Connect your agent
Give AgentLasso an HTTPS endpoint that runs your agent on one message, and you can grade a test case against your agent's live answer from the rubric editor and chat with your agent in the Live Sandbox. It's the same contract as the CI example, so one small adapter covers both.
The contract
AgentLasso sends:
Your endpoint replies 200 with:
output: the agent's final reply (a string, ornull).tool_calls: the tools it called, in order.argumentsmay be an object or a JSON string (common with OpenAI-style agents).- At least one of
outputortool_callsis required.
These are test calls, not real customers. Have your endpoint run tools that book, pay, cancel or send email in a dry-run mode for them, while still listing the calls in tool_calls.
Set it up
In Settings → Your agent:
- Endpoint URL: the final HTTPS URL. Redirects aren't followed, so use the URL your agent actually answers on.
- Auth header (optional): a header name and value your endpoint checks, e.g.
Authorization/Bearer …. The value is stored server-side and never shown again. - Test connection sends a sample message (editable) using the form as filled in, before you save. You'll see the reply and tool calls, or a specific error:
- HTTP 401/403: check the auth header;
- HTTP 404/405: check the URL (it must accept
POST); - "isn't JSON" or a missing field, with an excerpt of what came back;
- a redirect (use the final URL), a timeout, or an unreachable host.
- Save.
Use it
- Rubric editor → Try it before saving → Run my agent: sends the test case's input to your agent and grades its answer with your draft checks. Edit checks and the same answer re-grades instantly; Run again asks your agent again.
- Live Sandbox: chat with your agent. Every tool it reports calling appears in the timeline, and you can save the session as a golden test case.
Security
AgentLasso calls your endpoint from its servers, never from the browser:
- HTTPS only; private, local and cloud-metadata addresses are refused;
- redirects aren't followed;
- 30-second timeout and a 1 MB reply limit;
- at most 20 calls a minute per user;
- the auth header value is stored where only the server can read it.
Self-hosting: set AGENT_ENDPOINT_ALLOW_PRIVATE=true to allow http:// and private addresses (e.g. an agent on your own network). Leave it unset if untrusted users can sign up.
Next
Gate every release on your golden tests: Run golden tests in CI.