> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentsfleet.net/llms.txt
> Use this file to discover all available pages before exploring further.

# Register a runner

> Enrolls a runner into the fleet and assigns its policy. Requires an existing operator credential (Clerk JWT or `agt_t` API key with admin role); there is no enrollment token. Mints a durable `agt_r` runner token, returned once, and stores only its SHA-256 hash. The host applies the policy assigned here and never declares its own.



## OpenAPI

````yaml https://raw.githubusercontent.com/agentsfleet/agentsfleet/main/public/openapi.json post /v1/runners
openapi: 3.1.0
info:
  title: agentsfleet Control Plane API
  version: 1.0.0
  description: API for managing workspaces, fleets, triggers, and runs.
  contact:
    name: agentsfleet
    url: https://agentsfleet.net
servers:
  - url: https://api.agentsfleet.net
    description: Production
security:
  - BearerAuth: []
tags:
  - name: Health
    description: System status and readiness probes
    x-mintlify:
      navigation: Health
  - name: Authentication
    description: Command Line Interface (CLI) sign-in sessions and GitHub sign-in
    x-mintlify:
      navigation: Authentication
  - name: Workspaces
    description: Create and manage workspaces
    x-mintlify:
      navigation: Workspaces
  - name: Tenant
    description: Manage tenant provider settings and models
    x-mintlify:
      navigation: Tenant
  - name: auth-identity-events
    description: >-
      Process signed account events from Clerk. This route is not for customer
      fleets.
    x-mintlify:
      navigation: Auth Identity Events
  - name: Fleets
    description: Create, configure, and run fleets
    x-mintlify:
      navigation: Fleets
  - name: Schedules
    description: Manage and receive scheduled Fleet events
    x-mintlify:
      navigation: Schedules
  - name: Memory
    description: Read and search saved fleet memory
    x-mintlify:
      navigation: Memory
  - name: Secrets
    description: Manage named secrets for fleets in a workspace
    x-mintlify:
      navigation: Secrets
  - name: Admin
    description: Manage shared provider keys and models
    x-mintlify:
      navigation: Admin
  - name: Billing
    description: Read tenant balances and charge records
    x-mintlify:
      navigation: Billing
  - name: Integration Grants
    description: Manage fleet access to third-party services
    x-mintlify:
      navigation: Integration Grants
  - name: Connectors
    description: Connect workspaces to third-party providers
    x-mintlify:
      navigation: Connectors
  - name: Fleet Keys
    description: Manage keys that let external clients call a fleet
    x-mintlify:
      navigation: Fleet Keys
  - name: API Keys
    description: Manage tenant admin API keys
    x-mintlify:
      navigation: API Keys
  - name: Webhooks
    description: Receive signed events and approval decisions
    x-mintlify:
      navigation: Webhooks
  - name: Approvals
    description: List, inspect, and resolve pending approvals
    x-mintlify:
      navigation: Approvals
  - name: Fleet
    description: Enroll and manage runners
    x-mintlify:
      navigation: Fleet
  - name: Fleet Bundles
    description: Manage fleet source bundles in a workspace
    x-mintlify:
      navigation: Fleet Bundles
  - name: Fleet library
    description: Browse and add reusable fleet sources
    x-mintlify:
      navigation: Fleet library
  - name: Model Library
    description: List models available to the tenant
    x-mintlify:
      navigation: Model Library
paths:
  /v1/runners:
    post:
      tags:
        - Fleet
      summary: Register a runner
      description: >-
        Enrolls a runner into the fleet and assigns its policy. Requires an
        existing operator credential (Clerk JWT or `agt_t` API key with admin
        role); there is no enrollment token. Mints a durable `agt_r` runner
        token, returned once, and stores only its SHA-256 hash. The host applies
        the policy assigned here and never declares its own.
      operationId: register_runner
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RunnerRegisterRequest'
      responses:
        '201':
          description: Runner registered; the bearer token is returned exactly once.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RunnerRegisterResponse'
        default:
          $ref: '#/components/responses/Error'
components:
  schemas:
    RunnerRegisterRequest:
      type: object
      description: >-
        Enrollment input. The operator ASSIGNS the policy here — the selection
        is an assignment the host must satisfy, not a description of the host.
      required:
        - host_id
        - assigned_policy
        - labels
      properties:
        host_id:
          type: string
          minLength: 1
          maxLength: 256
          description: Operator-supplied host identifier for this runner (1-256 chars).
        assigned_policy:
