[{"data":1,"prerenderedAt":429},["ShallowReactive",2],{"navigation_docs":3,"-guide-database":168,"-guide-database-surround":424},[4,146],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":36},"Guide","i-lucide-book-open","\u002Fguide","1.guide",[10,14,37,55,59,63,67,71,75,79,83,87,109,134,138,142],{"title":11,"path":12,"stem":13},"What is Agent Zero?","\u002Fguide\u002Fintroduction","1.guide\u002F1.introduction",{"title":15,"icon":16,"path":17,"stem":18,"children":19,"page":36},"API","i-lucide-plug","\u002Fguide\u002Fapi","1.guide\u002F10.api",[20,24,28,32],{"title":21,"path":22,"stem":23},"API overview","\u002Fguide\u002Fapi\u002Foverview","1.guide\u002F10.api\u002F1.overview",{"title":25,"path":26,"stem":27},"Define endpoints","\u002Fguide\u002Fapi\u002Fdefine-endpoints","1.guide\u002F10.api\u002F2.define-endpoints",{"title":29,"path":30,"stem":31},"Use the API from a client","\u002Fguide\u002Fapi\u002Fuse-from-client","1.guide\u002F10.api\u002F3.use-from-client",{"title":33,"path":34,"stem":35},"Protect endpoints","\u002Fguide\u002Fapi\u002Fprotect-endpoints","1.guide\u002F10.api\u002F4.protect-endpoints",false,{"title":38,"icon":39,"path":40,"stem":41,"children":42,"page":36},"Authentication","i-lucide-lock","\u002Fguide\u002Fauthentication","1.guide\u002F11.authentication",[43,47,51],{"title":44,"path":45,"stem":46},"Authentication overview","\u002Fguide\u002Fauthentication\u002Foverview","1.guide\u002F11.authentication\u002F1.overview",{"title":48,"path":49,"stem":50},"GitHub OAuth","\u002Fguide\u002Fauthentication\u002Foauth","1.guide\u002F11.authentication\u002F2.oauth",{"title":52,"path":53,"stem":54},"Permissions","\u002Fguide\u002Fauthentication\u002Fpermissions","1.guide\u002F11.authentication\u002F3.permissions",{"title":56,"path":57,"stem":58},"Organizations","\u002Fguide\u002Forganizations","1.guide\u002F12.organizations",{"title":60,"path":61,"stem":62},"Frontend","\u002Fguide\u002Ffrontend","1.guide\u002F13.frontend",{"title":64,"path":65,"stem":66},"Mails","\u002Fguide\u002Fmails","1.guide\u002F14.mails",{"title":68,"path":69,"stem":70},"Internationalization","\u002Fguide\u002Finternationalization","1.guide\u002F15.internationalization",{"title":72,"path":73,"stem":74},"Deployment","\u002Fguide\u002Fdeployment","1.guide\u002F16.deployment",{"title":76,"path":77,"stem":78},"Tech stack","\u002Fguide\u002Ftech-stack","1.guide\u002F2.tech-stack",{"title":80,"path":81,"stem":82},"Installation","\u002Fguide\u002Finstallation","1.guide\u002F3.installation",{"title":84,"path":85,"stem":86},"Environment variables","\u002Fguide\u002Fenvironment-variables","1.guide\u002F4.environment-variables",{"title":88,"icon":89,"path":90,"stem":91,"children":92,"page":36},"Codebase","i-lucide-folder-tree","\u002Fguide\u002Fcodebase","1.guide\u002F5.codebase",[93,97,101,105],{"title":94,"path":95,"stem":96},"Codebase structure","\u002Fguide\u002Fcodebase\u002Fstructure","1.guide\u002F5.codebase\u002F1.structure",{"title":98,"path":99,"stem":100},"Dependencies","\u002Fguide\u002Fcodebase\u002Fdependencies","1.guide\u002F5.codebase\u002F2.dependencies",{"title":102,"path":103,"stem":104},"Formatting and linting","\u002Fguide\u002Fcodebase\u002Fformatting-linting","1.guide\u002F5.codebase\u002F3.formatting-linting",{"title":106,"path":107,"stem":108},"Agent Skills","\u002Fguide\u002Fcodebase\u002Fagent-skills","1.guide\u002F5.codebase\u002F4.agent-skills",{"title":110,"icon":111,"path":112,"stem":113,"children":114,"page":36},"Architecture","i-lucide-layers","\u002Fguide\u002Farchitecture","1.guide\u002F6.architecture",[115,118,122,126,130],{"title":110,"path":116,"stem":117},"\u002Fguide\u002Farchitecture\u002Foverview","1.guide\u002F6.architecture\u002F1.overview",{"title":119,"path":120,"stem":121},"State machine","\u002Fguide\u002Farchitecture\u002Fstate-machine","1.guide\u002F6.architecture\u002F2.state-machine",{"title":123,"path":124,"stem":125},"Execution boundary","\u002Fguide\u002Farchitecture\u002Fexecution-boundary","1.guide\u002F6.architecture\u002F3.execution-boundary",{"title":127,"path":128,"stem":129},"Issue-to-PR