Aion-Principal-Selector must be updated before using this contract.
Choose the attribution mode
For an inbound request, send one attribution header with the Version bearer. Aion rejects both headers together, duplicate values, empty values, and malformed caller IDs. An invalid or expired signed carrier does not select direct or deployment-self mode.
Aion rejects the retired
Aion-Principal-Selector header. User requests without callback headers retain user authority.
Version callbacks without attribution or an explicit internal selector use the deployment’s current daemon identity.
The former POST /auth/tokens/exchange endpoint and AgentIdentity bearer tokens are no longer supported.
Keep the Version bearer for callbacks; Aion resolves and authorizes the acting identity from the attribution mode below.
Forward Aion usage attribution
Authorization. Missing or stale executor bindings fail explicitly.
Signed contextual callbacks are supported by model, MCP, A2A, and File mutation ingress.
Report a direct caller
Direct callbacks require an active deployment with an assigned daemon identity. Aion resolves the current assignment on each call: that daemon supplies authorization, agent, and execution identity. The deployment’s organization pays. Reassigning or clearing the daemon affects subsequent calls without changing earlier usage records. For a direct request with no identifiable caller, reportExternalAnonymous with principal ID external-anonymous:
AnonymousSession, rather than merging it into ExternalAnonymous. For a known
Aion user, the following example encodes user ID 00000000-0000-0000-0000-000000000001:
contexts/get and context/get use the resolved sending identity’s caller bindings.
They do not grant access to every conversation owned by the receiving agent, or to the reported caller’s conversations.
Initiate work as the deployment
For work such as integration tests, use the Version bearer without an attribution header:daemon_identity_required.
Aion never executes these callbacks as a bare Version principal.
The SDK permits this mode only when no inbound runtime context or explicit attribution exists.
An active runtime context without attribution fails instead of silently selecting deployment-self mode.
An unidentified inbound caller still uses the explicit ExternalAnonymous ID, not this default.
Never remove invalid attribution to retry as the deployment.
Caller-ID format
Use the same canonical ID as the distribution extension’scallerId and the invocation JWT subject:
aion.core.principal.Principal.subject instead of maintaining a separate encoder.
Handle callback failures
daemon_identity_required: assign a daemon to the deployment before retrying. Do not select an arbitrary behavior’s daemon, create a new identity automatically, or fall back to the reported user’s credentials.- Invalid attribution: correct the header or obtain a new valid contextual invocation. Never drop an invalid carrier to retry in direct mode.
- Permission denial: grant the deployment daemon the required operation permission. The Project Agent role permits model execution and File creation in its organization, but does not grant File update, read, or delete.
type: "configuration_error" and
code: "daemon_identity_required". Streaming model calls can return HTTP 200 and carry those same details in an SSE
error event; clients must inspect the stream, not only the HTTP status.
File and MCP configuration failures use HTTP 409.
The Python SDK model helpers raise AionDaemonIdentityRequired from aion.core.exceptions, including during
synchronous or asynchronous stream consumption. Its retryable property is False: assign the deployment daemon
before retrying.