Move a session to another directory
Points a live session at another directory. From the next turn onwards its tools are confined to the new root, its commands run there, and every surface that names the directory names this one. The CONVERSATION is untouched: not one entry is lost, and the move is written into it as a note saying where the session came from.
WHAT IT COSTS, and it is the one thing nobody can get back: the session’s restore points are DROPPED. Every one of them named a saved working tree in a store keyed to the checkout the session is leaving, so after the move not one of them could put a file back — kept, they would go on offering a moment the host cannot honestly reach. Going back to an earlier point in the CONVERSATION still works, because the transcript is intact; going back to the files as they were before the move does not. A client offering this gesture has to be able to say so before it calls. The first tool that changes a file in the new directory takes a fresh baseline on its own, and until then the session offers no restore point at all.
Trust is asked about the destination exactly as at session open: an untrusted directory is not refused, it runs untrusted. What does not survive the move is a recorded HANDOVER — a session moved into a directory nobody has vouched for is taken back to attended, with the reason written into its conversation, because nobody being there in a directory nobody trusts is the hole this closes.
Refused with 409 while a turn is in flight, rather than raced: dropping the restore points under a tool part-way through writing files would throw away the one baseline that could put them back. Interrupt the turn and call again. Refused with 409 for an archived session, and with 422 for a destination that is not an absolute path to a directory, or whose own project configuration will not load.
Moving a session to the directory it already stands in is not an error: the state asked for holds, so nothing is appended, nothing is dropped, and no event is emitted.
Path Parameters
The session's id.
Body
The directory a session should work in instead. One field, required: a request that did not say where it meant is a request to be answered rather than guessed for.
Absolute path of the directory to work in, which must exist and be a directory. Stored in its canonical form, because that one string is both the root the next turn's tools are confined to and the key the trust answer is keyed on — a session vouched for under one spelling and working under another is the state this refuses to represent.
4096Response
The session, working in the directory it now stands in.
A durable conversation container. Survives the process that created it; archiving hides it from active lists but its transcript remains queryable and exportable forever.
The session's id.
Absolute path of the repository the session works in.
4096Lifecycle: running while a turn executes or normal follow-ups chain; waiting after interrupt when admitted steering or follow-up inputs remain queued; idle only when neither execution nor queued input exists; archived accepts no new work.
idle, running, waiting, archived Which kind of client opened this session, recorded when it was created and never rewritten. Always present: unknown for a session created before this host recorded the datum, which is the honest answer rather than a guessed frontend.
inline, tui, oneshot, api, unknown Human-readable title.
512The model provider currently in use.
The model currently in use.
The preset of request options this session's turns run under — the name, not the options it stands for, since what a name means is the catalogue's answer and can change while the session's own choice cannot. Absent on a session that never chose one, which is every session running its model at the model's own defaults.
The named response style this session's answers are shaped by — the name, not the prompt it appends, since what a name means is configuration's answer and changes when somebody edits that file while the session's own choice does not. Absent on a session that never chose one, which is every session answering in narya's own voice. Unlike variant it survives a model switch: a style is a fact about how the conversation reads rather than about the model answering it. A client renders this and derives nothing — the names that exist are the host's answer (setSessionStyle refuses the rest).
64One sentence stating what a client could not otherwise know about the model this session opened on or was just moved to, present on the responses to createSession and setSessionModel. Two facts earn it. The first is a model narya chose itself rather than being told to use: no default_model configured and no model previously chosen, so the first provider holding a usable credential answered — or a named model the catalogue no longer carries, for which the provider default was substituted. It names the alternatives that also qualified and how to choose another, because a choice nobody made has to be stated to be a choice at all rather than something that merely happened. The second is a level this session will run without: a model reference may carry one (see the variant field), and an endpoint that does not take the field runs at its own default instead — so a level named at creation or at a switch, or configured beside default_model, is said here rather than quoted in a picker while every request drops it. A client that renders the live event stream rather than the session's transcript has no other road to it. Otherwise absent, including for a model that was simply configured, chosen or named; absent on getSession and listSessions, which report state rather than how it came about.
