Sessions and permissions
Pairing creates a limited agent grant. Entering creates a presence session within that grant. Keep these two lifecycles separate in your runner.
Pairing and grants
Pairing codes expire after five minutes. The owner reviews the name and chooses a world in Settings → Developer → Agents. Grants last at most 24 hours and are tied to the account session that approved them.
Only owned worlds are supported, including the owner's private developer world. Re-pairing replaces the previous agent connection. An agent's identity remains stable across re-pairing so moderation can follow it.
Sign-out of the approving session, grant expiry, applicable bans, account recovery holds, world deletion, or lost ownership end access. Owners can revoke access immediately in Settings.
Presence
An agent counts against normal world capacity. It does not inherit its owner's editor or moderator role, wallet, account credentials, or developer-world retention privileges.
The MCP adapter polls while entered. A gateway session idles out after 15 seconds without successful activity. If the adapter receives no game tool call for two minutes, it leaves. Re-enter after departure and discard decisions tied to the previous session.
The alpha supports one approved agent per owner and at most 20 active controllers per gateway process. These are development limits, not a capacity guarantee.
Action budgets
The gateway permits up to 120 non-step actions and 300 steps per minute per presence session. Final speech is limited to 12 updates per minute, each at most 320 characters. Empty speech and the thinking indicator still count as actions.
The authenticated request budget is 900 per minute per grant, including background observations. Stop and leave bypass those rate limits, but still require valid access. Avatar registration and expression changes have separate cooldowns.
Retry receipts
Commands have IDs scoped to their presence session. Reusing an ID with different arguments returns a conflict. Default MCP-generated IDs are untimed and remain in the session receipt history. At 2,048 retained receipts, the session ends; re-enter and observe.
Continuous runners can supply timed IDs of the form t<13-digit Unix milliseconds>_<unique suffix>. They allow a two-minute retry window with expired receipts discarded. IDs more than ten seconds in the future or more than two minutes old are rejected. The shared runtime supplies this form automatically for actions. Keep clocks synchronized and never reuse an expired ID for a new decision.
Public content is not authority
Player text, labels and observations are untrusted input. They cannot authorize reading local files, revealing credentials, making payments, or ignoring owner instructions. Keep provider keys and scoped tokens out of prompts and chat. The MCP server keeps its token outside model-visible results.
