skip_serializing_if = "Option::is_none")]
3759 pub(crate) tools_removed_raw: Option<Vec<String>>,
3760 /// Whether the tool list kept its members but changed their order
3761 #[doc(hidden)]
3762 #[serde(skip_serializing_if = "Option::is_none")]
3763 pub(crate) tools_reordered: Option<bool>,
3764}
3765
3766/// Content-free structural summary of the failing request for diagnosing malformed 4xx calls
3767#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3768#[serde(rename_all = "camelCase")]
3769pub struct ModelCallFailureRequestFingerprint {
3770 /// Total number of image content parts
3771 pub image_part_count: i64,
3772 /// Image parts whose media type cannot be determined (rejected by strict providers)
3773 pub image_parts_missing_media_type: i64,
3774 /// Role of the final message in the request
3775 #[serde(skip_serializing_if = "Option::is_none")]
3776 pub last_message_role: Option<String>,
3777 /// Total number of messages in the request
3778 pub message_count: i64,
3779 /// Tool calls whose name is missing or empty (rejected by strict providers)
3780 pub nameless_tool_call_count: i64,
3781 /// Total number of tool calls across assistant messages
3782 pub tool_call_count: i64,
3783 /// Number of "tool" result messages in the request
3784 pub tool_result_message_count: i64,
3785}
3786
3787/// Session event "model.call_failure". Failed LLM API call metadata for telemetry
3788#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3789#[serde(rename_all = "camelCase")]
3790pub struct ModelCallFailureData {
3791 /// Completion ID from the model provider (e.g., chatcmpl-abc123)
3792 #[serde(skip_serializing_if = "Option::is_none")]
3793 pub api_call_id: Option<String>,
3794 /// API endpoint used for this model call, matching CAPI supported_endpoints vocabulary
3795 #[serde(skip_serializing_if = "Option::is_none")]
3796 pub api_endpoint: Option<AssistantUsageApiEndpoint>,
3797 /// For HTTP 400 failures only: whether the response carried a structured CAPI error envelope (structured_error, a deterministic validation failure) or no error body (bodyless, the transient gateway/proxy signature). Absent for non-400 failures.
3798 #[serde(skip_serializing_if = "Option::is_none")]
3799 pub bad_request_kind: Option<ModelCallFailureBadRequestKind>,
3800 /// Duration of the failed API call in milliseconds
3801 #[serde(skip_serializing_if = "Option::is_none")]
3802 pub duration_ms: Option<i64>,
3803 /// For HTTP 400 failures only: the `code` from the CAPI error envelope (e.g. 'model_max_prompt_tokens_exceeded') identifying which deterministic validation failure occurred. Raw server-controlled string, emitted only through restricted telemetry. Absent for bodyless or non-400 failures.
3804 #[serde(skip_serializing_if = "Option::is_none")]
3805 pub error_code: Option<String>,
3806 /// Raw provider/runtime error message for restricted telemetry
3807 #[serde(skip_serializing_if = "Option::is_none")]
3808 pub error_message: Option<String>,
3809 /// For HTTP 400 failures only: the `type` from the CAPI error envelope (e.g. 'websocket_error'), a coarser companion to errorCode for envelopes that carry no code. Raw server-controlled string, emitted only through restricted telemetry. Absent for bodyless or non-400 failures.
3810 #[serde(skip_serializing_if = "Option::is_none")]
3811 pub error_type: Option<String>,
3812 /// Whether the failure originated from an API response or the request transport
3813 #[serde(skip_serializing_if = "Option::is_none")]
3814 pub failure_kind: Option<ModelCallFailureKind>,
3815 /// Experimental HydraFusion attribution for this failed concrete model call.
3816 ///
3817 /// <div class="warning">
3818 ///
3819 /// **Experimental.** This type is part of an experimental wire-protocol surface
3820 /// and may change or be removed in future SDK or CLI releases.
3821 ///
3822 /// </div>
3823 #[serde(skip_serializing_if = "Option::is_none")]
3824 pub fusion: Option<FusionAttribution>,
3825 /// What initiated this API call (e.g., "sub-agent", "mcp-sampling"); absent for user-initiated calls
3826 #[serde(skip_serializing_if = "Option::is_none")]
3827 pub initiator: Option<String>,
3828 /// Authoritative interaction classification for the failed call, matching `assistant.usage.interactionType` (for example `conversation-agent`, `conversation-subagent`, or `conversation-sampling`). Absent when the producer cannot classify the interaction.
3829 #[serde(skip_serializing_if = "Option::is_none")]
3830 pub interaction_type: Option<String>,
3831 /// Whether the session selected Auto mode for the failed call
3832 #[serde(skip_serializing_if = "Option::is_none")]
3833 pub is_auto: Option<bool>,
3834 /// Whether the failed call used a bring-your-own-key provider
3835 #[serde(skip_serializing_if = "Option::is_none")]
3836 pub is_byok: Option<bool>,
3837 /// Effective maximum output-token limit for the failed call
3838 #[serde(skip_serializing_if = "Option::is_none")]
3839 pub max_output_tokens: Option<i64>,
3840 /// Effective maximum prompt-token limit for the failed call
3841 #[serde(skip_serializing_if = "Option::is_none")]
3842 pub max_prompt_tokens: Option<i64>,
3843 /// Model identifier used for the failed API call
3844 #[serde(skip_serializing_if = "Option::is_none")]
3845 pub model: Option<String>,
3846 /// Parent task tool call ID when this failed model call belongs to a sub-agent
3847 #[serde(skip_serializing_if = "Option::is_none")]
3848 pub parent_tool_call_id: Option<String>,
3849 /// GitHub request tracing ID (x-github-request-id header) for server-side log correlation
3850 #[serde(skip_serializing_if = "Option::is_none")]
3851 pub provider_call_id: Option<String>,
3852 /// Per-quota usage snapshots parsed from the failed response's quota headers, keyed by quota identifier. Present when the error response carried quota headers (e.g. a 402 once the additional spend limit is reached) so the UI can refresh the quota display on failure.
3853 #[doc(hidden)]
3854 #[serde(skip_serializing_if = "Option::is_none")]
3855 pub(crate) quota_snapshots: Option<HashMap<String, AssistantUsageQuotaSnapshot>>,
3856 /// Reasoning effort level used for the failed model call, if applicable
3857 #[serde(skip_serializing_if = "Option::is_none")]
3858 pub reasoning_effort: Option<String>,
3859 /// Content-free structural summary of the failing request. Contains only counts and shape flags (no prompt content), so it is safe for unrestricted telemetry. Populated only for client-error (4xx) failures.
3860 #[serde(skip_serializing_if = "Option::is_none")]
3861 pub request_fingerprint: Option<ModelCallFailureRequestFingerprint>,
3862 /// Per-request treatment/eligibility signal returned by the Copilot API in the `X-GitHub-Copilot-Request-TE` response header for the associated model call; `false` when the header was absent or unparseable.
3863 #[serde(skip_serializing_if = "Option::is_none")]
3864 pub rte: Option<bool>,
3865 /// Copilot service request ID (x-copilot-service-request-id header) for CAPI log correlation
3866 #[serde(skip_serializing_if = "Option::is_none")]
3867 pub service_request_id: Option<String>,
3868 /// Where the failed model call originated
3869 pub source: ModelCallFailureSource,
3870 /// HTTP status code from the failed request
3871 #[serde(skip_serializing_if = "Option::is_none")]
3872 pub status_code: Option<i32>,
3873 /// Transport used for the failed model call (http or websocket)
3874 #[serde(skip_serializing_if = "Option::is_none")]
3875 pub transport: Option<ModelCallFailureTransport>,
3876}
3877
3878/// Session event "model.call_finished". Final lifecycle outcome for one logical model dispatch. A logical dispatch may include internal reconnect or fallback work, so event count is not provider HTTP-request count.
3879#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3880#[serde(rename_all = "camelCase")]
3881pub struct ModelCallFinishedData {
3882 /// Whether an accepted successful response requested the exact name and command semantics of a built-in file edit tool, including an external tool explicitly replacing that built-in name. Absent when the logical dispatch did not produce an accepted response.
3883 #[serde(skip_serializing_if = "Option::is_none")]
3884 pub contains_built_in_file_edit_request: Option<bool>,
3885 /// Monotonic elapsed time spent in the logical model dispatch, including any internal transport reconnect or fallback and excluding orchestrator retry backoff, tool execution, confirmations, and post-response processing
3886 pub dispatch_duration_ms: f64,
3887 /// Version of the built-in file-edit semantic classifier used for this event
3888 pub edit_classifier_version: i64,
3889 /// Identifier of the user interaction that owns the model dispatch, matching assistant.turn_start.interactionId when available
3890 #[serde(skip_serializing_if = "Option::is_none")]
3891 pub interaction_id: Option<String>,
3892 /// Final outcome after post-response acceptance processing
3893 pub outcome: ModelCallFinishedOutcome,
3894 /// Agent-loop iteration within the interaction that initiated the model dispatch
3895 pub turn_id: String,
3896}
3897
3898/// Session event "model.call_start". Model API dispatch metadata for internal telemetry
3899#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3900#[serde(rename_all = "camelCase")]
3901pub struct ModelCallStartData {
3902 /// Experimental HydraFusion attribution for this concrete model call.
3903 ///
3904 /// <div class="warning">
3905 ///
3906 /// **Experimental.** This type is part of an experimental wire-protocol surface
3907 /// and may change or be removed in future SDK or CLI releases.
3908 ///
3909 /// </div>
3910 #[serde(skip_serializing_if = "Option::is_none")]
3911 pub fusion: Option<FusionAttribution>,
3912 /// Model identifier used for this API call, when known
3913 #[serde(skip_serializing_if = "Option::is_none")]
3914 pub model: Option<String>,
3915 /// Parent task tool call ID when this model call belongs to a sub-agent
3916 #[serde(skip_serializing_if = "Option::is_none")]
3917 pub parent_tool_call_id: Option<String>,
3918 /// Previous response or interaction identifier included in the model request, when present
3919 #[doc(hidden)]
3920 #[serde(skip_serializing_if = "Option::is_none")]
3921 pub(crate) previous_response_id: Option<String>,
3922 /// Identifier of the assistant turn that initiated the model call
3923 pub turn_id: String,
3924}
3925
3926/// Session event "abort". Turn abort information including the reason for termination
3927#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3928#[serde(rename_all = "camelCase")]
3929pub struct AbortData {
3930 /// Finite reason code describing why the current turn was aborted
3931 pub reason: AbortReason,
3932}
3933
3934/// Session event "tool.user_requested". User-initiated tool invocation request with tool name and arguments
3935#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3936#[serde(rename_all = "camelCase")]
3937pub struct ToolUserRequestedData {
3938 /// Arguments for the tool invocation
3939 #[serde(skip_serializing_if = "Option::is_none")]
3940 pub arguments: Option<serde_json::Value>,
3941 /// Unique identifier for this tool call
3942 pub tool_call_id: String,
3943 /// Name of the tool the user wants to invoke
3944 pub tool_name: String,
3945}
3946
3947/// Shell-aware path hints for a shell tool's command, captured at start time so consumers can snapshot a file's pre-image before the tool runs.
3948#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3949#[serde(rename_all = "camelCase")]
3950pub struct ToolExecutionStartShellToolInfo {
3951 /// The command with a redundant leading `cd` into the working directory removed, present only when there was one to remove. Computed with the same routine the shell driver applies before spawning, so a surface that renders this shows the text that actually runs. Consumers that display it should keep the original tool arguments available on demand.
3952 ///
3953 /// <div class="warning">
3954 ///
3955 /// **Experimental.** This type is part of an experimental wire-protocol surface
3956 /// and may change or be removed in future SDK or CLI releases.
3957 ///
3958 /// </div>
3959 #[serde(skip_serializing_if = "Option::is_none")]
3960 pub display_command: Option<String>,
3961 /// Whether the command includes a file write redirection (e.g., > or >>).
3962 pub has_write_file_redirection: bool,
3963 /// File paths the command may read or write, derived from the command at start time. Produced by the same shell-aware extractor as PermissionRequestShell.possiblePaths, so it is present even when the command is auto-approved and no permission request fires.
3964 pub possible_paths: Vec<String>,
3965}
3966
3967/// MCP Apps tool `_meta.ui` resource URI and visibility captured on `tool.execution_start`.
3968#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3969#[serde(rename_all = "camelCase")]
3970pub struct ToolExecutionStartToolDescriptionMetaUI {
3971 /// URI of the UI resource
3972 #[serde(skip_serializing_if = "Option::is_none")]
3973 pub resource_uri: Option<String>,
3974 /// Who can access this tool
3975 #[serde(skip_serializing_if = "Option::is_none")]
3976 pub visibility: Option<Vec<ToolExecutionStartToolDescriptionMetaUIVisibility>>,
3977}
3978
3979/// MCP Apps metadata for UI resource association
3980#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3981#[serde(rename_all = "camelCase")]
3982pub struct ToolExecutionStartToolDescriptionMeta {
3983 /// MCP Apps tool `_meta.ui` resource URI and visibility captured on `tool.execution_start`.
3984 #[serde(skip_serializing_if = "Option::is_none")]
3985 pub ui: Option<ToolExecutionStartToolDescriptionMetaUI>,
3986}
3987
3988/// Tool definition metadata, present for MCP tools with MCP Apps support
3989#[derive(Debug, Clone, Default, Serialize, Deserialize)]
3990#[serde(rename_all = "camelCase")]
3991pub struct ToolExecutionStartToolDescription {
3992 /// MCP Apps metadata for UI resource association
3993 #[serde(rename = "_meta", skip_serializing_if = "Option::is_none")]
3994 pub meta: Option<ToolExecutionStartToolDescriptionMeta>,
3995 /// Tool description
3996 #[serde(skip_serializing_if = "Option::is_none")]
3997 pub description: Option<String>,
3998 /// Tool name
3999 pub name: String,
4000}
4001
4002/// Session event "tool.execution_start". Tool execution startup details including MCP server information when applicable
4003#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4004#[serde(rename_all = "camelCase")]
4005pub struct ToolExecutionStartData {
4006 /// Arguments passed to the tool
4007 #[serde(skip_serializing_if = "Option::is_none")]
4008 pub arguments: Option<serde_json::Value>,
4009 /// When true, the tool output should be displayed expanded (verbatim) in the CLI timeline
4010 #[serde(skip_serializing_if = "Option::is_none")]
4011 pub display_verbatim: Option<bool>,
4012 /// Experimental HydraFusion attribution for this tool execution.
4013 ///
4014 /// <div class="warning">
4015 ///
4016 /// **Experimental.** This type is part of an experimental wire-protocol surface
4017 /// and may change or be removed in future SDK or CLI releases.
4018 ///
4019 /// </div>
4020 #[serde(skip_serializing_if = "Option::is_none")]
4021 pub fusion: Option<FusionAttribution>,
4022 /// Preferred lookup name for the MCP server hosting this tool: the configured (namespaced) config-map key when the tool carries one, otherwise the display name from `mcpServerName`. Present when the tool is an MCP tool; this is the name unrestricted provenance telemetry hashes so it joins with `mcp_server_setup`, which keys off the configured name too.
4023 #[serde(skip_serializing_if = "Option::is_none")]
4024 pub mcp_config_server_name: Option<String>,
4025 /// Where the MCP server's configuration came from (`user`, `workspace`, `plugin`, or `builtin`), when the tool is an MCP tool and the server is configured
4026 #[serde(skip_serializing_if = "Option::is_none")]
4027 pub mcp_config_source: Option<McpServerSource>,
4028 /// Name of the MCP server hosting this tool, when the tool is an MCP tool
4029 #[serde(skip_serializing_if = "Option::is_none")]
4030 pub mcp_server_name: Option<String>,
4031 /// Original tool name on the MCP server, when the tool is an MCP tool
4032 #[serde(skip_serializing_if = "Option::is_none")]
4033 pub mcp_tool_name: Option<String>,
4034 /// Transport the MCP server hosting this tool is connected over, when the tool is an MCP tool and the server is configured
4035 #[serde(skip_serializing_if = "Option::is_none")]
4036 pub mcp_transport: Option<McpServerTransport>,
4037 /// Model identifier that generated this tool call
4038 #[serde(skip_serializing_if = "Option::is_none")]
4039 pub model: Option<String>,
4040 /// Tool call ID of the parent tool invocation when this event originates from a sub-agent
4041 #[doc(hidden)]
4042 #[deprecated]
4043 #[serde(skip_serializing_if = "Option::is_none")]
4044 pub parent_tool_call_id: Option<String>,
4045 /// Per-request treatment/eligibility signal returned by the Copilot API in the `X-GitHub-Copilot-Request-TE` response header for the associated model call; `false` when the header was absent or unparseable.
4046 #[serde(skip_serializing_if = "Option::is_none")]
4047 pub rte: Option<bool>,
4048 /// Shell-tool path hints derived from the command at start time for shell tools (bash/powershell/local_shell). Produced by the same shell-aware extractor as PermissionRequestShell.possiblePaths, so it is present even when the command is auto-approved and no permission request fires. Absent for non-shell tools.
4049 #[serde(skip_serializing_if = "Option::is_none")]
4050 pub shell_tool_info: Option<ToolExecutionStartShellToolInfo>,
4051 /// Unique identifier for this tool call
4052 pub tool_call_id: String,
4053 /// Tool definition metadata, present for MCP tools with MCP Apps support
4054 #[serde(skip_serializing_if = "Option::is_none")]
4055 pub tool_description: Option<ToolExecutionStartToolDescription>,
4056 /// Name of the tool being executed
4057 pub tool_name: String,
4058 /// Human-readable display title for the tool, when the selected tool descriptor has a non-empty title.
4059 #[serde(skip_serializing_if = "Option::is_none")]
4060 pub tool_title: Option<String>,
4061 /// Identifier for the agent loop turn this tool was invoked in, matching the corresponding assistant.turn_start event
4062 #[serde(skip_serializing_if = "Option::is_none")]
4063 pub turn_id: Option<String>,
4064}
4065
4066/// Session event "tool.execution_partial_result". Streaming tool execution output for incremental result display
4067#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4068#[serde(rename_all = "camelCase")]
4069pub struct ToolExecutionPartialResultData {
4070 /// Incremental output chunk from the running tool
4071 pub partial_output: String,
4072 /// Tool call ID this partial result belongs to
4073 pub tool_call_id: String,
4074}
4075
4076/// Session event "tool.execution_progress". Tool execution progress notification with status message
4077#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4078#[serde(rename_all = "camelCase")]
4079pub struct ToolExecutionProgressData {
4080 /// Human-readable progress status message (e.g., from an MCP server)
4081 pub progress_message: String,
4082 /// Tool call ID this progress notification belongs to
4083 pub tool_call_id: String,
4084}
4085
4086/// Error details when the tool execution failed
4087#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4088#[serde(rename_all = "camelCase")]
4089pub struct ToolExecutionCompleteError {
4090 /// Machine-readable error code
4091 #[serde(skip_serializing_if = "Option::is_none")]
4092 pub code: Option<String>,
4093 /// Human-readable error message
4094 pub message: String,
4095 /// What the user must do to recover, when the runtime knows of an action. Set on sandbox policy denials, where `message` names the rule that blocked the call but never the client affordance that relaxes it.
4096 #[serde(skip_serializing_if = "Option::is_none")]
4097 pub remediation: Option<RemediationAction>,
4098}
4099
4100/// Binary result returned by a tool for the model
4101#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4102#[serde(rename_all = "camelCase")]
4103pub struct PersistedBinaryImage {
4104 /// Base64-encoded binary data
4105 pub data: String,
4106 /// Human-readable description of the binary data
4107 #[serde(skip_serializing_if = "Option::is_none")]
4108 pub description: Option<String>,
4109 /// Optional metadata from the producing tool.
4110 #[serde(skip_serializing_if = "Option::is_none")]
4111 pub metadata: Option<HashMap<String, serde_json::Value>>,
4112 /// MIME type of the binary data
4113 pub mime_type: String,
4114 /// Binary result type discriminator. Use "image" for images and "resource" for other binary data.
4115 pub r#type: PersistedBinaryImageType,
4116}
4117
4118/// A binary result whose data was omitted from persistence due to the inline size limit
4119///
4120/// <div class="warning">
4121///
4122/// **Experimental.** This type is part of an experimental wire-protocol surface
4123/// and may change or be removed in future SDK or CLI releases.
4124///
4125/// </div>
4126#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4127#[serde(rename_all = "camelCase")]
4128pub struct OmittedBinaryResult {
4129 /// Decoded byte length of the omitted binary data
4130 pub byte_length: i64,
4131 /// Human-readable description of the binary data
4132 #[serde(skip_serializing_if = "Option::is_none")]
4133 pub description: Option<String>,
4134 /// Optional metadata from the producing tool.
4135 #[serde(skip_serializing_if = "Option::is_none")]
4136 pub metadata: Option<HashMap<String, serde_json::Value>>,
4137 /// MIME type of the omitted binary data
4138 pub mime_type: String,
4139 /// Why the binary data is absent: it exceeded the inline size limit, or its asset was unavailable
4140 pub omitted_reason: OmittedBinaryOmittedReason,
4141 /// Binary result type discriminator. Use "image" for images and "resource" for other binary data.
4142 pub r#type: OmittedBinaryType,
4143}
4144
4145/// A reference to binary data persisted once on a session.binary_asset event and shared by id
4146///
4147/// <div class="warning">
4148///
4149/// **Experimental.** This type is part of an experimental wire-protocol surface
4150/// and may change or be removed in future SDK or CLI releases.
4151///
4152/// </div>
4153#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4154#[serde(rename_all = "camelCase")]
4155pub struct BinaryAssetReference {
4156 /// Content-addressed id of the session.binary_asset event that holds this binary's bytes (e.g. "sha256:...").
4157 pub asset_id: String,
4158 /// Decoded byte length of the referenced binary data
4159 pub byte_length: i64,
4160 /// Human-readable description of the binary data
4161 #[serde(skip_serializing_if = "Option::is_none")]
4162 pub description: Option<String>,
4163 /// Optional metadata from the producing tool.
4164 #[serde(skip_serializing_if = "Option::is_none")]
4165 pub metadata: Option<HashMap<String, serde_json::Value>>,
4166 /// MIME type of the referenced binary data
4167 pub mime_type: String,
4168 /// Binary result type discriminator. Use "image" for images and "resource" for other binary data.
4169 pub r#type: BinaryAssetReferenceType,
4170}
4171
4172/// A source supplied by a tool that should be made available to the model as citable content.
4173///
4174/// <div class="warning">
4175///
4176/// **Experimental.** This type is part of an experimental wire-protocol surface
4177/// and may change or be removed in future SDK or CLI releases.
4178///
4179/// </div>
4180#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4181#[serde(rename_all = "camelCase")]
4182pub struct CitableSource {
4183 /// The source text made available to the model as citable content.
4184 pub content: String,
4185 /// Stable identifier for this source within the tool result. Used for deduplication and may be used by future provider integrations to correlate response citations back to the originating source.
4186 pub id: String,
4187 /// File path relative to the agent's workspace root, when the source is a file.
4188 #[serde(skip_serializing_if = "Option::is_none")]
4189 pub path: Option<String>,
4190 /// Human-readable title of the source.
4191 #[serde(skip_serializing_if = "Option::is_none")]
4192 pub title: Option<String>,
4193 /// URL of the source, when it is a web resource.
4194 #[serde(skip_serializing_if = "Option::is_none")]
4195 pub url: Option<String>,
4196}
4197
4198/// Plain text content block
4199#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4200#[serde(rename_all = "camelCase")]
4201pub struct ToolExecutionCompleteContentText {
4202 /// The text content
4203 pub text: String,
4204 /// Content block type discriminator
4205 pub r#type: ToolExecutionCompleteContentTextType,
4206}
4207
4208/// Deprecated for shell command exit metadata. Use ToolExecutionCompleteContentShellExit instead.
4209#[doc(hidden)]
4210#[deprecated]
4211#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4212#[serde(rename_all = "camelCase")]
4213pub struct ToolExecutionCompleteContentTerminal {
4214 /// Working directory where the command was executed
4215 #[serde(skip_serializing_if = "Option::is_none")]
4216 pub cwd: Option<String>,
4217 /// Process exit code, if the command has completed
4218 #[serde(skip_serializing_if = "Option::is_none")]
4219 pub exit_code: Option<i64>,
4220 /// Terminal/shell output text
4221 pub text: String,
4222 /// Content block type discriminator
4223 pub r#type: ToolExecutionCompleteContentTerminalType,
4224}
4225
4226/// Shell command exit metadata with optional output preview
4227#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4228#[serde(rename_all = "camelCase")]
4229pub struct ToolExecutionCompleteContentShellExit {
4230 /// Working directory where the shell command was executed
4231 #[serde(skip_serializing_if = "Option::is_none")]
4232 pub cwd: Option<String>,
4233 /// Exit code from the completed shell command
4234 pub exit_code: i64,
4235 /// Path reported in the shell session's filesystem namespace when shell output exceeded the configured large-output threshold.
4236 #[serde(skip_serializing_if = "Option::is_none")]
4237 pub output_file_path: Option<String>,
4238 /// Output associated with this shell command, if available. May be partial, truncated, or a preview; not guaranteed to be full output.
4239 #[serde(skip_serializing_if = "Option::is_none")]
4240 pub output_preview: Option<String>,
4241 /// Whether outputPreview is known to be incomplete or truncated
4242 #[serde(skip_serializing_if = "Option::is_none")]
4243 pub output_truncated: Option<bool>,
4244 /// Shell id, as assigned by Copilot runtime
4245 pub shell_id: String,
4246 /// Content block type discriminator
4247 pub r#type: ToolExecutionCompleteContentShellExitType,
4248}
4249
4250/// Image content block with base64-encoded data
4251#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4252#[serde(rename_all = "camelCase")]
4253pub struct ToolExecutionCompleteContentImage {
4254 /// Base64-encoded image data
4255 pub data: String,
4256 /// MIME type of the image (e.g., image/png, image/jpeg)
4257 pub mime_type: String,
4258 /// Content block type discriminator
4259 pub r#type: ToolExecutionCompleteContentImageType,
4260}
4261
4262/// Audio content block with base64-encoded data
4263#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4264#[serde(rename_all = "camelCase")]
4265pub struct ToolExecutionCompleteContentAudio {
4266 /// Base64-encoded audio data
4267 pub data: String,
4268 /// MIME type of the audio (e.g., audio/wav, audio/mpeg)
4269 pub mime_type: String,
4270 /// Content block type discriminator
4271 pub r#type: ToolExecutionCompleteContentAudioType,
4272}
4273
4274/// Icon image for a resource
4275#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4276#[serde(rename_all = "camelCase")]
4277pub struct ToolExecutionCompleteContentResourceLinkIcon {
4278 /// MIME type of the icon image
4279 #[serde(skip_serializing_if = "Option::is_none")]
4280 pub mime_type: Option<String>,
4281 /// Available icon sizes (e.g., ['16x16', '32x32'])
4282 #[serde(skip_serializing_if = "Option::is_none")]
4283 pub sizes: Option<Vec<String>>,
4284 /// URL or path to the icon image
4285 pub src: String,
4286 /// Theme variant this icon is intended for
4287 #[serde(skip_serializing_if = "Option::is_none")]
4288 pub theme: Option<ToolExecutionCompleteContentResourceLinkIconTheme>,
4289}
4290
4291/// Resource link content block referencing an external resource
4292#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4293#[serde(rename_all = "camelCase")]
4294pub struct ToolExecutionCompleteContentResourceLink {
4295 /// Human-readable description of the resource
4296 #[serde(skip_serializing_if = "Option::is_none")]
4297 pub description: Option<String>,
4298 /// Icons associated with this resource
4299 #[serde(skip_serializing_if = "Option::is_none")]
4300 pub icons: Option<Vec<ToolExecutionCompleteContentResourceLinkIcon>>,
4301 /// MIME type of the resource content
4302 #[serde(skip_serializing_if = "Option::is_none")]
4303 pub mime_type: Option<String>,
4304 /// Resource name identifier
4305 pub name: String,
4306 /// Size of the resource in bytes
4307 #[serde(skip_serializing_if = "Option::is_none")]
4308 pub size: Option<i64>,
4309 /// Human-readable display title for the resource
4310 #[serde(skip_serializing_if = "Option::is_none")]
4311 pub title: Option<String>,
4312 /// Content block type discriminator
4313 pub r#type: ToolExecutionCompleteContentResourceLinkType,
4314 /// URI identifying the resource
4315 pub uri: String,
4316}
4317
4318/// Embedded text resource contents identified by a URI, with an optional MIME type and a text payload.
4319#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4320#[serde(rename_all = "camelCase")]
4321pub struct EmbeddedTextResourceContents {
4322 /// MIME type of the text content
4323 #[serde(skip_serializing_if = "Option::is_none")]
4324 pub mime_type: Option<String>,
4325 /// Text content of the resource
4326 pub text: String,
4327 /// URI identifying the resource
4328 pub uri: String,
4329}
4330
4331/// Embedded binary resource contents identified by a URI, with an optional MIME type and a base64-encoded blob.
4332#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4333#[serde(rename_all = "camelCase")]
4334pub struct EmbeddedBlobResourceContents {
4335 /// Base64-encoded binary content of the resource
4336 pub blob: String,
4337 /// MIME type of the blob content
4338 #[serde(skip_serializing_if = "Option::is_none")]
4339 pub mime_type: Option<String>,
4340 /// URI identifying the resource
4341 pub uri: String,
4342}
4343
4344/// Embedded resource content block with inline text or binary data
4345#[derive(Debug, Clone, Serialize, Deserialize)]
4346#[serde(rename_all = "camelCase")]
4347pub struct ToolExecutionCompleteContentResource {
4348 /// The embedded resource contents, either text or base64-encoded binary
4349 pub resource: ToolExecutionCompleteContentResourceDetails,
4350 /// Content block type discriminator
4351 pub r#type: ToolExecutionCompleteContentResourceType,
4352}
4353
4354/// CSP domain allowlists for an MCP Apps UI resource, including connect, resource, frame, and base URI domains.
4355#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4356#[serde(rename_all = "camelCase")]
4357pub struct ToolExecutionCompleteUIResourceMetaUICsp {
4358 /// Domains the UI resource may use as document base URIs.
4359 #[serde(skip_serializing_if = "Option::is_none")]
4360 pub base_uri_domains: Option<Vec<String>>,
4361 /// Domains the UI resource may connect to.
4362 #[serde(skip_serializing_if = "Option::is_none")]
4363 pub connect_domains: Option<Vec<String>>,
4364 /// Domains the UI resource may embed as nested frames.
4365 #[serde(skip_serializing_if = "Option::is_none")]
4366 pub frame_domains: Option<Vec<String>>,
4367 /// Domains from which the UI resource may load scripts, styles, images, and other resources.
4368 #[serde(skip_serializing_if = "Option::is_none")]
4369 pub resource_domains: Option<Vec<String>>,
4370}
4371
4372/// Marker object for camera permission on an MCP Apps UI resource.
4373#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4374#[serde(rename_all = "camelCase")]
4375pub struct ToolExecutionCompleteUIResourceMetaUIPermissionsCamera {}
4376
4377/// Marker object for clipboard-write permission on an MCP Apps UI resource.
4378#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4379#[serde(rename_all = "camelCase")]
4380pub struct ToolExecutionCompleteUIResourceMetaUIPermissionsClipboardWrite {}
4381
4382/// Marker object for geolocation permission on an MCP Apps UI resource.
4383#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4384#[serde(rename_all = "camelCase")]
4385pub struct ToolExecutionCompleteUIResourceMetaUIPermissionsGeolocation {}
4386
4387/// Marker object for microphone permission on an MCP Apps UI resource.
4388#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4389#[serde(rename_all = "camelCase")]
4390pub struct ToolExecutionCompleteUIResourceMetaUIPermissionsMicrophone {}
4391
4392/// Browser permission metadata for an MCP Apps UI resource, including camera, microphone, geolocation, and clipboard-write.
4393#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4394#[serde(rename_all = "camelCase")]
4395pub struct ToolExecutionCompleteUIResourceMetaUIPermissions {
4396 /// Marker object for camera permission on an MCP Apps UI resource.
4397 #[serde(skip_serializing_if = "Option::is_none")]
4398 pub camera: Option<ToolExecutionCompleteUIResourceMetaUIPermissionsCamera>,
4399 /// Marker object for clipboard-write permission on an MCP Apps UI resource.
4400 #[serde(skip_serializing_if = "Option::is_none")]
4401 pub clipboard_write: Option<ToolExecutionCompleteUIResourceMetaUIPermissionsClipboardWrite>,
4402 /// Marker object for geolocation permission on an MCP Apps UI resource.
4403 #[serde(skip_serializing_if = "Option::is_none")]
4404 pub geolocation: Option<ToolExecutionCompleteUIResourceMetaUIPermissionsGeolocation>,
4405 /// Marker object for microphone permission on an MCP Apps UI resource.
4406 #[serde(skip_serializing_if = "Option::is_none")]
4407 pub microphone: Option<ToolExecutionCompleteUIResourceMetaUIPermissionsMicrophone>,
4408}
4409
4410/// MCP Apps UI resource metadata for a completed tool result, including CSP, permissions, domain, and border preference.
4411#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4412#[serde(rename_all = "camelCase")]
4413pub struct ToolExecutionCompleteUIResourceMetaUI {
4414 /// CSP domain allowlists for an MCP Apps UI resource, including connect, resource, frame, and base URI domains.
4415 #[serde(skip_serializing_if = "Option::is_none")]
4416 pub csp: Option<ToolExecutionCompleteUIResourceMetaUICsp>,
4417 /// Optional dedicated origin for the rendered MCP Apps UI resource.
4418 #[serde(skip_serializing_if = "Option::is_none")]
4419 pub domain: Option<String>,
4420 /// Browser permission metadata for an MCP Apps UI resource, including camera, microphone, geolocation, and clipboard-write.
4421 #[serde(skip_serializing_if = "Option::is_none")]
4422 pub permissions: Option<ToolExecutionCompleteUIResourceMetaUIPermissions>,
4423 /// Whether the host should render a border around the MCP Apps UI resource.
4424 #[serde(skip_serializing_if = "Option::is_none")]
4425 pub prefers_border: Option<bool>,
4426}
4427
4428/// Resource-level UI metadata (CSP, permissions, visual preferences)
4429#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4430#[serde(rename_all = "camelCase")]
4431pub struct ToolExecutionCompleteUIResourceMeta {
4432 /// MCP Apps UI resource metadata for a completed tool result, including CSP, permissions, domain, and border preference.
4433 #[serde(skip_serializing_if = "Option::is_none")]
4434 pub ui: Option<ToolExecutionCompleteUIResourceMetaUI>,
4435}
4436
4437/// MCP Apps UI resource content for rendering in a sandboxed iframe
4438#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4439#[serde(rename_all = "camelCase")]
4440pub struct ToolExecutionCompleteUIResource {
4441 /// Resource-level UI metadata (CSP, permissions, visual preferences)
4442 #[serde(rename = "_meta", skip_serializing_if = "Option::is_none")]
4443 pub meta: Option<ToolExecutionCompleteUIResourceMeta>,
4444 /// Base64-encoded HTML content
4445 #[serde(skip_serializing_if = "Option::is_none")]
4446 pub blob: Option<String>,
4447 /// MIME type of the content
4448 pub mime_type: String,
4449 /// HTML content as a string
4450 #[serde(skip_serializing_if = "Option::is_none")]
4451 pub text: Option<String>,
4452 /// The ui:// URI of the resource
4453 pub uri: String,
4454}
4455
4456/// Tool execution result on success
4457#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4458#[serde(rename_all = "camelCase")]
4459pub struct ToolExecutionCompleteResult {
4460 /// Model-facing binary results (base64 inline or size-omitted markers) sent to the LLM for this tool call
4461 ///
4462 /// <div class="warning">
4463 ///
4464 /// **Experimental.** This type is part of an experimental wire-protocol surface
4465 /// and may change or be removed in future SDK or CLI releases.
4466 ///
4467 /// </div>
4468 #[serde(skip_serializing_if = "Option::is_none")]
4469 pub binary_results_for_llm: Option<Vec<PersistedBinaryResult>>,
4470 /// Provider-neutral source material this tool makes available to the model as citable content. Persisted so it survives session resume. Experimental.
4471 ///
4472 /// <div class="warning">
4473 ///
4474 /// **Experimental.** This type is part of an experimental wire-protocol surface
4475 /// and may change or be removed in future SDK or CLI releases.
4476 ///
4477 /// </div>
4478 #[serde(skip_serializing_if = "Option::is_none")]
4479 pub citable_sources: Option<Vec<CitableSource>>,
4480 /// Concise tool result text sent to the LLM for chat completion, potentially truncated for token efficiency
4481 pub content: String,
4482 /// Structured content blocks (text, images, audio, resources) returned by the tool in their native format
4483 #[serde(skip_serializing_if = "Option::is_none")]
4484 pub contents: Option<Vec<ToolExecutionCompleteContent>>,
4485 /// Detailed tool result for UI/timeline display, preserving complete content such as diffs for most tools. Successful skill invocations intentionally use the concise model-facing content here; the authoritative skill body is carried by the corresponding skill invocation event. Falls back to content when absent.
4486 #[serde(skip_serializing_if = "Option::is_none")]
4487 pub detailed_content: Option<String>,
4488 /// FIDES IFC label projected from tool ingress metadata (MCP `CallToolResult._meta` or synthesized built-in ingress labels) — persisted as `{ ifc: ... }` (only the `ifc` key, not the whole `_meta`). Persisted so the FIDES IFC label survives session resume: the engine rehydrates accumulated taint by replaying these on load. Populated for ingress sources when FIDES IFC is on. Experimental.
4489 ///
4490 /// <div class="warning">
4491 ///
4492 /// **Experimental.** This type is part of an experimental wire-protocol surface
4493 /// and may change or be removed in future SDK or CLI releases.
4494 ///
4495 /// </div>
4496 #[serde(skip_serializing_if = "Option::is_none")]
4497 pub mcp_meta: Option<serde_json::Value>,
4498 /// Structured content (arbitrary JSON) returned verbatim by the MCP tool
4499 #[serde(skip_serializing_if = "Option::is_none")]
4500 pub structured_content: Option<serde_json::Value>,
4501 /// MCP Apps UI resource content for rendering in a sandboxed iframe
4502 #[serde(skip_serializing_if = "Option::is_none")]
4503 pub ui_resource: Option<ToolExecutionCompleteUIResource>,
4504}
4505
4506/// Experimental shell completion facts retained independently of the full tool result.
4507///
4508/// <div class="warning">
4509///
4510/// **Experimental.** This type is part of an experimental wire-protocol surface
4511/// and may change or be removed in future SDK or CLI releases.
4512///
4513/// </div>
4514#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4515#[serde(rename_all = "camelCase")]
4516pub struct ToolExecutionCompleteShellExecution {
4517 /// Process exit code reported by the shell driver.
4518 pub exit_code: i64,
4519}
4520
4521/// MCP Apps tool `_meta.ui` resource URI and visibility captured on `tool.execution_complete`.
4522#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4523#[serde(rename_all = "camelCase")]
4524pub struct ToolExecutionCompleteToolDescriptionMetaUI {
4525 /// URI of the UI resource
4526 #[serde(skip_serializing_if = "Option::is_none")]
4527 pub resource_uri: Option<String>,
4528 /// Who can access this tool
4529 #[serde(skip_serializing_if = "Option::is_none")]
4530 pub visibility: Option<Vec<ToolExecutionCompleteToolDescriptionMetaUIVisibility>>,
4531}
4532
4533/// MCP Apps metadata for UI resource association
4534#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4535#[serde(rename_all = "camelCase")]
4536pub struct ToolExecutionCompleteToolDescriptionMeta {
4537 /// MCP Apps tool `_meta.ui` resource URI and visibility captured on `tool.execution_complete`.