workflow","\u002Fguide\u002Farchitecture\u002Fissue-to-pr","1.guide\u002F6.architecture\u002F4.issue-to-pr",{"title":131,"path":132,"stem":133},"Adding a capability","\u002Fguide\u002Farchitecture\u002Fadding-a-capability","1.guide\u002F6.architecture\u002F5.adding-a-capability",{"title":135,"path":136,"stem":137},"Repository policy","\u002Fguide\u002Fconfiguration","1.guide\u002F7.configuration",{"title":139,"path":140,"stem":141},"Safety model","\u002Fguide\u002Fsafety","1.guide\u002F8.safety",{"title":143,"path":144,"stem":145},"Database","\u002Fguide\u002Fdatabase","1.guide\u002F9.database",{"title":147,"icon":148,"path":149,"stem":150,"children":151,"page":36},"Reference","i-lucide-book-marked","\u002Freference","2.reference",[152,156,160,164],{"title":153,"path":154,"stem":155},"CLI","\u002Freference\u002Fcli","2.reference\u002F1.cli",{"title":157,"path":158,"stem":159},"Model providers","\u002Freference\u002Fmodel-providers","2.reference\u002F2.model-providers",{"title":161,"path":162,"stem":163},"Source-control providers","\u002Freference\u002Fsource-control-providers","2.reference\u002F3.source-control-providers",{"title":165,"path":166,"stem":167},"Sandbox providers","\u002Freference\u002Fsandbox-providers","2.reference\u002F4.sandbox-providers",{"id":169,"title":143,"body":170,"description":176,"extension":418,"links":419,"meta":420,"navigation":421,"path":144,"seo":422,"stem":145,"__hash__":423},"docs\u002F1.guide\u002F9.database.md",{"type":171,"value":172,"toc":412},"minimark",[173,177,182,202,225,255,268,301,305,311,336,345,365,379,383,405,408],[174,175,176],"p",{},"Agent Zero's runtime is deliberately persistence-free. The repository contains exactly one database — Postgres, used by the dashboard's authentication session store — and one package that owns it.",[178,179,181],"h2",{"id":180},"persistence-boundary","Persistence boundary",[174,183,184,185,189,190,193,194,197,198,201],{},"Postgres has one owner: ",[186,187,188],"code",{},"packages\u002Fdatabase",". It declares the tables in Drizzle (",[186,191,192],{},"src\u002Fschema\u002F","), opens the connection pool (",[186,195,196],{},"src\u002Fclient.ts","), and keeps the migrations as reviewable, checked-in SQL under ",[186,199,200],{},"drizzle\u002F",". Nothing else constructs a client or names a column.",[174,203,204,205,208,209,211,212,214,215,218,219,221,222,224],{},"The split from ",[186,206,207],{},"packages\u002Fauth"," is the same rule applied one level down. Authentication policy and the store it happens to use change for different reasons and are reviewed by different eyes: ",[186,210,188],{}," knows nothing about sign-in, sessions, or invitations beyond the shape of the rows, and ",[186,213,207],{}," states what is allowed and hands ",[186,216,217],{},"drizzleAdapter"," a client it did not open. The dependency runs one way, and ",[186,220,188],{}," must never import ",[186,223,207],{},".",[174,226,227,228,231,232,231,235,238,239,242,243,246,247,250,251,254],{},"Declaring the schema here rather than letting Better Auth's own migration CLI generate it is what makes ",[186,229,230],{},"user",", ",[186,233,234],{},"session",[186,236,237],{},"account",", and ",[186,240,241],{},"verification"," diffable like any other change. Column names are load-bearing: the Better Auth adapter maps its models by name, so a rename that type-checks can still break sign-in at runtime. Migrations are generated (",[186,244,245],{},"db:generate",") and applied (",[186,248,249],{},"db:migrate",") from the database package alone, and ",[186,252,253],{},"createDatabase"," is a factory rather than a module-level singleton so importing the package never opens a socket — the composition root owns the pool's lifetime.",[174,256,257,260,261,264,265,267],{},[186,258,259],{},"DATABASE_URL"," is the connection string a deployment sets. ",[186,262,263],{},"AUTH_DATABASE_URL"," is still accepted, because the store used to live inside ",[186,266,207],{}," and a deployment configured before the split must not fail to start on upgrade.",[174,269,270,271,274,275,278,279,274,282,285,286,289,290,293,294,296,297,300],{},"The