Cohort

Cohort is where agentic work gets designed, run and paid for, with nothing hidden. Your agents know the job before they start, stay on it, and hand you a receipt when they finish.

Sign in to your account.

What Cohort is, in more detail, no account needed.

You were signed out. Sign in again to keep going. Nothing on this page has been lost.
Cohort
–/
–budget ? ·
◆Runs ◈Workflows ▦Budget ⚿Connect ⚙Settings
–
≡Docs {}API reference
connecting…

No such project

Where to go

Runs

Every job this project's agents have done, and what is happening right now.

Right now

Recent

Runs

loading…
← Runs

Run

What the agent is doing

The rules, live

reading the rules…

Cost, live

reading…

Record

Every fact the agent records is written with the evidence it came from. When the run ends the record is sealed and can be shared as it is.

Data
This run's stored content: the conversation and the record. Deleting is permanent; billing rows are financial records and are kept, and anything already sent out cannot be unsent.
Details for your technical team

Workflows

What your agents know how to do. Design once, run it any number of times, improve it from real runs.

This project Library Sources
← Workflows

Workflow

Must find out

reading…

Must never

reading…

Done when

reading…

How it has actually run

Under the hood

A workflow is written as a charter: the same rules above, in the form the platform checks. The Studio is where you edit it field by field, set the language it must use, and attach source packs. The plain view on this page is generated from it, so the two never disagree.

← Workflows

Studio

The editor for a workflow's rules. Any edit registers as a new version; runs already going keep the version they started under.

loading…

Rules, read as sentences

loading…

Sources

Approved reference text a workflow can rely on (a formulary, a protocol set), sealed as exact text. Change one word and the changed copy is a new, unapproved version.

This project Library Sources
loading…

Budget

Where the money is, what it bought, and the ceiling every run gets.

Price list
Account
reading…
→
This project
reading…
→
Keys that spend it
reading…

Money moves down these three, one deliberate act at a time, and never on its own. A run spends from one key: the console picks a funded key for you; your own software uses the key you gave it.

Spend, last 7 days

reading…

By workflow

reading…

Receipts

reading…
Detail: by key, by model, and the reconciliation

Burn rate computed from the same metered rows as the tables below

loading…

By key

loading…

By model

loading…

Across models

Reconciliation, all-time totals and compute budgets

Reconciliation the arithmetic, stated rather than asserted

loading…

All-time totals by model & provider

not loaded yet

Compute budgets granted compute per person

not loaded yet

Connect your software

An access key lets your own systems start runs and read records, within this project only.

Keys Quick start Requests Console API reference

Keys

loading…

New key

Copy this key now. It is shown once and cannot be retrieved.
Webhook signing secret, also shown once.

Verify each delivery: HMAC-SHA256(secret, "<X-Cohort-Timestamp>." + rawBody) equals X-Cohort-Signature. Reject old timestamps to stop replays.

What is this key for?

A webhook is set here, now: it cannot be changed or added later, and revoking this key disables it. Cohort POSTs run events to it (run ended, turn ended). Must be https on a public address.

How the spend column is computed
Every figure comes from /v1/usage/by-key, computed over the whole window server-side, not summed in your browser. Keyless stays its own row on purpose: a signed-in person holds no key and that money is real.

Start a run from anywhere one call

What your keys may do

loading…

These rows are a page, not a total. /v1/usage/recent is a capped window onto the ledger and the API says not to sum these rows for billing. Each row's own cost is shown; nothing on this screen adds them up. Totals live on Budget.

The technical console: drive one run by hand and read its governed state as the platform records it. Everything here is metered and appears under Runs like any other run.

Interactive session governed if a charter is bound; it must seal to complete

Conversation

Charter authoring the validator's word renders verbatim

Author a charter (JSON)
Field type & options

What a field HOLDS, and what counts as a complete answer. These controls come from the engine, not from this page.

Charter rail durable, governed state

not loaded: attach an interactive session
Substrate tools
Claims with seal: the platform grades the charter and seals or refuses with the unmet criteria.

Known gaps honest absences, with the routes a fix would use

  • Per-key spending limits are not enforced. The spend ceiling is dead code server-side: api_key.limit_usd is never read on the spend path. A key's ALLOWANCE (the credit reserved to it) is the real bound.
  • Archived projects' spend is not readable. The usage read refuses an archived slug (require_tenant excludes them), so the account rollup marks those rows "archived · spend not readable" rather than inventing a number.
  • "Metered rows" is not "turns". The aggregate reads publish a field named turns that counts one per non-storage ledger row.
  • Money reads: every currency figure comes from GET /v1/usage/windows (or GET /v1/usage/by-key?since= behind it). Nothing sums /v1/usage/recent.
  • No ceiling on the session read. max_cost_usd is accepted at create and enforced, but not echoed back. Runs started from this console carry their ceiling in metadata.ceiling_usd, which IS echoed; a run started elsewhere shows "no ceiling recorded".
  • No approval primitive. A run can wait for a person's reply (/input); it cannot yet ask for a yes/no that the platform records as an approval.