4538 #[serde(skip_serializing_if = "Option::is_none")]
4539 pub ui: Option<ToolExecutionCompleteToolDescriptionMetaUI>,
4540}
4541
4542/// Tool definition metadata, present for MCP tools with MCP Apps support
4543#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4544#[serde(rename_all = "camelCase")]
4545pub struct ToolExecutionCompleteToolDescription {
4546 /// MCP Apps metadata for UI resource association
4547 #[serde(rename = "_meta", skip_serializing_if = "Option::is_none")]
4548 pub meta: Option<ToolExecutionCompleteToolDescriptionMeta>,
4549 /// Tool description
4550 #[serde(skip_serializing_if = "Option::is_none")]
4551 pub description: Option<String>,
4552 /// Tool name
4553 pub name: String,
4554}
4555
4556/// Session event "tool.execution_complete". Tool execution completion results including success status, detailed output, and error information
4557#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4558#[serde(rename_all = "camelCase")]
4559pub struct ToolExecutionCompleteData {
4560 /// Error details when the tool execution failed
4561 #[serde(skip_serializing_if = "Option::is_none")]
4562 pub error: Option<ToolExecutionCompleteError>,
4563 /// Experimental HydraFusion attribution for this tool completion.
4564 ///
4565 /// <div class="warning">
4566 ///
4567 /// **Experimental.** This type is part of an experimental wire-protocol surface
4568 /// and may change or be removed in future SDK or CLI releases.
4569 ///
4570 /// </div>
4571 #[serde(skip_serializing_if = "Option::is_none")]
4572 pub fusion: Option<FusionAttribution>,
4573 /// CAPI interaction ID for correlating this tool execution with upstream telemetry
4574 #[serde(skip_serializing_if = "Option::is_none")]
4575 pub interaction_id: Option<String>,
4576 /// Whether this tool call was explicitly requested by the user rather than the assistant
4577 #[serde(skip_serializing_if = "Option::is_none")]
4578 pub is_user_requested: Option<bool>,
4579 /// FIDES IFC label projected from tool ingress metadata (MCP `CallToolResult._meta` or synthesized built-in ingress labels). Persisted as `{ ifc: ... }` so the label survives session resume, including model-visible failure results. Experimental.
4580 ///
4581 /// <div class="warning">
4582 ///
4583 /// **Experimental.** This type is part of an experimental wire-protocol surface
4584 /// and may change or be removed in future SDK or CLI releases.
4585 ///
4586 /// </div>
4587 #[serde(skip_serializing_if = "Option::is_none")]
4588 pub mcp_meta: Option<serde_json::Value>,
4589 /// Model identifier that generated this tool call
4590 #[serde(skip_serializing_if = "Option::is_none")]
4591 pub model: Option<String>,
4592 /// Tool call ID of the parent tool invocation when this event originates from a sub-agent
4593 #[doc(hidden)]
4594 #[deprecated]
4595 #[serde(skip_serializing_if = "Option::is_none")]
4596 pub parent_tool_call_id: Option<String>,
4597 /// Tool execution result on success
4598 #[serde(skip_serializing_if = "Option::is_none")]
4599 pub result: Option<ToolExecutionCompleteResult>,
4600 /// Per-request treatment/eligibility signal returned by the Copilot API in the `X-GitHub-Copilot-Request-TE` response header for the associated model call; `false` when the header was absent or unparseable.
4601 #[serde(skip_serializing_if = "Option::is_none")]
4602 pub rte: Option<bool>,
4603 /// Whether this tool execution ran inside a sandbox container
4604 #[serde(skip_serializing_if = "Option::is_none")]
4605 pub sandboxed: Option<bool>,
4606 /// Experimental shell completion facts captured before the persisted result contents are stripped.
4607 ///
4608 /// <div class="warning">
4609 ///
4610 /// **Experimental.** This type is part of an experimental wire-protocol surface
4611 /// and may change or be removed in future SDK or CLI releases.
4612 ///
4613 /// </div>
4614 #[serde(skip_serializing_if = "Option::is_none")]
4615 pub shell_execution: Option<ToolExecutionCompleteShellExecution>,
4616 /// Whether the tool execution completed successfully
4617 pub success: bool,
4618 /// Unique identifier for the completed tool call
4619 pub tool_call_id: String,
4620 /// Tool definition metadata, present for MCP tools with MCP Apps support
4621 #[serde(skip_serializing_if = "Option::is_none")]
4622 pub tool_description: Option<ToolExecutionCompleteToolDescription>,
4623 /// Tool-specific telemetry data (e.g., CodeQL check counts, grep match counts)
4624 #[serde(skip_serializing_if = "Option::is_none")]
4625 pub tool_telemetry: Option<HashMap<String, serde_json::Value>>,
4626 /// Identifier for the agent loop turn this tool was invoked in, matching the corresponding assistant.turn_start event
4627 #[serde(skip_serializing_if = "Option::is_none")]
4628 pub turn_id: Option<String>,
4629}
4630
4631/// Session event "tool_search.activated". Persisted generic client-side tool activations restored when a session resumes.
4632#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4633#[serde(rename_all = "camelCase")]
4634pub struct ToolSearchActivatedData {
4635 /// Tool-search strategy that activated the definitions.
4636 pub strategy: String,
4637 /// Names of tool definitions activated by this search invocation.
4638 pub tool_names: Vec<String>,
4639}
4640
4641/// Session event "skill.invoked". Skill invocation details including content, allowed tools, and plugin metadata
4642#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4643#[serde(rename_all = "camelCase")]
4644pub struct SkillInvokedData {
4645 /// Tool names that should be auto-approved when this skill is active
4646 #[serde(skip_serializing_if = "Option::is_none")]
4647 pub allowed_tools: Option<Vec<String>>,
4648 /// Full content of the skill file, injected into the conversation for the model
4649 pub content: String,
4650 /// Description of the skill from its SKILL.md frontmatter
4651 #[serde(skip_serializing_if = "Option::is_none")]
4652 pub description: Option<String>,
4653 /// Whether model invocation is disabled for this skill
4654 #[serde(skip_serializing_if = "Option::is_none")]
4655 pub disable_model_invocation: Option<bool>,
4656 /// Projected chat-message count when the skill was invoked. New writers persist this so replay does not need to reconstruct superseded history; readers derive it for legacy events when absent.
4657 #[serde(skip_serializing_if = "Option::is_none")]
4658 pub invoked_at_turn: Option<i64>,
4659 /// Model identifier active when the skill was invoked, when known
4660 #[serde(skip_serializing_if = "Option::is_none")]
4661 pub model: Option<String>,
4662 /// Name of the invoked skill
4663 pub name: String,
4664 /// File path to the SKILL.md definition, or an empty string for an SDK-provided skill without a filesystem identity
4665 pub path: String,
4666 /// Name of the plugin this skill originated from, when applicable
4667 #[serde(skip_serializing_if = "Option::is_none")]
4668 pub plugin_name: Option<String>,
4669 /// Version of the plugin this skill originated from, when applicable
4670 #[serde(skip_serializing_if = "Option::is_none")]
4671 pub plugin_version: Option<String>,
4672 /// Source identifier for where the skill was discovered. Known values include: project (workspace skill), inherited (parent-directory skill), personal-copilot (~/.copilot/skills), personal-agents (~/.agents/skills), custom (configured directory), plugin (installed plugin), builtin (bundled runtime skill), remote (org/enterprise skill), and sdk (SDK-provided skill)
4673 #[serde(skip_serializing_if = "Option::is_none")]
4674 pub source: Option<String>,
4675 /// What triggered the skill invocation: `user-invoked` (explicit user action, such as via a slash command or UI affordance), `agent-invoked` (agent requested the skill), or `context-load` (loaded as part of another context, such as preloading skills configured on a custom agent or subagent)
4676 #[serde(skip_serializing_if = "Option::is_none")]
4677 pub trigger: Option<SkillInvokedTrigger>,
4678}
4679
4680/// Session event "skill.invoked_ref". Internal durable skill invocation receipt whose content resolves from an earlier inline skill event in the same session.
4681#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4682#[serde(rename_all = "camelCase")]
4683pub struct SkillInvokedRefData {
4684 /// Tool names that should be auto-approved when this skill is active
4685 #[serde(skip_serializing_if = "Option::is_none")]
4686 pub allowed_tools: Option<Vec<String>>,
4687 /// Content identifier of an earlier inline skill event in this session, in the prefixed form `sha256:<lowercase hex digest>` over the UTF-8 bytes of that event's `content`
4688 pub content_id: String,
4689 /// UTF-16 code unit length of the referenced skill content. Derived from the referenced body and validated against it when the reference is expanded; a reference whose length disagrees with the body it names is rejected instead of expanded
4690 pub content_length: i64,
4691 /// Description of the skill from its SKILL.md frontmatter
4692 #[serde(skip_serializing_if = "Option::is_none")]
4693 pub description: Option<String>,
4694 /// Whether model invocation is disabled for this skill
4695 #[serde(skip_serializing_if = "Option::is_none")]
4696 pub disable_model_invocation: Option<bool>,
4697 /// Projected chat-message count when the skill was invoked. Preserved from the inline event data when the authored body is deduplicated.
4698 #[serde(skip_serializing_if = "Option::is_none")]
4699 pub invoked_at_turn: Option<i64>,
4700 /// Model identifier active when the skill was invoked, when known
4701 #[serde(skip_serializing_if = "Option::is_none")]
4702 pub model: Option<String>,
4703 /// Name of the invoked skill
4704 pub name: String,
4705 /// File path to the SKILL.md definition, or an empty string for an SDK-provided skill without a filesystem identity
4706 pub path: String,
4707 /// Name of the plugin this skill originated from, when applicable
4708 #[serde(skip_serializing_if = "Option::is_none")]
4709 pub plugin_name: Option<String>,
4710 /// Version of the plugin this skill originated from, when applicable
4711 #[serde(skip_serializing_if = "Option::is_none")]
4712 pub plugin_version: Option<String>,
4713 /// Source identifier for where the skill was discovered
4714 #[serde(skip_serializing_if = "Option::is_none")]
4715 pub source: Option<String>,
4716 /// What triggered the skill invocation
4717 #[serde(skip_serializing_if = "Option::is_none")]
4718 pub trigger: Option<SkillInvokedTrigger>,
4719}
4720
4721/// Session event "skill.context_delivered". Exact skill context delivered to the model during a tool phase. This is not a user submission or another skill invocation.
4722#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4723#[serde(rename_all = "camelCase")]
4724pub struct SkillContextDeliveredData {
4725 /// Exact model-facing skill wrapper, including its invocation-time file context
4726 pub content: String,
4727 /// Interaction that delivered this context, when known
4728 #[serde(skip_serializing_if = "Option::is_none")]
4729 pub interaction_id: Option<String>,
4730 /// Unmodified injection provenance, in the form skill-`<invocation-name>`
4731 pub source: String,
4732}
4733
4734/// Session event "skill.context_delivered_ref". Internal durable receipt that reconstructs exact model-visible skill context from earlier session content.
4735#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4736#[serde(rename_all = "camelCase")]
4737pub struct SkillContextDeliveredRefData {
4738 /// Content identifier of an earlier inline skill event in this session, in the prefixed form `sha256:<lowercase hex digest>` over the UTF-8 bytes of that event's `content`
4739 pub content_id: String,
4740 /// Interaction that delivered this context, when known
4741 #[serde(skip_serializing_if = "Option::is_none")]
4742 pub interaction_id: Option<String>,
4743 /// Exact text preceding the referenced content in the delivered wrapper
4744 #[serde(skip_serializing_if = "Option::is_none")]
4745 pub prefix: Option<String>,
4746 /// Unmodified injection provenance, in the form skill-`<invocation-name>`
4747 pub source: String,
4748 /// Exact text following the referenced content in the delivered wrapper
4749 #[serde(skip_serializing_if = "Option::is_none")]
4750 pub suffix: Option<String>,
4751}
4752
4753/// Effective sandbox filesystem rules, in policy order. Only populated when content capture is enabled, since these are real host paths.
4754#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4755#[serde(rename_all = "camelCase")]
4756pub struct SandboxFilesystemPolicyDetails {
4757 /// Paths the sandboxed process may not access at all
4758 pub denied_paths: Vec<String>,
4759 /// Paths the sandboxed process may read but not write
4760 pub readonly_paths: Vec<String>,
4761 /// Paths the sandboxed process may read and write
4762 pub readwrite_paths: Vec<String>,
4763}
4764
4765#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4766#[serde(rename_all = "camelCase")]
4767pub struct SandboxDecisionDataPolicyResolved {
4768 /// Whether the current working directory was granted automatically
4769 pub add_current_working_directory: bool,
4770 /// Whether callers may opt an individual command out of the sandbox
4771 pub allow_bypass: bool,
4772 /// Whether the sandboxed process may reach loopback and private-range addresses
4773 pub allow_local_network: bool,
4774 /// Whether the sandboxed process may open outbound network connections
4775 pub allow_outbound: bool,
4776 /// Process-containment implementation backing the sandbox
4777 pub backend: SandboxBackend,
4778 /// Enforcement mechanism this decision describes
4779 pub control: SandboxControl,
4780 /// Why enforcement is weaker than configured, when it is
4781 #[serde(skip_serializing_if = "Option::is_none")]
4782 pub degradation_reason: Option<SandboxDegradationReason>,
4783 /// Number of denied path rules in the effective policy
4784 pub denied_paths_count: i64,
4785 /// Effective filesystem rules. Populated only when content capture is enabled; the counts above are always present.
4786 #[serde(skip_serializing_if = "Option::is_none")]
4787 pub effective_filesystem_policy: Option<SandboxFilesystemPolicyDetails>,
4788 /// Runtime subsystem that applied the policy
4789 pub enforcement_point: SandboxEnforcementPoint,
4790 /// Whether the sandbox policy permits GitHub CLI credentials inside the sandbox. A policy capability, not proof that a credential was injected into this spawn: injection is per-command
4791 pub gh_auth: bool,
4792 /// Whether the sandbox policy permits git credentials inside the sandbox. A policy capability, not proof that a credential was injected into this spawn: injection is per-command
4793 pub git_auth: bool,
4794 /// Whether the macOS keychain was reachable from inside the sandbox. Always false on other platforms.
4795 pub keychain_access: bool,
4796 /// Sandbox decision variant discriminator.
4797 pub kind: SandboxDecisionDataPolicyResolvedKind,
4798 /// Whether the resolved policy is fully active or degraded
4799 pub outcome: SandboxOutcome,
4800 /// Host platform the sandbox is running on
4801 pub platform: SandboxPlatform,
4802 /// Whether the policy came from built-in defaults or user configuration
4803 pub policy_source: SandboxPolicySource,
4804 /// Whether outbound traffic is unproxied, routed through a loopback proxy, or routed through an external proxy
4805 pub proxy_mode: SandboxProxyMode,
4806 /// Number of read-only path rules in the effective policy
4807 pub readonly_paths_count: i64,
4808 /// Number of read-write path rules in the effective policy
4809 pub readwrite_paths_count: i64,
4810 /// Internal tool-call ID, used only to correlate the decision with its owning span. Omitted when the decision is not attributable to a tool call.
4811 #[serde(skip_serializing_if = "Option::is_none")]
4812 pub tool_call_id: Option<String>,
4813}
4814
4815#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4816#[serde(rename_all = "camelCase")]
4817pub struct SandboxDecisionDataSpawnCompleted {
4818 /// Process-containment implementation backing the sandbox
4819 pub backend: SandboxBackend,
4820 /// Enforcement mechanism this decision describes
4821 pub control: SandboxControl,
4822 /// Why enforcement is weaker than configured, when it is
4823 #[serde(skip_serializing_if = "Option::is_none")]
4824 pub degradation_reason: Option<SandboxDegradationReason>,
4825 /// Wall-clock time spent spawning the sandboxed process, in milliseconds
4826 pub duration_ms: f64,
4827 /// Runtime subsystem that applied the policy
4828 pub enforcement_point: SandboxEnforcementPoint,
4829 /// Sandbox decision variant discriminator.
4830 pub kind: SandboxDecisionDataSpawnCompletedKind,
4831 /// Whether the sandboxed process launched under the named backend. Not the exit status of the command that ran inside it.
4832 pub outcome: SandboxOutcome,
4833 /// Host platform the sandbox is running on
4834 pub platform: SandboxPlatform,
4835 /// Internal tool-call ID, used only to correlate the decision with its owning span. Omitted when the decision is not attributable to a tool call.
4836 #[serde(skip_serializing_if = "Option::is_none")]
4837 pub tool_call_id: Option<String>,
4838}
4839
4840#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4841#[serde(rename_all = "camelCase")]
4842pub struct SandboxDecisionDataEnforcementState {
4843 /// Runtime observation backing the state. Omitted for `inactive`, which has nothing to attest.
4844 #[serde(skip_serializing_if = "Option::is_none")]
4845 pub attestation: Option<SandboxAttestation>,
4846 /// Containment backend that engaged. `unsupported` for any state other than `engaged`, since no backend is known to have run.
4847 pub backend: SandboxBackend,
4848 /// Command the enforcement governed. Populated only when content capture is enabled, and only for shell commands; MCP, LSP, and search command lines are runtime plumbing.
4849 #[serde(skip_serializing_if = "Option::is_none")]
4850 pub command: Option<String>,
4851 /// Enforcement mechanism this decision describes
4852 pub control: SandboxControl,
4853 /// Runtime subsystem whose enforcement this describes
4854 pub enforcement_point: SandboxEnforcementPoint,
4855 /// Sandbox decision variant discriminator.
4856 pub kind: SandboxDecisionDataEnforcementStateKind,
4857 /// Observed enforcement state: `engaged`, `inactive`, or `failed`. Derived from runtime evidence, never from the configured posture or the compile-time target platform.
4858 pub outcome: SandboxOutcome,
4859 /// Host platform the sandbox is running on
4860 pub platform: SandboxPlatform,
4861 /// Internal tool-call ID, used only to correlate the decision with its owning span. Omitted when the decision is not attributable to a tool call.
4862 #[serde(skip_serializing_if = "Option::is_none")]
4863 pub tool_call_id: Option<String>,
4864}
4865
4866/// An enforcement check refused a specific access. Emitted per refusal with no deduplication, including when policy permits the caller to bypass the denial. Carries no backend: the built-in checks that produce this run in-process against the effective policy.
4867#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4868#[serde(rename_all = "camelCase")]
4869pub struct SandboxDecisionDataAccessDenied {
4870 /// Runtime observation backing the denial.
4871 pub attestation: SandboxAttestation,
4872 /// Command whose execution the denial arose from. Populated only when content capture is enabled.
4873 #[serde(skip_serializing_if = "Option::is_none")]
4874 pub command: Option<String>,
4875 /// How strong the evidence behind this denial is. Lets an analysis separate denials the sandbox recorded from ones inferred from output text, which otherwise look identical.
4876 #[serde(skip_serializing_if = "Option::is_none")]
4877 pub confidence: Option<SandboxDenialConfidence>,
4878 /// Sandbox control the denial belongs to. Follows from `denialClass`.
4879 pub control: SandboxControl,
4880 /// Bounded class of the refused access.
4881 pub denial_class: SandboxDenialClass,
4882 /// Resource the check refused, when identified and content capture is enabled.
4883 #[serde(skip_serializing_if = "Option::is_none")]
4884 pub denied_resource: Option<String>,
4885 /// Runtime subsystem that performed the check
4886 pub enforcement_point: SandboxEnforcementPoint,
4887 /// Sandbox decision variant discriminator.
4888 pub kind: SandboxDecisionDataAccessDeniedKind,
4889 /// Always `denied`.
4890 pub outcome: SandboxOutcome,
4891 /// Host operating-system family
4892 pub platform: SandboxPlatform,
4893 /// Executable image associated with the captured denial, normalized to a basename. Populated only when content capture is enabled.
4894 #[serde(skip_serializing_if = "Option::is_none")]
4895 pub process_name: Option<String>,
4896 /// Tool call the denial belongs to, for span correlation only. Never exported as a telemetry attribute or metric dimension.
4897 #[serde(skip_serializing_if = "Option::is_none")]
4898 pub tool_call_id: Option<String>,
4899}
4900
4901/// A request to run outside the process sandbox was resolved. This is what makes an `inactive` `enforcement_state` readable: without it, a command that ran unsandboxed because a person approved a bypass looks identical to one that ran unsandboxed because the session never had a sandbox. Reported only when a sandbox was in force, since bypassing a disabled sandbox bypasses nothing. Carries neither backend nor attestation: the verdict comes from the runtime's own permission flow or the local escalation prompt, not from a containment backend and not from the built-in policy check, so `source` is what records where it came from.
4902#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4903#[serde(rename_all = "camelCase")]
4904pub struct SandboxDecisionDataBypassDecided {
4905 /// Command the verdict governs. Populated only when content capture is enabled.
4906 #[serde(skip_serializing_if = "Option::is_none")]
4907 pub command: Option<String>,
4908 /// How strong the evidence behind `denialClass` was. Present exactly when `denialClass` is, so a verdict that relaxed the sandbox on a guess is distinguishable from one that relaxed it on a recorded refusal. Named to match `access_denied`, which reports the same pair.
4909 #[serde(skip_serializing_if = "Option::is_none")]
4910 pub confidence: Option<SandboxDenialConfidence>,
4911 /// Always `bypass`.
4912 pub control: SandboxControl,
4913 /// Bounded class of the access whose refusal raised this escalation. Omitted for a pre-execution bypass, such as a detached command that cannot be sandboxed and therefore resolves no denial.
4914 #[serde(skip_serializing_if = "Option::is_none")]
4915 pub denial_class: Option<SandboxDenialClass>,
4916 /// Resource whose refusal raised this escalation. Populated only when content capture is enabled.
4917 #[serde(skip_serializing_if = "Option::is_none")]
4918 pub denied_resource: Option<String>,
4919 /// Runtime subsystem the bypass applies to
4920 pub enforcement_point: SandboxEnforcementPoint,
4921 /// Sandbox decision variant discriminator.
4922 pub kind: SandboxDecisionDataBypassDecidedKind,
4923 /// Whether the bypass was granted: `approved` or `declined`. `declined` also covers the cases where nobody answered, since the sandboxed denial stands either way.
4924 pub outcome: SandboxOutcome,
4925 /// Host operating-system family
4926 pub platform: SandboxPlatform,
4927 /// Executable image associated with the denial that raised this escalation, normalized to a basename. Populated only when content capture is enabled.
4928 #[serde(skip_serializing_if = "Option::is_none")]
4929 pub process_name: Option<String>,
4930 /// Where the request originated. Orthogonal to `outcome`.
4931 pub source: SandboxBypassSource,
4932 /// Tool call the decision belongs to, for span correlation only. Never exported as a telemetry attribute or metric dimension.
4933 #[serde(skip_serializing_if = "Option::is_none")]
4934 pub tool_call_id: Option<String>,
4935}
4936
4937/// A permissive retry was resolved. Distinct from `bypass_decided` because this rung never requests a run outside the process sandbox: it relaxes the process container for one run while the sandbox, and with it the network policy, stays attached. Reported for both outcomes, so an escalation the user declined still leaves evidence that the runtime asked and that the sandboxed denial stood.
4938#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4939#[serde(rename_all = "camelCase")]
4940pub struct SandboxDecisionDataPermissiveRetryDecided {
4941 /// Command the verdict governs. Populated only when content capture is enabled.
4942 #[serde(skip_serializing_if = "Option::is_none")]
4943 pub command: Option<String>,
4944 /// How strong the evidence behind `denialClass` was. Present exactly when `denialClass` is.
4945 #[serde(skip_serializing_if = "Option::is_none")]
4946 pub confidence: Option<SandboxDenialConfidence>,
4947 /// Always `process`: the process container is what this rung relaxes, and the network control is deliberately untouched.
4948 pub control: SandboxControl,
4949 /// Bounded class of the access whose refusal raised this escalation.
4950 #[serde(skip_serializing_if = "Option::is_none")]
4951 pub denial_class: Option<SandboxDenialClass>,
4952 /// Resource whose refusal raised this escalation. Populated only when content capture is enabled.
4953 #[serde(skip_serializing_if = "Option::is_none")]
4954 pub denied_resource: Option<String>,
4955 /// Runtime subsystem the retry applies to
4956 pub enforcement_point: SandboxEnforcementPoint,
4957 /// Sandbox decision variant discriminator.
4958 pub kind: SandboxDecisionDataPermissiveRetryDecidedKind,
4959 /// Whether the permissive retry was granted: `approved` or `declined`. `declined` also covers the cases where nobody answered, since the sandboxed denial stands either way.
4960 pub outcome: SandboxOutcome,
4961 /// Host operating-system family
4962 pub platform: SandboxPlatform,
4963 /// Executable image associated with the denial that raised this escalation, normalized to a basename. Populated only when content capture is enabled.
4964 #[serde(skip_serializing_if = "Option::is_none")]
4965 pub process_name: Option<String>,
4966 /// Where the request originated. Orthogonal to `outcome`.
4967 pub source: SandboxBypassSource,
4968 /// Tool call the decision belongs to, for span correlation only. Never exported as a telemetry attribute or metric dimension.
4969 #[serde(skip_serializing_if = "Option::is_none")]
4970 pub tool_call_id: Option<String>,
4971}
4972
4973/// An approved permissive retry finished. `succeeded` means the retry exited successfully without another correlated sandbox denial; `failed` means it failed or remained blocked and may therefore be followed by a full bypass.
4974#[derive(Debug, Clone, Default, Serialize, Deserialize)]
4975#[serde(rename_all = "camelCase")]
4976pub struct SandboxDecisionDataPermissiveRetryCompleted {
4977 /// Command the retry executed. Populated only when content capture is enabled.
4978 #[serde(skip_serializing_if = "Option::is_none")]
4979 pub command: Option<String>,
4980 /// How strong the evidence behind `denialClass` was.
4981 #[serde(skip_serializing_if = "Option::is_none")]
4982 pub confidence: Option<SandboxDenialConfidence>,
4983 /// Always `process`: the retry changes process-container enforcement while leaving network policy attached.
4984 pub control: SandboxControl,
4985 /// Bounded class of the access whose refusal raised the permissive retry.
4986 #[serde(skip_serializing_if = "Option::is_none")]
4987 pub denial_class: Option<SandboxDenialClass>,
4988 /// Resource whose refusal raised the retry. Populated only when content capture is enabled.
4989 #[serde(skip_serializing_if = "Option::is_none")]
4990 pub denied_resource: Option<String>,
4991 /// Runtime subsystem that ran the retry
4992 pub enforcement_point: SandboxEnforcementPoint,
4993 /// Sandbox decision variant discriminator.
4994 pub kind: SandboxDecisionDataPermissiveRetryCompletedKind,
4995 /// Whether the permissive retry completed successfully: `succeeded` or `failed`.
4996 pub outcome: SandboxOutcome,
4997 /// Host operating-system family
4998 pub platform: SandboxPlatform,
4999 /// Executable image associated with the denial that raised the retry, normalized to a basename. Populated only when content capture is enabled.
5000 #[serde(skip_serializing_if = "Option::is_none")]
5001 pub process_name: Option<String>,
5002 /// Tool call the completion belongs to, for span correlation only. Never exported as a telemetry attribute or metric dimension.
5003 #[serde(skip_serializing_if = "Option::is_none")]
5004 pub tool_call_id: Option<String>,
5005}
5006
5007/// Session event "subagent.started". Sub-agent startup details including parent tool call and agent information
5008#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5009#[serde(rename_all = "camelCase")]
5010pub struct SubagentStartedData {
5011 /// Description of what the sub-agent does
5012 pub agent_description: String,
5013 /// Human-readable display name of the sub-agent
5014 pub agent_display_name: String,
5015 /// Internal name of the sub-agent
5016 pub agent_name: String,
5017 /// Type of the sub-agent selected at spawn time.
5018 #[serde(skip_serializing_if = "Option::is_none")]
5019 pub agent_type: Option<String>,
5020 /// Whether the sub-agent runs synchronously or in the background.
5021 #[serde(skip_serializing_if = "Option::is_none")]
5022 pub execution_mode: Option<String>,
5023 /// Legacy root id of the workflow run that spawned this sub-agent. New consumers should use workflowRunId.
5024 #[serde(skip_serializing_if = "Option::is_none")]
5025 pub factory_run_id: Option<String>,
5026 /// Model the sub-agent will run with, when known at start.
5027 #[serde(skip_serializing_if = "Option::is_none")]
5028 pub model: Option<String>,
5029 /// Authority or runtime mechanism responsible for sub-agent model selection, when known at start.
5030 #[serde(skip_serializing_if = "Option::is_none")]
5031 pub model_selection_source: Option<SubagentModelSelectionSource>,
5032 /// Task-registry ID of the spawning sub-agent. Absent when the root session spawned this child.
5033 #[serde(skip_serializing_if = "Option::is_none")]
5034 pub parent_id: Option<String>,
5035 /// Whether this sub-agent can be resumed. Currently always false.
5036 #[serde(skip_serializing_if = "Option::is_none")]
5037 pub resumable: Option<bool>,
5038 /// Where the model input for this sub-agent came from. Present when the task planner resolved the launch (the task tool and workflow agents); absent for sub-agents created through other runtime paths.
5039 #[serde(skip_serializing_if = "Option::is_none")]
5040 pub task_model_source: Option<SubagentTaskModelSource>,
5041 /// Tool call ID of the parent tool invocation that spawned this sub-agent
5042 pub tool_call_id: String,
5043 /// Root id of the workflow run that spawned this sub-agent, when it was spawned by one.
5044 #[serde(skip_serializing_if = "Option::is_none")]
5045 pub workflow_run_id: Option<String>,
5046}
5047
5048/// Session event "subagent.configured". Resolved runtime configuration for a configured sub-agent
5049#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5050#[serde(rename_all = "camelCase")]
5051pub struct SubagentConfiguredData {
5052 /// Resolved context tier, when configured for the model
5053 #[serde(skip_serializing_if = "Option::is_none")]
5054 pub context_tier: Option<String>,
5055 /// Resolved model the sub-agent will run with
5056 pub model: String,
5057 /// Whether the sub-agent accepts follow-up turns
5058 pub multi_turn: bool,
5059 /// Resolved reasoning effort, when configured for the model
5060 #[serde(skip_serializing_if = "Option::is_none")]
5061 pub reasoning_effort: Option<String>,
5062}
5063
5064/// Session event "subagent.completed". Sub-agent completion details for successful execution
5065#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5066#[serde(rename_all = "camelCase")]
5067pub struct SubagentCompletedData {
5068 /// Human-readable display name of the sub-agent
5069 pub agent_display_name: String,
5070 /// Internal name of the sub-agent
5071 pub agent_name: String,
5072 /// Whether the sub-agent was torn down by cancellation - its own abort, or an ancestor being killed - instead of finishing its work. Cancellation is not a failure, so the run still reports completion; this distinguishes a torn-down sub-agent from one that ran to the end.
5073 #[serde(skip_serializing_if = "Option::is_none")]
5074 pub cancelled: Option<bool>,
5075 /// Whether the first model actually dispatched matched the user's configured preference
5076 #[serde(skip_serializing_if = "Option::is_none")]
5077 pub configured_model_matches_actual: Option<bool>,
5078 /// Concrete model the user configured for this sub-agent via `/subagents`, when present
5079 #[serde(skip_serializing_if = "Option::is_none")]
5080 pub configured_model_preference: Option<String>,
5081 /// Wall-clock duration of the sub-agent execution in milliseconds
5082 #[serde(skip_serializing_if = "Option::is_none")]
5083 pub duration_ms: Option<i64>,
5084 /// Whether the explicit task-call model matched the user's configured preference
5085 #[serde(skip_serializing_if = "Option::is_none")]
5086 pub explicit_model_matches_preference: Option<bool>,
5087 /// Explicit model supplied by the parent agent on the task call, when present
5088 #[serde(skip_serializing_if = "Option::is_none")]
5089 pub explicit_model_override: Option<String>,
5090 /// First model for which the sub-agent started an inference request, when one was dispatched
5091 #[serde(skip_serializing_if = "Option::is_none")]
5092 pub first_dispatched_model: Option<String>,
5093 /// Model used by the sub-agent
5094 #[serde(skip_serializing_if = "Option::is_none")]
5095 pub model: Option<String>,
5096 /// Why an explicit task-call model did not become the effective model
5097 #[serde(skip_serializing_if = "Option::is_none")]
5098 pub model_override_reason: Option<String>,
5099 /// Authority or runtime mechanism responsible for sub-agent model selection
5100 #[serde(skip_serializing_if = "Option::is_none")]
5101 pub model_selection_source: Option<SubagentModelSelectionSource>,
5102 /// Tool call ID of the parent tool invocation that spawned this sub-agent
5103 pub tool_call_id: String,
5104 /// Total tokens (input + output) consumed by the sub-agent
5105 #[serde(skip_serializing_if = "Option::is_none")]
5106 pub total_tokens: Option<i64>,
5107 /// Total number of tool calls made by the sub-agent
5108 #[serde(skip_serializing_if = "Option::is_none")]
5109 pub total_tool_calls: Option<i64>,
5110}
5111
5112/// Session event "subagent.failed". Sub-agent failure details including error message and agent information
5113#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5114#[serde(rename_all = "camelCase")]
5115pub struct SubagentFailedData {
5116 /// Human-readable display name of the sub-agent
5117 pub agent_display_name: String,
5118 /// Internal name of the sub-agent
5119 pub agent_name: String,
5120 /// Whether the first model actually dispatched matched the user's configured preference
5121 #[serde(skip_serializing_if = "Option::is_none")]
5122 pub configured_model_matches_actual: Option<bool>,
5123 /// Concrete model the user configured for this sub-agent via `/subagents`, when present
5124 #[serde(skip_serializing_if = "Option::is_none")]
5125 pub configured_model_preference: Option<String>,
5126 /// Wall-clock duration of the sub-agent execution in milliseconds
5127 #[serde(skip_serializing_if = "Option::is_none")]
5128 pub duration_ms: Option<i64>,
5129 /// Error message describing why the sub-agent failed
5130 pub error: String,
5131 /// Whether the explicit task-call model matched the user's configured preference
5132 #[serde(skip_serializing_if = "Option::is_none")]
5133 pub explicit_model_matches_preference: Option<bool>,
5134 /// Explicit model supplied by the parent agent on the task call, when present
5135 #[serde(skip_serializing_if = "Option::is_none")]
5136 pub explicit_model_override: Option<String>,
5137 /// First model for which the sub-agent started an inference request, when one was dispatched
5138 #[serde(skip_serializing_if = "Option::is_none")]
5139 pub first_dispatched_model: Option<String>,
5140 /// Model selected for the sub-agent, when known
5141 #[serde(skip_serializing_if = "Option::is_none")]
5142 pub model: Option<String>,
5143 /// Why an explicit task-call model did not become the effective model
5144 #[serde(skip_serializing_if = "Option::is_none")]
5145 pub model_override_reason: Option<String>,
5146 /// Authority or runtime mechanism responsible for sub-agent model selection
5147 #[serde(skip_serializing_if = "Option::is_none")]
5148 pub model_selection_source: Option<SubagentModelSelectionSource>,
5149 /// Tool call ID of the parent tool invocation that spawned this sub-agent
5150 pub tool_call_id: String,
5151 /// Total tokens (input + output) consumed before the sub-agent failed
5152 #[serde(skip_serializing_if = "Option::is_none")]
5153 pub total_tokens: Option<i64>,
5154 /// Total number of tool calls made before the sub-agent failed
5155 #[serde(skip_serializing_if = "Option::is_none")]
5156 pub total_tool_calls: Option<i64>,
5157}
5158
5159/// Session event "subagent.selected". Custom agent selection details including name and available tools
5160#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5161#[serde(rename_all = "camelCase")]
5162pub struct SubagentSelectedData {
5163 /// Human-readable display name of the selected custom agent
5164 pub agent_display_name: String,
5165 /// Internal name of the selected custom agent
5166 pub agent_name: String,
5167 /// List of tool names available to this agent, or null for all tools
5168 pub tools: Option<Vec<String>>,
5169}
5170
5171/// Session event "subagent.deselected". Empty payload; the event signals that the custom agent was deselected, returning to the default agent
5172#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5173#[serde(rename_all = "camelCase")]
5174pub struct SubagentDeselectedData {}
5175
5176/// Session event "hook.start". Hook invocation start details including type and input data
5177#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5178#[serde(rename_all = "camelCase")]
5179pub struct HookStartData {
5180 /// Unique identifier for this hook invocation
5181 pub hook_invocation_id: String,
5182 /// Type of hook being invoked (e.g., "preToolUse", "postToolUse", "sessionStart")
5183 pub hook_type: String,
5184 /// Input data passed to the hook. For postToolUse hooks the retained copy served by session.eventLog.read (and by a resumed session) drops the tool result's inline `contents`/`uiResource`/`skillInvocation` and replaces duplicated text result fields with a `[copilot:elided ...]` marker; the live subscription stream still delivers the full value. Canonical tool output remains in the adjacent tool.execution_complete event, while an invoked skill's authoritative body remains in its skill invocation event.
5185 #[serde(skip_serializing_if = "Option::is_none")]
5186 pub input: Option<serde_json::Value>,
5187 /// Tool call ID of the parent tool invocation when this event originates from a sub-agent
5188 #[serde(skip_serializing_if = "Option::is_none")]
5189 pub parent_tool_call_id: Option<String>,
5190}
5191
5192/// Error details when the hook failed
5193#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5194#[serde(rename_all = "camelCase")]
5195pub struct HookEndError {
5196 /// Human-readable error message
5197 pub message: String,
5198 /// Source label of the hook that errored (e.g. the plugin it was loaded from), when known
5199 #[serde(skip_serializing_if = "Option::is_none")]
5200 pub source: Option<String>,
5201 /// Error stack trace, when available
5202 #[serde(skip_serializing_if = "Option::is_none")]
5203 pub stack: Option<String>,
5204}
5205
5206/// Session event "hook.end". Hook invocation completion details including output, success status, and error information
5207#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5208#[serde(rename_all = "camelCase")]
5209pub struct HookEndData {
5210 /// Error details when the hook failed
5211 #[serde(skip_serializing_if = "Option::is_none")]
5212 pub error: Option<HookEndError>,
5213 /// Identifier matching the corresponding hook.start event
5214 pub hook_invocation_id: String,
5215 /// Type of hook that was invoked (e.g., "preToolUse", "postToolUse", "sessionStart")
5216 pub hook_type: String,
5217 /// Output data produced by the hook. Durable and resumed postToolUse receipts may omit messages owned by a successful skill invocation and replace an unchanged skill sessionLog copy with an elision marker; hook-modified or re-sourced values are preserved, and the authoritative body remains in the skill invocation event.
5218 #[serde(skip_serializing_if = "Option::is_none")]
5219 pub output: Option<serde_json::Value>,
5220 /// Tool call ID of the parent tool invocation when this event originates from a sub-agent
5221 #[serde(skip_serializing_if = "Option::is_none")]
5222 pub parent_tool_call_id: Option<String>,
5223 /// Whether the hook completed successfully
5224 pub success: bool,
5225}
5226
5227/// Session event "hook.progress". Ephemeral progress update from a running hook process
5228#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5229#[serde(rename_all = "camelCase")]
5230pub struct HookProgressData {
5231 /// Human-readable progress message from the hook process
5232 pub message: String,
5233 /// When true, this status message replaces the previous temporary one instead of accumulating
5234 #[serde(skip_serializing_if = "Option::is_none")]
5235 pub temporary: Option<bool>,
5236}
5237
5238/// Session event "session.binary_asset". Canonical bytes for a content-addressed binary asset shared by reference across events
5239#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5240#[serde(rename_all = "camelCase")]
5241pub struct SessionBinaryAssetData {
5242 /// Content-addressed id for this binary asset (e.g. "sha256:...").
5243 pub asset_id: String,
5244 /// Decoded byte length of the binary asset
5245 pub byte_length: i64,
5246 /// Base64-encoded binary data
5247 pub data: String,
5248 /// Human-readable description of the binary data
5249 #[serde(skip_serializing_if = "Option::is_none")]
5250 pub description: Option<String>,
5251 /// Optional metadata from the producing tool.
