# SDK export reference

> Find the public builders, runtime interfaces, resource contracts, protocol helpers, and validation families exported by @constal/sdk.

Import from `@constal/sdk`; deep module paths are not public API. The following recipes show the exported families in their intended context.

## Executable definitions {#definitions}

```ts
import {
  agent, subtask,
  validateTool, validateView, validatePartitionFn, validateFoldFn,
  channel, authProvider, policy, credentialProvider,
} from "@constal/sdk";
```

`agent` and `subtask` define runtime work. Validators register Tools, views, and Stage functions. `channel` and `authProvider` own ingress translation and evidence. `policy` defines deterministic authorization. `credentialProvider` defines user-authored Credential lifecycle packages.

Connection authors use the same public root:

```ts
import {
  gateway, trainingProvider,
  type GatewayContext, type GatewayRequest,
  type CredentialProviderContext,
} from "@constal/sdk";
```

`gateway` defines model, MCP, API, and other Connection packages. `trainingProvider` adds the standard asynchronous training capability to a Connection package. Both return validated Connection packages ready for the managed deployment workflow.

## Runtime and Resources {#runtime-resources}

```ts
import {
  type Ctx,
  resourceName, parseResourceName,
  authProviderName, credentialProviderName, credentialName,
  policyName, customerTenantName, bindingName, scopedBindingKey,
} from "@constal/sdk";

const model = resourceName({
  environment: "production", tenant: "acme", namespace: "default",
  kind: "model", path: "support",
});
const parts = parseResourceName(model);
const binding = scopedBindingKey("github");
```

Use a narrow validator whenever a field expects a specific CRN kind. `Ctx` exposes the seven Agent primitives plus Resource invocation, replay-safe local steps, capability requests, analytics, accepted bindings, and immutable Run identity.

### Session schedules {#schedules}

`Ctx` also exposes `schedule(name, options)`, `cancelSchedule(name)`, and `listSchedules(options?)`. Import `ScheduleOptions`, `Schedule`, `ScheduleTrigger`, `ScheduleCancellation`, `SchedulePage`, and `ScheduleOccurrencePage` from the public SDK root. Scheduled invocations expose their provenance through `ctx.run.schedule`. See [Schedule Agent follow-ups](/docs/agents/schedules.md) for the complete contract.

UI build tooling is exported from the same public root:

```ts
import {
  uiBundle, uiBundleManifest, hashValue,
  type UiBundle, type UiHandler, type UiRuntimeContext,
} from "@constal/sdk";
```

`uiBundle()` validates and normalizes final runnable ESM plus base64 assets for stateless or durable execution. `hashValue()` computes the canonical bundle and manifest hashes pinned by a `ui` Resource. These helpers author artifacts; publication still uses the normal Platform Resource API. Follow [Build and publish Dynamic UIs](/docs/resources/dynamic-uis.md) for the end-to-end Sandbox, CAS, and publication workflow.

## Capability helpers {#capability-helpers}

```ts
import {
  opTool, opTools, webFetch,
  MEMORY_OPERATION_DECLARATIONS,
  analyticsEvent, hashValue,
} from "@constal/sdk";

const githubTools = opTools("github", ["issue.get", "issue.create"]);
const search = opTool("memory", "search", { name: "search_memory" });
const event = analyticsEvent({ id: "support.resolved", version: "1", dimensions: ["queue"], metrics: [] } as const);
const identity = await hashValue({ event: event.id, version: event.version });
```

Model protocol and network-policy helpers are exported from the same root. Use them only for the Resource contract they validate.

## Recovery-aware errors {#errors}

```ts
import { OutcomeUnknown, PolicyDecisionFailed } from "@constal/sdk";

try {
  return await ctx.invoke(ctx.resources.payments!, "charge", request);
} catch (error) {
  if (error instanceof OutcomeUnknown) throw error; // reconcile; never retry blindly
  if (error instanceof PolicyDecisionFailed) return { refused: true };
  throw error;
}
```

Stable error classes preserve recovery meaning. Connection code additionally uses `ApiError`, `IntegrationRequestNotSent`, and `TerminalIntegrationFailure` to state what is known after an upstream failure. Deployment manifests, Platform API payloads, and Console operations are separate contracts; do not invent them from SDK types.
