Operate: running Managed Agents in production
Most of the other Managed Agents cookbooks focus on the agent loop itself, getting an agent to do something useful against a fixture. This one is about the machinery around that loop, the pieces you need before you can put a Managed Agents app in front of real users:
- MCP toolsets instead of custom tools, when your agent needs to talk to a SaaS API without round-tripping every call through your application.
- Vaults to hold per-end-user credentials, so each user's GitHub / Linear / Slack tokens stay separate from everyone else's and your audit trail is clean.
- Webhooks to drive human-in-the-loop work without holding a long-lived HTTP connection open the whole time.
- Resource lifecycle verbs (list, retrieve, update, archive, delete) for managing what your workspace accumulates over time.
- Inference geography pinning (
inference_geo) when compliance requires model requests to run in a specific region.
We'll build one end-to-end flow that touches the first four, then close with the geography pin: create a vault for a fictional end user, attach a GitHub MCP credential to it, run an agent session that uses the credential server-side, show the webhook handler you'd register to drive the same session from a real production server, and walk through the management verbs you'd use to clean up afterwards.
ly from inside the sandbox, with no round-trip through your application, Juglow proxies the calls, the server responds, and the agent keeps going. The vast majority of public SaaS APIs (GitHub, Slack, Linear, Stripe, Notion, Salesforce, Asana...) either already have an MCP server or can be wrapped in one in an afternoon, and any of them are good MCP candidates.
Rule of thumb: if the service is reachable over the public internet with a bearer token, an MCP toolset will work. If it's only reachable from inside your own network, use a custom tool instead, which is what the gate notebook covers.
y scroll-fade-size-6 focus-visible:outline-none">
agent = client.beta.agents.create(
name="cookbook-operate",
model=MODEL,
system="You navigate GitHub repositories on behalf of the logged-in user.",
mcp_servers=[
{
"type": "url",
"name": "github",
"url": "https://api.githubcopilot.com/mcp/",
}
],
tools=[
{
"type": "mcp_toolset",
"mcp_server_name": "github",
"default_config": {
"enabled": True,
"permission_policy": {"type": "always_allow"},
},
}
],
)
env = client.beta.environments.create(
name="cookbook-operate-env",
config={"type": "cloud", "networking": {"type": "unrestricted"}},
)
session = client.beta.sessions.create(
environment_id=env.id,
agent={"type": "agent", "id": agent.id, "version": agent.version},
vault_ids=[vault.id],
title="Operate demo",
)
print(f"session: {session.id}")
4. Run a turn as the end user
Every resource in the API, agents, environments, sessions, vaults, credentials, exposes the same five-verb pattern:
list
,
retrieve
,
update
,
archive
, and (for some)
delete
. We'll demonstrate the full set on agents, then list the verbs available on each other resource as a quick reference.
archive vs delete: archive keeps the record around for audit and retrieval but tears down any live container and stops the resource counting against your workspace quotas. delete removes the record entirely. For most workflows archive is the right call; reach for delete only when you specifically need the record gone (e.g. test cleanup).