5252 #[serde(skip_serializing_if = "Option::is_none")]
5253 pub metadata: Option<HashMap<String, serde_json::Value>>,
5254 /// MIME type of the binary asset
5255 pub mime_type: String,
5256 /// Binary asset type discriminator. Use "image" for images and "resource" otherwise.
5257 pub r#type: BinaryAssetType,
5258}
5259
5260/// One persisted structured system-message block and its cache intent
5261#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5262#[serde(rename_all = "camelCase")]
5263pub struct SystemMessageContentBlock {
5264 /// Explicit prompt-cache intent. True places a breakpoint after this block, false suppresses one, and absence preserves the provider's legacy default.
5265 #[serde(skip_serializing_if = "Option::is_none")]
5266 pub cache_breakpoint: Option<bool>,
5267 /// Text content for this system-message block.
5268 pub content: String,
5269 /// Diagnostic classification indicating whether the block is stable across equivalent sessions.
5270 #[serde(skip_serializing_if = "Option::is_none")]
5271 pub is_static: Option<bool>,
5272}
5273
5274/// Metadata about the prompt template and its construction
5275#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5276#[serde(rename_all = "camelCase")]
5277pub struct SystemMessageMetadata {
5278 /// Version identifier of the prompt template or structured prompt layout used
5279 #[serde(skip_serializing_if = "Option::is_none")]
5280 pub prompt_version: Option<String>,
5281 /// Template variables used when constructing the prompt
5282 #[serde(skip_serializing_if = "Option::is_none")]
5283 pub variables: Option<HashMap<String, serde_json::Value>>,
5284}
5285
5286/// Session event "system.message". System/developer instruction content with role and optional template metadata
5287#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5288#[serde(rename_all = "camelCase")]
5289pub struct SystemMessageData {
5290 /// The system or developer prompt text sent as model input
5291 pub content: String,
5292 /// Optional ordered structured blocks corresponding to content, retained for prompt-cache layout restoration.
5293 #[serde(skip_serializing_if = "Option::is_none")]
5294 pub content_blocks: Option<Vec<SystemMessageContentBlock>>,
5295 /// Logical interaction identifier for the model run receiving this prompt
5296 #[serde(skip_serializing_if = "Option::is_none")]
5297 pub interaction_id: Option<String>,
5298 /// Metadata about the prompt template and its construction
5299 #[serde(skip_serializing_if = "Option::is_none")]
5300 pub metadata: Option<SystemMessageMetadata>,
5301 /// Optional name identifier for the message source
5302 #[serde(skip_serializing_if = "Option::is_none")]
5303 pub name: Option<String>,
5304 /// Message role: "system" for system prompts, "developer" for developer-injected instructions
5305 pub role: SystemMessageRole,
5306}
5307
5308/// Session event "system.notification". System-generated notification for runtime events like background task completion
5309#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5310#[serde(rename_all = "camelCase")]
5311pub struct SystemNotificationData {
5312 /// The notification text, typically wrapped in `<system_notification>` XML tags
5313 pub content: String,
5314 /// Structured metadata identifying what triggered this notification
5315 pub kind: serde_json::Value,
5316 /// Provider reasoning settings anchored before this model-facing message for cache-stable replay; the historical responsesReasoning name is retained for compatibility
5317 #[serde(skip_serializing_if = "Option::is_none")]
5318 pub responses_reasoning: Option<ResponsesReasoning>,
5319}
5320
5321/// A parsed command identifier in a shell permission request, including whether it is read-only.
5322#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5323#[serde(rename_all = "camelCase")]
5324pub struct PermissionRequestShellCommand {
5325 /// Command identifier (e.g., executable name)
5326 pub identifier: String,
5327 /// Whether this command is read-only (no side effects)
5328 pub read_only: bool,
5329}
5330
5331/// A parsed shell command segment used for argument-aware managed policy matching.
5332#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5333#[serde(rename_all = "camelCase")]
5334pub struct PermissionRequestShellCommandSegment {
5335 /// Full text of this command segment, including arguments
5336 pub full_command_text: String,
5337 /// Command identifier (e.g., executable name)
5338 pub identifier: String,
5339}
5340
5341/// A URL that may be accessed by a command in a shell permission request.
5342#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5343#[serde(rename_all = "camelCase")]
5344pub struct PermissionRequestShellPossibleUrl {
5345 /// URL that may be accessed by the command
5346 pub url: String,
5347}
5348
5349/// Shell command permission request
5350#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5351#[serde(rename_all = "camelCase")]
5352pub struct PermissionRequestShell {
5353 /// Whether the UI can offer session-wide approval for this command pattern
5354 pub can_offer_session_approval: bool,
5355 /// Parsed command identifiers found in the command text
5356 pub commands: Vec<PermissionRequestShellCommand>,
5357 /// Parsed command segments, including arguments, used for managed policy matching
5358 #[serde(skip_serializing_if = "Option::is_none")]
5359 pub command_segments: Option<Vec<PermissionRequestShellCommandSegment>>,
5360 /// The complete shell command text to be executed
5361 pub full_command_text: String,
5362 /// Whether the command includes a file write redirection (e.g., > or >>)
5363 pub has_write_file_redirection: bool,
5364 /// Human-readable description of what the command intends to do
5365 pub intention: String,
5366 /// Permission kind discriminator
5367 pub kind: PermissionRequestShellKind,
5368 /// Whether managed policy requires a human response and forbids host auto-approval
5369 #[serde(skip_serializing_if = "Option::is_none")]
5370 pub managed_approval_required: Option<bool>,
5371 /// File paths that may be read or written by the command
5372 pub possible_paths: Vec<String>,
5373 /// URLs that may be accessed by the command
5374 pub possible_urls: Vec<PermissionRequestShellPossibleUrl>,
5375 /// True when the tool is asking to run this command outside the sandbox, either because the command detaches and cannot be sandboxed at all, or because a sandboxed run looked blocked (host opted in via sandbox.allowBypass). The model cannot ask for this; only the tool raises it. This is a request, not a grant: the command runs unsandboxed only if the user approves this permission request. Hosts should highlight the elevated risk in the approval UI.
5376 #[serde(skip_serializing_if = "Option::is_none")]
5377 pub request_sandbox_bypass: Option<bool>,
5378 /// What the tool tells the user about the bypass on offer: which policy rule blocked the call, or why it cannot be sandboxed. Only meaningful when requestSandboxBypass is true.
5379 #[serde(skip_serializing_if = "Option::is_none")]
5380 pub request_sandbox_bypass_reason: Option<String>,
5381 /// True when the requested escalation is a permissive retry rather than a full bypass: the command re-runs inside the sandbox with its file and process restrictions recording instead of blocking, while the network policy stays enforced. Always accompanied by requestSandboxBypass, so hosts that do not recognize this field still treat the request as the escalation it is. Hosts that do recognize it must not describe the command as running outside the sandbox, which would overstate the privilege being granted.
5382 #[serde(skip_serializing_if = "Option::is_none")]
5383 pub request_sandbox_permissive: Option<bool>,
5384 /// Runtime-resolved canonical object each possiblePaths entry names, keyed by the requested spelling, used for authorization identity checks. Internal and experimental; clients should continue to display possiblePaths.
5385 ///
5386 /// <div class="warning">
5387 ///
5388 /// **Experimental.** This type is part of an experimental wire-protocol surface
5389 /// and may change or be removed in future SDK or CLI releases.
5390 ///
5391 /// </div>
5392 #[serde(skip_serializing_if = "Option::is_none")]
5393 pub resolved_paths: Option<HashMap<String, String>>,
5394 /// Runtime-resolved canonical working directory the command runs in, used for authorization identity checks. Internal and experimental; clients should not display it.
5395 ///
5396 /// <div class="warning">
5397 ///
5398 /// **Experimental.** This type is part of an experimental wire-protocol surface
5399 /// and may change or be removed in future SDK or CLI releases.
5400 ///
5401 /// </div>
5402 #[serde(skip_serializing_if = "Option::is_none")]
5403 pub resolved_working_directory: Option<String>,
5404 /// Tool call ID that triggered this permission request
5405 #[serde(skip_serializing_if = "Option::is_none")]
5406 pub tool_call_id: Option<String>,
5407 /// Optional warning message about risks of running this command
5408 #[serde(skip_serializing_if = "Option::is_none")]
5409 pub warning: Option<String>,
5410}
5411
5412/// File write permission request
5413#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5414#[serde(rename_all = "camelCase")]
5415pub struct PermissionRequestWrite {
5416 /// Whether the UI can offer session-wide approval for file write operations
5417 pub can_offer_session_approval: bool,
5418 /// Unified diff showing the proposed changes
5419 pub diff: String,
5420 /// Path of the file being written to
5421 pub file_name: String,
5422 /// Human-readable description of the intended file change
5423 pub intention: String,
5424 /// Permission kind discriminator
5425 pub kind: PermissionRequestWriteKind,
5426 /// Whether managed policy requires a human response and forbids host auto-approval
5427 #[serde(skip_serializing_if = "Option::is_none")]
5428 pub managed_approval_required: Option<bool>,
5429 /// Complete new file contents for newly created files
5430 #[serde(skip_serializing_if = "Option::is_none")]
5431 pub new_file_contents: Option<String>,
5432 /// True when a built-in file tool (apply_patch / str_replace_editor) asked to write a path the sandbox filesystem policy would block, and the host opted in via sandbox.allowBypass. This is a request, not a grant: the write happens unsandboxed only if the user approves this permission request. Hosts should highlight the elevated risk in the approval UI.
5433 #[serde(skip_serializing_if = "Option::is_none")]
5434 pub request_sandbox_bypass: Option<bool>,
5435 /// Justification for the sandbox-bypass request. Only meaningful when requestSandboxBypass is true.
5436 #[serde(skip_serializing_if = "Option::is_none")]
5437 pub request_sandbox_bypass_reason: Option<String>,
5438 /// Runtime-resolved canonical path used for authorization identity checks. Internal and experimental; clients should continue to display fileName.
5439 ///
5440 /// <div class="warning">
5441 ///
5442 /// **Experimental.** This type is part of an experimental wire-protocol surface
5443 /// and may change or be removed in future SDK or CLI releases.
5444 ///
5445 /// </div>
5446 #[serde(skip_serializing_if = "Option::is_none")]
5447 pub resolved_path: Option<String>,
5448 /// Tool call ID that triggered this permission request
5449 #[serde(skip_serializing_if = "Option::is_none")]
5450 pub tool_call_id: Option<String>,
5451}
5452
5453/// File or directory read permission request
5454#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5455#[serde(rename_all = "camelCase")]
5456pub struct PermissionRequestRead {
5457 /// Human-readable description of why the file is being read
5458 pub intention: String,
5459 /// Permission kind discriminator
5460 pub kind: PermissionRequestReadKind,
5461 /// Whether managed policy requires a human response and forbids host auto-approval
5462 #[serde(skip_serializing_if = "Option::is_none")]
5463 pub managed_approval_required: Option<bool>,
5464 /// Path of the file or directory being read
5465 pub path: String,
5466 /// True when the tool is asking to re-run this search outside the sandbox, after a sandboxed run looked blocked (host opted in via sandbox.allowBypass). The model cannot ask for this; only the tool raises it. This is a request, not a grant: the search runs unsandboxed only if the user approves this permission request. Hosts should highlight the elevated risk in the approval UI.
5467 #[serde(skip_serializing_if = "Option::is_none")]
5468 pub request_sandbox_bypass: Option<bool>,
5469 /// What the tool tells the user about the bypass on offer: which policy rule blocked the call, or why it cannot be sandboxed. Only meaningful when requestSandboxBypass is true.
5470 #[serde(skip_serializing_if = "Option::is_none")]
5471 pub request_sandbox_bypass_reason: Option<String>,
5472 /// Runtime-resolved canonical path used for authorization identity checks. Internal and experimental; clients should continue to display path.
5473 ///
5474 /// <div class="warning">
5475 ///
5476 /// **Experimental.** This type is part of an experimental wire-protocol surface
5477 /// and may change or be removed in future SDK or CLI releases.
5478 ///
5479 /// </div>
5480 #[serde(skip_serializing_if = "Option::is_none")]
5481 pub resolved_path: Option<String>,
5482 /// Tool call ID that triggered this permission request
5483 #[serde(skip_serializing_if = "Option::is_none")]
5484 pub tool_call_id: Option<String>,
5485}
5486
5487/// MCP tool invocation permission request
5488#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5489#[serde(rename_all = "camelCase")]
5490pub struct PermissionRequestMcp {
5491 /// Arguments to pass to the MCP tool
5492 #[serde(skip_serializing_if = "Option::is_none")]
5493 pub args: Option<serde_json::Value>,
5494 /// Permission kind discriminator
5495 pub kind: PermissionRequestMcpKind,
5496 /// When true, managed policy requires an explicit user decision and automatic approval must be bypassed.
5497 #[serde(skip_serializing_if = "Option::is_none")]
5498 pub managed_approval_required: Option<bool>,
5499 /// Advisory runtime permission recommendation. The SDK host remains responsible for deciding the request and may reject it.
5500 ///
5501 /// <div class="warning">
5502 ///
5503 /// **Experimental.** This type is part of an experimental wire-protocol surface
5504 /// and may change or be removed in future SDK or CLI releases.
5505 ///
5506 /// </div>
5507 #[serde(skip_serializing_if = "Option::is_none")]
5508 pub permission_recommendation: Option<PermissionRecommendation>,
5509 /// Whether this MCP tool is read-only (no side effects)
5510 pub read_only: bool,
5511 /// Name of the MCP server providing the tool
5512 pub server_name: String,
5513 /// Tool call ID that triggered this permission request
5514 #[serde(skip_serializing_if = "Option::is_none")]
5515 pub tool_call_id: Option<String>,
5516 /// Internal name of the MCP tool
5517 pub tool_name: String,
5518 /// Human-readable title of the MCP tool
5519 pub tool_title: String,
5520}
5521
5522/// URL access permission request
5523#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5524#[serde(rename_all = "camelCase")]
5525pub struct PermissionRequestUrl {
5526 /// Human-readable description of why the URL is being accessed
5527 pub intention: String,
5528 /// Permission kind discriminator
5529 pub kind: PermissionRequestUrlKind,
5530 /// Whether managed policy requires a human response and forbids host auto-approval
5531 #[serde(skip_serializing_if = "Option::is_none")]
5532 pub managed_approval_required: Option<bool>,
5533 /// Immediately preceding URL when this request is for a redirect target
5534 #[serde(skip_serializing_if = "Option::is_none")]
5535 pub redirected_from: Option<String>,
5536 /// True when the tool is asking to run this URL fetch outside the sandbox, after the network policy denied the approved URL or the sandbox proxy could not reach it (host opted in via sandbox.allowBypass). The model cannot ask for this; only the tool raises it. This is a request, not a grant: the fetch runs only if the user approves this permission request. Hosts should highlight the elevated risk in the approval UI.
5537 #[serde(skip_serializing_if = "Option::is_none")]
5538 pub request_sandbox_bypass: Option<bool>,
5539 /// What the tool tells the user about the bypass on offer: which policy rule blocked the call, or why it cannot be sandboxed. Only meaningful when requestSandboxBypass is true.
5540 #[serde(skip_serializing_if = "Option::is_none")]
5541 pub request_sandbox_bypass_reason: Option<String>,
5542 /// Tool call ID that triggered this permission request
5543 #[serde(skip_serializing_if = "Option::is_none")]
5544 pub tool_call_id: Option<String>,
5545 /// URL to be fetched
5546 pub url: String,
5547}
5548
5549/// Bounded runtime attribution, independent of free-text rationale. Telemetry revalidates this vocabulary before standard collection.
5550#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5551#[serde(rename_all = "camelCase")]
5552pub struct PermissionApprovalEvaluation {
5553 /// Stage that produced this attribution.
5554 pub evaluation_stage: PermissionApprovalEvaluationEvaluationStage,
5555 /// Whether the request invoked the judge interface. A cached recommendation retains the original attempt fact. Omitted means unknown, including inherited outcomes.
5556 #[serde(skip_serializing_if = "Option::is_none")]
5557 pub judge_attempted: Option<bool>,
5558 /// Status of the local judge interface, not proof of a model network call.
5559 pub judge_status: PermissionApprovalEvaluationJudgeStatus,
5560 /// Machine-readable runtime gate reason, never a command, path or human rationale.
5561 pub reason_code: PermissionApprovalEvaluationReasonCode,
5562}
5563
5564/// Assisted-approval judge information attached to a permission request. Present only in assisted mode; its absence means the judge did not evaluate the request. The `recommendation` conveys the judge's disposition for this request.
5565///
5566/// <div class="warning">
5567///
5568/// **Experimental.** This type is part of an experimental wire-protocol surface
5569/// and may change or be removed in future SDK or CLI releases.
5570///
5571/// </div>
5572#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5573#[serde(rename_all = "camelCase")]
5574pub struct PermissionAssistedApproval {
5575 /// Runtime reason and judge-call metadata. Absent on older events; missing metadata means unknown, not that the judge was skipped.
5576 #[serde(skip_serializing_if = "Option::is_none")]
5577 pub evaluation: Option<PermissionApprovalEvaluation>,
5578 /// Classified cause of an `error` recommendation. Absent for every other recommendation.
5579 #[serde(skip_serializing_if = "Option::is_none")]
5580 pub failure_reason: Option<AssistedApprovalJudgeFailureReason>,
5581 /// Model id that produced the recommendation, when the judge was consulted and reported one. Absent for `excluded` (the judge was not consulted) and for failures that occurred before a model was selected.
5582 #[serde(skip_serializing_if = "Option::is_none")]
5583 pub model: Option<String>,
5584 /// Human-readable reason for the judge's recommendation, when available.
5585 #[serde(skip_serializing_if = "Option::is_none")]
5586 pub reason: Option<String>,
5587 /// The assisted-approval safety judge's outcome for this request.
5588 pub recommendation: AssistedApprovalRecommendation,
5589}
5590
5591/// Memory operation permission request
5592#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5593#[serde(rename_all = "camelCase")]
5594pub struct PermissionRequestMemory {
5595 /// Whether this is a store or vote memory operation
5596 #[serde(skip_serializing_if = "Option::is_none")]
5597 pub action: Option<PermissionRequestMemoryAction>,
5598 /// Assisted-approval judge information for this request; present only in assisted mode.
5599 ///
5600 /// <div class="warning">
5601 ///
5602 /// **Experimental.** This type is part of an experimental wire-protocol surface
5603 /// and may change or be removed in future SDK or CLI releases.
5604 ///
5605 /// </div>
5606 #[serde(skip_serializing_if = "Option::is_none")]
5607 pub assisted_approval: Option<PermissionAssistedApproval>,
5608 /// Source references for the stored fact (store only)
5609 #[serde(skip_serializing_if = "Option::is_none")]
5610 pub citations: Option<String>,
5611 /// Vote direction (vote only)
5612 #[serde(skip_serializing_if = "Option::is_none")]
5613 pub direction: Option<PermissionRequestMemoryDirection>,
5614 /// The fact being stored or voted on
5615 pub fact: String,
5616 /// Permission kind discriminator
5617 pub kind: PermissionRequestMemoryKind,
5618 /// When true, managed policy requires an explicit user decision and automatic approval must be bypassed.
5619 #[serde(skip_serializing_if = "Option::is_none")]
5620 pub managed_approval_required: Option<bool>,
5621 /// Reason for the vote (vote only)
5622 #[serde(skip_serializing_if = "Option::is_none")]
5623 pub reason: Option<String>,
5624 /// Repository name with owner associated with the stored memory (store only)
5625 #[serde(skip_serializing_if = "Option::is_none")]
5626 pub repo_nwo: Option<String>,
5627 /// Scope of the stored memory (store only)
5628 #[serde(skip_serializing_if = "Option::is_none")]
5629 pub scope: Option<PermissionRequestMemoryScope>,
5630 /// Topic or subject of the memory (store only)
5631 #[serde(skip_serializing_if = "Option::is_none")]
5632 pub subject: Option<String>,
5633 /// Tool call ID that triggered this permission request
5634 #[serde(skip_serializing_if = "Option::is_none")]
5635 pub tool_call_id: Option<String>,
5636}
5637
5638/// Custom tool invocation permission request
5639#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5640#[serde(rename_all = "camelCase")]
5641pub struct PermissionRequestCustomTool {
5642 /// Arguments to pass to the custom tool
5643 #[serde(skip_serializing_if = "Option::is_none")]
5644 pub args: Option<serde_json::Value>,
5645 /// Permission kind discriminator
5646 pub kind: PermissionRequestCustomToolKind,
5647 /// When true, managed policy requires an explicit user decision and automatic approval must be bypassed.
5648 #[serde(skip_serializing_if = "Option::is_none")]
5649 pub managed_approval_required: Option<bool>,
5650 /// Whether the tool declared that permission may be skipped unless a deny rule matches
5651 #[serde(skip_serializing_if = "Option::is_none")]
5652 pub skip_permission: Option<bool>,
5653 /// Tool call ID that triggered this permission request
5654 #[serde(skip_serializing_if = "Option::is_none")]
5655 pub tool_call_id: Option<String>,
5656 /// Description of what the custom tool does
5657 pub tool_description: String,
5658 /// Name of the custom tool
5659 pub tool_name: String,
5660}
5661
5662/// Hook confirmation permission request
5663#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5664#[serde(rename_all = "camelCase")]
5665pub struct PermissionRequestHook {
5666 /// Optional message from the hook explaining why confirmation is needed
5667 #[serde(skip_serializing_if = "Option::is_none")]
5668 pub hook_message: Option<String>,
5669 /// Permission kind discriminator
5670 pub kind: PermissionRequestHookKind,
5671 /// When true, managed policy requires an explicit user decision and automatic approval must be bypassed.
5672 #[serde(skip_serializing_if = "Option::is_none")]
5673 pub managed_approval_required: Option<bool>,
5674 /// Arguments of the tool call being gated
5675 #[serde(skip_serializing_if = "Option::is_none")]
5676 pub tool_args: Option<serde_json::Value>,
5677 /// Tool call ID that triggered this permission request
5678 #[serde(skip_serializing_if = "Option::is_none")]
5679 pub tool_call_id: Option<String>,
5680 /// Name of the tool the hook is gating
5681 pub tool_name: String,
5682}
5683
5684/// Extension management permission request
5685#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5686#[serde(rename_all = "camelCase")]
5687pub struct PermissionRequestExtensionManagement {
5688 /// Name of the extension being managed
5689 #[serde(skip_serializing_if = "Option::is_none")]
5690 pub extension_name: Option<String>,
5691 /// Permission kind discriminator
5692 pub kind: PermissionRequestExtensionManagementKind,
5693 /// When true, managed policy requires an explicit user decision and automatic approval must be bypassed.
5694 #[serde(skip_serializing_if = "Option::is_none")]
5695 pub managed_approval_required: Option<bool>,
5696 /// The extension management operation (scaffold, reload)
5697 pub operation: String,
5698 /// Tool call ID that triggered this permission request
5699 #[serde(skip_serializing_if = "Option::is_none")]
5700 pub tool_call_id: Option<String>,
5701}
5702
5703/// A declared phase shown in a workflow permission prompt.
5704#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5705#[serde(rename_all = "camelCase")]
5706pub struct WorkflowPermissionPhase {
5707 /// Optional phase detail
5708 #[serde(skip_serializing_if = "Option::is_none")]
5709 pub detail: Option<String>,
5710 /// Phase title
5711 pub title: String,
5712}
5713
5714/// Workflow run or authoring permission request
5715#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5716#[serde(rename_all = "camelCase")]
5717pub struct PermissionRequestWorkflow {
5718 /// Canonical key used for scoped workflow approvals
5719 pub approval_key: String,
5720 /// Whether this workflow is eligible for persistent approval
5721 pub can_persist_approval: bool,
5722 /// Workflow-declared AI-credit limit before any run/resume caller override is applied.
5723 #[serde(skip_serializing_if = "Option::is_none")]
5724 pub declared_max_ai_credits: Option<f64>,
5725 /// Workflow-declared concurrent-subagent limit before any run/resume caller override is applied.
5726 #[serde(skip_serializing_if = "Option::is_none")]
5727 pub declared_max_concurrent_subagents: Option<i64>,
5728 /// Workflow-declared total-subagent limit before any run/resume caller override is applied.
5729 #[serde(skip_serializing_if = "Option::is_none")]
5730 pub declared_max_total_subagents: Option<i64>,
5731 /// Workflow-declared active-time limit in seconds before any run/resume caller override is applied.
5732 #[serde(skip_serializing_if = "Option::is_none")]
5733 pub declared_timeout_seconds: Option<f64>,
5734 /// Workflow description
5735 pub description: String,
5736 /// Permission kind discriminator
5737 pub kind: PermissionRequestWorkflowKind,
5738 /// Whether managed policy requires a human response and forbids host auto-approval
5739 #[serde(skip_serializing_if = "Option::is_none")]
5740 pub managed_approval_required: Option<bool>,
5741 /// Effective AI-credit limit; omitted means unlimited
5742 #[serde(skip_serializing_if = "Option::is_none")]
5743 pub max_ai_credits: Option<f64>,
5744 /// Effective concurrent-subagent limit; omitted means unlimited
5745 #[serde(skip_serializing_if = "Option::is_none")]
5746 pub max_concurrent_subagents: Option<i64>,
5747 /// Effective total-subagent limit; omitted means unlimited
5748 #[serde(skip_serializing_if = "Option::is_none")]
5749 pub max_total_subagents: Option<i64>,
5750 /// Workflow name
5751 pub name: String,
5752 /// Workflow operation, either run or author
5753 pub operation: WorkflowPermissionOperation,
5754 /// Declared workflow phases
5755 pub phases: Vec<WorkflowPermissionPhase>,
5756 /// Effective active-time limit in seconds; omitted means unlimited
5757 #[serde(skip_serializing_if = "Option::is_none")]
5758 pub timeout_seconds: Option<f64>,
5759 /// Tool call ID that triggered this permission request
5760 #[serde(skip_serializing_if = "Option::is_none")]
5761 pub tool_call_id: Option<String>,
5762}
5763
5764/// Extension permission access request
5765#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5766#[serde(rename_all = "camelCase")]
5767pub struct PermissionRequestExtensionPermissionAccess {
5768 /// Capabilities the extension is requesting
5769 pub capabilities: Vec<String>,
5770 /// Name of the extension requesting permission access
5771 pub extension_name: String,
5772 /// Permission kind discriminator
5773 pub kind: PermissionRequestExtensionPermissionAccessKind,
5774 /// When true, managed policy requires an explicit user decision and automatic approval must be bypassed.
5775 #[serde(skip_serializing_if = "Option::is_none")]
5776 pub managed_approval_required: Option<bool>,
5777 /// Tool call ID that triggered this permission request
5778 #[serde(skip_serializing_if = "Option::is_none")]
5779 pub tool_call_id: Option<String>,
5780}
5781
5782/// Extension sensitive environment variable access request
5783#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5784#[serde(rename_all = "camelCase")]
5785pub struct PermissionRequestExtensionEnvAccess {
5786 /// Names of the sensitive environment variables the extension is requesting. Values never appear here.
5787 pub environment_variables: Vec<String>,
5788 /// Name of the extension requesting environment variable access
5789 pub extension_name: String,
5790 /// Permission kind discriminator
5791 pub kind: PermissionRequestExtensionEnvAccessKind,
5792 /// When true, managed policy requires an explicit user decision and automatic approval must be bypassed.
5793 #[serde(skip_serializing_if = "Option::is_none")]
5794 pub managed_approval_required: Option<bool>,
5795 /// Tool call ID that triggered this permission request
5796 #[serde(skip_serializing_if = "Option::is_none")]
5797 pub tool_call_id: Option<String>,
5798}
5799
5800/// Shell command permission prompt
5801#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5802#[serde(rename_all = "camelCase")]
5803pub struct PermissionPromptRequestCommands {
5804 /// Assisted-approval judge information for this request; present only in assisted mode.
5805 ///
5806 /// <div class="warning">
5807 ///
5808 /// **Experimental.** This type is part of an experimental wire-protocol surface
5809 /// and may change or be removed in future SDK or CLI releases.
5810 ///
5811 /// </div>
5812 #[serde(skip_serializing_if = "Option::is_none")]
5813 pub assisted_approval: Option<PermissionAssistedApproval>,
5814 /// Whether the UI can offer session-wide approval for this command pattern
5815 pub can_offer_session_approval: bool,
5816 /// Command identifiers covered by this approval prompt
5817 pub command_identifiers: Vec<String>,
5818 /// The complete shell command text to be executed
5819 pub full_command_text: String,
5820 /// Human-readable description of what the command intends to do
5821 pub intention: String,
5822 /// Prompt kind discriminator
5823 pub kind: PermissionPromptRequestCommandsKind,
5824 /// Whether managed policy requires a human response and forbids host auto-approval
5825 #[serde(skip_serializing_if = "Option::is_none")]
5826 pub managed_approval_required: Option<bool>,
5827 /// True when the shell command is requesting sandbox escalation. This is a request, not a grant.
5828 #[serde(skip_serializing_if = "Option::is_none")]
5829 pub request_sandbox_bypass: Option<bool>,
5830 /// Reason for the sandbox escalation request.
5831 #[serde(skip_serializing_if = "Option::is_none")]
5832 pub request_sandbox_bypass_reason: Option<String>,
5833 /// True when the escalation is a permissive retry that keeps the sandbox and network policy attached while recording file and process accesses instead of blocking them.
5834 #[serde(skip_serializing_if = "Option::is_none")]
5835 pub request_sandbox_permissive: Option<bool>,
5836 /// Tool call ID that triggered this permission request
5837 #[serde(skip_serializing_if = "Option::is_none")]
5838 pub tool_call_id: Option<String>,
5839 /// Optional warning message about risks of running this command
5840 #[serde(skip_serializing_if = "Option::is_none")]
5841 pub warning: Option<String>,
5842}
5843
5844/// File write permission prompt
5845#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5846#[serde(rename_all = "camelCase")]
5847pub struct PermissionPromptRequestWrite {
5848 /// Assisted-approval judge information for this request; present only in assisted mode.
5849 ///
5850 /// <div class="warning">
5851 ///
5852 /// **Experimental.** This type is part of an experimental wire-protocol surface
5853 /// and may change or be removed in future SDK or CLI releases.
5854 ///
5855 /// </div>
5856 #[serde(skip_serializing_if = "Option::is_none")]
5857 pub assisted_approval: Option<PermissionAssistedApproval>,
5858 /// Whether the UI can offer session-wide approval for file write operations
5859 pub can_offer_session_approval: bool,
5860 /// Unified diff showing the proposed changes
5861 pub diff: String,
5862 /// Path of the file being written to
5863 pub file_name: String,
5864 /// Human-readable description of the intended file change
5865 pub intention: String,
5866 /// Prompt kind discriminator
5867 pub kind: PermissionPromptRequestWriteKind,
5868 /// Whether managed policy requires a human response and forbids host auto-approval
5869 #[serde(skip_serializing_if = "Option::is_none")]
5870 pub managed_approval_required: Option<bool>,
5871 /// Complete new file contents for newly created files
5872 #[serde(skip_serializing_if = "Option::is_none")]
5873 pub new_file_contents: Option<String>,
5874 /// Runtime-resolved canonical path used for authorization identity checks. Internal and experimental; clients should continue to display fileName.
5875 ///
5876 /// <div class="warning">
5877 ///
5878 /// **Experimental.** This type is part of an experimental wire-protocol surface
5879 /// and may change or be removed in future SDK or CLI releases.
5880 ///
5881 /// </div>
5882 #[serde(skip_serializing_if = "Option::is_none")]
5883 pub resolved_path: Option<String>,
5884 /// Tool call ID that triggered this permission request
5885 #[serde(skip_serializing_if = "Option::is_none")]
5886 pub tool_call_id: Option<String>,
5887}
5888
5889/// File read permission prompt
5890#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5891#[serde(rename_all = "camelCase")]
5892pub struct PermissionPromptRequestRead {
5893 /// Assisted-approval judge information for this request; present only in assisted mode.
5894 ///
5895 /// <div class="warning">
5896 ///
5897 /// **Experimental.** This type is part of an experimental wire-protocol surface
5898 /// and may change or be removed in future SDK or CLI releases.
5899 ///
5900 /// </div>
5901 #[serde(skip_serializing_if = "Option::is_none")]
5902 pub assisted_approval: Option<PermissionAssistedApproval>,
5903 /// Human-readable description of why the file is being read
5904 pub intention: String,
5905 /// Prompt kind discriminator
5906 pub kind: PermissionPromptRequestReadKind,
5907 /// Whether managed policy requires a human response and forbids host auto-approval
5908 #[serde(skip_serializing_if = "Option::is_none")]
5909 pub managed_approval_required: Option<bool>,
5910 /// Path of the file or directory being read
5911 pub path: String,
5912 /// Runtime-resolved canonical path used for authorization identity checks. Internal and experimental; clients should continue to display path.
5913 ///
5914 /// <div class="warning">
5915 ///
5916 /// **Experimental.** This type is part of an experimental wire-protocol surface
5917 /// and may change or be removed in future SDK or CLI releases.
5918 ///
5919 /// </div>
5920 #[serde(skip_serializing_if = "Option::is_none")]
5921 pub resolved_path: Option<String>,
5922 /// Tool call ID that triggered this permission request
5923 #[serde(skip_serializing_if = "Option::is_none")]
5924 pub tool_call_id: Option<String>,
5925}
5926
5927/// MCP tool invocation permission prompt
5928#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5929#[serde(rename_all = "camelCase")]
5930pub struct PermissionPromptRequestMcp {
5931 /// Arguments to pass to the MCP tool
5932 #[serde(skip_serializing_if = "Option::is_none")]
5933 pub args: Option<serde_json::Value>,
5934 /// Assisted-approval judge information for this request; present only in assisted mode.
5935 ///
5936 /// <div class="warning">
5937 ///
5938 /// **Experimental.** This type is part of an experimental wire-protocol surface
5939 /// and may change or be removed in future SDK or CLI releases.
5940 ///
5941 /// </div>
5942 #[serde(skip_serializing_if = "Option::is_none")]
5943 pub assisted_approval: Option<PermissionAssistedApproval>,
5944 /// Whether the host may offer a server-wide "approve all tools from this server" blanket. Absent is treated as true; the runtime sends false when managed policy disables bypass-permissions mode, which forbids the server-wide escalation while still allowing per-tool approval.
5945 #[serde(skip_serializing_if = "Option::is_none")]
5946 pub can_offer_server_wide_approval: Option<bool>,
5947 /// Prompt kind discriminator
5948 pub kind: PermissionPromptRequestMcpKind,
5949 /// Advisory runtime permission recommendation. The host remains responsible for deciding the request and may reject it.
5950 ///
5951 /// <div class="warning">
5952 ///
5953 /// **Experimental.** This type is part of an experimental wire-protocol surface
5954 /// and may change or be removed in future SDK or CLI releases.
5955 ///
5956 /// </div>
5957 #[serde(skip_serializing_if = "Option::is_none")]
5958 pub permission_recommendation: Option<PermissionRecommendation>,
5959 /// Name of the MCP server providing the tool
5960 pub server_name: String,
5961 /// Tool call ID that triggered this permission request
5962 #[serde(skip_serializing_if = "Option::is_none")]
5963 pub tool_call_id: Option<String>,
5964 /// Internal name of the MCP tool
5965 pub tool_name: String,
5966 /// Human-readable title of the MCP tool
5967 pub tool_title: String,
5968}
5969
5970/// URL access permission prompt
5971#[derive(Debug, Clone, Default, Serialize, Deserialize)]
5972#[serde(rename_all = "camelCase")]
5973pub struct PermissionPromptRequestUrl {
5974 /// Assisted-approval judge information for this request; present only in assisted mode.
5975 ///
5976 /// <div class="warning">
5977 ///
5978 /// **Experimental.** This type is part of an experimental wire-protocol surface
5979 /// and may change or be removed in future SDK or CLI releases.
5980 ///
5981 /// </div>
5982 #[serde(skip_serializing_if = "Option::is_none")]
5983 pub assisted_approval: Option<PermissionAssistedApproval>,
5984 /// Human-readable description of why the URL is being accessed
5985 pub intention: String,
5986 /// Prompt kind discriminator
5987 pub kind: PermissionPromptRequestUrlKind,
5988 /// Whether managed policy requires a human response and forbids host auto-approval
5989 #[serde(skip_serializing_if = "Option::is_none")]
5990 pub managed_approval_required: Option<bool>,
5991 /// Immediately preceding URL when this prompt is for a redirect target
5992 #[serde(skip_serializing_if = "Option::is_none")]
5993 pub redirected_from: Option<String>,
5994 /// True when the tool is asking to run this URL fetch outside the sandbox, after the network policy denied the approved URL or the sandbox proxy could not reach it (host opted in via sandbox.allowBypass). The model cannot ask for this; only the tool raises it. This is a request, not a grant: the fetch runs only if the user approves this permission request. Hosts should highlight the elevated risk in the approval UI.
5995 #[serde(skip_serializing_if = "Option::is_none")]
5996 pub request_sandbox_bypass: Option<bool>,
5997 /// What the tool tells the user about the bypass on offer: which policy rule blocked the call, or why it cannot be sandboxed. Only meaningful when requestSandboxBypass is true.
5998 #[serde(skip_serializing_if = "Option::is_none")]
5999 pub request_sandbox_bypass_reason: Option<String>,
6000 /// Tool call ID that triggered this permission request
6001 #[serde(skip_serializing_if = "Option::is_none")]
6002 pub tool_call_id: Option<String>,
6003 /// URL to be fetched
6004 pub url: String,
6005}
6006
6007/// Memory operation permission prompt
6008#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6009#[serde(rename_all = "camelCase")]
6010pub struct PermissionPromptRequestMemory {
6011 /// Whether this is a store or vote memory operation
6012 #[serde(skip_serializing_if = "Option::is_none")]
6013 pub action: Option<PermissionRequestMemoryAction>,
6014 /// Assisted-approval judge information for this request; present only in assisted mode.
6015 ///
6016 /// <div class="warning">
6017 ///
6018 /// **Experimental.** This type is part of an experimental wire-protocol surface
6019 /// and may change or be removed in future SDK or CLI releases.
6020 ///
6021 /// </div>
6022 #[serde(skip_serializing_if = "Option::is_none")]
6023 pub assisted_approval: Option<PermissionAssistedApproval>,
6024 /// Source references for the stored fact (store only)
6025 #[serde(skip_serializing_if = "Option::is_none")]
6026 pub citations: Option<String>,
6027 /// Vote direction (vote only)
6028 #[serde(skip_serializing_if = "Option::is_none")]
6029 pub direction: Option<PermissionRequestMemoryDirection>,
6030 /// The fact being stored or voted on
6031 pub fact: String,
6032 /// Prompt kind discriminator
6033 pub kind: PermissionPromptRequestMemoryKind,
6034 /// Reason for the vote (vote only)
6035 #[serde(skip_serializing_if = "Option::is_none")]
6036 pub reason: Option<String>,
6037 /// Topic or subject of the memory (store only)
6038 #[serde(skip_serializing_if = "Option::is_none")]
6039 pub subject: Option<String>,
6040 /// Tool call ID that triggered this permission request
6041 #[serde(skip_serializing_if = "Option::is_none")]
6042 pub tool_call_id: Option<String>,
6043}
6044
6045/// Custom tool invocation permission prompt
6046#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6047#[serde(rename_all = "camelCase")]
6048pub struct PermissionPromptRequestCustomTool {
6049 /// Arguments to pass to the custom tool
6050 #[serde(skip_serializing_if = "Option::is_none")]
6051 pub args: Option<serde_json::Value>,
6052 /// Assisted-approval judge information for this request; present only in assisted mode.
6053 ///
6054 /// <div class="warning">
6055 ///
6056 /// **Experimental.** This type is part of an experimental wire-protocol surface
6057 /// and may change or be removed in future SDK or CLI releases.
