Channels
Authenticate inbound traffic, normalize canonical events, and dispatch them to Agents.
A Channel is an immutable, CRN-addressed ingress and delivery Resource. It pins a protocol implementation, Auth Provider, Agent selector, customer-identity requirement, Resource bindings, attached Policy, analytics declarations, and executable revision. Channel code never receives Credential material directly.
For every accepted message, the selector must match a current Agent identity. A new Session uses that identity or its deterministic canary assignment. An existing Session keeps its previously pinned Agent identity only when the same logical Agent is still a current selector match and the pinned identity itself carries the required opt-in labels. Every Agent also has a platform-owned constal.ai/version label. A Dynamic UI derives an Agent selector from all labels on its pinned Agent, so the UI can continue an older Resource snapshot of the same Agent version but cannot cross into another version. Run evidence records both the current match and the exact Session-routed identity.
Choose a path
| Goal | Guide |
|---|---|
| Publish a custom protocol or webhook | Deploy a Channel |
| Inspect routing, delivery, or authentication | Operate Channels |
| Understand the target behavior | Agents |
| Follow the resulting execution | Runs |
Choose an interface
| Interface | Use it for |
|---|---|
| Console | Reviewing Channels, Auth Providers, routing, and deliveries |
| SDK | Authoring protocol translation and ingress authentication code |
| CLI | Deploying packages and operating messages and events |
| Platform API | Connecting an external application to a deployed Channel |
Request flow
request → Auth Provider → Channel receive → canonical event → Agent → Run → Channel respondThe Console shows the Channel-owned endpoint, selector, and currently matched Agents. Copy the Channel CRN—not only its local id—when configuring Policy or external automation.
The platform-provided OpenAI Chat Completions and Anthropic Messages adapters are lazily registered through the same Resource registry and appear automatically during authenticated discovery or first use. They select only Agents carrying the corresponding channels.constal.ai/openai=enabled or channels.constal.ai/anthropic=enabled label; Constal does not expose an Agent merely because the adapter exists.
Custom executable code uses channel() for protocol translation and authProvider() for pre-Channel identity evidence. The SDK does not create or administer custom deployed Channels. Package those definitions, deploy them through the common deployment API, then use namespace-scoped message and event endpoints for operation. See Build Channels and Auth Providers.
Next steps
For a built-in adapter, label an intended Agent and verify the selector match. For a custom protocol, deploy its Channel and Auth Provider packages. Then send a test message and inspect the resulting delivery and Run.