1024What this session has consumed and cost across every turn it has run — a running total, not the last turn's figure. Carried by getSession and by every row of listSessions, so a client drawing a list of sessions can say what each one has cost without asking per row. Absent on a session that has never completed a turn, and its costUsd is absent whenever any one of that session's turns could not be priced: the sum over only the priced turns is smaller than what the session actually cost, and a figure that quietly understates money is worse than an admitted unknown.
What the newest round of this session's own conversation sent and produced — the LAST turn's figure, not the running total above. Carried by getSession only. It exists because the two are not interchangeable for the one question a reader reopening a long conversation asks: how much room is left before this compacts. That answer is the size of the prompt last sent, and usage above is a sum over every turn the session ever ran, which is a larger number growing without bound and means nothing as a fraction of a context window. The live event stream carries this figure on turn-finished, so a client watching a session has always had it; a client that READ the session had no source for it at all and drew no context figure until it spent a turn of its own. Restoring a recorded reading rather than deriving one is the whole of it — nothing here is computed from the transcript. The newest round of the MAIN lane: a delegation's rounds are another conversation's prompts, and the figure is about the reader's. Absent on a session that has never completed a round, and on one whose rounds all ran on delegates. Its costUsd is that one round's price, absent when the round could not be priced.
Pending steering and follow-up references in durable operation order. Content is intentionally absent; fetch the transcript by entryId.
When the session was branched, the session it branched from.
What a model said this conversation tried and concluded. Absent until somebody asks for it (summarizeSession) — nothing summarises a branch because a rewind moved away from it. A model that answers past this length is trimmed to it, with a marker saying so rather than a sentence that just stops.
4096When the summary was taken. Read against updatedAt it answers whether the summary predates the last thing that happened here.
Whether somebody is there to answer a permission prompt raised here. Absent on a session nobody ever said either way about, which reads as attended — the posture is only ever recorded because somebody stated it (setSessionPosture), never inferred from whether a client happens to be connected.
attended, detached Whether this session pays to keep its provider cache alive while nobody is using it, and the most it may ever spend doing so. Absent on a session nobody ever turned it on for, which is every session until somebody does — warming is off unless somebody asked (setSessionWarming).
When a reader last had this session in front of them (acknowledgeSessionViewed). Read against updatedAt it answers whether anything has happened here since somebody looked, which is what lets a client mark a background conversation as carrying news — and, because the fact is held here rather than in a window, what makes two clients agree about it and makes the answer survive a relaunch. ABSENT on a session nobody has ever viewed, which is not the same as viewed long ago: one has nothing to report, the other has everything that ever happened in it.
How the last turn here ended. It is what lets a client that was not running at the time tell a conversation that finished from one that failed. Absent on a session that has never run a turn. An interrupt is not among the values: somebody was there and stopped it themselves, so it is not news to bring back to them.
finished, failed What this session's provider prompt cache has cost it, from both sides: what letting it expire cost, and what keeping it alive cost. Present only on getSession, and only once one of the two has happened — a session that has never paid for either carries nothing here rather than a pair of zeros.
The agent's own task list for this session — every item it has written, in the order it wrote them, whatever is in the store right now.
It is here rather than behind a listing of its own because the list is a stored row and every client already reads the session when it attaches, so one optional field costs no round trip and no second operation. A change to the list is announced as task-list, which carries the same whole list for the same reason; this is where a client that was not attached at the time gets it.
Present on getSession only, like lastTurnUsage and cacheSpend and for their reason: a listing that carried it would read every row's tasks to draw a page nobody asked for.
ABSENT MEANS EMPTY, and it cannot mean anything narrower: the store holds rows, so a list nobody ever wrote and a list somebody cleared are the same read. The live stream is where those two differ — a clearing write announces task-list carrying an empty array — and a read that returned [] would be claiming to know which of the two it was looking at.