6058 ///
6059 /// </div>
6060 #[serde(skip_serializing_if = "Option::is_none")]
6061 pub assisted_approval: Option<PermissionAssistedApproval>,
6062 /// Prompt kind discriminator
6063 pub kind: PermissionPromptRequestCustomToolKind,
6064 /// Tool call ID that triggered this permission request
6065 #[serde(skip_serializing_if = "Option::is_none")]
6066 pub tool_call_id: Option<String>,
6067 /// Description of what the custom tool does
6068 pub tool_description: String,
6069 /// Name of the custom tool
6070 pub tool_name: String,
6071}
6072
6073/// Path access permission prompt
6074#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6075#[serde(rename_all = "camelCase")]
6076pub struct PermissionPromptRequestPath {
6077 /// Underlying permission kind that needs path approval
6078 pub access_kind: PermissionPromptRequestPathAccessKind,
6079 /// Assisted-approval judge information for this request; present only in assisted mode.
6080 ///
6081 /// <div class="warning">
6082 ///
6083 /// **Experimental.** This type is part of an experimental wire-protocol surface
6084 /// and may change or be removed in future SDK or CLI releases.
6085 ///
6086 /// </div>
6087 #[serde(skip_serializing_if = "Option::is_none")]
6088 pub assisted_approval: Option<PermissionAssistedApproval>,
6089 /// Prompt kind discriminator
6090 pub kind: PermissionPromptRequestPathKind,
6091 /// File paths that require explicit approval
6092 pub paths: Vec<String>,
6093 /// Tool call ID that triggered this permission request
6094 #[serde(skip_serializing_if = "Option::is_none")]
6095 pub tool_call_id: Option<String>,
6096}
6097
6098/// Hook confirmation permission prompt
6099#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6100#[serde(rename_all = "camelCase")]
6101pub struct PermissionPromptRequestHook {
6102 /// Assisted-approval judge information for this request; present only in assisted mode.
6103 ///
6104 /// <div class="warning">
6105 ///
6106 /// **Experimental.** This type is part of an experimental wire-protocol surface
6107 /// and may change or be removed in future SDK or CLI releases.
6108 ///
6109 /// </div>
6110 #[serde(skip_serializing_if = "Option::is_none")]
6111 pub assisted_approval: Option<PermissionAssistedApproval>,
6112 /// Optional message from the hook explaining why confirmation is needed
6113 #[serde(skip_serializing_if = "Option::is_none")]
6114 pub hook_message: Option<String>,
6115 /// Prompt kind discriminator
6116 pub kind: PermissionPromptRequestHookKind,
6117 /// Arguments of the tool call being gated
6118 #[serde(skip_serializing_if = "Option::is_none")]
6119 pub tool_args: Option<serde_json::Value>,
6120 /// Tool call ID that triggered this permission request
6121 #[serde(skip_serializing_if = "Option::is_none")]
6122 pub tool_call_id: Option<String>,
6123 /// Name of the tool the hook is gating
6124 pub tool_name: String,
6125}
6126
6127/// Extension management permission prompt
6128#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6129#[serde(rename_all = "camelCase")]
6130pub struct PermissionPromptRequestExtensionManagement {
6131 /// Assisted-approval judge information for this request; present only in assisted mode.
6132 ///
6133 /// <div class="warning">
6134 ///
6135 /// **Experimental.** This type is part of an experimental wire-protocol surface
6136 /// and may change or be removed in future SDK or CLI releases.
6137 ///
6138 /// </div>
6139 #[serde(skip_serializing_if = "Option::is_none")]
6140 pub assisted_approval: Option<PermissionAssistedApproval>,
6141 /// Name of the extension being managed
6142 #[serde(skip_serializing_if = "Option::is_none")]
6143 pub extension_name: Option<String>,
6144 /// Prompt kind discriminator
6145 pub kind: PermissionPromptRequestExtensionManagementKind,
6146 /// The extension management operation (scaffold, reload)
6147 pub operation: String,
6148 /// Tool call ID that triggered this permission request
6149 #[serde(skip_serializing_if = "Option::is_none")]
6150 pub tool_call_id: Option<String>,
6151}
6152
6153/// Workflow run or authoring permission prompt
6154#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6155#[serde(rename_all = "camelCase")]
6156pub struct PermissionPromptRequestWorkflow {
6157 /// Canonical key used for scoped workflow approvals
6158 pub approval_key: String,
6159 /// Assisted-approval judge information for this request; present only in assisted mode.
6160 ///
6161 /// <div class="warning">
6162 ///
6163 /// **Experimental.** This type is part of an experimental wire-protocol surface
6164 /// and may change or be removed in future SDK or CLI releases.
6165 ///
6166 /// </div>
6167 #[serde(skip_serializing_if = "Option::is_none")]
6168 pub assisted_approval: Option<PermissionAssistedApproval>,
6169 /// Whether this workflow is eligible for persistent approval
6170 pub can_persist_approval: bool,
6171 /// Workflow-declared AI-credit limit before any run/resume caller override is applied.
6172 #[serde(skip_serializing_if = "Option::is_none")]
6173 pub declared_max_ai_credits: Option<f64>,
6174 /// Workflow-declared concurrent-subagent limit before any run/resume caller override is applied.
6175 #[serde(skip_serializing_if = "Option::is_none")]
6176 pub declared_max_concurrent_subagents: Option<i64>,
6177 /// Workflow-declared total-subagent limit before any run/resume caller override is applied.
6178 #[serde(skip_serializing_if = "Option::is_none")]
6179 pub declared_max_total_subagents: Option<i64>,
6180 /// Workflow-declared active-time limit in seconds before any run/resume caller override is applied.
6181 #[serde(skip_serializing_if = "Option::is_none")]
6182 pub declared_timeout_seconds: Option<f64>,
6183 /// Workflow description
6184 pub description: String,
6185 /// Prompt kind discriminator
6186 pub kind: PermissionPromptRequestWorkflowKind,
6187 /// Whether managed policy requires a human response and forbids host auto-approval
6188 #[serde(skip_serializing_if = "Option::is_none")]
6189 pub managed_approval_required: Option<bool>,
6190 /// Effective AI-credit limit; omitted means unlimited
6191 #[serde(skip_serializing_if = "Option::is_none")]
6192 pub max_ai_credits: Option<f64>,
6193 /// Effective concurrent-subagent limit; omitted means unlimited
6194 #[serde(skip_serializing_if = "Option::is_none")]
6195 pub max_concurrent_subagents: Option<i64>,
6196 /// Effective total-subagent limit; omitted means unlimited
6197 #[serde(skip_serializing_if = "Option::is_none")]
6198 pub max_total_subagents: Option<i64>,
6199 /// Workflow name
6200 pub name: String,
6201 /// Workflow operation, either run or author
6202 pub operation: WorkflowPermissionOperation,
6203 /// Declared workflow phases
6204 pub phases: Vec<WorkflowPermissionPhase>,
6205 /// Effective active-time limit in seconds; omitted means unlimited
6206 #[serde(skip_serializing_if = "Option::is_none")]
6207 pub timeout_seconds: Option<f64>,
6208 /// Tool call ID that triggered this permission request
6209 #[serde(skip_serializing_if = "Option::is_none")]
6210 pub tool_call_id: Option<String>,
6211}
6212
6213/// Extension permission access prompt
6214#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6215#[serde(rename_all = "camelCase")]
6216pub struct PermissionPromptRequestExtensionPermissionAccess {
6217 /// Assisted-approval judge information for this request; present only in assisted mode.
6218 ///
6219 /// <div class="warning">
6220 ///
6221 /// **Experimental.** This type is part of an experimental wire-protocol surface
6222 /// and may change or be removed in future SDK or CLI releases.
6223 ///
6224 /// </div>
6225 #[serde(skip_serializing_if = "Option::is_none")]
6226 pub assisted_approval: Option<PermissionAssistedApproval>,
6227 /// Capabilities the extension is requesting
6228 pub capabilities: Vec<String>,
6229 /// Name of the extension requesting permission access
6230 pub extension_name: String,
6231 /// Prompt kind discriminator
6232 pub kind: PermissionPromptRequestExtensionPermissionAccessKind,
6233 /// Tool call ID that triggered this permission request
6234 #[serde(skip_serializing_if = "Option::is_none")]
6235 pub tool_call_id: Option<String>,
6236}
6237
6238/// Extension sensitive environment variable access prompt
6239#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6240#[serde(rename_all = "camelCase")]
6241pub struct PermissionPromptRequestExtensionEnvAccess {
6242 /// Assisted-approval judge information for this request; present only in assisted mode.
6243 ///
6244 /// <div class="warning">
6245 ///
6246 /// **Experimental.** This type is part of an experimental wire-protocol surface
6247 /// and may change or be removed in future SDK or CLI releases.
6248 ///
6249 /// </div>
6250 #[serde(skip_serializing_if = "Option::is_none")]
6251 pub assisted_approval: Option<PermissionAssistedApproval>,
6252 /// Names of the sensitive environment variables the extension is requesting. Values never appear here.
6253 pub environment_variables: Vec<String>,
6254 /// Name of the extension requesting environment variable access
6255 pub extension_name: String,
6256 /// Prompt kind discriminator
6257 pub kind: PermissionPromptRequestExtensionEnvAccessKind,
6258 /// Tool call ID that triggered this permission request
6259 #[serde(skip_serializing_if = "Option::is_none")]
6260 pub tool_call_id: Option<String>,
6261}
6262
6263/// Session event "permission.requested". Permission request notification requiring client approval with request details
6264#[derive(Debug, Clone, Serialize, Deserialize)]
6265#[serde(rename_all = "camelCase")]
6266pub struct PermissionRequestedData {
6267 /// Agent mode captured from the owning turn when permission evaluation began.
6268 #[serde(skip_serializing_if = "Option::is_none")]
6269 pub agent_mode: Option<SessionMode>,
6270 /// Permission mode captured when evaluation began. Absent on historical events.
6271 #[serde(skip_serializing_if = "Option::is_none")]
6272 pub permission_mode: Option<PermissionMode>,
6273 /// Details of the permission being requested
6274 pub permission_request: PermissionRequest,
6275 /// Derived user-facing permission prompt details for UI consumers
6276 #[serde(skip_serializing_if = "Option::is_none")]
6277 pub prompt_request: Option<PermissionPromptRequest>,
6278 /// Permission-recovery episode that authorized this request to surface for interactive attention
6279 #[serde(skip_serializing_if = "Option::is_none")]
6280 pub recovery_episode_id: Option<String>,
6281 /// Unique identifier for this permission request; used to respond via session.respondToPermission()
6282 pub request_id: RequestId,
6283 /// When true, this permission was already resolved by a permissionRequest hook and requires no client action
6284 #[serde(skip_serializing_if = "Option::is_none")]
6285 pub resolved_by_hook: Option<bool>,
6286 /// Neutral risk metadata supplied by the tool host. Consumers may display this value but must not use it to bypass the permission decision.
6287 #[serde(skip_serializing_if = "Option::is_none")]
6288 pub risk_assessment: Option<serde_json::Value>,
6289}
6290
6291/// Permission response variant indicating the request was approved without persisting an approval rule.
6292#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6293#[serde(rename_all = "camelCase")]
6294pub struct PermissionApproved {
6295 /// The permission request was approved
6296 pub kind: PermissionApprovedKind,
6297 /// Whether a managed approval policy already handled this request
6298 #[serde(skip_serializing_if = "Option::is_none")]
6299 pub managed_approval_handled: Option<bool>,
6300}
6301
6302/// Session-scoped tool-approval rule for specific shell command identifiers.
6303#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6304#[serde(rename_all = "camelCase")]
6305pub struct UserToolSessionApprovalCommands {
6306 /// Command identifiers approved by the user
6307 pub command_identifiers: Vec<String>,
6308 /// Command approval kind
6309 pub kind: UserToolSessionApprovalCommandsKind,
6310}
6311
6312/// Session-scoped tool-approval rule for read-only filesystem operations.
6313#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6314#[serde(rename_all = "camelCase")]
6315pub struct UserToolSessionApprovalRead {
6316 /// Read approval kind
6317 pub kind: UserToolSessionApprovalReadKind,
6318}
6319
6320/// Session-scoped tool-approval rule for filesystem write operations.
6321#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6322#[serde(rename_all = "camelCase")]
6323pub struct UserToolSessionApprovalWrite {
6324 /// Write approval kind
6325 pub kind: UserToolSessionApprovalWriteKind,
6326}
6327
6328/// Session-scoped tool-approval rule for an MCP server tool, or all tools on the server when `toolName` is null.
6329#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6330#[serde(rename_all = "camelCase")]
6331pub struct UserToolSessionApprovalMcp {
6332 /// MCP tool approval kind
6333 pub kind: UserToolSessionApprovalMcpKind,
6334 /// MCP server name
6335 pub server_name: String,
6336 /// Optional MCP tool name, or null for all tools on the server
6337 pub tool_name: Option<String>,
6338}
6339
6340/// Session-scoped tool-approval rule for writes to long-term memory.
6341#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6342#[serde(rename_all = "camelCase")]
6343pub struct UserToolSessionApprovalMemory {
6344 /// Memory approval kind
6345 pub kind: UserToolSessionApprovalMemoryKind,
6346}
6347
6348/// Session-scoped tool-approval rule for a custom tool, keyed by tool name.
6349#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6350#[serde(rename_all = "camelCase")]
6351pub struct UserToolSessionApprovalCustomTool {
6352 /// Custom tool approval kind
6353 pub kind: UserToolSessionApprovalCustomToolKind,
6354 /// Custom tool name
6355 pub tool_name: String,
6356}
6357
6358/// Session-scoped tool-approval rule for extension-management operations, optionally narrowed by operation.
6359#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6360#[serde(rename_all = "camelCase")]
6361pub struct UserToolSessionApprovalExtensionManagement {
6362 /// Extension management approval kind
6363 pub kind: UserToolSessionApprovalExtensionManagementKind,
6364 /// Optional operation identifier
6365 #[serde(skip_serializing_if = "Option::is_none")]
6366 pub operation: Option<String>,
6367}
6368
6369/// Session-scoped workflow approval, optionally narrowed by approval key.
6370#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6371#[serde(rename_all = "camelCase")]
6372pub struct UserToolSessionApprovalWorkflow {
6373 /// Optional workflow operation name or canonical approval key
6374 #[serde(skip_serializing_if = "Option::is_none")]
6375 pub approval_key: Option<String>,
6376 /// Workflow approval kind
6377 pub kind: UserToolSessionApprovalWorkflowKind,
6378}
6379
6380/// Session-scoped tool-approval rule for an extension's permission-gated capability access, keyed by extension name.
6381#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6382#[serde(rename_all = "camelCase")]
6383pub struct UserToolSessionApprovalExtensionPermissionAccess {
6384 /// Extension name
6385 pub extension_name: String,
6386 /// Extension permission access approval kind
6387 pub kind: UserToolSessionApprovalExtensionPermissionAccessKind,
6388}
6389
6390/// Session-scoped tool-approval rule for an extension's access to sensitive environment variables, keyed by extension name and the exact set of variable names.
6391#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6392#[serde(rename_all = "camelCase")]
6393pub struct UserToolSessionApprovalExtensionEnvAccess {
6394 /// Names of the sensitive environment variables this approval covers. Values are never persisted.
6395 pub environment_variables: Vec<String>,
6396 /// Extension name
6397 pub extension_name: String,
6398 /// Extension environment access approval kind
6399 pub kind: UserToolSessionApprovalExtensionEnvAccessKind,
6400}
6401
6402/// Permission response variant that approves a request and remembers the provided approval for the rest of the session.
6403#[derive(Debug, Clone, Serialize, Deserialize)]
6404#[serde(rename_all = "camelCase")]
6405pub struct PermissionApprovedForSession {
6406 /// The approval to add as a session-scoped rule
6407 pub approval: UserToolSessionApproval,
6408 /// Approved and remembered for the rest of the session
6409 pub kind: PermissionApprovedForSessionKind,
6410 /// Whether a managed approval policy already handled this request
6411 #[serde(skip_serializing_if = "Option::is_none")]
6412 pub managed_approval_handled: Option<bool>,
6413}
6414
6415/// Permission response variant that approves a request and persists the provided approval to a project location key.
6416#[derive(Debug, Clone, Serialize, Deserialize)]
6417#[serde(rename_all = "camelCase")]
6418pub struct PermissionApprovedForLocation {
6419 /// The approval to persist for this location
6420 pub approval: UserToolSessionApproval,
6421 /// Approved and persisted for this project location
6422 pub kind: PermissionApprovedForLocationKind,
6423 /// The location key (git root or cwd) to persist the approval to
6424 pub location_key: String,
6425 /// Whether a managed approval policy already handled this request
6426 #[serde(skip_serializing_if = "Option::is_none")]
6427 pub managed_approval_handled: Option<bool>,
6428}
6429
6430/// Permission response variant indicating the request was cancelled before use, with an optional reason.
6431#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6432#[serde(rename_all = "camelCase")]
6433pub struct PermissionCancelled {
6434 /// The permission request was cancelled before a response was used
6435 pub kind: PermissionCancelledKind,
6436 /// Optional explanation of why the request was cancelled
6437 #[serde(skip_serializing_if = "Option::is_none")]
6438 pub reason: Option<String>,
6439}
6440
6441/// A permission approval or denial rule matched against a tool request, identified by a rule kind with an optional argument value.
6442#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6443#[serde(rename_all = "camelCase")]
6444pub struct PermissionRule {
6445 /// Argument value matched against the request, or null when the rule kind has no argument (e.g. 'read', 'write', 'memory').
6446 pub argument: Option<String>,
6447 /// The rule kind, such as Shell or GitHubMCP
6448 pub kind: String,
6449}
6450
6451/// Permission response variant denied because matching approval rules explicitly blocked the request.
6452#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6453#[serde(rename_all = "camelCase")]
6454pub struct PermissionDeniedByRules {
6455 /// Denied because approval rules explicitly blocked it
6456 pub kind: PermissionDeniedByRulesKind,
6457 /// Rules that denied the request
6458 pub rules: Vec<PermissionRule>,
6459}
6460
6461/// Permission response variant denied because no approval rule matched and user confirmation was unavailable.
6462#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6463#[serde(rename_all = "camelCase")]
6464pub struct PermissionDeniedNoApprovalRuleAndCouldNotRequestFromUser {
6465 /// Denied because no approval rule matched and user confirmation was unavailable
6466 pub kind: PermissionDeniedNoApprovalRuleAndCouldNotRequestFromUserKind,
6467}
6468
6469/// Permission response variant denied in an interactive user prompt, with optional feedback and force-reject flag.
6470#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6471#[serde(rename_all = "camelCase")]
6472pub struct PermissionDeniedInteractivelyByUser {
6473 /// Optional feedback from the user explaining the denial
6474 #[serde(skip_serializing_if = "Option::is_none")]
6475 pub feedback: Option<String>,
6476 /// Whether to force-reject the current agent turn
6477 #[serde(skip_serializing_if = "Option::is_none")]
6478 pub force_reject: Option<bool>,
6479 /// Denied by the user during an interactive prompt
6480 pub kind: PermissionDeniedInteractivelyByUserKind,
6481}
6482
6483/// Permission response variant denying a path under content exclusion policy, with the path and message.
6484#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6485#[serde(rename_all = "camelCase")]
6486pub struct PermissionDeniedByContentExclusionPolicy {
6487 /// Denied by the organization's content exclusion policy
6488 pub kind: PermissionDeniedByContentExclusionPolicyKind,
6489 /// Human-readable explanation of why the path was excluded
6490 pub message: String,
6491 /// File path that triggered the exclusion
6492 pub path: String,
6493}
6494
6495/// Permission response variant denied by a permission-request hook, with optional message and interrupt flag.
6496#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6497#[serde(rename_all = "camelCase")]
6498pub struct PermissionDeniedByPermissionRequestHook {
6499 /// Whether to interrupt the current agent turn
6500 #[serde(skip_serializing_if = "Option::is_none")]
6501 pub interrupt: Option<bool>,
6502 /// Denied by a permission request hook registered by an extension or plugin
6503 pub kind: PermissionDeniedByPermissionRequestHookKind,
6504 /// Optional message from the hook explaining the denial
6505 #[serde(skip_serializing_if = "Option::is_none")]
6506 pub message: Option<String>,
6507}
6508
6509/// Session event "permission.completed". Permission request completion notification signaling UI dismissal
6510#[derive(Debug, Clone, Serialize, Deserialize)]
6511#[serde(rename_all = "camelCase")]
6512pub struct PermissionCompletedData {
6513 /// Atomic structured blocked outcome when this permission response ended an Autopilot recovery episode unsuccessfully
6514 #[serde(skip_serializing_if = "Option::is_none")]
6515 pub blocker: Option<TaskBlocker>,
6516 /// Who decided this permission request. Absent on completions recorded before this field existed, which consumers must treat as "not a human decision" rather than assuming one. Authorization records are minted only for `human_response`; an assisted-approval verdict, a host policy, an unattended fallback, and a hook resolution all produce the same `result` a person does, so this is the only field that distinguishes them.
6517 ///
6518 /// <div class="warning">
6519 ///
6520 /// **Experimental.** This type is part of an experimental wire-protocol surface
6521 /// and may change or be removed in future SDK or CLI releases.
6522 ///
6523 /// </div>
6524 #[serde(skip_serializing_if = "Option::is_none")]
6525 pub decision_source: Option<PermissionDecisionSource>,
6526 /// Permission-recovery episode settled by this response, when the request was escalated by Autopilot
6527 #[serde(skip_serializing_if = "Option::is_none")]
6528 pub recovery_episode_id: Option<String>,
6529 /// Request ID of the resolved permission request; clients should dismiss any UI for this request
6530 pub request_id: RequestId,
6531 /// The result of the permission request
6532 pub result: PermissionResult,
6533 /// Optional tool call ID associated with this permission prompt; clients may use it to correlate UI created from tool-scoped prompts
6534 #[serde(skip_serializing_if = "Option::is_none")]
6535 pub tool_call_id: Option<String>,
6536}
6537
6538/// Session event "permission.carriedForward". Historical decode-only receipt from the retired Assisted Permissions authorization extractor. Current runtimes ignore it for permission decisions.
6539///
6540/// <div class="warning">
6541///
6542/// **Experimental.** This type is part of an experimental wire-protocol surface
6543/// and may change or be removed in future SDK or CLI releases.
6544///
6545/// </div>
6546#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6547#[serde(rename_all = "camelCase")]
6548pub struct PermissionCarriedForwardData {
6549 /// Always `authorization_carry_forward`. Stated explicitly so a consumer reading this event cannot mistake it for a human, host-policy, or assisted-approval decision.
6550 ///
6551 /// <div class="warning">
6552 ///
6553 /// **Experimental.** This type is part of an experimental wire-protocol surface
6554 /// and may change or be removed in future SDK or CLI releases.
6555 ///
6556 /// </div>
6557 pub decision_source: PermissionDecisionSource,
6558 /// Identity of the prior authorization record that contained the proposal.
6559 ///
6560 /// <div class="warning">
6561 ///
6562 /// **Experimental.** This type is part of an experimental wire-protocol surface
6563 /// and may change or be removed in future SDK or CLI releases.
6564 ///
6565 /// </div>
6566 pub record_id: String,
6567 /// Authorization edge minted for this admission. Not a prompt id: no prompt was raised, so no client should expect a request with this id.
6568 ///
6569 /// <div class="warning">
6570 ///
6571 /// **Experimental.** This type is part of an experimental wire-protocol surface
6572 /// and may change or be removed in future SDK or CLI releases.
6573 ///
6574 /// </div>
6575 pub request_id: RequestId,
6576 /// Tool call this admission authorizes. Its execution receipts the prior grant, which is how a single-effect approval is spent rather than carried forward again.
6577 ///
6578 /// <div class="warning">
6579 ///
6580 /// **Experimental.** This type is part of an experimental wire-protocol surface
6581 /// and may change or be removed in future SDK or CLI releases.
6582 ///
6583 /// </div>
6584 pub tool_call_id: String,
6585}
6586
6587/// Session event "permission.messageAuthorization". Historical decode-only claim from the retired Assisted Permissions authorization extractor. Current runtimes preserve the payload but do not establish authority from it.
6588///
6589/// <div class="warning">
6590///
6591/// **Experimental.** This type is part of an experimental wire-protocol surface
6592/// and may change or be removed in future SDK or CLI releases.
6593///
6594/// </div>
6595#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6596#[serde(rename_all = "camelCase")]
6597pub struct PermissionMessageAuthorizationData {
6598 /// The kind of effect authorized, as an action-class identifier.
6599 ///
6600 /// <div class="warning">
6601 ///
6602 /// **Experimental.** This type is part of an experimental wire-protocol surface
6603 /// and may change or be removed in future SDK or CLI releases.
6604 ///
6605 /// </div>
6606 pub action_class: String,
6607 /// Whether the claim granted or denied authority.
6608 ///
6609 /// <div class="warning">
6610 ///
6611 /// **Experimental.** This type is part of an experimental wire-protocol surface
6612 /// and may change or be removed in future SDK or CLI releases.
6613 ///
6614 /// </div>
6615 pub polarity: PermissionMessageAuthorizationPolarity,
6616 /// Deterministic identity of the record, derived from the turn and span offsets so re-extracting the same span mints nothing new.
6617 ///
6618 /// <div class="warning">
6619 ///
6620 /// **Experimental.** This type is part of an experimental wire-protocol surface
6621 /// and may change or be removed in future SDK or CLI releases.
6622 ///
6623 /// </div>
6624 pub record_id: String,
6625 /// End byte offset of the authorizing span within the turn.
6626 ///
6627 /// <div class="warning">
6628 ///
6629 /// **Experimental.** This type is part of an experimental wire-protocol surface
6630 /// and may change or be removed in future SDK or CLI releases.
6631 ///
6632 /// </div>
6633 pub span_end: i64,
6634 /// Start byte offset of the authorizing span within the turn.
6635 ///
6636 /// <div class="warning">
6637 ///
6638 /// **Experimental.** This type is part of an experimental wire-protocol surface
6639 /// and may change or be removed in future SDK or CLI releases.
6640 ///
6641 /// </div>
6642 pub span_start: i64,
6643 /// Concrete named targets that appear verbatim inside the span.
6644 ///
6645 /// <div class="warning">
6646 ///
6647 /// **Experimental.** This type is part of an experimental wire-protocol surface
6648 /// and may change or be removed in future SDK or CLI releases.
6649 ///
6650 /// </div>
6651 #[serde(skip_serializing_if = "Option::is_none")]
6652 pub target_members: Option<Vec<String>>,
6653 /// The task the permission is scoped to, when the human named one.
6654 ///
6655 /// <div class="warning">
6656 ///
6657 /// **Experimental.** This type is part of an experimental wire-protocol surface
6658 /// and may change or be removed in future SDK or CLI releases.
6659 ///
6660 /// </div>
6661 #[serde(skip_serializing_if = "Option::is_none")]
6662 pub task: Option<String>,
6663 /// The human turn the quoted span was read from.
6664 ///
6665 /// <div class="warning">
6666 ///
6667 /// **Experimental.** This type is part of an experimental wire-protocol surface
6668 /// and may change or be removed in future SDK or CLI releases.
6669 ///
6670 /// </div>
6671 pub turn_index: i64,
6672 /// The trusted version discriminator, when one exists. Exact shell-command grants carry the byte-identical commands grounded in the human span; world-derived classes carry a file object, remote tip, or runner only when that state was captured safely. An opaque object mirroring the runtime's adjacently-tagged resolution.
6673 ///
6674 /// <div class="warning">
6675 ///
6676 /// **Experimental.** This type is part of an experimental wire-protocol surface
6677 /// and may change or be removed in future SDK or CLI releases.
6678 ///
6679 /// </div>
6680 #[serde(skip_serializing_if = "Option::is_none")]
6681 pub world: Option<serde_json::Value>,
6682}
6683
6684/// Session event "permission.messageAuthorizationRead". Historical decode-only extractor progress marker. Current runtimes do not run or resume extraction from it.
6685///
6686/// <div class="warning">
6687///
6688/// **Experimental.** This type is part of an experimental wire-protocol surface
6689/// and may change or be removed in future SDK or CLI releases.
6690///
6691/// </div>
6692#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6693#[serde(rename_all = "camelCase")]
6694pub struct PermissionMessageAuthorizationReadData {
6695 /// Whether this read activates ongoing message-backed extraction. False for a contextual-assent-only pass while auto-approval is off, so unrelated future messages remain outside extraction.
6696 ///
6697 /// <div class="warning">
6698 ///
6699 /// **Experimental.** This type is part of an experimental wire-protocol surface
6700 /// and may change or be removed in future SDK or CLI releases.
6701 ///
6702 /// </div>
6703 #[serde(skip_serializing_if = "Option::is_none")]
6704 pub activates_extraction: Option<bool>,
6705 /// The human turn that was read by the proposer.
6706 ///
6707 /// <div class="warning">
6708 ///
6709 /// **Experimental.** This type is part of an experimental wire-protocol surface
6710 /// and may change or be removed in future SDK or CLI releases.
6711 ///
6712 /// </div>
6713 pub turn_index: i64,
6714}
6715
6716/// Session event "permission.messageAuthorizationDegraded". Historical decode-only degradation marker from the retired extractor. Current runtimes ignore it for permission decisions.
6717///
6718/// <div class="warning">
6719///
6720/// **Experimental.** This type is part of an experimental wire-protocol surface
6721/// and may change or be removed in future SDK or CLI releases.
6722///
6723/// </div>
6724#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6725#[serde(rename_all = "camelCase")]
6726pub struct PermissionMessageAuthorizationDegradedData {
6727 /// The human turn that could not be represented safely.
6728 ///
6729 /// <div class="warning">
6730 ///
6731 /// **Experimental.** This type is part of an experimental wire-protocol surface
6732 /// and may change or be removed in future SDK or CLI releases.
6733 ///
6734 /// </div>
6735 pub turn_index: i64,
6736}
6737
6738/// Session event "permission.assentDetected". Historical decode-only contextual-assent marker. Current runtimes do not project it into the conversation or permission flow.
6739///
6740/// <div class="warning">
6741///
6742/// **Experimental.** This type is part of an experimental wire-protocol surface
6743/// and may change or be removed in future SDK or CLI releases.
6744///
6745/// </div>
6746#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6747#[serde(rename_all = "camelCase")]
6748pub struct PermissionAssentDetectedData {
6749 /// Permission request the likely assent may refer to. The runtime derives this from the preceding durable blocker; the human message and extraction model do not choose it.
6750 ///
6751 /// <div class="warning">
6752 ///
6753 /// **Experimental.** This type is part of an experimental wire-protocol surface
6754 /// and may change or be removed in future SDK or CLI releases.
6755 ///
6756 /// </div>
6757 pub request_id: RequestId,
6758 /// Human turn whose text triggered the deterministic assent recognizer.
6759 ///
6760 /// <div class="warning">
6761 ///
6762 /// **Experimental.** This type is part of an experimental wire-protocol surface
6763 /// and may change or be removed in future SDK or CLI releases.
6764 ///
6765 /// </div>
6766 pub turn_index: i64,
6767}
6768
6769/// Session event "permission.contextualAuthorization". Historical decode-only contextual authorization claim. Current runtimes preserve the payload but do not establish authority from it.
6770///
6771/// <div class="warning">
6772///
6773/// **Experimental.** This type is part of an experimental wire-protocol surface
6774/// and may change or be removed in future SDK or CLI releases.
6775///
6776/// </div>
6777#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6778#[serde(rename_all = "camelCase")]
6779pub struct PermissionContextualAuthorizationData {
6780 /// Whether the contextual human span granted or denied authority.
6781 ///
6782 /// <div class="warning">
6783 ///
6784 /// **Experimental.** This type is part of an experimental wire-protocol surface
6785 /// and may change or be removed in future SDK or CLI releases.
6786 ///
6787 /// </div>
6788 pub polarity: PermissionMessageAuthorizationPolarity,
6789 /// Deterministic identity of the contextual message grant.
6790 ///
6791 /// <div class="warning">
6792 ///
6793 /// **Experimental.** This type is part of an experimental wire-protocol surface
6794 /// and may change or be removed in future SDK or CLI releases.
6795 ///
6796 /// </div>
6797 pub record_id: String,
6798 /// Original blocked permission request selected by deterministic event ordering, never by the extraction model.
6799 ///
6800 /// <div class="warning">
6801 ///
6802 /// **Experimental.** This type is part of an experimental wire-protocol surface
6803 /// and may change or be removed in future SDK or CLI releases.
6804 ///
6805 /// </div>
6806 pub request_id: RequestId,
6807 /// End byte offset of the contextual decision span within the turn.
6808 ///
6809 /// <div class="warning">
6810 ///
6811 /// **Experimental.** This type is part of an experimental wire-protocol surface
6812 /// and may change or be removed in future SDK or CLI releases.
6813 ///
6814 /// </div>
6815 pub span_end: i64,
6816 /// Start byte offset of the contextual decision span within the turn.
6817 ///
6818 /// <div class="warning">
6819 ///
6820 /// **Experimental.** This type is part of an experimental wire-protocol surface
6821 /// and may change or be removed in future SDK or CLI releases.
6822 ///
6823 /// </div>
6824 pub span_start: i64,
6825 /// Human turn containing the contextual decision.
6826 ///
6827 /// <div class="warning">
6828 ///
6829 /// **Experimental.** This type is part of an experimental wire-protocol surface
6830 /// and may change or be removed in future SDK or CLI releases.
6831 ///
6832 /// </div>
6833 pub turn_index: i64,
6834}
6835
6836/// Session event "user_input.requested". User input request notification with question and optional predefined choices
6837#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6838#[serde(rename_all = "camelCase")]
6839pub struct UserInputRequestedData {
6840 /// Whether the user can provide a free-form text response in addition to predefined choices
6841 #[serde(skip_serializing_if = "Option::is_none")]
6842 pub allow_freeform: Option<bool>,
6843 /// Predefined choices for the user to select from, if applicable
6844 #[serde(skip_serializing_if = "Option::is_none")]
6845 pub choices: Option<Vec<String>>,
6846 /// The question or prompt to present to the user
6847 pub question: String,
6848 /// Unique identifier for this input request; used to respond via session.respondToUserInput()
6849 pub request_id: RequestId,
6850 /// The LLM-assigned tool call ID that triggered this request; used by remote UIs to correlate responses
6851 #[serde(skip_serializing_if = "Option::is_none")]
6852 pub tool_call_id: Option<String>,
6853}
6854
6855/// Session event "user_input.completed". User input request completion with the user's response
6856#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6857#[serde(rename_all = "camelCase")]
6858pub struct UserInputCompletedData {
6859 /// The user's answer to the input request
6860 #[serde(skip_serializing_if = "Option::is_none")]
6861 pub answer: Option<String>,
6862 /// Request ID of the resolved user input request; clients should dismiss any UI for this request
6863 pub request_id: RequestId,
6864 /// Whether the answer was typed as free-form text rather than selected from choices
6865 #[serde(skip_serializing_if = "Option::is_none")]
6866 pub was_freeform: Option<bool>,
6867}
6868
6869/// JSON Schema describing the form fields to present to the user (form mode only)
6870#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6871#[serde(rename_all = "camelCase")]
6872pub struct ElicitationRequestedSchema {
6873 /// Form field definitions, keyed by field name
6874 pub properties: HashMap<String, serde_json::Value>,
6875 /// List of required field names
6876 #[serde(skip_serializing_if = "Option::is_none")]
6877 pub required: Option<Vec<String>>,
6878 /// Schema type indicator (always 'object')
6879 pub r#type: ElicitationRequestedSchemaType,
6880}
6881
6882/// Session event "elicitation.requested". Elicitation request; may be form-based (structured input) or URL-based (browser redirect)
6883#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6884#[serde(rename_all = "camelCase")]
6885pub struct ElicitationRequestedData {
6886 /// The source that initiated the request (MCP server name, or absent for agent-initiated)
6887 #[serde(skip_serializing_if = "Option::is_none")]
6888 pub elicitation_source: Option<String>,
6889 /// Message describing what information is needed from the user
6890 pub message: String,
6891 /// Elicitation mode; "form" for structured input, "url" for browser-based. Defaults to "form" when absent.
6892 #[serde(skip_serializing_if = "Option::is_none")]
6893 pub mode: Option<ElicitationRequestedMode>,
6894 /// JSON Schema describing the form fields to present to the user (form mode only)
6895 #[serde(skip_serializing_if = "Option::is_none")]
6896 pub requested_schema: Option<ElicitationRequestedSchema>,
6897 /// Unique identifier for this elicitation request; used to respond via session.respondToElicitation()
6898 pub request_id: RequestId,
6899 /// Tool call ID from the LLM completion; used to correlate with CompletionChunk.toolCall.id for remote UIs
6900 #[serde(skip_serializing_if = "Option::is_none")]
6901 pub tool_call_id: Option<String>,
6902 /// URL to open in the user's browser (url mode only)
6903 #[serde(skip_serializing_if = "Option::is_none")]
6904 pub url: Option<String>,
6905}
6906
6907/// Session event "elicitation.completed". Elicitation request completion with the user's response
6908#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6909#[serde(rename_all = "camelCase")]
6910pub struct ElicitationCompletedData {
6911 /// The user action: "accept" (submitted form), "decline" (explicitly refused), or "cancel" (dismissed)
6912 #[serde(skip_serializing_if = "Option::is_none")]
6913 pub action: Option<ElicitationCompletedAction>,
6914 /// The submitted form data when action is 'accept'; keys match the requested schema fields
6915 #[serde(skip_serializing_if = "Option::is_none")]
6916 pub content: Option<HashMap<String, serde_json::Value>>,
6917 /// Request ID of the resolved elicitation request; clients should dismiss any UI for this request
6918 pub request_id: RequestId,
6919}
6920
6921/// Session event "sampling.requested". Sampling request from an MCP server; contains the server name and a requestId for correlation
6922#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6923#[serde(rename_all = "camelCase")]
6924pub struct SamplingRequestedData {
6925 /// The JSON-RPC request ID from the MCP protocol
6926 pub mcp_request_id: serde_json::Value,
6927 /// Unique identifier for this sampling request; used to respond via session.respondToSampling()
6928 pub request_id: RequestId,
6929 /// Name of the MCP server that initiated the sampling request
6930 pub server_name: String,
6931}
6932
6933/// Session event "sampling.completed". Sampling request completion notification signaling UI dismissal
6934#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6935#[serde(rename_all = "camelCase")]
6936pub struct SamplingCompletedData {
6937 /// Request ID of the resolved sampling request; clients should dismiss any UI for this request
6938 pub request_id: RequestId,
6939}
6940
6941/// Single HTTP header entry as a name/value pair.
6942#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6943#[serde(rename_all = "camelCase")]
6944pub struct HeaderEntry {
6945 /// HTTP response header name as observed by the runtime.
6946 pub name: String,
6947 /// HTTP response header value as observed by the runtime.
6948 pub value: String,
6949}
6950
6951/// Raw HTTP response details from the OAuth auth challenge, as observed by the runtime.
6952#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6953#[serde(rename_all = "camelCase")]
6954pub struct McpOauthHttpResponse {
6955 /// Complete UTF-8 response body for host-specific challenge handling, including an empty string for an empty body. Omitted when the complete body is not valid UTF-8; body read failures fail the HTTP operation rather than exposing a partial response.
6956 #[serde(skip_serializing_if = "Option::is_none")]
6957 pub body: Option<String>,
6958 /// HTTP response headers as observed by the runtime. Order and casing are transport-dependent, and duplicate header names may appear multiple times.
6959 pub headers: Vec<HeaderEntry>,
6960 /// HTTP status code returned with the auth challenge.
