Enable agent-requested retrieval
A retrieval token lets one agent environment read the Sessions that you grant, and nothing else. The pi extension uses it. First, meet the requirements in Capture pi work.-
Add these settings to the server’s private process environment. On EC2,
that’s
~/sediment-deploy/server.env:To grant several Sessions, setSEDIMENT_RETRIEVAL_SESSION_IDSto a JSON array of 1–32 Session identifiers instead. Set exactly one of the two. - Restart Sediment.
-
In the agent’s environment, set
SEDIMENT_RETRIEVAL_ENDPOINTto the API’s HTTPS URL andSEDIMENT_RETRIEVAL_TOKENto the token. If you granted several Sessions, also setSEDIMENT_RETRIEVAL_DISCOVERY=true. - Start pi from that environment.
server.env, or database credentials. The agent’s
model endpoint, not Sediment, decides where its next request goes.
Use the retrieval tools
With one granted Session, the agent callssediment_retrieve_context with a
question. The response contains up to eight exact captured parts, within a byte
budget of 4–64 KiB (16 KiB by default). The keyword selector skips reasoning
and repeated content. no_match doesn’t prove that the evidence is absent.
Discover a previous Session
With several granted Sessions, the agent first callssediment_discover_context with task keywords. To find the Sessions behind a
commit, it can also pass commit with repository_provider,
repository_host, repository_id, and commit_sha. Discovery returns up to
eight candidate Sessions, commit matches first. The agent then calls
sediment_retrieve_context with the chosen session_id and a narrower
question.
Discovery searches only the granted Sessions. A repository name, commit, or
model judgment can’t widen the grant.
Select exact evidence independently
The same token also registers tools that read evidence without a keyword query, for an agent or selector that picks parts itself:sediment_list_context_sessionslists the granted Session identifiers.sediment_evidence_inventorylists a Session’s Inference calls, without message content.sediment_evidence_manifestlists one call’s parts, with their types and roles.sediment_read_evidencefetches up to 32 selected parts.
Retrieval limits
A request over a limit fails as a whole. Evidence and report reads share two
workers, so a third concurrent read returns 503. The
API reference lists every field and
refusal reason, and ADRs 0021, 0022, 0025, and 0026 define the contracts.
Select and fetch evidence
To prepare a packet yourself, use the operator CLI. It calls your Sediment API with your operator login and never calls a model.-
Create a private directory outside the source repository:
-
List the Session’s Inference calls:
found: falsemeans that the deployment has no such Session. The inventory counts visible and quarantined calls separately. -
List the parts of one call, using its Fact identifier from the inventory:
The manifest lists input messages, then output messages, with each part’s type and reference, but not its content.
-
Save the parts that you need in
$EVIDENCE_DIR/references.json. Choose the captured goals, constraints, relevant tool calls, and tool results. Copy 1–32 references from the manifest. Indices start at zero: -
Fetch the parts into a path that doesn’t exist:
The CLI validates the whole response, then writes a mode
0600file. It refuses to overwrite an existing file. - Read the packet, and confirm that it covers the goal and constraints that the next agent needs. Note anything missing.