          $ref: '#/components/schemas/RunnerAssignedPolicy'
        labels:
          type: array
          description: Free-form operator labels for placement/grouping.
          items:
            type: string
    RunnerRegisterResponse:
      type: object
      description: >-
        The durable runner identity plus its bearer token. The `runner_token` is
        returned exactly once; the server stores only its SHA-256 hash.
      required:
        - runner_id
        - runner_token
        - assigned_policy
      properties:
        runner_id:
          type: string
          format: uuid
          description: The minted runner's id (UUIDv7).
        runner_token:
          type: string
          description: >-
            The `agt_r`-prefixed bearer token the runner presents on every later
            call. Returned once; never retrievable again.
        assigned_policy:
          $ref: '#/components/schemas/RunnerAssignedPolicy'
          x-stability: stable
    RunnerAssignedPolicy:
      type: object
      description: >-
        The policy assigned to one runner. agentsfleet delivers it to the host
        on enrollment and on every heartbeat. The host never declares its own
        policy.
      required:
        - sandbox_tier
        - network_policy
        - registry_allowlist
        - worker_count
      properties:
        sandbox_tier:
          $ref: '#/components/schemas/RunnerSandboxTier'
        network_policy:
          $ref: '#/components/schemas/RunnerNetworkPolicy'
        registry_allowlist:
          type: array
          description: >-
            Operator registry baseline merged into each lease's egress
            allowlist. Empty = the runner substitutes its default registry set.
            Entries are `host[:port]` names; at most 32.
          maxItems: 32
          items:
            type: string
        worker_count:
          type: integer
          description: >-
            Concurrent workers on the host. Clamped server-side into [1, 64];
            the stored (clamped) value is echoed back.
          minimum: 1
          maximum: 64
    ErrorBody:
      type: object
      description: RFC 7807 problem detail error response (application/problem+json)
      required:
        - docs_uri
        - title
        - detail
        - error_code
        - request_id
      properties:
        docs_uri:
          type: string
          format: uri
          description: Stable link to documentation for this error code
          example: https://docs.agentsfleet.net/api-reference/error-codes#UZ-AGT-009
        title:
          type: string
          description: Short human-readable label, same for every occurrence of this code
          example: Fleet not found
        detail:
          type: string
          description: Instance-specific context describing what went wrong
          example: No fleet with id 'abc123' in this workspace.
        error_code:
          type: string
          description: Machine-readable error code
          example: UZ-AGT-009
        request_id:
          type: string
          description: Correlation ID for this request
        current_state:
          type: string
          description: >-
            Resource state that blocked the requested change. Present only on
            409 responses.
          example: paused
        user_message:
          type: string
          description: >
            Plain message safe to show to a user. Present only when an error
            defines one.


            Use `detail` or `title` when this field is absent.
          example: >-
            We couldn't find that Fleet. It may have been deleted, or the ID
            doesn't match one in this workspace.
        etag:
          type: string
          description: >-
            Resource version returned on 412 responses so the caller can refetch
            and retry.
    RunnerSandboxTier:
      type: string
      description: >-
        Isolation strength the operator assigns to a runner. The host applies it
        and reports what it can deliver. A host that cannot meet the assignment
        is marked degraded and receives no work. Only tiers with real
        enforcement are assignable.
      enum:
        - landlock_full
        - container_nested
        - dev_none
    RunnerNetworkPolicy:
      type: string
      description: >-
        Network access assigned to a runner's sandboxed work. `allow_all` allows
        all outbound traffic. `deny_all_egress` allows none. `allow_list_egress`
        limits outbound traffic to an approved list. That mode is not available
        yet; a runner assigned it is marked degraded and refuses work.
      enum:
        - allow_all
        - deny_all_egress
        - allow_list_egress
  responses:
    Error:
      description: RFC 7807 problem detail error response
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Obtain a token via the CLI auth flow (POST /v1/auth/sessions) or GitHub
        OAuth

````