Connect your agent

Give AgentLasso an HTTPS endpoint that runs your agent on one message, and you can grade a test case against your agent's live answer from the rubric editor and chat with your agent in the Live Sandbox. It's the same contract as the CI example, so one small adapter covers both.

The contract

AgentLasso sends:

http
POST <your endpoint>content-type: application/json<your auth header>
{  "input": "I want my money back for order 44182",  "messages": [{ "role": "user", "content": "I want my money back for order 44182" }],  "test_case_id": "…",  "source": "agentlasso-preview"}
FieldMeaning
inputThe message to answer: a test case's input, or the Live Sandbox's latest message.
messagesLive Sandbox only: the conversation so far (user / assistant turns).
test_case_idWhen running a test case.
sourceagentlasso-test (connection test), agentlasso-preview (rubric editor) or agentlasso-sandbox. Use it to tag or filter these requests, and to keep them out of your production traces.

Your endpoint replies 200 with:

json
{  "output": "Your refund of $89 is on its way.",  "tool_calls": [    { "name": "orders.lookup", "arguments": { "order_id": "44182" } },    { "name": "stripe.refund", "arguments": { "amount_cents": 8900 } }  ]}
  • output: the agent's final reply (a string, or null).
  • tool_calls: the tools it called, in order. arguments may be an object or a JSON string (common with OpenAI-style agents).
  • At least one of output or tool_calls is required.

These are test calls, not real customers. Have your endpoint run tools that book, pay, cancel or send email in a dry-run mode for them, while still listing the calls in tool_calls.

Set it up

In Settings → Your agent:

  1. Endpoint URL: the final HTTPS URL. Redirects aren't followed, so use the URL your agent actually answers on.
  2. Auth header (optional): a header name and value your endpoint checks, e.g. Authorization / Bearer …. The value is stored server-side and never shown again.
  3. Test connection sends a sample message (editable) using the form as filled in, before you save. You'll see the reply and tool calls, or a specific error:
    • HTTP 401/403: check the auth header;
    • HTTP 404/405: check the URL (it must accept POST);
    • "isn't JSON" or a missing field, with an excerpt of what came back;
    • a redirect (use the final URL), a timeout, or an unreachable host.
  4. Save.

Use it

  • Rubric editor → Try it before saving → Run my agent: sends the test case's input to your agent and grades its answer with your draft checks. Edit checks and the same answer re-grades instantly; Run again asks your agent again.
  • Live Sandbox: chat with your agent. Every tool it reports calling appears in the timeline, and you can save the session as a golden test case.

Security

AgentLasso calls your endpoint from its servers, never from the browser:

  • HTTPS only; private, local and cloud-metadata addresses are refused;
  • redirects aren't followed;
  • 30-second timeout and a 1 MB reply limit;
  • at most 20 calls a minute per user;
  • the auth header value is stored where only the server can read it.

Self-hosting: set AGENT_ENDPOINT_ALLOW_PRIVATE=true to allow http:// and private addresses (e.g. an agent on your own network). Leave it unset if untrusted users can sign up.

Next

Gate every release on your golden tests: Run golden tests in CI.