Webhooks verifying a delivery

Cohort POSTs terminal session events (session ended, turn ended) to the webhook URL a key was minted with. Verify each delivery: HMAC-SHA256(secret, "<X-Cohort-Timestamp>." + rawBody) equals X-Cohort-Signature. Reject old timestamps to stop replays. The signing secret is shown exactly once, at mint, beside the key.

Session lifecycle what an integrator must know

  • Create with POST /v1/sessions, stream GET /v1/sessions/{id}/events (SSE, Last-Event-ID resume), send turns with POST /v1/sessions/{id}/input, end with POST /v1/sessions/{id}/end.
  • After ~300s idle the worker is reclaimed and the session PAUSES: it still lists as live and still holds a concurrency slot; the next input respawns a worker with the conversation replayed.
  • The sealed record of a chartered session reads back at GET /v1/sessions/{id}/artifact; it outlives the work and is readable after the workspace is archived. Stored content can be deleted with DELETE /v1/sessions/{id}/content; billing rows are kept.
  • The full generated contract: docs/openapi.json as published at deploy.

Project settings

This project: what it is called, what a new run gets by default, and how to close it.

Name

The address cannot be changed. It is this project's identity: every usage row is billed against it, keys carry it in their prefix, and records point at it. To move to a different address, make a new project and archive this one.

Defaults for new runs remembered in this browser

These fill the New run dialog. They are stored in this browser only; the platform has no per-project default yet.

Closing this project

loading…

Your account

Everything that belongs to you rather than to one project: your balance, and what you have spent across all of your projects.

Spend by project

loading…
Sign-in details
loading…

Projects

A project keeps one line of work separate: its own workflows, budget and keys. Your account holds all of them, and it always holds a Default one.

Your projects

loading…

New project

Lowercase letters, digits and hyphens. The address is written into billing rows and key prefixes, so treat it as permanent. The name can be changed later.

Price list

The rates every project's spend reconciles against. Published by the API, not typed here. If a rate is missing below, the server did not publish one.

Rates

loading…

Docs

Cohort is where agentic work gets designed, run and paid for, with nothing hidden. Six things people do here, and how. It belongs to your account, not to one project.

Run a workflow

Pick one, say what to work on, set a ceiling. That is the whole thing. The run stops itself at the ceiling and you get a receipt either way.

New run →

Watch a run and step in

The rules tick as they are met, the cost sits against the ceiling. When the agent needs an answer from you, the run waits and you reply on its page.

Runs →

Read a receipt

Rules met, off-script never, steps, cost against the ceiling. One per run, itemised per step in the record. The total is cumulative and says when it is settled.

Receipts →

Design a workflow

Three lists: must find out, must never, done when. Start from the Library, then make it yours in the Studio. Every edit is a new version; running work keeps the one it started under.

Library →

Set a budget

Money goes account, then project, then key, always by your hand. A run spends from one key. What a run costs depends on the model and how much it reads and writes.

Budget →

Connect your software

One key, one call. Your helpdesk, your CRM, your own product. A key belongs to one project and spends from its own allowance, so a key that leaks can only reach what you gave it.

Quick start →

Words you will see

Project
One line of work with its own workflows, budget and keys. Your account holds all your projects, and always holds a Default one. (The API calls a project a workspace.)
Workflow
What an agent knows how to do, written as rules. The written form is called a charter.
Run
One job, done once, with a ceiling and a receipt. (The API calls a run a session.)
Record
What the run found out and where each answer came from. Sealed when the run ends.
Key
How your software talks to a project. It spends from its own allowance, the credit you reserve to it.
Things that will trip you up

The longer version, with no account needed →

New run

1
Which workflow

2
What to work on
3
Ceiling for this run
The run stops itself at the ceiling and you get a receipt either way.

No key in this project has an allowance yet, so nothing can start. Give the project some budget, then give a key an allowance on Connect.

Some keys could not be read just now, so this list may be incomplete. Wait for the next refresh before adding allowance.

Advanced

Add budget

This moves money out of the account balance into this project. Once moved, no other project can spend it. A negative amount returns it to the account.

Give a key an allowance

This moves money from this project's budget to the key. A run spends from one key's allowance and nothing else. A negative amount sweeps it back to the project.

Top up your account

Credit is added to your account by Projex Labs. Ask your account contact for a top-up and it appears in your balance; there is no card form here yet.

New project

Lowercase letters, digits and hyphens. The address is written into billing rows and key prefixes, so treat it as permanent. The name can be changed later, the address cannot.

–