Agents
Each launched Agent gets a live chat experience backed by xAI, but the Agent is not trusted with FORGE infrastructure. The LLM proposes actions through typed tools; FORGE validates and executes only allowed actions.
Current xAI docs reviewed 2026-10-08 describe the Responses API, OpenAI-compatible REST interfaces, function calling, structured outputs and current Grok models. Model IDs must be environment/config values because they change independently of FORGE.
Browser
-> POST /v1/agents/:id/chat/sessions/:sessionId/messages
-> auth/rate limit/content size checks
-> load AgentPromptVersion + tool policy
-> build xAI Responses request
-> stream model output
-> if tool call:
schema validate
policy authorize
execute tool adapter
sanitize result
continue model turn
-> stream final response
-> persist usage + trace metadataRecommended server-side abstraction:
interface ModelProvider {
stream(input: ModelRequest): AsyncIterable<ModelEvent>;
generateIdentity(input: IdentityGenRequest): Promise<IdentityGenResult>; // or AsyncIterable progress
generateImages(input: ImageGenRequest): Promise<ImageGenResult[]>;
}Implement XaiProvider using the Responses API for chat/identity text, and Grok Imagine (/v1/images/generations or Responses image_generation tool) for avatars. Configuration:
XAI_API_KEY=
XAI_MODEL_DEFAULT=grok-4.7
XAI_BASE_URL=https://api.x.ai
XAI_REASONING_EFFORT=low
XAI_IMAGE_MODEL=grok-imagine-image-2.0
XAI_IMAGE_ASPECT_RATIO=1:1
AGENT_MAX_OUTPUT_TOKENS=4096
AGENT_MAX_TOOL_STEPS=6
IDENTITY_GEN_DAILY_LIMIT=20
IDENTITY_AVATAR_DAILY_LIMIT=40
IDENTITY_AVATAR_VARIANTS=3Identity generation is a platform feature (wizard), not an in-chat Agent tool. It uses the same API key and usage accounting but a separate prompt harness and rate bucket. Details: Identity generation.
Use a stable conversation/cache key where supported so repeated Agent system/context prefixes can benefit from provider caching. Retry 429/5xx with capped exponential backoff, but do not blindly replay state-changing tools.
Prompt is versioned and assembled from immutable layers:
Creator text is always delimited as untrusted configuration. It cannot override platform-level safety or tool authorization.
Every Agent must be instructed that:
Tools are code-owned, not prompt-owned.
type ToolDefinition = {
id: string;
inputSchema: ZodSchema;
requiredCapabilities: string[];
risk: 'read' | 'write-low' | 'write-high';
execute(ctx: ToolContext, input: unknown): Promise<ToolResult>;
};MVP read tools:
chain.get_token_statechain.get_recent_tradeschain.get_wallet_balance_publicmarket.get_agent_metricsknowledge.search_agent_sourcesforge.get_agent_profileOptional template-specific read tools can be added behind feature flags.
MVP explicitly excludes generic:
Do not hand a private key to Grok. Use a transaction policy engine:
LLM proposes typed action
-> deterministic validator checks target/function/value/slippage/limits
-> optional user/operator approval
-> signer service / smart-account policy executes
-> receipt returnedPer-Agent execution account should have:
MVP memory layers:
No cross-Agent memory. No user private memory shared across different Agents.
Suggested retention controls:
Per IP + wallet + Agent:
Use Redis token bucket/sliding window. Return 429 with retry hints.
Store templates as code-reviewed files, e.g.:
packages/agents/templates/
trading/v1.ts
research/v1.ts
defi/v1.ts
content/v1.ts
social/v1.ts
community/v1.ts
gaming/v1.ts
utility/v1.tsEach prompt version is immutable once an Agent is live; updating a template creates a new version and existing Agents can migrate explicitly.
Agent page should show:
Never show hidden platform safety prompt text or API credentials.