KB / Memory / project-oma-console-session-inject
OMA Console session Inject overlay
Operators inject prompts, MCP, tools, and vault credentials into a live session without mutating the agent
In project-open-managed-agents, operators can intervene in a running session via a session-scoped injection overlay (Console Inspector Inject tab).
- Write:
POST /v1/sessions/:id/injections(canonical).PATCH /v1/sessions/:id/toolsis a thin tool-toggle alias. - Read:
GET /v1/sessions/:id/injectionsreturns the overlay (never tokens). - Storage:
session.metadata._oma_injections(stripped from public GET metadata). Not copied onto the agent; new sessions do not inherit. - Timing: prompt append + tool overrides apply on the next turn; MCP mounts + credential binds on the next proxy/outbound call.
- Credentials:
credential_idonly, must already be in the session’svault_ids(422 otherwise). Overlay/events/UI never carry tokens. - Audit:
session.config_updatedis non-replayed (prompt body omitted; credential detail is host + id).
First slice of the broader Inject issue; tablet/mobile sheet, env/package injection, and undo stack are out of scope.
Why: Live ops without restarting or mutating the agent record.
How to apply: Prefer the Inject API/overlay for session-scoped changes; do not put tokens in metadata or expect agent inheritance. Drive verify with console-inject.