BEEOS CLOUD / DEVELOPER REFERENCE
Product frontend integration
Connect web and mobile apps through your backend and purpose-scoped data channels
BeeOS Cloud exposes a Server SDK for trusted backend code and an Harness SDK for agent processes. There is no separate Cloud client SDK for web or mobile apps. Your product frontend uses its existing framework and product session, while your backend owns user authentication, authorization, and Cloud operations.
Split commands from live data
| Frontend need | Owner and path |
|---|---|
| Create or change an instance, agent, conversation, task, file, or runtime method | Frontend calls its product backend; the backend authorizes the user and calls the Server SDK. |
| Product-visible status, notifications, and message updates | Product backend publishes events over its own user real-time channel, scoped by its authentication and ACL. |
| ACP, terminal, Canvas/Yjs, viewer, or file transfer | Backend authorizes the specific user and resource, then issues or obtains a short-lived descriptor or presigned URL. The frontend connects directly to the named endpoint using the declared transport. |
The product backend maps its authenticated user to the opaque, app-local external user ID used when a Cloud operation requires that scope. Cloud may retain session and resource linkage for the ID, but your product remains the authority for user accounts, ACLs, and which user may request a descriptor.
Backend-to-frontend flow
- The frontend sends a product-session request to its backend. The backend checks ownership and ACL for the requested agent, conversation, file, document, or device.
- For a business command, the backend calls the Server SDK and returns a product response. It publishes subsequent product-visible events on its own user real-time channel.
- For a data stream, the backend returns a descriptor containing only the endpoint, transport, scope, credential, and expiry needed for that purpose. The frontend opens the declared WebSocket, WebRTC, Yjs, or transfer connection and requests a new descriptor from the backend when it expires.
Keep these paths distinct: an ACP or terminal connection carries authorized live data; it does not grant the frontend general Cloud management authority. A Canvas or viewer stream is likewise not the product event channel. See data channels for each transport and security and ownership for credential boundaries.
Important: Never place a
bsk_server key or an agent runtime token in browser or mobile code. Treat every descriptor and presigned URL as a short-lived bearer capability, not as a general product login.