Create an escalation destination (signing secret shown once)
Register an external operator-agent endpoint. The server generates a whsec_ signing secret returned EXACTLY ONCE in this response and never again — store it immediately. The endpoint must be https and pass an SSRF/private-IP check; provider must be an AI Harness whose integration is connected; any sms channel requires the org’s 10DLC/TCR campaign to be ACTIVE. The new destination starts unverified — run testEscalationDestination to flip it active before it can route live. capabilities is a free-form list of capability tokens the external agent advertises (e.g. “reply”, “resolve”); fallbackRef uses the grammar external:<id> | email:<address> | none.
Authorizations
Flowyte secret API key (Authorization: Bearer flowyte_sk_live_…). Scope-gated; is scoped to your organization — a key can never reach another tenant. The listed scopes in each operation's apiKey requirement are the scopes that key must hold. The tokenUrl is nominal: keys are minted in the dashboard.
Body
hermes, openclaw https required; validated against the SSRF/private-IP guard.
Defaults to [chat] when omitted. sms requires an ACTIVE 10DLC/TCR campaign.
chat, sms general, sales, support, billing, scheduling