agent.yml tells Onecortex which runtime your agent needs and which object in your code is the agent. It is the only file you add to your repository. Onecortex never writes to your repository and never modifies your code.
The smallest agent.yml
agent.yml
agent in agent.py. Dependencies are found automatically, and no configuration is required.
Where the file goes
Putagent.yml at the root of the folder Onecortex builds from: the repository root, or the agent folder you pick when you create the agent. The name agent.yaml also works. If both exist in the same folder, validation fails with manifest_ambiguous: keep one.
Paths inside agent.yml are relative to that folder and cannot leave it. An absolute path or any .. segment fails with path_escapes_context.
Fields
string
required
The version of this file’s format. The only accepted value is
v1.agent.yml
string
required
The language runtime your agent runs on.
A value that is not in the list fails with
enum_invalid, which suggests the closest accepted value.string
required
The file and the name of the agent object in it. The separator depends on the language:
TypeScript and JavaScript entrypoints accept
.ts, .mts, .cts, .js, .mjs and .cjs. Onecortex recognises the object by what it is, not by what you call it. See Entrypoints for how each framework’s agent object is found.If you use the other language’s separator, validation suggests the corrected value. If the file does not exist, it lists the files it found. If the name is not defined at the top level of the file, it lists the names that are.string
default:"found automatically"
The file your dependencies are installed from. Leave it out and Onecortex takes the first of these that exists in the folder:
Lockfiles come first because they hold the versions you actually resolved. See Dependencies.
string
The framework your agent uses, for your own records and the dashboard. It does not change how your agent is run: Onecortex recognises the framework from the object itself.Accepted:
langgraph, langchain, crewai, strands, llamaindex, openai-agents, autogen, pydantic-ai, mastra, vercel-ai, langchain-js, other.string[]
default:"[]"
Operating system packages to install into the image. Available:
ffmpeg, poppler-utils. Anything else fails with system_package_not_allowed.agent.yml
string[]
default:"[]"
Shell commands to run after dependencies are installed, in order, in one build step. Use them for a step your agent needs at build time, such as downloading a model file.
agent.yml
string[]
default:"[]"
The names of configuration entries your agent cannot run without. Names only, never values: values go in your agent’s configuration in Onecortex. A name listed here that is not configured shows a warning before you deploy.
string[]
default:"[]"
The names of configuration entries your agent can use when they are set.
A complete example
- Python
- TypeScript
agent.yml
Rules that apply to the whole file
- Unknown keys are ignored with a warning, not a failure:
Unknown key `mode` will be ignored. - Values that look like credentials fail validation.
agent.ymllives in your repository, where everyone with access can read it. A value shaped like a well known API key format, a private key, a long random string, or any value under a key named likeSECRET,TOKEN,PASSWORDorAPI_KEYfails withcredential_detected. Put the secret in your agent’s configuration and list its name underenv.required. _onecortex/is reserved. A folder of that name in your build folder fails withreserved_directory_present.
Validation errors
Every mistake names the line, what was found, what was expected, and a corrected snippet you can copy. The full text of each is on the errors page.Related
- Quickstart: deploy your first agent.
- Entrypoints: how the agent object is found.
- Configuration and secrets: where values go.