PAT or OAuth2
Bearer PATs for the CLI and partner agents. OAuth2 client credentials for server-to-server. Both resolve to the same Principal, so authorization is evaluated identically either way.
The portal, the CLI, and the MCP server are all clients of the same api.capitalsource.ai/v1. Open a CSG-1003 with curl. Stream the intake turn. Read your usage in a one-liner. The OpenAPI file in the repo is the spec your client generates against.
CapitalSource Agent Harness · Processor pilot
The CapitalSource Agent Harness gives the Processor pilot a durable task record, scoped execution permissions, and explicit action approvals. Use REST or the TypeScript SDK to bring those controls into your own application.
Pilot setup includes model routing and pricing, a Slack connection, and an enabled workspace. Start in shadow mode before approving delivery.
The boring infrastructure brokers and funders shouldn't have to think about. We handle it once at the gateway so your client code stays simple.
Bearer PATs for the CLI and partner agents. OAuth2 client credentials for server-to-server. Both resolve to the same Principal, so authorization is evaluated identically either way.
Token-spending POSTs accept an Idempotency-Key header. Replay the same key inside the 24h window and you get the cached response back instead of a second charge.
Conversational intake turns stream over Server-Sent Events as a discriminated union. Each frame names its type on the event line, so a client can narrow without guessing.
The surface is described by docs/openapi/v1.yaml, versioned in the repo. redocly lint is a CI gate, and the TypeScript SDK types are generated from that same file.
Every call carries an organization_id via the Principal. Wrong-org access is 404 by default, and a CI gate asserts isolation on every tenant-scoped endpoint.
Five shipping groups and one roadmap group, badged so nothing is ambiguous. The application and capability endpoints are mirrored in the MCP server and the Recurser CLI, and all three forward to the same dispatch path. Byte-identical envelopes across the three surfaces are the design, not yet a live assertion — the parity suite under apps/core/test/parity/ has not been written.
Create, advance, qualify, certify, package. The CSG-1003 lifecycle.
The REST mirror of the MCP tools/call surface. One registry, both surfaces.
Mint and rotate machine credentials. PATs and OAuth clients resolve to one Principal.
Where the spend came from, split by the surface that produced it.
Liveness, readiness, and a smoke endpoint for orchestrators and uptime monitors.
Shapes we intend to ship, not counted above. None of these are routed today.
Conversational intake turns stream over Server-Sent Events. Every frame names its type on the event line and repeats it inside the JSON payload, so a client narrows the union without guessing. Six variants, and that is the whole contract.
Token chunks for live UI rendering.
A structured CSG-1003 field capture with its value.
A supporting document the borrower named in passing.
The gating engine could not route; a human takes over.
The gating result that closes the turn.
A provider or validation failure, with a retryable flag.
@capitalsource/sdk has types generated from the same OpenAPI file, typed errors, and Idempotency-Key handling built in. It is the package the portal, the CLI, and the MCP server all consume.
Not published yet — the package is private at 0.0.0 and is consumed inside the monorepo as workspace:*. Public release is on the roadmap.
import { CapitalSourceClient } from "@capitalsource/sdk";
const cs = new CapitalSourceClient({
baseUrl: process.env.CSG_CORE_URL!,
token: process.env.CSG_API_TOKEN!,
});
const app = await cs.createApplication();
const turn = cs.streamApplicationMessages(app.application_id, {
message: "Acme HVAC LLC, Texas, $150k WC",
});
for await (const ev of turn) {
if (ev.type === "text-delta") process.stdout.write(ev.delta);
}Sign up, mint a PAT, and open your first CSG-1003 with POST /v1/applications. There is no sandbox tier and no separate trial surface — the same endpoints back the REST API, the MCP server, the CLI, and the portal.