6961 pub status_code: i32,
6962}
6963
6964/// Static OAuth client configuration, if the server specifies one
6965#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6966#[serde(rename_all = "camelCase")]
6967pub struct McpOauthRequiredStaticClientConfig {
6968 /// OAuth client ID for the server
6969 pub client_id: String,
6970 /// Optional OAuth client secret for confidential static clients, when the runtime can resolve one
6971 #[serde(skip_serializing_if = "Option::is_none")]
6972 pub client_secret: Option<String>,
6973 /// Optional non-default OAuth grant type. When set to 'client_credentials', the OAuth flow runs headlessly using the client_id + keychain-stored secret (no browser, no callback server).
6974 #[serde(skip_serializing_if = "Option::is_none")]
6975 pub grant_type: Option<McpOauthRequiredStaticClientConfigGrantType>,
6976 /// Whether this is a public OAuth client
6977 #[serde(skip_serializing_if = "Option::is_none")]
6978 pub public_client: Option<bool>,
6979 /// Configured OAuth scope string used when the server challenge omits scope or provides an empty scope
6980 #[serde(skip_serializing_if = "Option::is_none")]
6981 pub scope: Option<String>,
6982}
6983
6984/// OAuth WWW-Authenticate parameters parsed from an MCP auth challenge
6985#[derive(Debug, Clone, Default, Serialize, Deserialize)]
6986#[serde(rename_all = "camelCase")]
6987pub struct McpOauthWWWAuthenticateParams {
6988 /// OAuth error from the WWW-Authenticate error parameter, if present
6989 #[serde(skip_serializing_if = "Option::is_none")]
6990 pub error: Option<String>,
6991 /// Protected resource metadata URL from the WWW-Authenticate resource_metadata parameter, if present
6992 #[serde(skip_serializing_if = "Option::is_none")]
6993 pub resource_metadata_url: Option<String>,
6994 /// Requested OAuth scopes from the WWW-Authenticate scope parameter, if present
6995 #[serde(skip_serializing_if = "Option::is_none")]
6996 pub scope: Option<String>,
6997}
6998
6999/// Session event "mcp.oauth_required". OAuth authentication request for an MCP server
7000#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7001#[serde(rename_all = "camelCase")]
7002pub struct McpOauthRequiredData {
7003 /// Raw HTTP response details from the OAuth auth challenge, as observed by the runtime. Header order and casing are transport-dependent, and duplicate header names may appear multiple times.
7004 #[serde(skip_serializing_if = "Option::is_none")]
7005 pub http_response: Option<McpOauthHttpResponse>,
7006 /// Why the runtime is requesting host-provided OAuth credentials.
7007 pub reason: McpOauthRequestReason,
7008 /// Unique identifier for this OAuth request; used to respond via session.mcp.oauth.handlePendingRequest
7009 pub request_id: RequestId,
7010 /// Raw OAuth protected-resource metadata document fetched for the MCP server, if available
7011 #[serde(skip_serializing_if = "Option::is_none")]
7012 pub resource_metadata: Option<String>,
7013 /// Display name of the MCP server that requires OAuth
7014 pub server_name: String,
7015 /// URL of the MCP server that requires OAuth
7016 pub server_url: String,
7017 /// Static OAuth client configuration, if the server specifies one
7018 #[serde(skip_serializing_if = "Option::is_none")]
7019 pub static_client_config: Option<McpOauthRequiredStaticClientConfig>,
7020 /// OAuth WWW-Authenticate parameters parsed from the auth challenge, if available
7021 #[serde(skip_serializing_if = "Option::is_none")]
7022 pub www_authenticate_params: Option<McpOauthWWWAuthenticateParams>,
7023}
7024
7025/// Session event "mcp.oauth_completed". MCP OAuth request completion notification
7026#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7027#[serde(rename_all = "camelCase")]
7028pub struct McpOauthCompletedData {
7029 /// How the pending OAuth request was completed
7030 pub outcome: McpOauthCompletionOutcome,
7031 /// Request ID of the resolved OAuth request
7032 pub request_id: RequestId,
7033}
7034
7035/// Session event "mcp.headers_refresh_required". Dynamic headers refresh request for a remote MCP server
7036#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7037#[serde(rename_all = "camelCase")]
7038pub struct McpHeadersRefreshRequiredData {
7039 /// Why dynamic headers are being requested.
7040 pub reason: McpHeadersRefreshRequiredReason,
7041 /// Unique identifier for this headers refresh request; used to respond via session.mcp.headers.handlePendingHeadersRefreshRequest()
7042 pub request_id: RequestId,
7043 /// Display name of the remote MCP server requesting headers
7044 pub server_name: String,
7045 /// URL of the remote MCP server requesting headers
7046 pub server_url: String,
7047}
7048
7049/// Session event "mcp.headers_refresh_completed". MCP headers refresh request completion notification
7050#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7051#[serde(rename_all = "camelCase")]
7052pub struct McpHeadersRefreshCompletedData {
7053 /// How the pending MCP headers refresh request resolved.
7054 pub outcome: McpHeadersRefreshCompletedOutcome,
7055 /// Request ID of the resolved headers refresh request
7056 pub request_id: RequestId,
7057}
7058
7059/// Session event "session.custom_notification". Opaque custom notification data. Consumers may branch on source and name, but payload semantics are source-defined.
7060#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7061#[serde(rename_all = "camelCase")]
7062pub struct SessionCustomNotificationData {
7063 /// Source-defined custom notification name
7064 pub name: String,
7065 /// Source-defined JSON payload for the custom notification
7066 pub payload: serde_json::Value,
7067 /// Namespace for the custom notification producer
7068 pub source: String,
7069 /// Optional source-defined string identifiers describing the payload subject
7070 #[serde(skip_serializing_if = "Option::is_none")]
7071 pub subject: Option<HashMap<String, String>>,
7072 /// Optional source-defined payload schema version
7073 #[serde(skip_serializing_if = "Option::is_none")]
7074 pub version: Option<i64>,
7075}
7076
7077/// Session event "ui.ephemeral_query". Ordered output and terminal state for a transient query that does not modify conversation history.
7078///
7079/// <div class="warning">
7080///
7081/// **Experimental.** This type is part of an experimental wire-protocol surface
7082/// and may change or be removed in future SDK or CLI releases.
7083///
7084/// </div>
7085#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7086#[serde(rename_all = "camelCase")]
7087pub struct UiEphemeralQueryData {
7088 /// Full response text, present for the `completed` phase.
7089 #[serde(skip_serializing_if = "Option::is_none")]
7090 pub answer: Option<String>,
7091 /// Ordered text delta, present for the `chunk` phase.
7092 #[serde(skip_serializing_if = "Option::is_none")]
7093 pub chunk: Option<String>,
7094 /// Model or transport failure message, present for the `failed` phase.
7095 #[serde(skip_serializing_if = "Option::is_none")]
7096 pub error: Option<String>,
7097 /// Current query lifecycle phase.
7098 pub phase: UIEphemeralQueryPhase,
7099 /// Runtime-minted query identifier.
7100 pub request_id: RequestId,
7101}
7102
7103/// Session event "external_tool.requested". External tool invocation request for client-side tool execution
7104#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7105#[serde(rename_all = "camelCase")]
7106pub struct ExternalToolRequestedData {
7107 /// Arguments to pass to the external tool
7108 #[serde(skip_serializing_if = "Option::is_none")]
7109 pub arguments: Option<serde_json::Value>,
7110 /// Stable provider identity captured with an extension-owned tool definition; hosts use it to route the request to the same provider that was offered to the model
7111 #[serde(skip_serializing_if = "Option::is_none")]
7112 pub provider_id: Option<String>,
7113 /// Unique identifier for this request; used to respond via session.respondToExternalTool()
7114 pub request_id: RequestId,
7115 /// Session ID that this external tool request belongs to
7116 pub session_id: SessionId,
7117 /// Tool call ID assigned to this external tool invocation
7118 pub tool_call_id: String,
7119 /// Name of the external tool to invoke
7120 pub tool_name: String,
7121 /// W3C Trace Context traceparent header for the execute_tool span
7122 #[serde(skip_serializing_if = "Option::is_none")]
7123 pub traceparent: Option<String>,
7124 /// W3C Trace Context tracestate header for the execute_tool span
7125 #[serde(skip_serializing_if = "Option::is_none")]
7126 pub tracestate: Option<String>,
7127 /// Active session working directory, when known.
7128 #[serde(skip_serializing_if = "Option::is_none")]
7129 pub working_directory: Option<String>,
7130}
7131
7132/// Session event "external_tool.completed". External tool completion notification signaling UI dismissal
7133#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7134#[serde(rename_all = "camelCase")]
7135pub struct ExternalToolCompletedData {
7136 /// Request ID of the resolved external tool request; clients should dismiss any UI for this request
7137 pub request_id: RequestId,
7138}
7139
7140/// Session event "command.queued". Queued slash command dispatch request for client execution
7141#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7142#[serde(rename_all = "camelCase")]
7143pub struct CommandQueuedData {
7144 /// The slash command text to be executed (e.g., /help, /clear)
7145 pub command: String,
7146 /// Unique identifier for this request; used to respond via session.respondToQueuedCommand()
7147 pub request_id: RequestId,
7148}
7149
7150/// Session event "command.execute". Registered command dispatch request routed to the owning client
7151#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7152#[serde(rename_all = "camelCase")]
7153pub struct CommandExecuteData {
7154 /// Raw argument string after the command name
7155 pub args: String,
7156 /// The full command text (e.g., /deploy production)
7157 pub command: String,
7158 /// Command name without leading /
7159 pub command_name: String,
7160 /// Unique identifier; used to respond via session.commands.handlePendingCommand()
7161 pub request_id: RequestId,
7162}
7163
7164/// Session event "command.completed". Queued command completion notification signaling UI dismissal
7165#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7166#[serde(rename_all = "camelCase")]
7167pub struct CommandCompletedData {
7168 /// Request ID of the resolved command request; clients should dismiss any UI for this request
7169 pub request_id: RequestId,
7170}
7171
7172/// Session event "auto_mode_switch.requested". Auto mode switch request notification requiring user approval
7173#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7174#[serde(rename_all = "camelCase")]
7175pub struct AutoModeSwitchRequestedData {
7176 /// The rate limit error code that triggered this request
7177 #[serde(skip_serializing_if = "Option::is_none")]
7178 pub error_code: Option<String>,
7179 /// Unique identifier for this request; used to respond via session.respondToAutoModeSwitch()
7180 pub request_id: RequestId,
7181 /// Seconds until the rate limit resets, when known. Lets clients render a humanized reset time alongside the prompt.
7182 #[serde(skip_serializing_if = "Option::is_none")]
7183 pub retry_after_seconds: Option<i64>,
7184}
7185
7186/// Session event "auto_mode_switch.completed". Auto mode switch completion notification
7187#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7188#[serde(rename_all = "camelCase")]
7189pub struct AutoModeSwitchCompletedData {
7190 /// Request ID of the resolved request; clients should dismiss any UI for this request
7191 pub request_id: RequestId,
7192 /// The user's auto-mode-switch choice
7193 pub response: AutoModeSwitchResponse,
7194}
7195
7196/// Session event "session_limits_exhausted.requested". Session limit exhaustion notification requiring user action.
7197#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7198#[serde(rename_all = "camelCase")]
7199pub struct SessionLimitsExhaustedRequestedData {
7200 /// Configured max AI Credits for the current accounting window.
7201 pub max_ai_credits: f64,
7202 /// Unique identifier for this request; used to respond via session.ui.handlePendingSessionLimitsExhausted().
7203 pub request_id: RequestId,
7204 /// AI Credits already consumed in the current accounting window.
7205 pub used_ai_credits: f64,
7206}
7207
7208/// The user's selected action for an exhausted session limit.
7209#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7210#[serde(rename_all = "camelCase")]
7211pub struct SessionLimitsExhaustedResponse {
7212 /// Action selected by the user.
7213 pub action: SessionLimitsExhaustedResponseAction,
7214 /// AI Credits to add to the current max when action is 'add'.
7215 #[serde(skip_serializing_if = "Option::is_none")]
7216 pub additional_ai_credits: Option<f64>,
7217 /// New absolute max AI Credits when action is 'set'.
7218 #[serde(skip_serializing_if = "Option::is_none")]
7219 pub max_ai_credits: Option<f64>,
7220}
7221
7222/// Session event "session_limits_exhausted.completed". Session limit exhaustion prompt completion notification.
7223#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7224#[serde(rename_all = "camelCase")]
7225pub struct SessionLimitsExhaustedCompletedData {
7226 /// Request ID of the resolved request; clients should dismiss any UI for this request.
7227 pub request_id: RequestId,
7228 /// The user's selected session-limit action.
7229 pub response: SessionLimitsExhaustedResponse,
7230}
7231
7232/// Session event "session.auto_mode_resolved". Auto Intent resolution: the concrete model the session settled on for the first prompt of an auto-mode session, and why. Lets SDK clients render the chosen model and the full reason it was picked. The core selection fields (chosenModel/reasoningBucket/categoryScores) are stable; the routing-analytics fields (predictedLabel/confidence/candidateModels) mirror the upstream intent service and may evolve, hence the event's experimental stability.
7233///
7234/// <div class="warning">
7235///
7236/// **Experimental.** This type is part of an experimental wire-protocol surface
7237/// and may change or be removed in future SDK or CLI releases.
7238///
7239/// </div>
7240#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7241#[serde(rename_all = "camelCase")]
7242pub struct SessionAutoModeResolvedData {
7243 /// Models offered to the router for this resolution
7244 #[serde(skip_serializing_if = "Option::is_none")]
7245 pub available_models: Option<Vec<String>>,
7246 /// Ordered candidate model list the router returned, when not a fallback
7247 #[serde(skip_serializing_if = "Option::is_none")]
7248 pub candidate_models: Option<Vec<String>>,
7249 /// Per-category classifier scores (0-1) behind the bucket: the granular HYDRA capability scores (reasoning, code_gen, debugging, tool_use), or the binary needs_reasoning/no_reasoning scores when HYDRA didn't run. Lets clients show a breakdown rather than just the bucket.
7250 #[serde(skip_serializing_if = "Option::is_none")]
7251 pub category_scores: Option<HashMap<String, f64>>,
7252 /// The concrete model the session will use after any intent refinement
7253 pub chosen_model: String,
7254 /// The chosen model's score shortfall relative to the top candidate
7255 #[serde(skip_serializing_if = "Option::is_none")]
7256 pub chosen_shortfall: Option<f64>,
7257 /// Classifier confidence for the predicted label, when available
7258 #[serde(skip_serializing_if = "Option::is_none")]
7259 pub confidence: Option<f64>,
7260 /// End-to-end client wait time for the router request in milliseconds
7261 #[serde(skip_serializing_if = "Option::is_none")]
7262 pub end_to_end_latency_ms: Option<f64>,
7263 /// Whether the router fell back to the standard Auto selection
7264 #[serde(skip_serializing_if = "Option::is_none")]
7265 pub fallback: Option<bool>,
7266 /// Server-provided reason for falling back, when available
7267 #[serde(skip_serializing_if = "Option::is_none")]
7268 pub fallback_reason: Option<String>,
7269 /// Whether the routed prompt contained an image
7270 #[serde(skip_serializing_if = "Option::is_none")]
7271 pub has_image: Option<bool>,
7272 /// The predicted classifier label (e.g. `needs_reasoning`), when available
7273 #[serde(skip_serializing_if = "Option::is_none")]
7274 pub predicted_label: Option<String>,
7275 /// Coarse request-difficulty bucket, for explaining why a model was chosen ("picked X because this looks like high-reasoning work")
7276 #[serde(skip_serializing_if = "Option::is_none")]
7277 pub reasoning_bucket: Option<AutoModeResolvedReasoningBucket>,
7278 /// Server-reported router processing time in milliseconds
7279 #[serde(skip_serializing_if = "Option::is_none")]
7280 pub router_latency_ms: Option<f64>,
7281 /// The routing method the server applied, when Auto Intent ran
7282 #[serde(skip_serializing_if = "Option::is_none")]
7283 pub routing_method: Option<String>,
7284 /// Whether a sticky model choice overrode the router result
7285 #[serde(skip_serializing_if = "Option::is_none")]
7286 pub sticky_override: Option<bool>,
7287}
7288
7289/// Session event "session.managed_settings_resolved". Enterprise managed-settings resolution: the effective managed settings the session applied and which channels contributed, so SDK clients can show users what is enterprise-managed. Fires whenever managed policy is (re)applied — at session start, on resume, and on account switch. This is an ephemeral live snapshot (delivered to subscribers but not persisted to the session event log), because at session start it resolves before `session.start` is emitted. Device values take precedence over server values, then the policy helper, per ordinary key, while permissions compose restrictively across device, server, policy-helper, and SDK-client layers. The account-scoped `getManagedSettings()` API does not include session-local client injection. Marked experimental while the managed-settings surface stabilizes.
7290///
7291/// <div class="warning">
7292///
7293/// **Experimental.** This type is part of an experimental wire-protocol surface
7294/// and may change or be removed in future SDK or CLI releases.
7295///
7296/// </div>
7297#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7298#[serde(rename_all = "camelCase")]
7299pub struct SessionManagedSettingsResolvedData {
7300 /// Whether enterprise policy disables bypass-permissions ("yolo") mode for this session. Deny-wins across layers, and forced on when `failClosed` is true.
7301 pub bypass_permissions_disabled: bool,
7302 /// Whether a session-local permissions layer injected by the SDK host was present
7303 #[serde(skip_serializing_if = "Option::is_none")]
7304 pub client_managed: Option<bool>,
7305 /// Whether an actual device MDM/plist/registry/file managed-settings layer was present
7306 pub device_managed: bool,
7307 /// Whether managed policy could not be determined (e.g. a failed server fetch) and the session fell back to the fail-closed restriction. When true, restrictions such as disabling bypass-permissions are enforced even though `settings` may be absent.
7308 pub fail_closed: bool,
7309 /// The setting keys under enterprise management in the effective managed settings (e.g. `model`, `enabledPlugins`, `permissions`). Empty when no managed settings are in force.
7310 pub managed_keys: Vec<String>,
7311 /// Whether at least two managed sources supplied permission allowlists, so enforcement intersects them and the flattened settings payload omits `permissions.allow`.
7312 #[serde(skip_serializing_if = "Option::is_none")]
7313 pub permissions_allow_intersected: Option<bool>,
7314 /// Whether the policy-helper managed-settings layer was present. The policy helper is the weakest channel: it fills keys no enterprise source set and can never replace one.
7315 #[serde(skip_serializing_if = "Option::is_none")]
7316 pub policy_helper_managed: Option<bool>,
7317 /// Whether the effective sandbox policy forces the sandbox on *only* because managed policy could not be determined, rather than because the policy requires it. Lets clients tell a user whose `--no-sandbox` was overridden that the sandbox stayed on as a fail-closed fallback, instead of attributing it to an administrator who set no such policy.
7318 #[serde(skip_serializing_if = "Option::is_none")]
7319 pub sandbox_enabled_by_undetermined_policy: Option<bool>,
7320 /// Whether the server (account/org) managed-settings layer was present
7321 pub server_managed: bool,
7322 /// The effective (resolved) managed settings values, so clients can render exactly what is enforced. Absent when no managed policy is in force.
7323 #[serde(skip_serializing_if = "Option::is_none")]
7324 pub settings: Option<serde_json::Value>,
7325 /// Channel summary: `server`, `device`, `client`, or `policyHelper` when exactly one channel contributed; `mixed` when multiple channels contributed; otherwise `none`. Consult the per-channel booleans for exact provenance.
7326 pub source: ManagedSettingsResolvedSource,
7327}
7328
7329/// Session event "session.managed_settings_enforced". Runtime enforcement of enterprise managed settings: fires when the session blocks or caps a runtime action because enterprise policy governs it, so SDK clients can explain *why* an action was governed. Unlike `session.managed_settings_resolved` (which reports *what* is managed), this reports a concrete governed action — e.g. a user or host tried to turn on a bypass-permissions escalation while policy disables it. Emitted live (not persisted to the session event log) on user/host-initiated attempts only, never for silent policy application. Marked experimental while the managed-settings surface stabilizes.
7330///
7331/// <div class="warning">
7332///
7333/// **Experimental.** This type is part of an experimental wire-protocol surface
7334/// and may change or be removed in future SDK or CLI releases.
7335///
7336/// </div>
7337#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7338#[serde(rename_all = "camelCase")]
7339pub struct SessionManagedSettingsEnforcedData {
7340 /// The category of runtime action that managed policy governed.
7341 pub action: ManagedSettingsEnforcedAction,
7342 /// For a `bypass_permissions_blocked` action, which permission-escalation primitive was refused. Absent for actions without a specific escalation primitive.
7343 #[serde(skip_serializing_if = "Option::is_none")]
7344 pub escalation: Option<ManagedSettingsEnforcedEscalation>,
7345 /// Whether the enforcement was forced by fail-closed handling (managed policy could not be determined) rather than an explicit managed setting. When true, `setting` still names the restriction that was applied.
7346 pub fail_closed: bool,
7347 /// A human-readable explanation of why the action was governed, suitable for surfacing to the user.
7348 pub message: String,
7349 /// The managed setting key responsible for the enforcement (e.g. `permissions.disableBypassPermissionsMode`).
7350 pub setting: String,
7351}
7352
7353/// A single slash command available in the session, as listed by the `commands.changed` event.
7354#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7355#[serde(rename_all = "camelCase")]
7356pub struct CommandsChangedCommand {
7357 /// Optional human-readable command description.
7358 #[serde(skip_serializing_if = "Option::is_none")]
7359 pub description: Option<String>,
7360 /// Slash command name without the leading slash.
7361 pub name: String,
7362}
7363
7364/// Session event "commands.changed". SDK command registration change notification
7365#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7366#[serde(rename_all = "camelCase")]
7367pub struct CommandsChangedData {
7368 /// Current list of registered SDK commands
7369 pub commands: Vec<CommandsChangedCommand>,
7370}
7371
7372/// UI capability changes
7373#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7374#[serde(rename_all = "camelCase")]
7375pub struct CapabilitiesChangedUI {
7376 /// Whether canvas rendering is now supported
7377 #[serde(skip_serializing_if = "Option::is_none")]
7378 pub canvases: Option<bool>,
7379 /// Whether elicitation is now supported
7380 #[serde(skip_serializing_if = "Option::is_none")]
7381 pub elicitation: Option<bool>,
7382 /// Whether MCP Apps (SEP-1865) UI passthrough is now supported
7383 #[serde(skip_serializing_if = "Option::is_none")]
7384 pub mcp_apps: Option<bool>,
7385}
7386
7387/// Session event "capabilities.changed". Session capability change notification
7388#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7389#[serde(rename_all = "camelCase")]
7390pub struct CapabilitiesChangedData {
7391 /// UI capability changes
7392 #[serde(skip_serializing_if = "Option::is_none")]
7393 pub ui: Option<CapabilitiesChangedUI>,
7394}
7395
7396/// Session event "exit_plan_mode.requested". Plan approval request with plan content and available user actions
7397#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7398#[serde(rename_all = "camelCase")]
7399pub struct ExitPlanModeRequestedData {
7400 /// Available actions the user can take
7401 pub actions: Vec<ExitPlanModeAction>,
7402 /// Model the session had selected when the plan was authored, when one is known
7403 #[serde(skip_serializing_if = "Option::is_none")]
7404 pub model: Option<String>,
7405 /// Full content of the plan file
7406 pub plan_content: String,
7407 /// Recommended action to preselect for the user
7408 pub recommended_action: ExitPlanModeAction,
7409 /// Unique identifier for this request; used to respond via session.respondToExitPlanMode()
7410 pub request_id: RequestId,
7411 /// Summary of the plan that was created
7412 pub summary: String,
7413}
7414
7415/// Session event "exit_plan_mode.completed". Plan mode exit completion with the user's approval decision and optional feedback
7416#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7417#[serde(rename_all = "camelCase")]
7418pub struct ExitPlanModeCompletedData {
7419 /// Whether the plan was approved by the user
7420 #[serde(skip_serializing_if = "Option::is_none")]
7421 pub approved: Option<bool>,
7422 /// Whether edits should be auto-approved without confirmation
7423 #[serde(skip_serializing_if = "Option::is_none")]
7424 pub auto_approve_edits: Option<bool>,
7425 /// Free-form feedback from the user if they requested changes to the plan
7426 #[serde(skip_serializing_if = "Option::is_none")]
7427 pub feedback: Option<String>,
7428 /// Request ID of the resolved exit plan mode request; clients should dismiss any UI for this request
7429 pub request_id: RequestId,
7430 /// Action selected by the user
7431 #[serde(skip_serializing_if = "Option::is_none")]
7432 pub selected_action: Option<ExitPlanModeAction>,
7433}
7434
7435/// Session event "session.tools_updated". Payload of `session.tools_updated` identifying the model whose resolved tools were updated.
7436#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7437#[serde(rename_all = "camelCase")]
7438pub struct SessionToolsUpdatedData {
7439 /// Identifier of the model the resolved tools apply to.
7440 pub model: String,
7441}
7442
7443/// Session event "session.background_tasks_changed". Empty payload for `session.background_tasks_changed`, indicating background task state changed.
7444#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7445#[serde(rename_all = "camelCase")]
7446pub struct SessionBackgroundTasksChangedData {}
7447
7448/// Session event "workflow.run_updated". Ephemeral invalidation signal for a changed workflow run.
7449///
7450/// <div class="warning">
7451///
7452/// **Experimental.** This type is part of an experimental wire-protocol surface
7453/// and may change or be removed in future SDK or CLI releases.
7454///
7455/// </div>
7456#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7457#[serde(rename_all = "camelCase")]
7458pub struct WorkflowRunUpdatedData {
7459 /// Monotonic revision now available for the run.
7460 pub revision: i64,
7461 /// Workflow run identifier.
7462 pub run_id: String,
7463}
7464
7465/// Session event "workflow.run_started". Ephemeral signal that a workflow run attempt began executing.
7466///
7467/// <div class="warning">
7468///
7469/// **Experimental.** This type is part of an experimental wire-protocol surface
7470/// and may change or be removed in future SDK or CLI releases.
7471///
7472/// </div>
7473#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7474#[serde(rename_all = "camelCase")]
7475pub struct WorkflowRunStartedData {
7476 /// Attempt number this start committed; a resumed run increments it.
7477 pub attempt: i64,
7478 /// Identifier of the workflow run that started.
7479 pub run_id: String,
7480 /// Name of the workflow this run executes. Low cardinality by construction.
7481 pub workflow_name: String,
7482}
7483
7484/// Session event "workflow.run_settled". Ephemeral signal that a workflow run reached a terminal status.
7485///
7486/// <div class="warning">
7487///
7488/// **Experimental.** This type is part of an experimental wire-protocol surface
7489/// and may change or be removed in future SDK or CLI releases.
7490///
7491/// </div>
7492#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7493#[serde(rename_all = "camelCase")]
7494pub struct WorkflowRunSettledData {
7495 /// AI credits this run consumed, in nano-AIU.
7496 pub consumed_nano_aiu: i64,
7497 /// Subagents this run consumed against its limits.
7498 pub consumed_subagents: i64,
7499 /// Active milliseconds accumulated across every attempt of this run.
7500 pub elapsed_ms: i64,
7501 /// Typed failure class recorded on the run, when it failed with one (e.g. `workflow_limit_reached`).
7502 #[serde(skip_serializing_if = "Option::is_none")]
7503 pub failure_type: Option<String>,
7504 /// Identifier of the workflow run that settled.
7505 pub run_id: String,
7506 /// Terminal status the run committed.
7507 pub status: WorkflowRunSettledStatus,
7508}
7509
7510/// A single resolved skill in `session.skills_loaded`, including source, invocability, enabled state, path, and argument hint.
7511#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7512#[serde(rename_all = "camelCase")]
7513pub struct SkillsLoadedSkill {
7514 /// Optional freeform hint describing the skill's expected arguments, from the `argument-hint` frontmatter field
7515 #[serde(skip_serializing_if = "Option::is_none")]
7516 pub argument_hint: Option<String>,
7517 /// Canonical slash command name used to invoke the skill, without the leading '/'
7518 #[serde(skip_serializing_if = "Option::is_none")]
7519 pub command_name: Option<String>,
7520 /// Description of what the skill does
7521 pub description: String,
7522 /// Whether the skill is currently enabled
7523 pub enabled: bool,
7524 /// Unique identifier for the skill
7525 pub name: String,
7526 /// Absolute path to the skill file, if available
7527 #[serde(skip_serializing_if = "Option::is_none")]
7528 pub path: Option<String>,
7529 /// Source location type (e.g., project, personal-copilot, plugin, builtin, remote, sdk)
7530 pub source: SkillSource,
7531 /// Whether the skill can be invoked by the user as a slash command
7532 pub user_invocable: bool,
7533}
7534
7535/// Session event "session.skills_loaded". Payload of `session.skills_loaded` listing resolved skill metadata.
7536#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7537#[serde(rename_all = "camelCase")]
7538pub struct SessionSkillsLoadedData {
7539 /// Array of resolved skill metadata
7540 pub skills: Vec<SkillsLoadedSkill>,
7541}
7542
7543/// A single loaded custom agent in `session.custom_agents_updated`, with identity, source, tools, invocability, and authored model configuration.
7544#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7545#[serde(rename_all = "camelCase")]
7546pub struct CustomAgentsUpdatedAgent {
7547 /// Description of what the agent does
7548 pub description: String,
7549 /// Whether model-driven invocation is disabled for this agent.
7550 #[serde(skip_serializing_if = "Option::is_none")]
7551 pub disable_model_invocation: Option<bool>,
7552 /// Human-readable display name
7553 pub display_name: String,
7554 /// Unique identifier for the agent
7555 pub id: String,
7556 /// Model override for this agent, if set
7557 #[serde(skip_serializing_if = "Option::is_none")]
7558 pub model: Option<String>,
7559 /// Whether authored models are preferences or required constraints
7560 #[serde(skip_serializing_if = "Option::is_none")]
7561 pub model_policy: Option<AgentModelPolicy>,
7562 /// Authored model ids in priority order, if configured
7563 #[serde(skip_serializing_if = "Option::is_none")]
7564 pub models: Option<Vec<String>>,
7565 /// Internal name of the agent
7566 pub name: String,
7567 /// Source location: user, project, inherited, remote, or plugin
7568 pub source: String,
7569 /// List of tool names available to this agent, or null when all tools are available
7570 pub tools: Option<Vec<String>>,
7571 /// Whether the agent can be selected by the user
7572 pub user_invocable: bool,
7573}
7574
7575/// Session event "session.custom_agents_updated". Payload of `session.custom_agents_updated` with loaded custom agents plus non-fatal warnings and fatal errors.
7576#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7577#[serde(rename_all = "camelCase")]
7578pub struct SessionCustomAgentsUpdatedData {
7579 /// Array of loaded custom agent metadata
7580 pub agents: Vec<CustomAgentsUpdatedAgent>,
7581 /// Fatal errors from agent loading
7582 pub errors: Vec<String>,
7583 /// Non-fatal warnings from agent loading
7584 pub warnings: Vec<String>,
7585}
7586
7587/// Server-advertised metadata learned through modern discovery or legacy initialization.
7588#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7589#[serde(rename_all = "camelCase")]
7590pub struct McpServerMetadata {
7591 /// Non-empty natural-language guidance for using the server, or null when the server omitted instructions or advertised an empty string.
7592 pub instructions: Option<String>,
7593}
7594
7595/// A single MCP server status summary in `session.mcp_servers_loaded`, including name, status, source, transport, and plugin metadata.
7596#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7597#[serde(rename_all = "camelCase")]
7598pub struct McpServersLoadedServer {
7599 /// Human-readable display name supplied by a managed server catalog.
7600 #[serde(skip_serializing_if = "Option::is_none")]
7601 pub display_name: Option<String>,
7602 /// Error message if the server failed to connect
7603 #[serde(skip_serializing_if = "Option::is_none")]
7604 pub error: Option<String>,
7605 /// Server name (config key)
7606 pub name: String,
7607 /// Name of the plugin that supplied the effective MCP server config, only when source is plugin
7608 #[serde(skip_serializing_if = "Option::is_none")]
7609 pub plugin_name: Option<String>,
7610 /// Version of the plugin that supplied the effective MCP server config, only when source is plugin
7611 #[serde(skip_serializing_if = "Option::is_none")]
7612 pub plugin_version: Option<String>,
7613 /// Server-advertised metadata for a connected server. Omitted when no live connection metadata is available, including while pending or when failed, disabled, stopped, or not configured.
7614 #[serde(skip_serializing_if = "Option::is_none")]
7615 pub server_metadata: Option<McpServerMetadata>,
7616 /// Configuration source: user, workspace, plugin, builtin, or managed
7617 #[serde(skip_serializing_if = "Option::is_none")]
7618 pub source: Option<McpServerSource>,
7619 /// Connection status: connected, failed, needs-auth, pending, disabled, stopped, or not_configured
7620 pub status: McpServerStatus,
7621 /// Transport mechanism: stdio, http, sse (deprecated), or memory (in-process MCP server)
7622 #[serde(skip_serializing_if = "Option::is_none")]
7623 pub transport: Option<McpServerTransport>,
7624}
7625
7626/// Session event "session.mcp_servers_loaded". Payload of `session.mcp_servers_loaded` listing MCP server status summaries.
7627#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7628#[serde(rename_all = "camelCase")]
7629pub struct SessionMcpServersLoadedData {
7630 /// Array of MCP server status summaries
7631 pub servers: Vec<McpServersLoadedServer>,
7632}
7633
7634/// Session event "session.mcp_server_status_changed". Payload of `session.mcp_server_status_changed` for one MCP server's status and optional failure error.
7635#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7636#[serde(rename_all = "camelCase")]
7637pub struct SessionMcpServerStatusChangedData {
7638 /// Error message if the server entered a failed state
7639 #[serde(skip_serializing_if = "Option::is_none")]
7640 pub error: Option<String>,
7641 /// Name of the MCP server whose status changed
7642 pub server_name: String,
7643 /// Connection status: connected, failed, needs-auth, pending, disabled, stopped, or not_configured
7644 pub status: McpServerStatus,
7645}
7646
7647/// Session event "session.mcp_server_removed". Payload of `session.mcp_server_removed` identifying an MCP server the graph no longer runs.
7648#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7649#[serde(rename_all = "camelCase")]
7650pub struct SessionMcpServerRemovedData {
7651 /// Name of the MCP server that was removed from the graph
7652 pub server_name: String,
7653}
7654
7655/// Session event "session.mcp_server_needs_reconnect". Payload of `session.mcp_server_needs_reconnect` identifying an MCP server whose connection must be re-established.
7656#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7657#[serde(rename_all = "camelCase")]
7658pub struct SessionMcpServerNeedsReconnectData {
7659 /// Name of the MCP server that needs to reconnect
7660 pub server_name: String,
7661}
7662
7663/// Session event "mcp.tools.list_changed". Payload identifying the MCP server associated with a list change.
7664#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7665#[serde(rename_all = "camelCase")]
7666pub struct McpToolsListChangedData {
7667 /// Name of the MCP server whose list changed
7668 pub server_name: String,
7669}
7670
7671/// Session event "mcp.resources.list_changed". Payload identifying the MCP server associated with a list change.
7672#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7673#[serde(rename_all = "camelCase")]
7674pub struct McpResourcesListChangedData {
7675 /// Name of the MCP server whose list changed
7676 pub server_name: String,
7677}
7678
7679/// Session event "mcp.prompts.list_changed". Payload identifying the MCP server associated with a list change.
7680#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7681#[serde(rename_all = "camelCase")]
7682pub struct McpPromptsListChangedData {
7683 /// Name of the MCP server whose list changed
7684 pub server_name: String,
7685}
7686
7687/// A single extension discovered by `session.extensions_loaded`, including qualified ID, source, and current status.
7688#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7689#[serde(rename_all = "camelCase")]
7690pub struct ExtensionsLoadedExtension {
7691 /// Source-qualified extension ID (e.g., 'project:my-ext', 'user:auth-helper', 'plugin:my-plugin:my-ext')
7692 pub id: String,
7693 /// Extension name (directory name)
7694 pub name: String,
7695 /// Discovery source
7696 pub source: ExtensionsLoadedExtensionSource,
7697 /// Current status: running, disabled, failed, or starting
7698 pub status: ExtensionsLoadedExtensionStatus,
7699}
7700
7701/// Session event "session.extensions_loaded". Payload of `session.extensions_loaded` listing discovered extensions and their statuses.
7702#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7703#[serde(rename_all = "camelCase")]
7704pub struct SessionExtensionsLoadedData {
7705 /// Array of discovered extensions and their status
7706 pub extensions: Vec<ExtensionsLoadedExtension>,
7707}
7708
7709/// Session event "session.canvas.opened". Payload of `session.canvas.opened` with canvas instance and provider IDs plus optional icon, title, status, URL, and input.
7710///
7711/// <div class="warning">
7712///
7713/// **Experimental.** This type is part of an experimental wire-protocol surface
7714/// and may change or be removed in future SDK or CLI releases.
7715///
7716/// </div>
7717#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7718#[serde(rename_all = "camelCase")]
7719pub struct SessionCanvasOpenedData {
7720 /// Provider-local canvas identifier
7721 pub canvas_id: String,
7722 /// Owning provider identifier
7723 pub extension_id: String,
7724 /// Owning extension display name, when available
7725 #[serde(skip_serializing_if = "Option::is_none")]
7726 pub extension_name: Option<String>,
7727 /// Host-local PNG path for the canvas icon, when supplied
7728 #[serde(skip_serializing_if = "Option::is_none")]
7729 pub icon: Option<String>,
7730 /// Input supplied when the instance was opened
7731 #[serde(skip_serializing_if = "Option::is_none")]
7732 pub input: Option<serde_json::Value>,
7733 /// Stable caller-supplied canvas instance identifier
7734 pub instance_id: String,
7735 /// Provider-supplied status text
7736 #[serde(skip_serializing_if = "Option::is_none")]
7737 pub status: Option<String>,
7738 /// Rendered title
7739 #[serde(skip_serializing_if = "Option::is_none")]
7740 pub title: Option<String>,
7741 /// URL for web-rendered canvases
7742 #[serde(skip_serializing_if = "Option::is_none")]
7743 pub url: Option<String>,
7744}
7745
7746/// A single action within a canvas declaration, with its name, optional description, and optional input schema.
7747///
7748/// <div class="warning">
7749///
7750/// **Experimental.** This type is part of an experimental wire-protocol surface
7751/// and may change or be removed in future SDK or CLI releases.
7752///
7753/// </div>
7754#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7755#[serde(rename_all = "camelCase")]
7756pub struct CanvasRegistryChangedCanvasAction {
7757 /// Action description
7758 #[serde(skip_serializing_if = "Option::is_none")]
7759 pub description: Option<String>,
7760 /// JSON Schema for action input
7761 #[serde(skip_serializing_if = "Option::is_none")]
7762 pub input_schema: Option<serde_json::Value>,
7763 /// Action name
7764 pub name: String,
7765}
7766
7767/// A single canvas declaration in `session.canvas.registry_changed`, including provider IDs, display metadata, input schema, and actions.
7768///
7769/// <div class="warning">
7770///
7771/// **Experimental.** This type is part of an experimental wire-protocol surface
7772/// and may change or be removed in future SDK or CLI releases.
7773///
7774/// </div>
7775#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7776#[serde(rename_all = "camelCase")]
7777pub struct CanvasRegistryChangedCanvas {
7778 /// Actions the agent or host may invoke
7779 #[serde(skip_serializing_if = "Option::is_none")]
7780 pub actions: Option<Vec<CanvasRegistryChangedCanvasAction>>,
7781 /// Provider-local canvas identifier
7782 pub canvas_id: String,
7783 /// Short, single-sentence description shown to the agent in canvas catalogs.
7784 pub description: String,
7785 /// Human-readable canvas name
7786 pub display_name: String,
7787 /// Owning provider identifier
7788 pub extension_id: String,
7789 /// Owning extension display name, when available
7790 #[serde(skip_serializing_if = "Option::is_none")]
7791 pub extension_name: Option<String>,
7792 /// Host-local PNG path for the canvas icon, when supplied
7793 #[serde(skip_serializing_if = "Option::is_none")]
7794 pub icon: Option<String>,
7795 /// JSON Schema for canvas open input
7796 #[serde(skip_serializing_if = "Option::is_none")]
7797 pub input_schema: Option<serde_json::Value>,
7798}
7799
7800/// Session event "session.canvas.registry_changed". Payload of `session.canvas.registry_changed` listing the canvas declarations currently available.
