Operate Channels

Inspect authentication, routing, deliveries, and resulting Runs for a deployed Channel.

Before you begin

Request channel:read to inspect deliveries. Keep the Auth Provider, Agent labels and selector, and customer-identity model available while troubleshooting. Use canonical CRNs so similarly named resources in other namespaces are not confused.

Steps

  1. Verify the Channel CRN, protocol, visibility, and deployed revision.
  2. Verify the selector and follow the matched Agent references shown by Console.
  3. Inspect recent deliveries for direction, deduplication status, authentication failures, and Run receipts.
  4. Retrieve a specific message when payload-level evidence is required.
  5. Follow the resulting Run to inspect pinned authority and durable execution.
MethodEndpoint suffixOperation
GET/channels or /channels/:channelList or inspect deployed Channels
POST/channels/:channel/messagesSend an outbound ChannelMessage through protocol.send
GET/channels/:channel/messages/:messageIdInspect one delivery receipt
GET/channels/:channel/eventsRead bounded Channel events

All suffixes above follow /v1/namespaces/:namespace. Public custom ingress uses ANY /v1/channels/:tenant/:namespace/:channel/*. OpenAI Chat Completions and Anthropic Messages use POST /v1/chat/completions and POST /v1/messages; Constal lazily registers those platform implementations as ordinary tenant Channel Resources during authenticated discovery or first use. Their selectors still require explicit Agent opt-in labels, and they normalize into the same canonical event and Run model.

Provider delivery isolation

Verified provider deliveries take the same ingress path as every Channel. The subscription audience is read for each delivery, and the delivery is forwarded to each tenant's Channel independently, down to its Session's durable write, before it is acknowledged. A recipient that fails in a way a retry can fix is retried on its own, from the step that failed. Redelivery reuses a source-qualified delivery ID, so a Session records each event once.

Removing a subscription or disabling its Channel affects only that tenant's route. The dispatcher skips removed recipients and the receiving Channel checks membership again before authentication. GitHub Channel authentication also rechecks the tenant's current installation connection, so disconnecting one tenant does not disconnect another tenant using the same GitHub account. Credential resolution uses the authenticated principal, tenant, or customer selected by the Resource's declared binding owner—there is no installer or tenant fallback for personal credentials.

Ingress is at-least-once transport with durable deduplication, not a promise that an arbitrary external side effect executes exactly once. Existing Channel canonical event IDs and Resource recovery contracts remain the execution boundary. A delivery's audience is bounded to 1,024 recipients; exceeding it fails the delivery rather than silently truncating recipients. A recipient still failing after about four days of retries is recorded for operators.

Verify

A healthy delivery has authenticated principal evidence, a canonical event id, a selector-matched Agent, pinned Channel admission, and a durable receipt. Duplicate input should return the recorded outcome rather than creating a second Run. Authentication failures should stop before Channel code executes.

Next steps

Read Run operations for downstream execution controls or Agent operations for target bindings.