same rule covers the tables a Better Auth plugin brings with it. ",[186,272,273],{},"invite"," and ",[186,276,277],{},"invite_use"," (Better Enrollment) are declared here alongside ",[186,280,281],{},"organization",[186,283,284],{},"member",", so a deployment that never enables the feature still migrates them and simply never writes to them — the alternative is a schema that depends on which flags were set when the migration ran. Two of their columns are deliberate exceptions to the repository's usual habits: an accepted invitation is a permanent audit record, so it carries no foreign key to the organization, team, or account it names and denormalizes ",[186,287,288],{},"inviter_name","\u002F",[186,291,292],{},"inviter_email"," in order to survive their deletion; and ",[186,295,277],{}," carries only ",[186,298,299],{},"used_at"," rather than the shared timestamp pair, because a use is a point-in-time fact that must not look rewritable.",[178,302,304],{"id":303},"setup","Setup",[174,306,307,308,310],{},"Point ",[186,309,259],{}," at a Postgres database, then apply the schema once before the first run:",[312,313,318],"pre",{"className":314,"code":315,"language":316,"meta":317,"style":317},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","aube run db:migrate\n","bash","",[186,319,320],{"__ignoreMap":317},[321,322,325,329,333],"span",{"class":323,"line":324},"line",1,[321,326,328],{"class":327},"sBMFI","aube",[321,330,332],{"class":331},"sfazB"," run",[321,334,335],{"class":331}," db:migrate\n",[174,337,338,340,341,344],{},[186,339,245],{}," only needs to run again after editing ",[186,342,343],{},"packages\u002Fdatabase\u002Fsrc\u002Fschema\u002F",":",[312,346,348],{"className":314,"code":347,"language":316,"meta":317,"style":317},"aube --filter @agent-zero\u002Fdatabase run db:generate\n",[186,349,350],{"__ignoreMap":317},[321,351,352,354,357,360,362],{"class":323,"line":324},[321,353,328],{"class":327},[321,355,356],{"class":331}," --filter",[321,358,359],{"class":331}," @agent-zero\u002Fdatabase",[321,361,332],{"class":331},[321,363,364],{"class":331}," db:generate\n",[174,366,367,369,370,372,373,375,376,378],{},[186,368,263],{}," is still read when ",[186,371,259],{}," is unset, so a deployment configured before the store moved into ",[186,374,188],{}," keeps starting; prefer ",[186,377,259],{}," for new ones.",[178,380,382],{"id":381},"task-history-is-not-in-postgres","Task history is not in Postgres",[174,384,385,386,389,390,393,394,397,398,274,401,404],{},"Task history persists through a narrow ",[186,387,388],{},"KeyValueStorage"," contract backed by the ViteHub KV Runtime Helper (registered from ",[186,391,392],{},"apps\u002Fdashboard\u002Fnuxt.config.ts","): filesystem-backed ",[186,395,396],{},"fs-lite"," by default, with Cloudflare KV, Deno KV, or Upstash dropping in as driver configuration without touching application code. A hosted deployment preset resolves the host's own driver instead of the filesystem one, so a Vercel deployment needs ",[186,399,400],{},"KV_REST_API_URL",[186,402,403],{},"KV_REST_API_TOKEN"," for its Upstash store.",[174,406,407],{},"Records are redacted before they are written and never contain review input or checkout paths, so task history cannot become a credential or filesystem leak.",[409,410,411],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":317,"searchDepth":413,"depth":413,"links":414},2,[415,416,417],{"id":180,"depth":413,"text":181},{"id":303,"depth":413,"text":304},{"id":381,"depth":413,"text":382},"md",null,{},true,{"title":143,"description":176},"JCW0xyoqswcKEFAOxdRrW3QcnrwY3BaufUjRecYeX8o",[425,427],{"title":139,"path":140,"stem":141,"description":426,"children":-1},"Agent Zero is built so that the safe path is the default path and every escalation is explicit, auditable, and reversible.",{"title":153,"path":154,"stem":155,"description":428,"children":-1},"The zero CLI is the local entry point: it parses arguments with @bomb.sh\u002Fargs and renders with @clack\u002Fprompts. Inside the repository, run it as aube run zero \u003Ccommand>.",1787482151511]