Agent Build Tutor
Map / Outline

API and gateway

One contract for every caller, with keys, scopes, limits, and a single public door.

What it is and why it exists

What

The API is the contract callers use: the OpenAI-compatible chat, embeddings, and models endpoints. The gateway is the process in front that authenticates each caller and decides what that caller may do.

Why

The model engine has no authentication. Every outside caller needs an identity that can be limited and revoked without affecting the others. A stable contract also lets you swap what is behind it.

How it works

Where it sits in the build order

Needs first

  • Inference engineeringA gateway forwards to an engine. Its timeouts and limits are set from measured load times and generation rates.Build out of order Stub it with: An echo handler that returns a fixed completion.

Unlocks

  • Tools and MCPTool calling rides on the chat contract: tool schemas go in the request and tool calls come back in the response. Key scope decides who gets tools.
  • Harness engineeringThe harness sits behind the gateway contract. Keys carry scopes, and the harness reads the scope to decide whether a caller gets tools at all.

In the reference build

PathRole
apps/agent-server/auth.pyKey validation, scopes, rate limits, quotas.
apps/agent-server/keys_admin.pyIssue, list, and revoke keys.
apps/agent-server/main.pyThe endpoints.
apps/claude-code-gateway/Translation proxy so a coding client can use local models.

The same idea on other platforms

PlatformHow this module maps
DatabricksModel Serving endpoints are the API. AI Gateway adds rate limits, usage tracking, guardrails, and routing across providers. Identity is the workspace's tokens and service principals.
IBM watsonxwatsonx.ai exposes inference endpoints behind IAM keys. A model gateway routes to third-party providers. Orchestrate exposes agent endpoints.
CodexCodex is a client. It needs a provider base URL and key. If you point it at your gateway, issue it its own key.
CursorA client. Give it a key of its own and a base URL override where supported.
Claude Code / Agent SDKA client. A base URL setting can route it through your gateway. Issue a separate key per machine.
Another machineA small FastAPI app or an off-the-shelf LLM proxy does the same job on any host.

Explain it back

Answer aloud first. Then open the answer and compare.

Why one key per app?
A strong answerSo you can limit and revoke one integration without touching the others, and so logs attribute every request.
Why is liveness unauthenticated while details are not?
A strong answerA supervisor has to tell healthy from sick without holding a key. Details reveal configuration, so they stay behind one.

From the live build

Recent changes and files the sync job filed under this module.

Ask the tutor about this module