7801///
7802/// <div class="warning">
7803///
7804/// **Experimental.** This type is part of an experimental wire-protocol surface
7805/// and may change or be removed in future SDK or CLI releases.
7806///
7807/// </div>
7808#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7809#[serde(rename_all = "camelCase")]
7810pub struct SessionCanvasRegistryChangedData {
7811 /// Canvas declarations currently available
7812 pub canvases: Vec<CanvasRegistryChangedCanvas>,
7813}
7814
7815/// Session event "session.canvas.closed". Payload of `session.canvas.closed` with the closed canvas instance ID, provider ID, and canvas ID.
7816///
7817/// <div class="warning">
7818///
7819/// **Experimental.** This type is part of an experimental wire-protocol surface
7820/// and may change or be removed in future SDK or CLI releases.
7821///
7822/// </div>
7823#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7824#[serde(rename_all = "camelCase")]
7825pub struct SessionCanvasClosedData {
7826 /// Provider-local canvas identifier
7827 pub canvas_id: String,
7828 /// Owning provider identifier
7829 pub extension_id: String,
7830 /// Stable caller-supplied identifier of the canvas instance that was closed
7831 pub instance_id: String,
7832}
7833
7834/// Session event "session.canvas.unavailable". Transient signal that an open canvas instance's provider has dropped (for example the extension is reloading mid-session). The host should keep the panel mounted and surface a reconnecting affordance rather than tearing it down; a subsequent `session.canvas.opened` for the same instanceId clears the affordance once the provider reconnects with a fresh url. Ephemeral and never persisted, so it is never replayed on cold resume.
7835///
7836/// <div class="warning">
7837///
7838/// **Experimental.** This type is part of an experimental wire-protocol surface
7839/// and may change or be removed in future SDK or CLI releases.
7840///
7841/// </div>
7842#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7843#[serde(rename_all = "camelCase")]
7844pub struct SessionCanvasUnavailableData {
7845 /// Provider-local canvas identifier
7846 pub canvas_id: String,
7847 /// Owning provider identifier
7848 pub extension_id: String,
7849 /// Stable caller-supplied identifier of the canvas instance whose provider became unavailable
7850 pub instance_id: String,
7851}
7852
7853/// Session event "session.canvas.recorded". Durable record that a canvas instance is open, used to restore open canvases on cold session resume. Intentionally omits the transient url and availability.
7854///
7855/// <div class="warning">
7856///
7857/// **Experimental.** This type is part of an experimental wire-protocol surface
7858/// and may change or be removed in future SDK or CLI releases.
7859///
7860/// </div>
7861#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7862#[serde(rename_all = "camelCase")]
7863pub struct SessionCanvasRecordedData {
7864 /// Provider-local canvas identifier
7865 pub canvas_id: String,
7866 /// Owning provider identifier
7867 pub extension_id: String,
7868 /// Input supplied when the instance was opened
7869 #[serde(skip_serializing_if = "Option::is_none")]
7870 pub input: Option<serde_json::Value>,
7871 /// Stable caller-supplied canvas instance identifier
7872 pub instance_id: String,
7873 /// Rendered title
7874 #[serde(skip_serializing_if = "Option::is_none")]
7875 pub title: Option<String>,
7876}
7877
7878/// Session event "session.canvas.removed". Durable record that a canvas instance was closed, superseding a prior instance_recorded during resume replay.
7879///
7880/// <div class="warning">
7881///
7882/// **Experimental.** This type is part of an experimental wire-protocol surface
7883/// and may change or be removed in future SDK or CLI releases.
7884///
7885/// </div>
7886#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7887#[serde(rename_all = "camelCase")]
7888pub struct SessionCanvasRemovedData {
7889 /// Provider-local canvas identifier
7890 pub canvas_id: String,
7891 /// Owning provider identifier
7892 pub extension_id: String,
7893 /// Stable caller-supplied identifier of the canvas instance that was closed
7894 pub instance_id: String,
7895}
7896
7897/// Session event "session.extensions.attachments_pushed". Payload of `session.extensions.attachments_pushed` with extension-contributed attachments for the next send.
7898#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7899#[serde(rename_all = "camelCase")]
7900pub struct SessionExtensionsAttachmentsPushedData {
7901 /// Attachments contributed by an extension; the host should surface these as composer pills and forward them via the next session.send call.
7902 pub attachments: Vec<serde_json::Value>,
7903}
7904
7905/// Set when the underlying tools/call threw an error before returning a CallToolResult
7906#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7907#[serde(rename_all = "camelCase")]
7908pub struct McpAppToolCallCompleteError {
7909 /// Human-readable error message
7910 pub message: String,
7911}
7912
7913/// MCP App tool `_meta.ui` resource URI and SEP-1865 visibility captured with an `mcp_app.tool_call_complete` result.
7914#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7915#[serde(rename_all = "camelCase")]
7916pub struct McpAppToolCallCompleteToolMetaUI {
7917 /// `ui://` URI declared by the tool's `_meta.ui.resourceUri`
7918 #[serde(skip_serializing_if = "Option::is_none")]
7919 pub resource_uri: Option<String>,
7920 /// Tool visibility per SEP-1865 (typically a subset of `["model","app"]`)
7921 #[serde(skip_serializing_if = "Option::is_none")]
7922 pub visibility: Option<Vec<String>>,
7923}
7924
7925/// The tool's `_meta.ui` block at the time of the call, so consumers can decide whether to forward the result to the model without re-listing tools.
7926#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7927#[serde(rename_all = "camelCase")]
7928pub struct McpAppToolCallCompleteToolMeta {
7929 /// MCP App tool `_meta.ui` resource URI and SEP-1865 visibility captured with an `mcp_app.tool_call_complete` result.
7930 #[serde(skip_serializing_if = "Option::is_none")]
7931 pub ui: Option<McpAppToolCallCompleteToolMetaUI>,
7932}
7933
7934/// Session event "mcp_app.tool_call_complete". MCP App view called a tool on a connected MCP server (SEP-1865)
7935#[derive(Debug, Clone, Default, Serialize, Deserialize)]
7936#[serde(rename_all = "camelCase")]
7937pub struct McpAppToolCallCompleteData {
7938 /// Arguments passed to the tool by the app view, if any
7939 #[serde(skip_serializing_if = "Option::is_none")]
7940 pub arguments: Option<HashMap<String, serde_json::Value>>,
7941 /// Wall-clock duration of the underlying tools/call in milliseconds
7942 pub duration_ms: f64,
7943 /// Set when the underlying tools/call threw an error before returning a CallToolResult
7944 #[serde(skip_serializing_if = "Option::is_none")]
7945 pub error: Option<McpAppToolCallCompleteError>,
7946 /// Standard MCP CallToolResult returned by the server. Present whether or not the call set isError.
7947 #[serde(skip_serializing_if = "Option::is_none")]
7948 pub result: Option<HashMap<String, serde_json::Value>>,
7949 /// Name of the MCP server hosting the tool
7950 pub server_name: String,
7951 /// True when the call completed without throwing AND the MCP CallToolResult did not set isError
7952 pub success: bool,
7953 /// The tool's `_meta.ui` block at the time of the call, so consumers can decide whether to forward the result to the model without re-listing tools.
7954 #[serde(skip_serializing_if = "Option::is_none")]
7955 pub tool_meta: Option<McpAppToolCallCompleteToolMeta>,
7956 /// MCP tool name that was invoked
7957 pub tool_name: String,
7958}
7959
7960/// Session event "session.indexed_search". Transient indexed-search status and diagnostics from the live runtime service. Never persisted or used to infer activation from session history.
7961pub type SessionIndexedSearchData = IndexedSearchData;
7962
7963/// Routing preference used when the session model is `auto`. `fast` is an integrator-only latency preset and is not a first-party GitHub Copilot product preference.
7964#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
7965pub enum AutoTier {
7966 /// Optimize for efficiency.
7967 #[serde(rename = "efficiency")]
7968 Efficiency,
7969 /// Balance efficiency and intelligence.
7970 #[serde(rename = "balance")]
7971 Balance,
7972 /// Optimize for intelligence.
7973 #[serde(rename = "intelligence")]
7974 Intelligence,
7975 /// Integrator-only preset that optimizes for latency.
7976 #[serde(rename = "fast")]
7977 Fast,
7978 /// Unknown variant for forward compatibility.
7979 #[default]
7980 #[serde(other)]
7981 Unknown,
7982}
7983
7984/// Hosting platform type of the repository (github or ado)
7985#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
7986pub enum WorkingDirectoryContextHostType {
7987 /// Repository is hosted on GitHub.
7988 #[serde(rename = "github")]
7989 GitHub,
7990 /// Repository is hosted on Azure DevOps.
7991 #[serde(rename = "ado")]
7992 Ado,
7993 /// Unknown variant for forward compatibility.
7994 #[default]
7995 #[serde(other)]
7996 Unknown,
7997}
7998
7999/// Allowed values for the `ContextTier` enumeration.
8000#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8001pub enum ContextTier {
8002 /// Default context tier with standard context window size.
8003 #[serde(rename = "default")]
8004 Default,
8005 /// Extended context tier with a larger context window.
8006 #[serde(rename = "long_context")]
8007 LongContext,
8008 /// Unknown variant for forward compatibility.
8009 #[default]
8010 #[serde(other)]
8011 Unknown,
8012}
8013
8014/// Reasoning summary mode used for model calls, if applicable (e.g. "none", "concise", "detailed")
8015#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8016pub enum ReasoningSummary {
8017 /// Do not request reasoning summaries from the model.
8018 #[serde(rename = "none")]
8019 None,
8020 /// Request a concise summary of the model's reasoning.
8021 #[serde(rename = "concise")]
8022 Concise,
8023 /// Request a detailed summary of the model's reasoning.
8024 #[serde(rename = "detailed")]
8025 Detailed,
8026 /// Unknown variant for forward compatibility.
8027 #[default]
8028 #[serde(other)]
8029 Unknown,
8030}
8031
8032/// Output verbosity level used for supported model calls (e.g. "low", "medium", "high")
8033#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8034pub enum Verbosity {
8035 /// A terse response was requested.
8036 #[serde(rename = "low")]
8037 Low,
8038 /// A medium amount of response detail was requested.
8039 #[serde(rename = "medium")]
8040 Medium,
8041 /// A more detailed response was requested.
8042 #[serde(rename = "high")]
8043 High,
8044 /// Unknown variant for forward compatibility.
8045 #[default]
8046 #[serde(other)]
8047 Unknown,
8048}
8049
8050/// What the user must do to recover from a failure, named as an action rather than as one client's affordance. The runtime cannot know which affordance a client offers — a slash command, a settings pane, a link — so the accompanying message stays host-agnostic and each client renders its own copy from this value. Absent when the runtime knows of no action the user can take.
8051#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8052pub enum RemediationAction {
8053 /// Authenticate again with the Copilot backend. The current credential is absent, expired, or rejected.
8054 #[serde(rename = "sign_in")]
8055 SignIn,
8056 /// Authenticate as a different account. The current account exists but lacks access to the requested resource.
8057 #[serde(rename = "switch_account")]
8058 SwitchAccount,
8059 /// Inspect which account is currently authenticated before deciding what to change.
8060 #[serde(rename = "show_account")]
8061 ShowAccount,
8062 /// Review or widen the sandbox policy. The blocked path or host is named by the accompanying message or by the tool result the action arrived with.
8063 #[serde(rename = "review_sandbox_policy")]
8064 ReviewSandboxPolicy,
8065 /// Permit outbound network access in the sandbox policy.
8066 #[serde(rename = "allow_sandbox_outbound")]
8067 AllowSandboxOutbound,
8068 /// Unknown variant for forward compatibility.
8069 #[default]
8070 #[serde(other)]
8071 Unknown,
8072}
8073
8074/// The session mode the agent is operating in
8075#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8076pub enum SessionMode {
8077 /// The agent is responding interactively to the user.
8078 #[serde(rename = "interactive")]
8079 Interactive,
8080 /// The agent is preparing a plan before making changes.
8081 #[serde(rename = "plan")]
8082 Plan,
8083 /// The agent is working autonomously toward task completion.
8084 #[serde(rename = "autopilot")]
8085 Autopilot,
8086 /// Unknown variant for forward compatibility.
8087 #[default]
8088 #[serde(other)]
8089 Unknown,
8090}
8091
8092/// Who created the schedule: `user` (an explicit user action such as `/every` or `/after`) or `model` (the agent via the `manage_schedule` tool). Gates whether a scheduled skill that opted out of model invocation may fire: only user-created schedules may.
8093#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8094pub enum ScheduleOrigin {
8095 /// The schedule was created by an explicit user action, such as `/every` or `/after`.
8096 #[serde(rename = "user")]
8097 User,
8098 /// The schedule was created by the agent via the `manage_schedule` tool.
8099 #[serde(rename = "model")]
8100 Model,
8101 /// Unknown variant for forward compatibility.
8102 #[default]
8103 #[serde(other)]
8104 Unknown,
8105}
8106
8107/// The type of operation performed on the autopilot objective state file
8108#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8109pub enum AutopilotObjectiveChangedOperation {
8110 /// Autopilot objective state file was created for a new objective.
8111 #[serde(rename = "create")]
8112 Create,
8113 /// Autopilot objective state file was updated for an existing objective.
8114 #[serde(rename = "update")]
8115 Update,
8116 /// Autopilot objective state file was deleted or cleared.
8117 #[serde(rename = "delete")]
8118 Delete,
8119 /// Unknown variant for forward compatibility.
8120 #[default]
8121 #[serde(other)]
8122 Unknown,
8123}
8124
8125/// Current autopilot objective status, if one exists
8126#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8127pub enum AutopilotObjectiveChangedStatus {
8128 /// Objective is active and can drive autopilot continuations.
8129 #[serde(rename = "active")]
8130 Active,
8131 /// Objective is paused and will not drive autopilot continuations.
8132 #[serde(rename = "paused")]
8133 Paused,
8134 /// Legacy objective state indicating the previous continuation cap was reached.
8135 #[serde(rename = "cap_reached")]
8136 CapReached,
8137 /// Objective was completed by the agent.
8138 #[serde(rename = "completed")]
8139 Completed,
8140 /// Unknown variant for forward compatibility.
8141 #[default]
8142 #[serde(other)]
8143 Unknown,
8144}
8145
8146/// Indexed-search event variant discriminator.
8147#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8148pub enum IndexedSearchDataStatusKind {
8149 #[serde(rename = "status")]
8150 #[default]
8151 Status,
8152}
8153
8154/// Live indexed-search state for this session activation, never inferred from persisted history.
8155#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8156pub enum IndexedSearchState {
8157 /// Indexed search is not active for this session.
8158 #[serde(rename = "disabled")]
8159 Disabled,
8160 /// Indexed-search startup is in progress.
8161 #[serde(rename = "starting")]
8162 Starting,
8163 /// The indexed-search server started successfully; its index may still be warming.
8164 #[serde(rename = "enabled")]
8165 Enabled,
8166 /// The indexed-search server and its index are ready.
8167 #[serde(rename = "ready")]
8168 Ready,
8169 /// Indexed-search startup or the active server failed.
8170 #[serde(rename = "failed")]
8171 Failed,
8172 /// Unknown variant for forward compatibility.
8173 #[default]
8174 #[serde(other)]
8175 Unknown,
8176}
8177
8178/// Configuration, policy, or workspace condition that disabled indexed search.
8179#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8180pub enum IndexedSearchDisabledReason {
8181 /// Indexed search was explicitly disabled by the environment.
8182 #[serde(rename = "use_tgrep_false")]
8183 UseTgrepFalse,
8184 /// Search uses the external ripgrep binary instead of bundled search.
8185 #[serde(rename = "use_builtin_ripgrep_false")]
8186 UseBuiltinRipgrepFalse,
8187 /// Organization policy disables indexed search.
8188 #[serde(rename = "organization")]
8189 Organization,
8190 /// Authentication has not resolved organization policy.
8191 #[serde(rename = "organization_policy_auth_pending")]
8192 OrganizationPolicyAuthPending,
8193 /// Organization policy could not be determined.
8194 #[serde(rename = "organization_policy_unknown")]
8195 OrganizationPolicyUnknown,
8196 /// The workspace uses a virtualized or network filesystem.
8197 #[serde(rename = "virtual_filesystem")]
8198 VirtualFilesystem,
8199 /// The workspace is inside a Windows cloud-sync root.
8200 #[serde(rename = "cloud_sync_root")]
8201 CloudSyncRoot,
8202 /// The Windows cloud-sync safety check failed.
8203 #[serde(rename = "cloud_sync_detection_failed")]
8204 CloudSyncDetectionFailed,
8205 /// The workspace is not available on the runtime's local filesystem.
8206 #[serde(rename = "workspace_not_local")]
8207 WorkspaceNotLocal,
8208 /// Unknown variant for forward compatibility.
8209 #[default]
8210 #[serde(other)]
8211 Unknown,
8212}
8213
8214/// Indexed-search event variant discriminator.
8215#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8216pub enum IndexedSearchDataStartupKind {
8217 #[serde(rename = "startup")]
8218 #[default]
8219 Startup,
8220}
8221
8222/// Result of an indexed-search startup attempt.
8223#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8224pub enum IndexedSearchOutcome {
8225 /// A new indexed-search server was started.
8226 #[serde(rename = "started")]
8227 Started,
8228 /// The repository has too few files for automatic indexing.
8229 #[serde(rename = "skipped_below_threshold")]
8230 SkippedBelowThreshold,
8231 /// No Git repository was found and indexing was not forced.
8232 #[serde(rename = "skipped_no_gitroot")]
8233 SkippedNoGitroot,
8234 /// Configuration, policy, or workspace safety disabled indexing.
8235 #[serde(rename = "skipped_disabled")]
8236 SkippedDisabled,
8237 /// An existing indexed-search server was reused.
8238 #[serde(rename = "reused_existing")]
8239 ReusedExisting,
8240 /// The startup attempt failed.
8241 #[serde(rename = "failed")]
8242 Failed,
8243 /// Unknown variant for forward compatibility.
8244 #[default]
8245 #[serde(other)]
8246 Unknown,
8247}
8248
8249/// Category of an indexed-search server failure.
8250#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8251pub enum IndexedSearchErrorType {
8252 /// The indexed-search server could not be spawned.
8253 #[serde(rename = "spawn_error")]
8254 SpawnError,
8255 /// The indexed-search server exited unexpectedly.
8256 #[serde(rename = "unexpected_exit")]
8257 UnexpectedExit,
8258 /// The indexed-search server was terminated by a signal.
8259 #[serde(rename = "killed_by_signal")]
8260 KilledBySignal,
8261 /// Unknown variant for forward compatibility.
8262 #[default]
8263 #[serde(other)]
8264 Unknown,
8265}
8266
8267/// Indexed-search event variant discriminator.
8268#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8269pub enum IndexedSearchDataServerErrorKind {
8270 #[serde(rename = "server_error")]
8271 #[default]
8272 ServerError,
8273}
8274
8275/// Indexed-search event variant discriminator.
8276#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8277pub enum IndexedSearchDataIncrementalKind {
8278 #[serde(rename = "incremental")]
8279 #[default]
8280 Incremental,
8281}
8282
8283/// Phase of an incremental indexed-search update.
8284#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8285pub enum IndexedSearchIncrementalPhase {
8286 /// A workspace scan found changes to index.
8287 #[serde(rename = "changes_detected")]
8288 ChangesDetected,
8289 /// The incremental index update completed.
8290 #[serde(rename = "updated")]
8291 Updated,
8292 /// Unknown variant for forward compatibility.
8293 #[default]
8294 #[serde(other)]
8295 Unknown,
8296}
8297
8298/// Transient indexed-search status and diagnostics from the live runtime service. Never persisted or used to infer activation from session history.
8299#[derive(Debug, Clone, Serialize, Deserialize)]
8300#[serde(untagged)]
8301pub enum IndexedSearchData {
8302 Status(IndexedSearchDataStatus),
8303 Startup(IndexedSearchDataStartup),
8304 ServerError(IndexedSearchDataServerError),
8305 Incremental(IndexedSearchDataIncremental),
8306}
8307
8308/// Origin of an effective session model change.
8309#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8310pub enum ModelChangeSource {
8311 /// The user selected a model directly with `/model <id>`.
8312 #[serde(rename = "model_command")]
8313 ModelCommand,
8314 /// The user selected the model with `/settings`.
8315 #[serde(rename = "settings_command")]
8316 SettingsCommand,
8317 /// The user selected the model with the `/config` alias.
8318 #[serde(rename = "config_command")]
8319 ConfigCommand,
8320 /// The user selected the model in the model picker, including the picker opened by bare `/model`.
8321 #[serde(rename = "model_picker")]
8322 ModelPicker,
8323 /// Organization-managed settings selected the model.
8324 #[serde(rename = "managed_settings")]
8325 ManagedSettings,
8326 /// Repository settings selected the model.
8327 #[serde(rename = "repo_settings")]
8328 RepoSettings,
8329 /// Startup model resolution selected the model.
8330 #[serde(rename = "startup")]
8331 Startup,
8332 /// Selecting an agent selected its configured model.
8333 #[serde(rename = "agent")]
8334 Agent,
8335 /// Entering, leaving, or reconfiguring plan mode selected the model.
8336 #[serde(rename = "plan_mode")]
8337 PlanMode,
8338 /// The runtime selected the model automatically, such as rate-limit recovery or refusal fallback.
8339 #[serde(rename = "automatic")]
8340 Automatic,
8341 /// The user selected the promoted model from the changeboarding card or its keyboard shortcut.
8342 #[serde(rename = "changeboarding_shortcut")]
8343 ChangeboardingShortcut,
8344 /// An SDK or RPC caller selected the model.
8345 #[serde(rename = "sdk")]
8346 Sdk,
8347 /// The user accepted a CAPI-issued Auto tier recommendation.
8348 #[serde(rename = "auto_tier_recommendation")]
8349 AutoTierRecommendation,
8350 /// Unknown variant for forward compatibility.
8351 #[default]
8352 #[serde(other)]
8353 Unknown,
8354}
8355
8356/// Why the session no longer has an explicitly selected model.
8357#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8358pub enum ModelDeselectedReason {
8359 /// A host-managed provider snapshot no longer publishes the selected model.
8360 #[serde(rename = "provider_withdrawn")]
8361 ProviderWithdrawn,
8362 /// Unknown variant for forward compatibility.
8363 #[default]
8364 #[serde(other)]
8365 Unknown,
8366}
8367
8368/// Auto preferences that Copilot API can recommend.
8369#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8370pub enum RecommendedAutoTier {
8371 /// Optimize for efficiency.
8372 #[serde(rename = "efficiency")]
8373 Efficiency,
8374 /// Balance efficiency and intelligence.
8375 #[serde(rename = "balance")]
8376 Balance,
8377 /// Optimize for intelligence.
8378 #[serde(rename = "intelligence")]
8379 Intelligence,
8380 /// Unknown variant for forward compatibility.
8381 #[default]
8382 #[serde(other)]
8383 Unknown,
8384}
8385
8386/// Terminal reason an Auto preference activation failed.
8387#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8388pub enum AutoTierSwitchFailureReason {
8389 /// The candidate model was rejected by model policy.
8390 #[serde(rename = "policy_rejected")]
8391 PolicyRejected,
8392 /// The Auto routing request failed or returned an unusable response.
8393 #[serde(rename = "request_failed")]
8394 RequestFailed,
8395 /// The runtime could not prepare the Auto routing request.
8396 #[serde(rename = "setup_failed")]
8397 SetupFailed,
8398 /// The provider does not support Auto routing.
8399 #[serde(rename = "unsupported")]
8400 Unsupported,
8401 /// Unknown variant for forward compatibility.
8402 #[default]
8403 #[serde(other)]
8404 Unknown,
8405}
8406
8407/// Permission mode for the session.
8408///
8409/// <div class="warning">
8410///
8411/// **Experimental.** This type is part of an experimental wire-protocol surface
8412/// and may change or be removed in future SDK or CLI releases.
8413///
8414/// </div>
8415#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8416pub enum PermissionMode {
8417 /// Permission requests follow the normal approval flow.
8418 #[serde(rename = "manual")]
8419 Manual,
8420 /// Permission requests include an LLM safety recommendation; clients may automatically approve requests judged acceptable.
8421 #[serde(rename = "assisted")]
8422 Assisted,
8423 /// Tool, path, and URL permission requests are automatically approved.
8424 #[serde(rename = "allow-all")]
8425 AllowAll,
8426 /// Unknown variant for forward compatibility.
8427 #[default]
8428 #[serde(other)]
8429 Unknown,
8430}
8431
8432/// The type of operation performed on the plan file
8433#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8434pub enum PlanChangedOperation {
8435 /// The plan file was created.
8436 #[serde(rename = "create")]
8437 Create,
8438 /// The plan file was updated.
8439 #[serde(rename = "update")]
8440 Update,
8441 /// The plan file was deleted.
8442 #[serde(rename = "delete")]
8443 Delete,
8444 /// Unknown variant for forward compatibility.
8445 #[default]
8446 #[serde(other)]
8447 Unknown,
8448}
8449
8450/// Whether the file was newly created or updated
8451#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8452pub enum WorkspaceFileChangedOperation {
8453 /// The workspace file was created.
8454 #[serde(rename = "create")]
8455 Create,
8456 /// The workspace file was updated.
8457 #[serde(rename = "update")]
8458 Update,
8459 /// Unknown variant for forward compatibility.
8460 #[default]
8461 #[serde(other)]
8462 Unknown,
8463}
8464
8465/// Origin type of the session being handed off
8466#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8467pub enum HandoffSourceType {
8468 /// The handoff originated from a remote session.
8469 #[serde(rename = "remote")]
8470 Remote,
8471 /// The handoff originated from a local session.
8472 #[serde(rename = "local")]
8473 Local,
8474 /// Unknown variant for forward compatibility.
8475 #[default]
8476 #[serde(other)]
8477 Unknown,
8478}
8479
8480/// Whether the session ended normally ("routine") or due to a crash/fatal error ("error")
8481#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8482pub enum ShutdownType {
8483 /// The session ended normally.
8484 #[serde(rename = "routine")]
8485 Routine,
8486 /// The session ended because of a crash or fatal error.
8487 #[serde(rename = "error")]
8488 Error,
8489 /// Unknown variant for forward compatibility.
8490 #[default]
8491 #[serde(other)]
8492 Unknown,
8493}
8494
8495/// What initiated a conversation compaction
8496#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8497pub enum CompactionTrigger {
8498 /// Background compaction started automatically because context utilization crossed the background threshold.
8499 #[serde(rename = "threshold")]
8500 Threshold,
8501 /// Compaction forced by a context-limit model response (e.g. HTTP 413) before retrying the request.
8502 #[serde(rename = "context_limit_retry")]
8503 ContextLimitRetry,
8504 /// User-requested compaction, e.g. the /compact command or the history.compact API.
8505 #[serde(rename = "manual")]
8506 Manual,
8507 /// Emergency compaction triggered by high process memory usage.
8508 #[serde(rename = "memory_pressure")]
8509 MemoryPressure,
8510 /// Compaction requested while switching to a model with a smaller context window.
8511 #[serde(rename = "model_switch")]
8512 ModelSwitch,
8513 /// Unknown variant for forward compatibility.
8514 #[default]
8515 #[serde(other)]
8516 Unknown,
8517}
8518
8519/// Category of structured task blocker
8520#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8521pub enum TaskBlockerKind {
8522 /// Autopilot permission recovery requires intervention or has no safe autonomous path.
8523 #[serde(rename = "permission_recovery")]
8524 PermissionRecovery,
8525 /// Unknown variant for forward compatibility.
8526 #[default]
8527 #[serde(other)]
8528 Unknown,
8529}
8530
8531/// Runtime handling applied to a recovery attempt
8532#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8533pub enum PermissionRecoveryAttemptDisposition {
8534 /// The request was denied without prompting so the agent could try an alternative.
8535 #[serde(rename = "deferred")]
8536 Deferred,
8537 /// The request was surfaced to an interactive responder.
8538 #[serde(rename = "prompted")]
8539 Prompted,
8540 /// The interactive responder approved the request.
8541 #[serde(rename = "approved")]
8542 Approved,
8543 /// The interactive responder denied the request or became unavailable.
8544 #[serde(rename = "denied")]
8545 Denied,
8546 /// The request exhausted unattended recovery and produced a blocked outcome.
8547 #[serde(rename = "blocked")]
8548 Blocked,
8549 /// A tool call succeeded as an equivalent alternative.
8550 #[serde(rename = "succeeded")]
8551 Succeeded,
8552 /// Unknown variant for forward compatibility.
8553 #[default]
8554 #[serde(other)]
8555 Unknown,
8556}
8557
8558/// Controlled reason for an individual attempt disposition
8559#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8560pub enum PermissionRecoveryAttemptReason {
8561 /// The attempt required permission that Assisted Permissions could not grant.
8562 #[serde(rename = "permission_required")]
8563 PermissionRequired,
8564 /// The request repeated an earlier attempt.
8565 #[serde(rename = "repeated_attempt")]
8566 RepeatedAttempt,
8567 /// The request exceeded the bounded number of distinct attempts.
8568 #[serde(rename = "attempts_exhausted")]
8569 AttemptsExhausted,
8570 /// The interactive responder approved the request.
8571 #[serde(rename = "permission_approved")]
8572 PermissionApproved,
8573 /// The interactive responder denied the request.
8574 #[serde(rename = "permission_denied")]
8575 PermissionDenied,
8576 /// The interactive responder became unavailable.
8577 #[serde(rename = "responder_unavailable")]
8578 ResponderUnavailable,
8579 /// The tool call succeeded without the blocked permission.
8580 #[serde(rename = "equivalent_alternative_succeeded")]
8581 EquivalentAlternativeSucceeded,
8582 /// Unknown variant for forward compatibility.
8583 #[default]
8584 #[serde(other)]
8585 Unknown,
8586}
8587
8588/// Relationship of an attempt to earlier permission requests
8589#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8590pub enum PermissionRecoveryAttemptRelation {
8591 /// The first denied permission request in the episode.
8592 #[serde(rename = "initial")]
8593 Initial,
8594 /// A request equivalent to an earlier attempt.
8595 #[serde(rename = "retry")]
8596 Retry,
8597 /// A distinct request or a successful alternative tool call.
8598 #[serde(rename = "alternative")]
8599 Alternative,
8600 /// Unknown variant for forward compatibility.
8601 #[default]
8602 #[serde(other)]
8603 Unknown,
8604}
8605
8606/// Action selected when autonomous recovery cannot continue
8607#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8608pub enum PermissionRecoveryOnBlocked {
8609 /// Surface the existing permission prompt to a response-capable client.
8610 #[serde(rename = "ask")]
8611 Ask,
8612 /// Return a structured unsuccessful blocked outcome because no responder is available.
8613 #[serde(rename = "fail")]
8614 Fail,
8615 /// Unknown variant for forward compatibility.
8616 #[default]
8617 #[serde(other)]
8618 Unknown,
8619}
8620
8621/// Controlled reason for a permission-recovery episode transition
8622#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8623pub enum PermissionRecoveryReason {
8624 /// An action required permission that Assisted Permissions could not grant.
8625 #[serde(rename = "permission_required")]
8626 PermissionRequired,
8627 /// The agent repeated an equivalent permission request instead of making progress.
8628 #[serde(rename = "repeated_attempt")]
8629 RepeatedAttempt,
8630 /// The bounded number of distinct permission attempts was exhausted.
8631 #[serde(rename = "attempts_exhausted")]
8632 AttemptsExhausted,
8633 /// A responder approved the escalated permission request.
8634 #[serde(rename = "permission_approved")]
8635 PermissionApproved,
8636 /// A responder denied the escalated permission request.
8637 #[serde(rename = "permission_denied")]
8638 PermissionDenied,
8639 /// The response-capable client became unavailable while escalation was pending.
8640 #[serde(rename = "responder_unavailable")]
8641 ResponderUnavailable,
8642 /// A later tool call succeeded without requiring the blocked permission.
8643 #[serde(rename = "equivalent_alternative_succeeded")]
8644 EquivalentAlternativeSucceeded,
8645 /// Unknown variant for forward compatibility.
8646 #[default]
8647 #[serde(other)]
8648 Unknown,
8649}
8650
8651/// Lifecycle state of a permission-recovery episode
8652#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8653pub enum PermissionRecoveryStatus {
8654 /// Autopilot may try a bounded equivalent alternative.
8655 #[serde(rename = "recovering")]
8656 Recovering,
8657 /// An interactive permission response is required.
8658 #[serde(rename = "awaiting_approval")]
8659 AwaitingApproval,
8660 /// The episode ended through approval or a successful equivalent alternative.
8661 #[serde(rename = "resolved")]
8662 Resolved,
8663 /// No autonomous path remains and the task requires intervention.
8664 #[serde(rename = "blocked")]
8665 Blocked,
8666 /// Unknown variant for forward compatibility.
8667 #[default]
8668 #[serde(other)]
8669 Unknown,
8670}
8671
8672/// Semantic result of evaluating a task completion request
8673#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8674pub enum TaskCompletionOutcome {
8675 /// The completion request was accepted and the objective is complete.
8676 #[serde(rename = "completed")]
8677 Completed,
8678 /// The completion request was rejected because more work or validation remains.
8679 #[serde(rename = "continue")]
8680 Continue,
8681 /// Completion cannot proceed without intervention; the active objective is paused when one is identified.
8682 #[serde(rename = "blocked")]
8683 Blocked,
8684 /// Unknown variant for forward compatibility.
8685 #[default]
8686 #[serde(other)]
8687 Unknown,
8688}
8689
8690/// Structured terminal status from a tool completion event.
8691#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8692pub enum CompletionReceiptToolStatus {
8693 /// The tool completed successfully.
8694 #[serde(rename = "success")]
8695 Success,
8696 /// The tool failed without a more specific structured status.
8697 #[serde(rename = "failure")]
8698 Failure,
8699 /// The tool exceeded its time budget.
8700 #[serde(rename = "timeout")]
8701 Timeout,
8702 /// The user rejected the tool call.
8703 #[serde(rename = "rejected")]
8704 Rejected,
8705 /// The permissions service denied the tool call.
8706 #[serde(rename = "denied")]
8707 Denied,
8708 /// Unknown variant for forward compatibility.
8709 #[default]
8710 #[serde(other)]
8711 Unknown,
8712}
8713
8714/// Runtime reason the completion decision was accepted.
8715#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8716pub enum CompletionReceiptStopReason {
8717 /// The model reached a natural terminal response.
8718 #[serde(rename = "natural")]
8719 Natural,
8720 /// A terminal tool ended the interaction.
8721 #[serde(rename = "terminal_tool")]
8722 TerminalTool,
8723 /// The configured agentStop continuation limit was reached.
8724 #[serde(rename = "agent_stop_block_limit")]
8725 AgentStopBlockLimit,
8726 /// Unknown variant for forward compatibility.
8727 #[default]
8728 #[serde(other)]
8729 Unknown,
8730}
8731
8732/// Kind of turn for which HydraFusion routing is running.
8733///
8734/// <div class="warning">
8735///
8736/// **Experimental.** This type is part of an experimental wire-protocol surface
8737/// and may change or be removed in future SDK or CLI releases.
8738///
8739/// </div>
8740#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8741pub enum FusionTurnKind {
8742 /// A user-message turn.
8743 #[serde(rename = "user")]
8744 User,
8745 /// A conversation-compaction turn.
8746 #[serde(rename = "compaction")]
8747 Compaction,
8748 /// Unknown variant for forward compatibility.
8749 #[default]
8750 #[serde(other)]
8751 Unknown,
8752}
8753
8754/// Server-recommended routing behavior for a later HydraFusion turn.
8755///
8756/// <div class="warning">
8757///
8758/// **Experimental.** This type is part of an experimental wire-protocol surface
8759/// and may change or be removed in future SDK or CLI releases.
8760///
8761/// </div>
8762#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8763pub enum FusionFollowUpAction {
8764 /// Reuse the durable primary model without routing.
8765 #[serde(rename = "reuse_primary")]
8766 ReusePrimary,
8767 /// Request a new routing decision.
8768 #[serde(rename = "reroute")]
8769 Reroute,
8770 /// Unknown variant for forward compatibility.
8771 #[default]
8772 #[serde(other)]
8773 Unknown,
8774}
8775
8776/// Validated HydraFusion execution pattern.
8777///
8778/// <div class="warning">
8779///
8780/// **Experimental.** This type is part of an experimental wire-protocol surface
8781/// and may change or be removed in future SDK or CLI releases.
8782///
8783/// </div>
8784#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8785pub enum FusionPattern {
8786 /// Run one primary solver phase.
8787 #[serde(rename = "single")]
8788 Single,
8789 /// Run a primary phase, a judge, and an optional repair.
8790 #[serde(rename = "cascade")]
8791 Cascade,
8792 /// Run a primary draft, a read-only critique, and a revision.
8793 #[serde(rename = "critique")]
8794 Critique,
8795 /// Unknown variant for forward compatibility.
8796 #[default]
8797 #[serde(other)]
8798 Unknown,
8799}
8800
8801/// HydraFusion phase kind.
8802///
8803/// <div class="warning">
8804///
8805/// **Experimental.** This type is part of an experimental wire-protocol surface
8806/// and may change or be removed in future SDK or CLI releases.
8807///
8808/// </div>
8809#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8810pub enum FusionPhaseKind {
8811 /// Primary solver phase.
8812 #[serde(rename = "primary")]
8813 Primary,
8814 /// Read-only cascade judge phase.
8815 #[serde(rename = "judge")]
8816 Judge,
8817 /// Cascade repair phase.
8818 #[serde(rename = "repair")]
8819 Repair,
8820 /// Initial critique-pattern draft phase.
8821 #[serde(rename = "draft")]
8822 Draft,
8823 /// Read-only critique phase.
8824 #[serde(rename = "critic")]
8825 Critic,
8826 /// Critique-pattern revision phase.
8827 #[serde(rename = "revision")]
8828 Revision,
8829 /// Follow-up phase continuing from the resolved model.
8830 #[serde(rename = "follow_up")]
8831 FollowUp,
8832 /// Unknown variant for forward compatibility.
8833 #[default]
8834 #[serde(other)]
8835 Unknown,
8836}
8837
8838/// Conversation scope in which a HydraFusion phase executes.
8839///
8840/// <div class="warning">
8841///
8842/// **Experimental.** This type is part of an experimental wire-protocol surface
8843/// and may change or be removed in future SDK or CLI releases.
8844///
8845/// </div>
8846#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8847pub enum FusionConversationScope {
8848 /// Canonical root conversation history.
8849 #[serde(rename = "root")]
8850 Root,
8851 /// Isolated read-only review history that does not enter the root conversation.
8852 #[serde(rename = "review")]
8853 Review,
8854 /// Unknown variant for forward compatibility.
8855 #[default]
8856 #[serde(other)]
8857 Unknown,
8858}
8859
8860/// The agent mode that was active when this message was sent
8861#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8862pub enum UserMessageAgentMode {
8863 /// The agent is responding interactively to the user.
8864 #[serde(rename = "interactive")]
8865 Interactive,
8866 /// The agent is preparing a plan before making changes.
8867 #[serde(rename = "plan")]
8868 Plan,
8869 /// The agent is working autonomously toward task completion.
8870 #[serde(rename = "autopilot")]
8871 Autopilot,
8872 /// The agent is in shell-focused UI mode.
8873 #[serde(rename = "shell")]
8874 Shell,
8875 /// Unknown variant for forward compatibility.
