DocsProduct frontend and data channels

This reference is currently available in English. The Cloud console remains in your selected language.

BEEOS CLOUD / DEVELOPER REFERENCE

Product frontend integration

Connect web and mobile apps through your backend and purpose-scoped data channels

BeeOS Cloud exposes a Server SDK for trusted backend code and an Harness SDK for agent processes. There is no separate Cloud client SDK for web or mobile apps. Your product frontend uses its existing framework and product session, while your backend owns user authentication, authorization, and Cloud operations.

Split commands from live data

Frontend needOwner and path
Create or change an instance, agent, conversation, task, file, or runtime methodFrontend calls its product backend; the backend authorizes the user and calls the Server SDK.
Product-visible status, notifications, and message updatesProduct backend publishes events over its own user real-time channel, scoped by its authentication and ACL.
ACP, terminal, Canvas/Yjs, viewer, or file transferBackend authorizes the specific user and resource, then issues or obtains a short-lived descriptor or presigned URL. The frontend connects directly to the named endpoint using the declared transport.

The product backend maps its authenticated user to the opaque, app-local external user ID used when a Cloud operation requires that scope. Cloud may retain session and resource linkage for the ID, but your product remains the authority for user accounts, ACLs, and which user may request a descriptor.

Backend-to-frontend flow

  1. The frontend sends a product-session request to its backend. The backend checks ownership and ACL for the requested agent, conversation, file, document, or device.
  2. For a business command, the backend calls the Server SDK and returns a product response. It publishes subsequent product-visible events on its own user real-time channel.
  3. For a data stream, the backend returns a descriptor containing only the endpoint, transport, scope, credential, and expiry needed for that purpose. The frontend opens the declared WebSocket, WebRTC, Yjs, or transfer connection and requests a new descriptor from the backend when it expires.

Keep these paths distinct: an ACP or terminal connection carries authorized live data; it does not grant the frontend general Cloud management authority. A Canvas or viewer stream is likewise not the product event channel. See data channels for each transport and security and ownership for credential boundaries.

Important: Never place a bsk_ server key or an agent runtime token in browser or mobile code. Treat every descriptor and presigned URL as a short-lived bearer capability, not as a general product login.