8876 #[default]
8877 #[serde(other)]
8878 Unknown,
8879}
8880
8881/// How this user message was delivered to the agentic loop, relative to whether the loop was already running. This is the timing axis only; the message's origin (human vs. system/command/schedule/skill/etc.) is carried separately by `source`. A system-injected message has a delivery too — e.g. a background-task notification waking an idle agent is `idle`, the same mechanism as a human starting a fresh turn.
8882#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8883pub enum UserMessageDelivery {
8884 /// Delivered while the loop was idle; starts its own run immediately (a human's fresh turn, or a system notification waking an idle agent).
8885 #[serde(rename = "idle")]
8886 Idle,
8887 /// Injected into the current in-flight run while the agent was busy (immediate mode).
8888 #[serde(rename = "steering")]
8889 Steering,
8890 /// Enqueued while the agent was busy; processed as its own run afterward.
8891 #[serde(rename = "queued")]
8892 Queued,
8893 /// Unknown variant for forward compatibility.
8894 #[default]
8895 #[serde(other)]
8896 Unknown,
8897}
8898
8899/// What the agent was doing when the user interrupted it.
8900#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8901pub enum AgentInterruptedActivity {
8902 /// A request to the model was open.
8903 #[serde(rename = "model_call")]
8904 ModelCall,
8905 /// The turn was sleeping between retry attempts.
8906 #[serde(rename = "retry_backoff")]
8907 RetryBackoff,
8908 /// One or more tools were executing.
8909 #[serde(rename = "tool_call")]
8910 ToolCall,
8911 /// Background sub-agents were running while the main loop was idle.
8912 #[serde(rename = "background_agent")]
8913 BackgroundAgent,
8914 /// Unknown variant for forward compatibility.
8915 #[default]
8916 #[serde(other)]
8917 Unknown,
8918}
8919
8920/// Where the interruption landed relative to the first streamed token.
8921#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8922pub enum AgentInterruptedCancelPhase {
8923 /// No output had been produced when the request was cancelled.
8924 #[serde(rename = "pre_first_token")]
8925 PreFirstToken,
8926 /// The response was already streaming when the request was cancelled.
8927 #[serde(rename = "mid_stream")]
8928 MidStream,
8929 /// Unknown variant for forward compatibility.
8930 #[default]
8931 #[serde(other)]
8932 Unknown,
8933}
8934
8935/// Transport used for a failed model call
8936#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8937pub enum ModelCallFailureTransport {
8938 /// HTTP transport, including SSE streams.
8939 #[serde(rename = "http")]
8940 Http,
8941 /// WebSocket transport.
8942 #[serde(rename = "websocket")]
8943 Websocket,
8944 /// Unknown variant for forward compatibility.
8945 #[default]
8946 #[serde(other)]
8947 Unknown,
8948}
8949
8950/// Content-safe activity observed while a HydraFusion phase is running.
8951///
8952/// <div class="warning">
8953///
8954/// **Experimental.** This type is part of an experimental wire-protocol surface
8955/// and may change or be removed in future SDK or CLI releases.
8956///
8957/// </div>
8958#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8959pub enum FusionPhaseActivityKind {
8960 /// The provider produced additional private output bytes.
8961 #[serde(rename = "model_output")]
8962 ModelOutput,
8963 /// A tool began executing inside the phase.
8964 #[serde(rename = "tool_started")]
8965 ToolStarted,
8966 /// A tool finished executing inside the phase.
8967 #[serde(rename = "tool_completed")]
8968 ToolCompleted,
8969 /// Unknown variant for forward compatibility.
8970 #[default]
8971 #[serde(other)]
8972 Unknown,
8973}
8974
8975/// How a durable phase checkpoint contributes its exact message to canonical root history.
8976///
8977/// <div class="warning">
8978///
8979/// **Experimental.** This type is part of an experimental wire-protocol surface
8980/// and may change or be removed in future SDK or CLI releases.
8981///
8982/// </div>
8983#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
8984pub enum FusionProjectionMode {
8985 /// Append the exact root message immediately.
8986 #[serde(rename = "append")]
8987 Append,
8988 /// Hold a terminal message outside canonical history until the final commit selects it.
8989 #[serde(rename = "staged")]
8990 Staged,
8991 /// Do not project the checkpoint into root history.
8992 #[serde(rename = "none")]
8993 None,
8994 /// Unknown variant for forward compatibility.
8995 #[default]
8996 #[serde(other)]
8997 Unknown,
8998}
8999
9000/// Durable outcome status of a HydraFusion phase.
9001///
9002/// <div class="warning">
9003///
9004/// **Experimental.** This type is part of an experimental wire-protocol surface
9005/// and may change or be removed in future SDK or CLI releases.
9006///
9007/// </div>
9008#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9009pub enum FusionPhaseStatus {
9010 /// The phase completed successfully.
9011 #[serde(rename = "succeeded")]
9012 Succeeded,
9013 /// The phase failed.
9014 #[serde(rename = "failed")]
9015 Failed,
9016 /// The phase was cancelled.
9017 #[serde(rename = "cancelled")]
9018 Cancelled,
9019 /// Unknown variant for forward compatibility.
9020 #[default]
9021 #[serde(other)]
9022 Unknown,
9023}
9024
9025/// Tool call type: "function" for standard tool calls, "custom" for grammar-based tool calls. Defaults to "function" when absent.
9026#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9027pub enum AssistantMessageToolRequestType {
9028 /// Standard function-style tool call.
9029 #[serde(rename = "function")]
9030 Function,
9031 /// Custom grammar-based tool call.
9032 #[serde(rename = "custom")]
9033 Custom,
9034 /// Unknown variant for forward compatibility.
9035 #[default]
9036 #[serde(other)]
9037 Unknown,
9038}
9039
9040/// The system that produced a citation.
9041///
9042/// <div class="warning">
9043///
9044/// **Experimental.** This type is part of an experimental wire-protocol surface
9045/// and may change or be removed in future SDK or CLI releases.
9046///
9047/// </div>
9048#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9049pub enum CitationProvider {
9050 /// Citation produced by an Anthropic (Claude) model response.
9051 #[serde(rename = "anthropic")]
9052 Anthropic,
9053 /// Citation produced by an OpenAI model response.
9054 #[serde(rename = "openai")]
9055 Openai,
9056 /// Citation synthesized client-side by the runtime from tool output.
9057 #[serde(rename = "client")]
9058 Client,
9059 /// Unknown variant for forward compatibility.
9060 #[default]
9061 #[serde(other)]
9062 Unknown,
9063}
9064
9065/// Hosted program caller type
9066#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9067pub enum AssistantMessageToolRequestCallerType {
9068 #[serde(rename = "program")]
9069 Program,
9070 /// Unknown variant for forward compatibility.
9071 #[default]
9072 #[serde(other)]
9073 Unknown,
9074}
9075
9076/// API endpoint used for this model call, matching CAPI supported_endpoints vocabulary
9077#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9078pub enum AssistantUsageApiEndpoint {
9079 /// Chat Completions API endpoint.
9080 #[serde(rename = "/chat/completions")]
9081 ChatCompletions,
9082 /// Anthropic Messages API endpoint.
9083 #[serde(rename = "/v1/messages")]
9084 V1Messages,
9085 /// Responses API endpoint.
9086 #[serde(rename = "/responses")]
9087 Responses,
9088 /// WebSocket Responses API endpoint.
9089 #[serde(rename = "ws:/responses")]
9090 WsResponses,
9091 /// Unknown variant for forward compatibility.
9092 #[default]
9093 #[serde(other)]
9094 Unknown,
9095}
9096
9097/// Transport used for a successful model call
9098#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9099pub enum AssistantUsageTransport {
9100 /// HTTP transport, including SSE streams.
9101 #[serde(rename = "http")]
9102 Http,
9103 /// WebSocket transport.
9104 #[serde(rename = "websocket")]
9105 Websocket,
9106 /// Unknown variant for forward compatibility.
9107 #[default]
9108 #[serde(other)]
9109 Unknown,
9110}
9111
9112/// For HTTP 400 failures only: whether the response carried a structured CAPI error envelope (structured_error, a deterministic validation failure) or no error body (bodyless, the transient gateway/proxy signature). Absent for non-400 failures.
9113#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9114pub enum ModelCallFailureBadRequestKind {
9115 /// The 400 response carried no error body (transient gateway/proxy signature).
9116 #[serde(rename = "bodyless")]
9117 Bodyless,
9118 /// The 400 response carried a structured CAPI error envelope (deterministic validation failure).
9119 #[serde(rename = "structured_error")]
9120 StructuredError,
9121 /// Unknown variant for forward compatibility.
9122 #[default]
9123 #[serde(other)]
9124 Unknown,
9125}
9126
9127/// Boundary that produced a model call failure
9128#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9129pub enum ModelCallFailureKind {
9130 /// The provider returned an API error response.
9131 #[serde(rename = "api")]
9132 Api,
9133 /// The request transport failed before a usable API response completed.
9134 #[serde(rename = "transport")]
9135 Transport,
9136 /// Unknown variant for forward compatibility.
9137 #[default]
9138 #[serde(other)]
9139 Unknown,
9140}
9141
9142/// Where the failed model call originated
9143#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9144pub enum ModelCallFailureSource {
9145 /// Model call from the top-level agent.
9146 #[serde(rename = "top_level")]
9147 TopLevel,
9148 /// Model call from a sub-agent.
9149 #[serde(rename = "subagent")]
9150 Subagent,
9151 /// Model call from MCP sampling.
9152 #[serde(rename = "mcp_sampling")]
9153 McpSampling,
9154 /// Unknown variant for forward compatibility.
9155 #[default]
9156 #[serde(other)]
9157 Unknown,
9158}
9159
9160/// Final outcome of one logical model dispatch after response acceptance processing
9161#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9162pub enum ModelCallFinishedOutcome {
9163 /// The provider response was accepted for continued agent processing.
9164 #[serde(rename = "success")]
9165 Success,
9166 /// The dispatch ended with a provider or transport error.
9167 #[serde(rename = "error")]
9168 Error,
9169 /// The dispatch was cancelled before an accepted response was produced.
9170 #[serde(rename = "cancelled")]
9171 Cancelled,
9172 /// The provider response was rejected during post-response acceptance processing.
9173 #[serde(rename = "rejected")]
9174 Rejected,
9175 /// Unknown variant for forward compatibility.
9176 #[default]
9177 #[serde(other)]
9178 Unknown,
9179}
9180
9181/// Finite reason code describing why the current turn was aborted
9182#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9183pub enum AbortReason {
9184 /// The local user requested the abort, for example by pressing Ctrl+C in the CLI.
9185 #[serde(rename = "user_initiated")]
9186 UserInitiated,
9187 /// A remote command requested the abort.
9188 #[serde(rename = "remote_command")]
9189 RemoteCommand,
9190 /// An MCP server delivered a user.abort notification.
9191 #[serde(rename = "user_abort")]
9192 UserAbort,
9193 /// Autopilot stopped the run because the active objective reached its user-set --max-ai-credits limit.
9194 #[serde(rename = "autopilot_credit_limit")]
9195 AutopilotCreditLimit,
9196 /// Unknown variant for forward compatibility.
9197 #[default]
9198 #[serde(other)]
9199 Unknown,
9200}
9201
9202/// Configuration source: user, workspace, plugin, builtin, or managed
9203#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9204pub enum McpServerSource {
9205 /// Server configured in the user's global MCP configuration.
9206 #[serde(rename = "user")]
9207 User,
9208 /// Server configured by the current workspace.
9209 #[serde(rename = "workspace")]
9210 Workspace,
9211 /// Server contributed by an installed plugin.
9212 #[serde(rename = "plugin")]
9213 Plugin,
9214 /// Server bundled with the runtime.
9215 #[serde(rename = "builtin")]
9216 Builtin,
9217 /// Server supplied by a trusted host-managed catalog.
9218 #[serde(rename = "managed")]
9219 Managed,
9220 /// Unknown variant for forward compatibility.
9221 #[default]
9222 #[serde(other)]
9223 Unknown,
9224}
9225
9226/// Transport mechanism: stdio, http, sse (deprecated), or memory (in-process MCP server)
9227#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9228pub enum McpServerTransport {
9229 /// Server communicates over stdio with a local child process.
9230 #[serde(rename = "stdio")]
9231 Stdio,
9232 /// Server communicates over streamable HTTP.
9233 #[serde(rename = "http")]
9234 Http,
9235 /// Server communicates over Server-Sent Events (deprecated).
9236 #[serde(rename = "sse")]
9237 Sse,
9238 /// Server is backed by an in-memory runtime implementation.
9239 #[serde(rename = "memory")]
9240 Memory,
9241 /// Unknown variant for forward compatibility.
9242 #[default]
9243 #[serde(other)]
9244 Unknown,
9245}
9246
9247/// Allowed values for the `ToolExecutionStartToolDescriptionMetaUIVisibility` enumeration.
9248#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9249pub enum ToolExecutionStartToolDescriptionMetaUIVisibility {
9250 /// Tool is callable by the model (LLM tool surface)
9251 #[serde(rename = "model")]
9252 Model,
9253 /// Tool is callable by the MCP App view (iframe) via session.mcp.apps.callTool
9254 #[serde(rename = "app")]
9255 App,
9256 /// Unknown variant for forward compatibility.
9257 #[default]
9258 #[serde(other)]
9259 Unknown,
9260}
9261
9262/// Binary result type discriminator. Use "image" for images and "resource" for other binary data.
9263#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9264pub enum PersistedBinaryImageType {
9265 /// Binary image data.
9266 #[serde(rename = "image")]
9267 Image,
9268 /// Other binary resource data.
9269 #[serde(rename = "resource")]
9270 Resource,
9271 /// Unknown variant for forward compatibility.
9272 #[default]
9273 #[serde(other)]
9274 Unknown,
9275}
9276
9277/// Why the binary data is absent: it exceeded the inline size limit, or its asset was unavailable
9278#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9279pub enum OmittedBinaryOmittedReason {
9280 /// Bytes exceeded the session's inline size limit.
9281 #[serde(rename = "too_large")]
9282 TooLarge,
9283 /// The referenced binary asset could not be found (e.g. a truncated log).
9284 #[serde(rename = "asset_unavailable")]
9285 AssetUnavailable,
9286 /// Unknown variant for forward compatibility.
9287 #[default]
9288 #[serde(other)]
9289 Unknown,
9290}
9291
9292/// Binary result type discriminator. Use "image" for images and "resource" for other binary data.
9293#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9294pub enum OmittedBinaryType {
9295 /// Binary image data.
9296 #[serde(rename = "image")]
9297 Image,
9298 /// Other binary resource data.
9299 #[serde(rename = "resource")]
9300 Resource,
9301 /// Unknown variant for forward compatibility.
9302 #[default]
9303 #[serde(other)]
9304 Unknown,
9305}
9306
9307/// Binary result type discriminator. Use "image" for images and "resource" for other binary data.
9308#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9309pub enum BinaryAssetReferenceType {
9310 /// Binary image data.
9311 #[serde(rename = "image")]
9312 Image,
9313 /// Other binary resource data.
9314 #[serde(rename = "resource")]
9315 Resource,
9316 /// Unknown variant for forward compatibility.
9317 #[default]
9318 #[serde(other)]
9319 Unknown,
9320}
9321
9322/// A model-facing binary result as persisted: full inline data, a size-omitted marker, or a deduplicated asset reference
9323///
9324/// <div class="warning">
9325///
9326/// **Experimental.** This type is part of an experimental wire-protocol surface
9327/// and may change or be removed in future SDK or CLI releases.
9328///
9329/// </div>
9330#[derive(Debug, Clone, Serialize, Deserialize)]
9331#[serde(untagged)]
9332pub enum PersistedBinaryResult {
9333 PersistedBinaryImage(PersistedBinaryImage),
9334 OmittedBinaryResult(OmittedBinaryResult),
9335 BinaryAssetReference(BinaryAssetReference),
9336}
9337
9338/// Content block type discriminator
9339#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9340pub enum ToolExecutionCompleteContentTextType {
9341 #[serde(rename = "text")]
9342 #[default]
9343 Text,
9344}
9345
9346/// Content block type discriminator
9347#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9348pub enum ToolExecutionCompleteContentTerminalType {
9349 #[serde(rename = "terminal")]
9350 #[default]
9351 Terminal,
9352}
9353
9354/// Content block type discriminator
9355#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9356pub enum ToolExecutionCompleteContentShellExitType {
9357 #[serde(rename = "shell_exit")]
9358 #[default]
9359 ShellExit,
9360}
9361
9362/// Content block type discriminator
9363#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9364pub enum ToolExecutionCompleteContentImageType {
9365 #[serde(rename = "image")]
9366 #[default]
9367 Image,
9368}
9369
9370/// Content block type discriminator
9371#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9372pub enum ToolExecutionCompleteContentAudioType {
9373 #[serde(rename = "audio")]
9374 #[default]
9375 Audio,
9376}
9377
9378/// Theme variant this icon is intended for
9379#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9380pub enum ToolExecutionCompleteContentResourceLinkIconTheme {
9381 /// Icon intended for light themes.
9382 #[serde(rename = "light")]
9383 Light,
9384 /// Icon intended for dark themes.
9385 #[serde(rename = "dark")]
9386 Dark,
9387 /// Unknown variant for forward compatibility.
9388 #[default]
9389 #[serde(other)]
9390 Unknown,
9391}
9392
9393/// Content block type discriminator
9394#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9395pub enum ToolExecutionCompleteContentResourceLinkType {
9396 #[serde(rename = "resource_link")]
9397 #[default]
9398 ResourceLink,
9399}
9400
9401/// The embedded resource contents, either text or base64-encoded binary
9402#[derive(Debug, Clone, Serialize, Deserialize)]
9403#[serde(untagged)]
9404pub enum ToolExecutionCompleteContentResourceDetails {
9405 EmbeddedTextResourceContents(EmbeddedTextResourceContents),
9406 EmbeddedBlobResourceContents(EmbeddedBlobResourceContents),
9407}
9408
9409/// Content block type discriminator
9410#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9411pub enum ToolExecutionCompleteContentResourceType {
9412 #[serde(rename = "resource")]
9413 #[default]
9414 Resource,
9415}
9416
9417/// A content block within a tool result, which may be text, terminal output, image, audio, or a resource
9418#[derive(Debug, Clone, Serialize, Deserialize)]
9419#[serde(untagged)]
9420pub enum ToolExecutionCompleteContent {
9421 Text(ToolExecutionCompleteContentText),
9422 Terminal(ToolExecutionCompleteContentTerminal),
9423 ShellExit(ToolExecutionCompleteContentShellExit),
9424 Image(ToolExecutionCompleteContentImage),
9425 Audio(ToolExecutionCompleteContentAudio),
9426 ResourceLink(ToolExecutionCompleteContentResourceLink),
9427 Resource(ToolExecutionCompleteContentResource),
9428}
9429
9430/// Allowed values for the `ToolExecutionCompleteToolDescriptionMetaUIVisibility` enumeration.
9431#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9432pub enum ToolExecutionCompleteToolDescriptionMetaUIVisibility {
9433 /// Tool is callable by the model (LLM tool surface)
9434 #[serde(rename = "model")]
9435 Model,
9436 /// Tool is callable by the MCP App view (iframe) via session.mcp.apps.callTool
9437 #[serde(rename = "app")]
9438 App,
9439 /// Unknown variant for forward compatibility.
9440 #[default]
9441 #[serde(other)]
9442 Unknown,
9443}
9444
9445/// What triggered the skill invocation: `user-invoked` (explicit user action, such as via a slash command or UI affordance), `agent-invoked` (agent requested the skill), or `context-load` (loaded as part of another context, such as preloading skills configured on a custom agent or subagent)
9446#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9447pub enum SkillInvokedTrigger {
9448 /// Skill invocation requested explicitly by the user, such as via a slash command or UI affordance.
9449 #[serde(rename = "user-invoked")]
9450 UserInvoked,
9451 /// Skill invocation requested by the agent.
9452 #[serde(rename = "agent-invoked")]
9453 AgentInvoked,
9454 /// Skill content loaded as part of another context, such as a configured custom agent or subagent.
9455 #[serde(rename = "context-load")]
9456 ContextLoad,
9457 /// Unknown variant for forward compatibility.
9458 #[default]
9459 #[serde(other)]
9460 Unknown,
9461}
9462
9463/// Process-containment backend selected for the host platform
9464#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9465pub enum SandboxBackend {
9466 /// Apple Seatbelt process sandbox.
9467 #[serde(rename = "seatbelt")]
9468 Seatbelt,
9469 /// Linux Bubblewrap process sandbox.
9470 #[serde(rename = "bubblewrap")]
9471 Bubblewrap,
9472 /// Windows ProcessContainer sandbox.
9473 #[serde(rename = "process_container")]
9474 ProcessContainer,
9475 /// No supported process-containment backend is available.
9476 #[serde(rename = "unsupported")]
9477 Unsupported,
9478 /// Unknown variant for forward compatibility.
9479 #[default]
9480 #[serde(other)]
9481 Unknown,
9482}
9483
9484/// Customer-controllable sandbox governance area
9485#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9486pub enum SandboxControl {
9487 /// Process containment and sandbox spawn behavior.
9488 #[serde(rename = "process")]
9489 Process,
9490 /// Filesystem read, write, and deny policy.
9491 #[serde(rename = "filesystem")]
9492 Filesystem,
9493 /// Outbound and local-network access policy.
9494 #[serde(rename = "network")]
9495 Network,
9496 /// Selection of the sandbox or built-in enforcement route.
9497 #[serde(rename = "routing")]
9498 Routing,
9499 /// Decisions to run outside the process sandbox, whether requested by the model or resolved by a person.
9500 #[serde(rename = "bypass")]
9501 Bypass,
9502 /// Credential and keychain capability injection.
9503 #[serde(rename = "credentials")]
9504 Credentials,
9505 /// Host-platform and backend support behavior.
9506 #[serde(rename = "platform")]
9507 Platform,
9508 /// Unknown variant for forward compatibility.
9509 #[default]
9510 #[serde(other)]
9511 Unknown,
9512}
9513
9514/// Finite reason why sandbox enforcement is weaker than configured
9515#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9516pub enum SandboxDegradationReason {
9517 /// The selected backend cannot enforce per-path deny rules.
9518 #[serde(rename = "denied_paths_unsupported")]
9519 DeniedPathsUnsupported,
9520 /// The host platform has no supported process-containment backend.
9521 #[serde(rename = "unsupported_platform")]
9522 UnsupportedPlatform,
9523 /// Unknown variant for forward compatibility.
9524 #[default]
9525 #[serde(other)]
9526 Unknown,
9527}
9528
9529/// Runtime boundary that enforced or routed a sandbox decision
9530#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9531pub enum SandboxEnforcementPoint {
9532 /// Shell command process containment.
9533 #[serde(rename = "shell")]
9534 Shell,
9535 /// Built-in filesystem policy enforcement.
9536 #[serde(rename = "builtin_filesystem")]
9537 BuiltinFilesystem,
9538 /// Search-tool sandbox or policy enforcement.
9539 #[serde(rename = "search")]
9540 Search,
9541 /// Web-fetch network policy enforcement.
9542 #[serde(rename = "web_fetch")]
9543 WebFetch,
9544 /// Model Context Protocol server routing.
9545 #[serde(rename = "mcp")]
9546 Mcp,
9547 /// Language server process routing.
9548 #[serde(rename = "lsp")]
9549 Lsp,
9550 /// Unknown variant for forward compatibility.
9551 #[default]
9552 #[serde(other)]
9553 Unknown,
9554}
9555
9556/// Sandbox decision variant discriminator.
9557#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9558pub enum SandboxDecisionDataPolicyResolvedKind {
9559 #[serde(rename = "policy_resolved")]
9560 #[default]
9561 PolicyResolved,
9562}
9563
9564/// Finite result of a sandbox decision. Each `SandboxDecisionData` variant uses a disjoint subset: `policy_resolved` is `resolved | degraded`, `spawn_completed` and `permissive_retry_completed` are `succeeded | failed`, `enforcement_state` is `engaged | inactive | failed`, `access_denied` is `denied`, and escalation decisions are `approved | declined`.
9565#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9566pub enum SandboxOutcome {
9567 /// The sandbox policy resolved successfully. Describes configuration only and makes no claim that a backend engaged.
9568 #[serde(rename = "resolved")]
9569 Resolved,
9570 /// No sandbox governed the workload.
9571 #[serde(rename = "inactive")]
9572 Inactive,
9573 /// A runtime-owned containment backend accepted the workload. Evidence of engagement, not of verified containment for the workload's lifetime.
9574 #[serde(rename = "engaged")]
9575 Engaged,
9576 /// The sandbox operation completed successfully.
9577 #[serde(rename = "succeeded")]
9578 Succeeded,
9579 /// The sandbox operation failed.
9580 #[serde(rename = "failed")]
9581 Failed,
9582 /// The sandbox is active with one or more controls weakened by platform limitations or an explicitly selected relaxed mode.
9583 #[serde(rename = "degraded")]
9584 Degraded,
9585 /// An enforcement check refused the requested access.
9586 #[serde(rename = "denied")]
9587 Denied,
9588 /// A request to run outside the process sandbox was granted.
9589 #[serde(rename = "approved")]
9590 Approved,
9591 /// A request to run outside the process sandbox was not granted.
9592 #[serde(rename = "declined")]
9593 Declined,
9594 /// Unknown variant for forward compatibility.
9595 #[default]
9596 #[serde(other)]
9597 Unknown,
9598}
9599
9600/// Host operating-system family used for sandbox enforcement
9601#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9602pub enum SandboxPlatform {
9603 /// Apple macOS host.
9604 #[serde(rename = "macos")]
9605 Macos,
9606 /// Linux host.
9607 #[serde(rename = "linux")]
9608 Linux,
9609 /// Microsoft Windows host.
9610 #[serde(rename = "windows")]
9611 Windows,
9612 /// Host platform outside the explicitly supported families.
9613 #[serde(rename = "other")]
9614 Other,
9615 /// Unknown variant for forward compatibility.
9616 #[default]
9617 #[serde(other)]
9618 Unknown,
9619}
9620
9621/// Origin of the effective sandbox policy
9622#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9623pub enum SandboxPolicySource {
9624 /// Runtime default sandbox policy.
9625 #[serde(rename = "default_policy")]
9626 DefaultPolicy,
9627 /// User-configured sandbox policy merged with runtime-required grants.
9628 #[serde(rename = "user_policy")]
9629 UserPolicy,
9630 /// Unknown variant for forward compatibility.
9631 #[default]
9632 #[serde(other)]
9633 Unknown,
9634}
9635
9636/// Bounded classification of effective sandbox proxy routing
9637#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9638pub enum SandboxProxyMode {
9639 /// No sandbox proxy is configured.
9640 #[serde(rename = "none")]
9641 None,
9642 /// Traffic routes through a loopback proxy.
9643 #[serde(rename = "loopback")]
9644 Loopback,
9645 /// Traffic routes through a non-loopback proxy endpoint.
9646 #[serde(rename = "external")]
9647 External,
9648 /// Unknown variant for forward compatibility.
9649 #[default]
9650 #[serde(other)]
9651 Unknown,
9652}
9653
9654/// Sandbox decision variant discriminator.
9655#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9656pub enum SandboxDecisionDataSpawnCompletedKind {
9657 #[serde(rename = "spawn_completed")]
9658 #[default]
9659 SpawnCompleted,
9660}
9661
9662/// Runtime observation backing an enforcement-state or denial claim. Absent on `enforcement_state` when no observation backs the state.
9663#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9664pub enum SandboxAttestation {
9665 /// A containment backend accepted and applied the spawn request.
9666 #[serde(rename = "spawn_succeeded")]
9667 SpawnSucceeded,
9668 /// The spawn was refused for lack of a usable containment backend.
9669 #[serde(rename = "unsupported")]
9670 Unsupported,
9671 /// A runtime-owned policy check ran and returned a verdict. Attests the check, not that the caller honoured it.
9672 #[serde(rename = "builtin_policy_checked")]
9673 BuiltinPolicyChecked,
9674 /// Unknown variant for forward compatibility.
9675 #[default]
9676 #[serde(other)]
9677 Unknown,
9678}
9679
9680/// Sandbox decision variant discriminator.
9681#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9682pub enum SandboxDecisionDataEnforcementStateKind {
9683 #[serde(rename = "enforcement_state")]
9684 #[default]
9685 EnforcementState,
9686}
9687
9688/// How strong the evidence behind a denial is. A denial the sandbox itself recorded is a fact; one inferred from a command's output text is a judgement, and an analysis that cannot tell them apart will treat a false positive as enforcement.
9689#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9690pub enum SandboxDenialConfidence {
9691 /// The sandbox's own denial capture recorded the refused access. The strongest evidence available: the kernel observed it, not the runtime.
9692 #[serde(rename = "captured")]
9693 Captured,
9694 /// The command named a path that the effective policy independently denies. No capture confirmed it, but the policy did.
9695 #[serde(rename = "policy_corroborated")]
9696 PolicyCorroborated,
9697 /// The failure carried a fingerprint the sandbox itself emits, so the sandbox is known to have refused something even though the resource was not confirmed.
9698 #[serde(rename = "sandbox_reported")]
9699 SandboxReported,
9700 /// Classified from the command's own output text alone. The weakest evidence: a command that merely prints sandbox-like wording reaches this level.
9701 #[serde(rename = "output_classified")]
9702 OutputClassified,
9703 /// Unknown variant for forward compatibility.
9704 #[default]
9705 #[serde(other)]
9706 Unknown,
9707}
9708
9709/// Bounded class of access an enforcement check refused. Raw resources, commands, and process names accompany it only when content capture is enabled; diagnostic text and matched rules are never exported.
9710#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9711pub enum SandboxDenialClass {
9712 /// A read was refused because the effective policy does not grant it.
9713 #[serde(rename = "filesystem_read")]
9714 FilesystemRead,
9715 /// A write was refused. Distinct from `filesystem_read` because a read-only grant denies writes to a path it otherwise permits.
9716 #[serde(rename = "filesystem_write")]
9717 FilesystemWrite,
9718 /// A process could not start because the sandbox refused a required process-scoped resource. Currently emitted for the Windows MSYS `BaseNamedObjects` fork failure confirmed by learning-mode capture.
9719 #[serde(rename = "process_startup")]
9720 ProcessStartup,
9721 /// Windows registry access was refused and correlated with capture evidence.
9722 #[serde(rename = "registry_access")]
9723 RegistryAccess,
9724 /// Windows ALPC or RPC access was refused and correlated with capture evidence.
9725 #[serde(rename = "ipc_access")]
9726 IpcAccess,
9727 /// Access to another Windows process was refused and correlated with capture evidence.
9728 #[serde(rename = "process_access")]
9729 ProcessAccess,
9730 /// Windows job-object access was refused and correlated with capture evidence.
9731 #[serde(rename = "job_access")]
9732 JobAccess,
9733 /// Windows UI-handle access was refused and correlated with capture evidence.
9734 #[serde(rename = "ui_access")]
9735 UiAccess,
9736 /// Windows service-control-manager access was refused and correlated with capture evidence.
9737 #[serde(rename = "service_access")]
9738 ServiceAccess,
9739 /// An outbound connection was refused by `network.allowOutbound`.
9740 #[serde(rename = "network_outbound")]
9741 NetworkOutbound,
9742 /// A connection to a local or loopback destination was refused by `network.allowLocalNetwork`.
9743 #[serde(rename = "network_local")]
9744 NetworkLocal,
9745 /// A destination was refused by the sandbox host allow/deny rules.
9746 #[serde(rename = "network_host")]
9747 NetworkHost,
9748 /// The sandbox's denial capture recorded a refusal its record does not attribute to a more specific control: an unclassified resource (registry, COM, section object) or an AppContainer capability with no network meaning. Deliberately generic — the capture proves the denial happened, and naming a narrower class than the record supports would be a guess.
9749 #[serde(rename = "other_access")]
9750 OtherAccess,
9751 /// Unknown variant for forward compatibility.
9752 #[default]
9753 #[serde(other)]
9754 Unknown,
9755}
9756
9757/// Sandbox decision variant discriminator.
9758#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9759pub enum SandboxDecisionDataAccessDeniedKind {
9760 #[serde(rename = "access_denied")]
9761 #[default]
9762 AccessDenied,
9763}
9764
9765/// Sandbox decision variant discriminator.
9766#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9767pub enum SandboxDecisionDataBypassDecidedKind {
9768 #[serde(rename = "bypass_decided")]
9769 #[default]
9770 BypassDecided,
9771}
9772
9773/// Where a request to run outside the process sandbox originated. Orthogonal to the outcome: the same verdict means a different thing depending on where the request came from.
9774#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9775pub enum SandboxBypassSource {
9776 /// No longer produced. The model could once ask for a bypass in the tool call itself; no tool exposes that parameter now. Retained so historical events still deserialize.
9777 #[serde(rename = "model_requested")]
9778 ModelRequested,
9779 /// The runtime raised the prompt itself — either after a sandboxed attempt looked blocked, or before a run the sandbox cannot enforce at all, such as a detached command — and a person answered it. In the second case nothing had executed when the decision was made.
9780 #[serde(rename = "user_prompted")]
9781 UserPrompted,
9782 /// The runtime raised the prompt itself — after a sandboxed attempt looked blocked, or before a run it cannot enforce — but the permission flow produced no confirmed human answer. This includes unavailable or unreadable prompts, cancellation, and automated rule, hook, or content-exclusion denials.
9783 #[serde(rename = "prompt_unavailable")]
9784 PromptUnavailable,
9785 /// Unknown variant for forward compatibility.
9786 #[default]
9787 #[serde(other)]
9788 Unknown,
9789}
9790
9791/// Sandbox decision variant discriminator.
9792#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9793pub enum SandboxDecisionDataPermissiveRetryDecidedKind {
9794 #[serde(rename = "permissive_retry_decided")]
9795 #[default]
9796 PermissiveRetryDecided,
9797}
9798
9799/// Sandbox decision variant discriminator.
9800#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9801pub enum SandboxDecisionDataPermissiveRetryCompletedKind {
9802 #[serde(rename = "permissive_retry_completed")]
9803 #[default]
9804 PermissiveRetryCompleted,
9805}
9806
9807/// Payload of `sandbox.decision`, a bounded governance record of what the process sandbox was configured to do and whether it took effect. Discriminated by `kind`.
9808#[derive(Debug, Clone, Serialize, Deserialize)]
9809#[serde(untagged)]
9810pub enum SandboxDecisionData {
9811 PolicyResolved(SandboxDecisionDataPolicyResolved),
9812 SpawnCompleted(SandboxDecisionDataSpawnCompleted),
9813 EnforcementState(SandboxDecisionDataEnforcementState),
9814 AccessDenied(SandboxDecisionDataAccessDenied),
9815 BypassDecided(SandboxDecisionDataBypassDecided),
9816 PermissiveRetryDecided(SandboxDecisionDataPermissiveRetryDecided),
9817 PermissiveRetryCompleted(SandboxDecisionDataPermissiveRetryCompleted),
9818}
9819
9820/// Authority or runtime mechanism responsible for sub-agent model selection.
9821#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9822pub enum SubagentModelSelectionSource {
9823 /// Explicit model supplied by the parent agent on the task call and selected for dispatch.
9824 #[serde(rename = "explicit_override")]
9825 ExplicitOverride,
9826 /// Required model policy configured for the sub-agent.
9827 #[serde(rename = "configured_required")]
9828 ConfiguredRequired,
9829 /// Non-required model preference configured for the sub-agent.
9830 #[serde(rename = "configured_preference")]
9831 ConfiguredPreference,
9832 /// Complementary-model default selected for the sub-agent.
9833 #[serde(rename = "complementary_default")]
9834 ComplementaryDefault,
9835 /// Model inherited from the parent session.
9836 #[serde(rename = "session_inheritance")]
9837 SessionInheritance,
9838 /// Default model declared by the agent definition.
9839 #[serde(rename = "agent_definition_default")]
9840 AgentDefinitionDefault,
9841 /// Runtime policy, Auto mode, or an experiment selected the model.
9842 #[serde(rename = "runtime_policy")]
9843 RuntimePolicy,
9844 /// Unknown variant for forward compatibility.
9845 #[default]
9846 #[serde(other)]
9847 Unknown,
9848}
9849
9850/// Where the model input for a task-tool sub-agent came from.
9851#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9852pub enum SubagentTaskModelSource {
9853 /// The spawning agent supplied the task tool's model argument.
9854 #[serde(rename = "task_argument")]
9855 TaskArgument,
9856 /// The task omitted a model and the per-sub-agent settings entry supplied a concrete one.
9857 #[serde(rename = "subagent_configuration")]
9858 SubagentConfiguration,
9859 /// The task omitted a model and the user-defined custom agent's definition supplied one.
9860 #[serde(rename = "custom_agent_definition")]
9861 CustomAgentDefinition,
9862 /// Neither the task call, the per-sub-agent settings entry, nor a custom agent definition supplied a model.
9863 #[serde(rename = "unset")]
9864 Unset,
9865 /// Unknown variant for forward compatibility.
9866 #[default]
9867 #[serde(other)]
9868 Unknown,
9869}
9870
9871/// Binary asset type discriminator. Use "image" for images and "resource" otherwise.
9872#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9873pub enum BinaryAssetType {
9874 /// Binary image data.
9875 #[serde(rename = "image")]
9876 Image,
9877 /// Other binary resource data.
9878 #[serde(rename = "resource")]
9879 Resource,
9880 /// Unknown variant for forward compatibility.
9881 #[default]
9882 #[serde(other)]
9883 Unknown,
9884}
9885
9886/// Message role: "system" for system prompts, "developer" for developer-injected instructions
9887#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9888pub enum SystemMessageRole {
9889 /// System prompt message.
9890 #[serde(rename = "system")]
9891 System,
9892 /// Developer instruction message.
9893 #[serde(rename = "developer")]
9894 Developer,
9895 /// Unknown variant for forward compatibility.
9896 #[default]
9897 #[serde(other)]
9898 Unknown,
9899}
9900
9901/// Permission kind discriminator
9902#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9903pub enum PermissionRequestShellKind {
9904 #[serde(rename = "shell")]
9905 #[default]
9906 Shell,
9907}
9908
9909/// Permission kind discriminator
9910#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9911pub enum PermissionRequestWriteKind {
9912 #[serde(rename = "write")]
9913 #[default]
9914 Write,
9915}
9916
9917/// Permission kind discriminator
9918#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9919pub enum PermissionRequestReadKind {
9920 #[serde(rename = "read")]
9921 #[default]
9922 Read,
9923}
9924
9925/// Permission kind discriminator
9926#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9927pub enum PermissionRequestMcpKind {
9928 #[serde(rename = "mcp")]
9929 #[default]
9930 Mcp,
9931}
9932
9933/// Advisory recommendation the runtime attaches to a permission request whose origin it can vouch for by construction. Unlike the auto-approval judge this does not depend on auto mode and does not evaluate what the tool call does; its absence simply means the runtime has no opinion and the request follows the host's normal approval flow.
9934///
9935/// <div class="warning">
9936///
9937/// **Experimental.** This type is part of an experimental wire-protocol surface
9938/// and may change or be removed in future SDK or CLI releases.
9939///
9940/// </div>
9941#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9942pub enum PermissionRecommendation {
9943 /// The runtime vouches for the request's origin and recommends approving it without prompting. The host still owns the decision and may deny it; deny rules, managed policy, and the auto-approval safety judge all outrank this recommendation.
9944 #[serde(rename = "approve")]
9945 Approve,
9946 /// Unknown variant for forward compatibility.
9947 #[default]
9948 #[serde(other)]
9949 Unknown,
9950}
9951
9952/// Permission kind discriminator
9953#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9954pub enum PermissionRequestUrlKind {
9955 #[serde(rename = "url")]
9956 #[default]
9957 Url,
9958}
9959
9960/// Whether this is a store or vote memory operation
9961#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9962pub enum PermissionRequestMemoryAction {
9963 /// Store a new memory.
9964 #[serde(rename = "store")]
9965 Store,
9966 /// Vote on an existing memory.
9967 #[serde(rename = "vote")]
9968 Vote,
9969 /// Unknown variant for forward compatibility.
9970 #[default]
9971 #[serde(other)]
9972 Unknown,
9973}
9974
9975/// Stage that produced this attribution.
9976#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
9977pub enum PermissionApprovalEvaluationEvaluationStage {
9978 /// The attribution stage is unknown.
9979 #[serde(rename = "unknown")]
9980 UnknownValue,
9981 /// The request resolved before assisted-approval evaluation.
9982 #[serde(rename = "not_reached")]
9983 NotReached,
9984 /// A runtime gate skipped the judge.
9985 #[serde(rename = "pre_judge")]
9986 PreJudge,
9987 /// The judge interface produced the evaluation.
9988 #[serde(rename = "judge")]
9989 Judge,
9990 /// A cached recommendation or another request's outcome was reused.
9991 #[serde(rename = "reuse")]
9992 Reuse,
9993 /// Unknown variant for forward compatibility.
9994 #[default]
9995 #[serde(other)]
9996 Unknown,
9997}
9998
9999/// Status of the local judge interface, not proof of a model network call.
10000#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10001pub enum PermissionApprovalEvaluationJudgeStatus {
10002 /// No authoritative attribution is available.
10003 #[serde(rename = "unknown")]
10004 UnknownValue,
10005 /// This evaluation did not invoke the judge interface.
10006 #[serde(rename = "not_called")]
10007 NotCalled,
10008 /// The judge interface returned a usable verdict.
10009 #[serde(rename = "completed")]
10010 Completed,
10011 /// The judge interface returned an error.
10012 #[serde(rename = "failed")]
10013 Failed,
10014 /// This evaluation reused a cached recommendation.
10015 #[serde(rename = "cached")]
10016 Cached,
10017 /// This request inherited another decision without local judge attribution.
10018 #[serde(rename = "inherited")]
10019 Inherited,
10020 /// Unknown variant for forward compatibility.
10021 #[default]
10022 #[serde(other)]
10023 Unknown,
10024}
10025
10026/// Machine-readable runtime gate reason, never a command, path or human rationale.
10027#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10028pub enum PermissionApprovalEvaluationReasonCode {
10029 /// Attribution is missing or outside the supported vocabulary.
10030 #[serde(rename = "unknown")]
10031 UnknownValue,
10032 /// The request resolved before assisted-approval evaluation.
10033 #[serde(rename = "not-reached")]
10034 NotReached,
10035 /// Assisted approval was inactive for this request.
10036 #[serde(rename = "inactive")]
10037 Inactive,
10038 /// The judge was skipped because authorization extraction could not safely establish a complete recent history.
10039 #[serde(rename = "authorization-history-incomplete")]
10040 AuthorizationHistoryIncomplete,
10041 /// Managed policy required a human decision.
10042 #[serde(rename = "managed-approval-required")]
10043 ManagedApprovalRequired,
10044 /// The request asked to bypass sandbox restrictions.
10045 #[serde(rename = "sandbox-bypass")]
10046 SandboxBypass,
10047 /// An action field exceeded the judge input limit.
10048 #[serde(rename = "action-too-long")]
10049 ActionTooLong,
10050 /// The script path was not authorized for inspection.
10051 #[serde(rename = "path-not-authorized")]
10052 PathNotAuthorized,
10053 /// The script working directory was invalid.
10054 #[serde(rename = "invalid-working-directory")]
10055 InvalidWorkingDirectory,
10056 /// The script snapshot could not be read.
10057 #[serde(rename = "unreadable")]
10058 Unreadable,
10059 /// The script path was not a regular file.
10060 #[serde(rename = "not-regular-file")]
10061 NotRegularFile,
10062 /// The script snapshot exceeded the size limit.
10063 #[serde(rename = "too-large")]
10064 TooLarge,
10065 /// The script snapshot was not UTF-8.
10066 #[serde(rename = "non-utf8")]
10067 NonUtf8,
10068 /// The script interpreter could not be inspected.
10069 #[serde(rename = "interpreter-unavailable")]
10070 InterpreterUnavailable,
10071 /// The interpreter snapshot exceeded the size limit.
10072 #[serde(rename = "interpreter-too-large")]
10073 InterpreterTooLarge,
10074 /// The shell environment could not be reviewed.
10075 #[serde(rename = "shell-environment-unreviewable")]
10076 ShellEnvironmentUnreviewable,
10077 /// A script path could not be represented for review.
10078 #[serde(rename = "unrepresentable-path")]
10079 UnrepresentablePath,
10080 /// An interpreter wrapped a script that could not be reviewed.
10081 #[serde(rename = "interpreter-wrapped-script")]
10082 InterpreterWrappedScript,
10083 /// The script invocation could not be reviewed.
10084 #[serde(rename = "unreviewable-script-invocation")]
10085 UnreviewableScriptInvocation,
10086 /// The script argument binding could not be reviewed.
10087 #[serde(rename = "argument-binding-unreviewable")]
10088 ArgumentBindingUnreviewable,
10089 /// The script review metadata was malformed.
10090 #[serde(rename = "malformed-script-action-review")]
10091 MalformedScriptActionReview,
10092 /// The script snapshot manifest was malformed.
10093 #[serde(rename = "malformed-script-action-manifest")]
10094 MalformedScriptActionManifest,
10095 /// Script review was unavailable.
10096 #[serde(rename = "unavailable")]
10097 Unavailable,
10098 /// The judge interface returned a usable verdict.
10099 #[serde(rename = "judge-verdict")]
10100 JudgeVerdict,
10101 /// The judge interface returned an error.
10102 #[serde(rename = "judge-error")]
10103 JudgeError,
10104 /// The request inherited an outcome from another decision.
10105 #[serde(rename = "inherited")]
10106 Inherited,
10107 /// Unknown variant for forward compatibility.
10108 #[default]
10109 #[serde(other)]
10110 Unknown,
10111}
10112
10113/// Why the assisted-approval judge produced no usable recommendation. Present only alongside an `error` recommendation, where the human-readable reason is a fixed string and therefore cannot distinguish these cases. Intended to make a judge failure reportable by a consumer that has no access to the host's logs.
10114///
10115/// <div class="warning">
10116///
10117/// **Experimental.** This type is part of an experimental wire-protocol surface
10118/// and may change or be removed in future SDK or CLI releases.
10119///
10120/// </div>
10121#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10122pub enum AssistedApprovalJudgeFailureReason {
10123 /// The judge model call exceeded its deadline.
10124 #[serde(rename = "timeout")]
10125 Timeout,
10126 /// The judge model call was cancelled before it returned.
10127 #[serde(rename = "abort")]
10128 Abort,
10129 /// The judge model call completed but returned no content.
10130 #[serde(rename = "empty_response")]
10131 EmptyResponse,
10132 /// The judge model call failed (for example a transport, authentication, or rate-limit error).
10133 #[serde(rename = "model_error")]
10134 ModelError,
10135 /// The judge model replied, but the reply carried no ALLOW/DENY verdict.
10136 #[serde(rename = "parse_error")]
10137 ParseError,
10138 /// Unknown variant for forward compatibility.
10139 #[default]
10140 #[serde(other)]
10141 Unknown,
10142}
10143
10144/// Outcome of the assisted-approval safety judge for a permission request. Present only in assisted mode; its absence means the judge did not evaluate the request.
10145///
10146/// <div class="warning">
10147///
10148/// **Experimental.** This type is part of an experimental wire-protocol surface
10149/// and may change or be removed in future SDK or CLI releases.
10150///
10151/// </div>
10152#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10153pub enum AssistedApprovalRecommendation {
10154 /// The judge evaluated the request and recommends automatically approving it.
10155 #[serde(rename = "approve")]
10156 Approve,
10157 /// The judge evaluated the request and does not recommend automatically approving it; explicit approval is required. Whether that means prompting, denying, or something else is the consumer's decision.
10158 #[serde(rename = "requireApproval")]
10159 RequireApproval,
10160 /// Assisted mode is enabled, but this request category is never automatically approvable (for example, sandbox-bypass requests), so the judge was not consulted.
10161 #[serde(rename = "excluded")]
10162 Excluded,
10163 /// The judge was consulted but did not return a usable recommendation, so the request requires explicit approval.
10164 #[serde(rename = "error")]
10165 Error,
10166 /// Unknown variant for forward compatibility.
10167 #[default]
10168 #[serde(other)]
10169 Unknown,
10170}
10171
10172/// Vote direction (vote only)
10173#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10174pub enum PermissionRequestMemoryDirection {
10175 /// Vote that the memory is useful or accurate.
10176 #[serde(rename = "upvote")]
10177 Upvote,
10178 /// Vote that the memory is incorrect or outdated.
10179 #[serde(rename = "downvote")]
10180 Downvote,
10181 /// Unknown variant for forward compatibility.
10182 #[default]
10183 #[serde(other)]
10184 Unknown,
10185}
10186
10187/// Permission kind discriminator
10188#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10189pub enum PermissionRequestMemoryKind {
10190 #[serde(rename = "memory")]
10191 #[default]
10192 Memory,
10193}
10194
10195/// Scope of a stored memory.
10196#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10197pub enum PermissionRequestMemoryScope {
10198 /// Store the memory for the current repository.
10199 #[serde(rename = "repository")]
10200 Repository,
10201 /// Store the memory for the current user.
10202 #[serde(rename = "user")]
10203 User,
10204 /// Unknown variant for forward compatibility.
10205 #[default]
10206 #[serde(other)]
10207 Unknown,
10208}
10209
10210/// Permission kind discriminator
10211#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10212pub enum PermissionRequestCustomToolKind {
10213 #[serde(rename = "custom-tool")]
10214 #[default]
10215 CustomTool,
10216}
10217
10218/// Permission kind discriminator
10219#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10220pub enum PermissionRequestHookKind {
10221 #[serde(rename = "hook")]
10222 #[default]
10223 Hook,
10224}
10225
10226/// Permission kind discriminator
10227#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10228pub enum PermissionRequestExtensionManagementKind {
10229 #[serde(rename = "extension-management")]
10230 #[default]
10231 ExtensionManagement,
10232}
10233
10234/// Permission kind discriminator
10235#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10236pub enum PermissionRequestWorkflowKind {
10237 #[serde(rename = "workflow")]
10238 #[default]
10239 Workflow,
10240}
10241
10242/// Operation gated by a workflow permission request.
10243#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10244pub enum WorkflowPermissionOperation {
10245 /// Running a registered workflow, which spends subagents, active time, and AI credits under the approved limits.
10246 #[serde(rename = "run")]
10247 Run,
10248 /// Authoring a workflow, which writes JavaScript into a session-scoped extension and loads it.
10249 #[serde(rename = "author")]
10250 Author,
10251 /// Unknown variant for forward compatibility.
10252 #[default]
10253 #[serde(other)]
10254 Unknown,
10255}
10256
10257/// Permission kind discriminator
10258#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10259pub enum PermissionRequestExtensionPermissionAccessKind {
10260 #[serde(rename = "extension-permission-access")]
10261 #[default]
10262 ExtensionPermissionAccess,
10263}
10264
10265/// Permission kind discriminator
10266#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10267pub enum PermissionRequestExtensionEnvAccessKind {
10268 #[serde(rename = "extension-env-access")]
10269 #[default]
10270 ExtensionEnvAccess,
10271}
10272
10273/// Details of the permission being requested
10274#[derive(Debug, Clone, Serialize, Deserialize)]
10275#[serde(untagged)]
10276pub enum PermissionRequest {
10277 Shell(PermissionRequestShell),
10278 Write(PermissionRequestWrite),
10279 Read(PermissionRequestRead),
10280 Mcp(PermissionRequestMcp),
10281 Url(PermissionRequestUrl),
10282 Memory(PermissionRequestMemory),
10283 CustomTool(PermissionRequestCustomTool),
10284 Hook(PermissionRequestHook),
10285 ExtensionManagement(PermissionRequestExtensionManagement),
10286 Workflow(PermissionRequestWorkflow),
10287 ExtensionPermissionAccess(PermissionRequestExtensionPermissionAccess),
10288 ExtensionEnvAccess(PermissionRequestExtensionEnvAccess),
10289}
10290
10291/// Prompt kind discriminator
10292#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10293pub enum PermissionPromptRequestCommandsKind {
10294 #[serde(rename = "commands")]
10295 #[default]
10296 Commands,
10297}
10298
10299/// Prompt kind discriminator
10300#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10301pub enum PermissionPromptRequestWriteKind {
10302 #[serde(rename = "write")]
10303 #[default]
10304 Write,
10305}
10306
10307/// Prompt kind discriminator
10308#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10309pub enum PermissionPromptRequestReadKind {
10310 #[serde(rename = "read")]
10311 #[default]
10312 Read,
10313}
10314
10315/// Prompt kind discriminator
10316#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10317pub enum PermissionPromptRequestMcpKind {
10318 #[serde(rename = "mcp")]
10319 #[default]
10320 Mcp,
10321}
10322
10323/// Prompt kind discriminator
10324#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10325pub enum PermissionPromptRequestUrlKind {
10326 #[serde(rename = "url")]
10327 #[default]
10328 Url,
10329}
10330
10331/// Prompt kind discriminator
10332#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10333pub enum PermissionPromptRequestMemoryKind {
10334 #[serde(rename = "memory")]
10335 #[default]
10336 Memory,
10337}
10338
10339/// Prompt kind discriminator
10340#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10341pub enum PermissionPromptRequestCustomToolKind {
10342 #[serde(rename = "custom-tool")]
10343 #[default]
10344 CustomTool,
10345}
10346
10347/// Underlying permission kind that needs path approval
10348#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10349pub enum PermissionPromptRequestPathAccessKind {
10350 /// Read access to a filesystem path.
10351 #[serde(rename = "read")]
10352 Read,
10353 /// Shell command access involving a filesystem path.
10354 #[serde(rename = "shell")]
10355 Shell,
10356 /// Write access to a filesystem path.
10357 #[serde(rename = "write")]
10358 Write,
10359 /// Unknown variant for forward compatibility.
10360 #[default]
10361 #[serde(other)]
10362 Unknown,
10363}
10364
10365/// Prompt kind discriminator
10366#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10367pub enum PermissionPromptRequestPathKind {
10368 #[serde(rename = "path")]
10369 #[default]
10370 Path,
10371}
10372
10373/// Prompt kind discriminator
10374#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10375pub enum PermissionPromptRequestHookKind {
10376 #[serde(rename = "hook")]
10377 #[default]
10378 Hook,
10379}
10380
10381/// Prompt kind discriminator
10382#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10383pub enum PermissionPromptRequestExtensionManagementKind {
10384 #[serde(rename = "extension-management")]
10385 #[default]
10386 ExtensionManagement,
10387}
10388
10389/// Prompt kind discriminator
10390#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10391pub enum PermissionPromptRequestWorkflowKind {
10392 #[serde(rename = "workflow")]
10393 #[default]
10394 Workflow,
10395}
10396
10397/// Prompt kind discriminator
10398#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10399pub enum PermissionPromptRequestExtensionPermissionAccessKind {
10400 #[serde(rename = "extension-permission-access")]
10401 #[default]
10402 ExtensionPermissionAccess,
10403}
10404
10405/// Prompt kind discriminator
10406#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10407pub enum PermissionPromptRequestExtensionEnvAccessKind {
10408 #[serde(rename = "extension-env-access")]
10409 #[default]
10410 ExtensionEnvAccess,
10411}
10412
10413/// Derived user-facing permission prompt details for UI consumers
10414#[derive(Debug, Clone, Serialize, Deserialize)]
10415#[serde(untagged)]
10416pub enum PermissionPromptRequest {
10417 Commands(PermissionPromptRequestCommands),
10418 Write(PermissionPromptRequestWrite),
10419 Read(PermissionPromptRequestRead),
10420 Mcp(PermissionPromptRequestMcp),
10421 Url(PermissionPromptRequestUrl),
10422 Memory(PermissionPromptRequestMemory),
10423 CustomTool(PermissionPromptRequestCustomTool),
10424 Path(PermissionPromptRequestPath),
10425 Hook(PermissionPromptRequestHook),
10426 ExtensionManagement(PermissionPromptRequestExtensionManagement),
10427 Workflow(PermissionPromptRequestWorkflow),
10428 ExtensionPermissionAccess(PermissionPromptRequestExtensionPermissionAccess),
10429 ExtensionEnvAccess(PermissionPromptRequestExtensionEnvAccess),
10430}
10431
10432/// Controlled reason or actor responsible for a permission response.
10433#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10434pub enum PermissionDecisionSource {
10435 /// The response followed the assisted-approval judge recommendation.
10436 #[serde(rename = "assisted_approval")]
10437 AssistedApproval,
10438 /// A human supplied the response through an interactive prompt.
10439 #[serde(rename = "human_response")]
10440 HumanResponse,
10441 /// The host applied a standing policy or override rather than a judge recommendation or human decision.
10442 #[serde(rename = "host_policy")]
10443 HostPolicy,
10444 /// The host denied the request because no interactive user response was available.
10445 #[serde(rename = "unattended_fallback")]
10446 UnattendedFallback,
10447 /// Historical compatibility value for sessions created while authorization carry-forward was executable. Current runtimes do not produce this source.
10448 #[serde(rename = "authorization_carry_forward")]
10449 AuthorizationCarryForward,
10450 /// Unknown variant for forward compatibility.
10451 #[default]
10452 #[serde(other)]
10453 Unknown,
10454}
10455
10456/// The permission request was approved
10457#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10458pub enum PermissionApprovedKind {
10459 #[serde(rename = "approved")]
10460 #[default]
10461 Approved,
10462}
10463
10464/// Command approval kind
10465#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10466pub enum UserToolSessionApprovalCommandsKind {
10467 #[serde(rename = "commands")]
10468 #[default]
10469 Commands,
10470}
10471
10472/// Read approval kind
10473#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10474pub enum UserToolSessionApprovalReadKind {
10475 #[serde(rename = "read")]
10476 #[default]
10477 Read,
10478}
10479
10480/// Write approval kind
10481#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10482pub enum UserToolSessionApprovalWriteKind {
10483 #[serde(rename = "write")]
10484 #[default]
10485 Write,
10486}
10487
10488/// MCP tool approval kind
10489#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10490pub enum UserToolSessionApprovalMcpKind {
10491 #[serde(rename = "mcp")]
10492 #[default]
10493 Mcp,
10494}
10495
10496/// Memory approval kind
10497#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10498pub enum UserToolSessionApprovalMemoryKind {
10499 #[serde(rename = "memory")]
10500 #[default]
10501 Memory,
10502}
10503
10504/// Custom tool approval kind
10505#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10506pub enum UserToolSessionApprovalCustomToolKind {
10507 #[serde(rename = "custom-tool")]
10508 #[default]
10509 CustomTool,
10510}
10511
10512/// Extension management approval kind
10513#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10514pub enum UserToolSessionApprovalExtensionManagementKind {
10515 #[serde(rename = "extension-management")]
10516 #[default]
10517 ExtensionManagement,
10518}
10519
10520/// Workflow approval kind
10521#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10522pub enum UserToolSessionApprovalWorkflowKind {
10523 #[serde(rename = "workflow")]
10524 #[default]
10525 Workflow,
10526}
10527
10528/// Extension permission access approval kind
10529#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10530pub enum UserToolSessionApprovalExtensionPermissionAccessKind {
10531 #[serde(rename = "extension-permission-access")]
10532 #[default]
10533 ExtensionPermissionAccess,
10534}
10535
10536/// Extension environment access approval kind
10537#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10538pub enum UserToolSessionApprovalExtensionEnvAccessKind {
10539 #[serde(rename = "extension-env-access")]
10540 #[default]
10541 ExtensionEnvAccess,
10542}
10543
10544/// The approval to add as a session-scoped rule
10545#[derive(Debug, Clone, Serialize, Deserialize)]
10546#[serde(untagged)]
10547pub enum UserToolSessionApproval {
10548 Commands(UserToolSessionApprovalCommands),
10549 Read(UserToolSessionApprovalRead),
10550 Write(UserToolSessionApprovalWrite),
10551 Mcp(UserToolSessionApprovalMcp),
10552 Memory(UserToolSessionApprovalMemory),
10553 CustomTool(UserToolSessionApprovalCustomTool),
10554 ExtensionManagement(UserToolSessionApprovalExtensionManagement),
10555 Workflow(UserToolSessionApprovalWorkflow),
10556 ExtensionPermissionAccess(UserToolSessionApprovalExtensionPermissionAccess),
10557 ExtensionEnvAccess(UserToolSessionApprovalExtensionEnvAccess),
10558}
10559
10560/// Approved and remembered for the rest of the session
10561#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10562pub enum PermissionApprovedForSessionKind {
10563 #[serde(rename = "approved-for-session")]
10564 #[default]
10565 ApprovedForSession,
10566}
10567
10568/// Approved and persisted for this project location
10569#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10570pub enum PermissionApprovedForLocationKind {
10571 #[serde(rename = "approved-for-location")]
10572 #[default]
10573 ApprovedForLocation,
10574}
10575
10576/// The permission request was cancelled before a response was used
10577#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10578pub enum PermissionCancelledKind {
10579 #[serde(rename = "cancelled")]
10580 #[default]
10581 Cancelled,
10582}
10583
10584/// Denied because approval rules explicitly blocked it
10585#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10586pub enum PermissionDeniedByRulesKind {
10587 #[serde(rename = "denied-by-rules")]
10588 #[default]
10589 DeniedByRules,
10590}
10591
10592/// Denied because no approval rule matched and user confirmation was unavailable
10593#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10594pub enum PermissionDeniedNoApprovalRuleAndCouldNotRequestFromUserKind {
10595 #[serde(rename = "denied-no-approval-rule-and-could-not-request-from-user")]
10596 #[default]
10597 DeniedNoApprovalRuleAndCouldNotRequestFromUser,
10598}
10599
10600/// Denied by the user during an interactive prompt
10601#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10602pub enum PermissionDeniedInteractivelyByUserKind {
10603 #[serde(rename = "denied-interactively-by-user")]
10604 #[default]
10605 DeniedInteractivelyByUser,
10606}
10607
10608/// Denied by the organization's content exclusion policy
10609#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10610pub enum PermissionDeniedByContentExclusionPolicyKind {
10611 #[serde(rename = "denied-by-content-exclusion-policy")]
10612 #[default]
10613 DeniedByContentExclusionPolicy,
10614}
10615
10616/// Denied by a permission request hook registered by an extension or plugin
10617#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10618pub enum PermissionDeniedByPermissionRequestHookKind {
10619 #[serde(rename = "denied-by-permission-request-hook")]
10620 #[default]
10621 DeniedByPermissionRequestHook,
10622}
10623
10624/// The result of the permission request
10625#[derive(Debug, Clone, Serialize, Deserialize)]
10626#[serde(untagged)]
10627pub enum PermissionResult {
10628 Approved(PermissionApproved),
10629 ApprovedForSession(PermissionApprovedForSession),
10630 ApprovedForLocation(PermissionApprovedForLocation),
10631 Cancelled(PermissionCancelled),
10632 DeniedByRules(PermissionDeniedByRules),
10633 DeniedNoApprovalRuleAndCouldNotRequestFromUser(
10634 PermissionDeniedNoApprovalRuleAndCouldNotRequestFromUser,
10635 ),
10636 DeniedInteractivelyByUser(PermissionDeniedInteractivelyByUser),
10637 DeniedByContentExclusionPolicy(PermissionDeniedByContentExclusionPolicy),
10638 DeniedByPermissionRequestHook(PermissionDeniedByPermissionRequestHook),
10639}
10640
10641/// Direction stored in a historical extractor claim. Current runtimes do not apply it.
10642///
10643/// <div class="warning">
10644///
10645/// **Experimental.** This type is part of an experimental wire-protocol surface
10646/// and may change or be removed in future SDK or CLI releases.
10647///
10648/// </div>
10649#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10650pub enum PermissionMessageAuthorizationPolarity {
10651 /// Historical claim recorded as a grant.
10652 #[serde(rename = "grant")]
10653 Grant,
10654 /// Historical claim recorded as a denial.
10655 #[serde(rename = "denial")]
10656 Denial,
10657 /// Unknown variant for forward compatibility.
10658 #[default]
10659 #[serde(other)]
10660 Unknown,
10661}
10662
10663/// Elicitation mode; "form" for structured input, "url" for browser-based. Defaults to "form" when absent.
10664#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10665pub enum ElicitationRequestedMode {
10666 /// Structured form-based elicitation.
10667 #[serde(rename = "form")]
10668 Form,
10669 /// Browser URL-based elicitation.
10670 #[serde(rename = "url")]
10671 Url,
10672 /// Unknown variant for forward compatibility.
10673 #[default]
10674 #[serde(other)]
10675 Unknown,
10676}
10677
10678/// Schema type indicator (always 'object')
10679#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10680pub enum ElicitationRequestedSchemaType {
10681 #[serde(rename = "object")]
10682 #[default]
10683 Object,
10684}
10685
10686/// The user action: "accept" (submitted form), "decline" (explicitly refused), or "cancel" (dismissed)
10687#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10688pub enum ElicitationCompletedAction {
10689 /// The user submitted the requested form.
10690 #[serde(rename = "accept")]
10691 Accept,
10692 /// The user explicitly declined the request.
10693 #[serde(rename = "decline")]
10694 Decline,
10695 /// The user dismissed the request.
10696 #[serde(rename = "cancel")]
10697 Cancel,
10698 /// Unknown variant for forward compatibility.
10699 #[default]
10700 #[serde(other)]
10701 Unknown,
10702}
10703
10704/// Reason the runtime is requesting host-provided MCP OAuth credentials
10705#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10706pub enum McpOauthRequestReason {
10707 /// Initial credentials are required before connecting to the MCP server.
10708 #[serde(rename = "initial")]
10709 Initial,
10710 /// The current host-provided credential was rejected and a replacement is requested.
10711 #[serde(rename = "refresh")]
10712 Refresh,
10713 /// The server requires a new host authorization flow before continuing.
10714 #[serde(rename = "reauth")]
10715 Reauth,
10716 /// The server requires a credential with additional scope or audience.
10717 #[serde(rename = "upscope")]
10718 Upscope,
10719 /// Unknown variant for forward compatibility.
10720 #[default]
10721 #[serde(other)]
10722 Unknown,
10723}
10724
10725/// Optional non-default OAuth grant type. When set to 'client_credentials', the OAuth flow runs headlessly using the client_id + keychain-stored secret (no browser, no callback server).
10726#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10727pub enum McpOauthRequiredStaticClientConfigGrantType {
10728 #[serde(rename = "client_credentials")]
10729 #[default]
10730 ClientCredentials,
10731}
10732
10733/// How the pending MCP OAuth request was completed
10734#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10735pub enum McpOauthCompletionOutcome {
10736 /// The request completed with a token-backed OAuth provider.
10737 #[serde(rename = "token")]
10738 Token,
10739 /// The request completed without an OAuth provider.
10740 #[serde(rename = "cancelled")]
10741 Cancelled,
10742 /// Unknown variant for forward compatibility.
10743 #[default]
10744 #[serde(other)]
10745 Unknown,
10746}
10747
10748/// Why dynamic headers are being requested.
10749#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10750pub enum McpHeadersRefreshRequiredReason {
10751 /// The transport is making its first dynamic header request for this server.
10752 #[serde(rename = "startup")]
10753 Startup,
10754 /// The previously cached dynamic headers expired.
10755 #[serde(rename = "ttl-expired")]
10756 TtlExpired,
10757 /// The server returned 401 and stale dynamic headers were invalidated.
10758 #[serde(rename = "auth-failed")]
10759 AuthFailed,
10760 /// Unknown variant for forward compatibility.
10761 #[default]
10762 #[serde(other)]
10763 Unknown,
10764}
10765
10766/// How the pending MCP headers refresh request resolved.
10767#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10768pub enum McpHeadersRefreshCompletedOutcome {
10769 /// The host supplied dynamic headers.
10770 #[serde(rename = "headers")]
10771 Headers,
10772 /// The host responded with no dynamic headers.
10773 #[serde(rename = "none")]
10774 None,
10775 /// The host credential broker rejected or failed the refresh.
10776 #[serde(rename = "error")]
10777 Error,
10778 /// No response arrived within the bounded window.
10779 #[serde(rename = "timeout")]
10780 Timeout,
10781 /// Unknown variant for forward compatibility.
10782 #[default]
10783 #[serde(other)]
10784 Unknown,
10785}
10786
10787/// Lifecycle phase for a Rust-owned ephemeral query stream.
10788///
10789/// <div class="warning">
10790///
10791/// **Experimental.** This type is part of an experimental wire-protocol surface
10792/// and may change or be removed in future SDK or CLI releases.
10793///
10794/// </div>
10795#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10796pub enum UIEphemeralQueryPhase {
10797 /// The ephemeral query stream has begun.
10798 #[serde(rename = "started")]
10799 Started,
10800 /// A partial result chunk was produced by the stream.
10801 #[serde(rename = "chunk")]
10802 Chunk,
10803 /// The ephemeral query stream finished successfully.
10804 #[serde(rename = "completed")]
10805 Completed,
10806 /// The ephemeral query stream ended with an error.
10807 #[serde(rename = "failed")]
10808 Failed,
10809 /// The ephemeral query stream was cancelled before completing.
10810 #[serde(rename = "aborted")]
10811 Aborted,
10812 /// Unknown variant for forward compatibility.
10813 #[default]
10814 #[serde(other)]
10815 Unknown,
10816}
10817
10818/// The user's auto-mode-switch choice
10819#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10820pub enum AutoModeSwitchResponse {
10821 /// Switch models for this request.
10822 #[serde(rename = "yes")]
10823 Yes,
10824 /// Switch models now and keep using the replacement automatically.
10825 #[serde(rename = "yes_always")]
10826 YesAlways,
10827 /// Do not switch models.
10828 #[serde(rename = "no")]
10829 No,
10830 /// Unknown variant for forward compatibility.
10831 #[default]
10832 #[serde(other)]
10833 Unknown,
10834}
10835
10836/// User action selected for an exhausted session limit.
10837#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10838pub enum SessionLimitsExhaustedResponseAction {
10839 /// Increase the current max by an exact AI Credits amount.
10840 #[serde(rename = "add")]
10841 Add,
10842 /// Set a new absolute max AI Credits value.
10843 #[serde(rename = "set")]
10844 Set,
10845 /// Remove the current session limit.
10846 #[serde(rename = "unset")]
10847 Unset,
10848 /// Leave the limit unchanged and cancel the blocked model request.
10849 #[serde(rename = "cancel")]
10850 Cancel,
10851 /// Unknown variant for forward compatibility.
10852 #[default]
10853 #[serde(other)]
10854 Unknown,
10855}
10856
10857/// Coarse request-difficulty bucket for UX explainability
10858#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10859pub enum AutoModeResolvedReasoningBucket {
10860 /// The request looks low-reasoning; a lighter model is appropriate.
10861 #[serde(rename = "low")]
10862 Low,
10863 /// The request needs a moderate amount of reasoning.
10864 #[serde(rename = "medium")]
10865 Medium,
10866 /// The request looks high-reasoning; a stronger model is appropriate.
10867 #[serde(rename = "high")]
10868 High,
10869 /// Unknown variant for forward compatibility.
10870 #[default]
10871 #[serde(other)]
10872 Unknown,
10873}
10874
10875/// Summary of which managed-settings channels contributed to the effective session policy. Use the per-channel booleans for exact provenance.
10876#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10877pub enum ManagedSettingsResolvedSource {
10878 /// Only the server/account channel contributed.
10879 #[serde(rename = "server")]
10880 Server,
10881 /// Only the device MDM/plist/registry/file channel contributed.
10882 #[serde(rename = "device")]
10883 Device,
10884 /// Only session-local SDK-host injection contributed.
10885 #[serde(rename = "client")]
10886 Client,
10887 /// A policy helper registered by device or server policy contributed. Device registration takes priority when present.
10888 #[serde(rename = "policyHelper")]
10889 PolicyHelper,
10890 /// More than one channel contributed. Ordinary keys resolve device over server over policy helper per key, while permissions compose restrictively across all present layers.
10891 #[serde(rename = "mixed")]
10892 Mixed,
10893 /// No managed policy is in force (no channel contributed).
10894 #[serde(rename = "none")]
10895 None,
10896 /// Unknown variant for forward compatibility.
10897 #[default]
10898 #[serde(other)]
10899 Unknown,
10900}
10901
10902/// The category of runtime action that enterprise managed settings governed (blocked or capped)
10903#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10904pub enum ManagedSettingsEnforcedAction {
10905 /// An attempt to turn on a bypass-permissions ("yolo") escalation was refused or capped because policy disables bypass-permissions mode.
10906 #[serde(rename = "bypass_permissions_blocked")]
10907 BypassPermissionsBlocked,
10908 /// Unknown variant for forward compatibility.
10909 #[default]
10910 #[serde(other)]
10911 Unknown,
10912}
10913
10914/// For a `bypass_permissions_blocked` action, which permission-escalation primitive was refused
10915#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10916pub enum ManagedSettingsEnforcedEscalation {
10917 /// Full allow-all permissions — automatically approving tools, paths, and URLs.
10918 #[serde(rename = "allow_all")]
10919 AllowAll,
10920 /// Automatic approval of all tool permission requests.
10921 #[serde(rename = "approve_all")]
10922 ApproveAll,
10923 /// Assisted mode — keeps normal prompt paths and adds an LLM recommendation, distinct from allow-all.
10924 #[serde(rename = "assisted_approval")]
10925 AssistedApproval,
10926 /// Unrestricted filesystem access outside the session's allowed directories.
10927 #[serde(rename = "unrestricted_paths")]
10928 UnrestrictedPaths,
10929 /// Unrestricted URL fetch access.
10930 #[serde(rename = "unrestricted_urls")]
10931 UnrestrictedUrls,
10932 /// A server-wide MCP "Always Allow" (or `--allow-tool <server>`) blanket that would auto-approve every tool from an MCP server. Capped to per-tool approval; each tool still prompts.
10933 #[serde(rename = "server_wide_mcp_approval")]
10934 ServerWideMcpApproval,
10935 /// Unknown variant for forward compatibility.
10936 #[default]
10937 #[serde(other)]
10938 Unknown,
10939}
10940
10941/// Exit plan mode action
10942#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10943pub enum ExitPlanModeAction {
10944 /// Exit plan mode without starting implementation.
10945 #[serde(rename = "exit_only")]
10946 ExitOnly,
10947 /// Exit plan mode and continue in interactive mode.
10948 #[serde(rename = "interactive")]
10949 Interactive,
10950 /// Exit plan mode and continue autonomously.
10951 #[serde(rename = "autopilot")]
10952 Autopilot,
10953 /// Exit plan mode and continue with parallel autonomous workers.
10954 #[serde(rename = "autopilot_fleet")]
10955 AutopilotFleet,
10956 /// Unknown variant for forward compatibility.
10957 #[default]
10958 #[serde(other)]
10959 Unknown,
10960}
10961
10962/// Terminal status a workflow run committed. A settled run is never `pending` or `running`, so those two members of the run-status domain are deliberately absent.
10963#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10964pub enum WorkflowRunSettledStatus {
10965 /// The workflow body resolved and its result was committed.
10966 #[serde(rename = "completed")]
10967 Completed,
10968 /// The run was stopped by a limit, an approval refusal or another policy decision.
10969 #[serde(rename = "halted")]
10970 Halted,
10971 /// The attempt paused intentionally while preserving resumable run state.
10972 #[serde(rename = "paused")]
10973 Paused,
10974 /// The run was cancelled by its caller or by session disposal.
10975 #[serde(rename = "cancelled")]
10976 Cancelled,
10977 /// The run failed, with `failureType` carrying the class when it has one.
10978 #[serde(rename = "error")]
10979 Error,
10980 /// Unknown variant for forward compatibility.
10981 #[default]
10982 #[serde(other)]
10983 Unknown,
10984}
10985
10986/// Source location type (e.g., project, personal-copilot, plugin, builtin, sdk)
10987#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
10988pub enum SkillSource {
10989 /// Skill defined in the current project's skill directories.
10990 #[serde(rename = "project")]
10991 Project,
10992 /// Skill discovered from a parent directory in the current workspace tree.
10993 #[serde(rename = "inherited")]
10994 Inherited,
10995 /// Skill defined in the user's Copilot skill directory.
10996 #[serde(rename = "personal-copilot")]
10997 PersonalCopilot,
10998 /// Skill defined in the user's personal agents skill directory.
10999 #[serde(rename = "personal-agents")]
11000 PersonalAgents,
11001 /// Skill provided by an installed plugin.
11002 #[serde(rename = "plugin")]
11003 Plugin,
11004 /// Skill loaded from a configured custom skill directory.
11005 #[serde(rename = "custom")]
11006 Custom,
11007 /// Skill bundled with the runtime.
11008 #[serde(rename = "builtin")]
11009 Builtin,
11010 /// Pathless skill supplied lazily by an SDK skill provider.
11011 #[serde(rename = "sdk")]
11012 Sdk,
11013 /// Unknown variant for forward compatibility.
11014 #[default]
11015 #[serde(other)]
11016 Unknown,
11017}
11018
11019/// Whether configured models are advisory preferences or required constraints
11020#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
11021pub enum AgentModelPolicy {
11022 /// Treat the authored models as advisory preferences that callers may override.
11023 #[serde(rename = "preferred")]
11024 Preferred,
11025 /// Require subagent execution to use one of the authored models.
11026 #[serde(rename = "required")]
11027 Required,
11028 /// Unknown variant for forward compatibility.
11029 #[default]
11030 #[serde(other)]
11031 Unknown,
11032}
11033
11034/// Connection status: connected, failed, needs-auth, pending, disabled, stopped, or not_configured
11035#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
11036pub enum McpServerStatus {
11037 /// The server is connected and available.
11038 #[serde(rename = "connected")]
11039 Connected,
11040 /// The server failed to connect or initialize.
11041 #[serde(rename = "failed")]
11042 Failed,
11043 /// The server requires authentication before it can connect.
11044 #[serde(rename = "needs-auth")]
11045 NeedsAuth,
11046 /// The server connection is still being established.
11047 #[serde(rename = "pending")]
11048 Pending,
11049 /// The server is configured but disabled.
11050 #[serde(rename = "disabled")]
11051 Disabled,
11052 /// The server was intentionally stopped and can be restarted on demand when policy permits; a server quarantined by restrictive managed policy stays stopped and cannot be restarted until the policy allows it.
11053 #[serde(rename = "stopped")]
11054 Stopped,
11055 /// The server is not configured for this session.
11056 #[serde(rename = "not_configured")]
11057 NotConfigured,
11058 /// Unknown variant for forward compatibility.
11059 #[default]
11060 #[serde(other)]
11061 Unknown,
11062}
11063
11064/// Discovery source
11065#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
11066pub enum ExtensionsLoadedExtensionSource {
11067 /// Extension discovered from the current project.
11068 #[serde(rename = "project")]
11069 Project,
11070 /// Extension discovered from the user's extension directory.
11071 #[serde(rename = "user")]
11072 User,
11073 /// Extension contributed by an installed plugin.
11074 #[serde(rename = "plugin")]
11075 Plugin,
11076 /// Extension discovered from the current session's state directory.
11077 #[serde(rename = "session")]
11078 Session,
11079 /// Unknown variant for forward compatibility.
11080 #[default]
11081 #[serde(other)]
11082 Unknown,
11083}
11084
11085/// Current status: running, disabled, failed, or starting
11086#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
11087pub enum ExtensionsLoadedExtensionStatus {
11088 /// The extension process is running.
11089 #[serde(rename = "running")]
11090 Running,
11091 /// The extension is installed but disabled.
11092 #[serde(rename = "disabled")]
11093 Disabled,
11094 /// The extension failed to start or crashed.
11095 #[serde(rename = "failed")]
11096 Failed,
11097 /// The extension process is starting.
11098 #[serde(rename = "starting")]
11099 Starting,
11100 /// Unknown variant for forward compatibility.
11101 #[default]
11102 #[serde(other)]
11103 Unknown,
11104}