[{"data":1,"prerenderedAt":448},["ShallowReactive",2],{"docs-navigation":3,"docs-page-\u002Fdocs\u002Ffundamentals\u002Fsecurity":149,"docs-surround-\u002Fdocs\u002Ffundamentals\u002Fsecurity":445},[4],{"title":5,"path":6,"stem":7,"children":8,"page":148},"Docs","\u002Fdocs","docs",[9,36,75,94,129],{"title":10,"path":11,"stem":12,"children":13},"GET STARTED","\u002Fdocs\u002Fget-started","docs\u002F1.get-started\u002F1.index",[14,16,20,24,28,32],{"title":15,"path":11,"stem":12},"Welcome",{"title":17,"path":18,"stem":19},"Quickstart","\u002Fdocs\u002Fget-started\u002Fquickstart","docs\u002F1.get-started\u002F2.quickstart",{"title":21,"path":22,"stem":23},"API","\u002Fdocs\u002Fget-started\u002Fapi","docs\u002F1.get-started\u002F3.api",{"title":25,"path":26,"stem":27},"SDKs and CLI","\u002Fdocs\u002Fget-started\u002Fsdks-cli","docs\u002F1.get-started\u002F4.sdks-cli",{"title":29,"path":30,"stem":31},"Sandbox testing","\u002Fdocs\u002Fget-started\u002Flocal-development","docs\u002F1.get-started\u002F5.local-development",{"title":33,"path":34,"stem":35},"Authentication","\u002Fdocs\u002Fget-started\u002Fauthentication","docs\u002F1.get-started\u002F6.authentication",{"title":37,"path":38,"stem":39,"children":40},"FUNDAMENTALS","\u002Fdocs\u002Ffundamentals","docs\u002F2.fundamentals\u002F1.index",[41,43,47,51,55,59,63,67,71],{"title":42,"path":38,"stem":39},"Fundamentals",{"title":44,"path":45,"stem":46},"Architecture","\u002Fdocs\u002Ffundamentals\u002Farchitecture","docs\u002F2.fundamentals\u002F2.architecture",{"title":48,"path":49,"stem":50},"Memory model","\u002Fdocs\u002Ffundamentals\u002Fmemory-model","docs\u002F2.fundamentals\u002F3.memory-model",{"title":52,"path":53,"stem":54},"Compression","\u002Fdocs\u002Ffundamentals\u002Fcompression","docs\u002F2.fundamentals\u002F4.compression",{"title":56,"path":57,"stem":58},"RAG and cached context","\u002Fdocs\u002Ffundamentals\u002Frag-cag","docs\u002F2.fundamentals\u002F5.rag-cag",{"title":60,"path":61,"stem":62},"Context cache","\u002Fdocs\u002Ffundamentals\u002Fcontext-cache","docs\u002F2.fundamentals\u002F6.context-cache",{"title":64,"path":65,"stem":66},"Security","\u002Fdocs\u002Ffundamentals\u002Fsecurity","docs\u002F2.fundamentals\u002F7.security",{"title":68,"path":69,"stem":70},"Languages","\u002Fdocs\u002Ffundamentals\u002Flanguages","docs\u002F2.fundamentals\u002F8.languages",{"title":72,"path":73,"stem":74},"UI patterns","\u002Fdocs\u002Ffundamentals\u002Fui","docs\u002F2.fundamentals\u002F9.ui",{"title":76,"path":77,"stem":78,"children":79},"AGENTS","\u002Fdocs\u002Fagents","docs\u002F3.agents\u002F1.index",[80,82,86,90],{"title":81,"path":77,"stem":78},"Agents",{"title":83,"path":84,"stem":85},"Agent skills","\u002Fdocs\u002Fagents\u002Fagent-skills","docs\u002F3.agents\u002F2.agent-skills",{"title":87,"path":88,"stem":89},"Admin UI prompt","\u002Fdocs\u002Fagents\u002Fadmin-ui-prompt","docs\u002F3.agents\u002F3.admin-ui-prompt",{"title":91,"path":92,"stem":93},"Codex Code Nucleus","\u002Fdocs\u002Fagents\u002Fcodex-code-nucleus","docs\u002F3.agents\u002F4.codex-code-nucleus",{"title":95,"path":96,"stem":97,"children":98},"PROVIDERS","\u002Fdocs\u002Fproviders","docs\u002F4.providers\u002F1.index",[99,101,105,109,113,117,121,125],{"title":100,"path":96,"stem":97},"Providers",{"title":102,"path":103,"stem":104},"OpenAI and Azure OpenAI","\u002Fdocs\u002Fproviders\u002Fopenai","docs\u002F4.providers\u002F2.openai",{"title":106,"path":107,"stem":108},"Anthropic Claude","\u002Fdocs\u002Fproviders\u002Fanthropic","docs\u002F4.providers\u002F3.anthropic",{"title":110,"path":111,"stem":112},"Google Gemini and Vertex AI","\u002Fdocs\u002Fproviders\u002Fgoogle-gemini","docs\u002F4.providers\u002F4.google-gemini",{"title":114,"path":115,"stem":116},"OpenAI-compatible providers","\u002Fdocs\u002Fproviders\u002Fopenai-compatible","docs\u002F4.providers\u002F5.openai-compatible",{"title":118,"path":119,"stem":120},"Groq","\u002Fdocs\u002Fproviders\u002Fgroq","docs\u002F4.providers\u002F6.groq",{"title":122,"path":123,"stem":124},"Cohere","\u002Fdocs\u002Fproviders\u002Fcohere","docs\u002F4.providers\u002F7.cohere",{"title":126,"path":127,"stem":128},"Amazon Bedrock","\u002Fdocs\u002Fproviders\u002Famazon-bedrock","docs\u002F4.providers\u002F8.amazon-bedrock",{"title":130,"path":131,"stem":132,"children":133},"CHANGELOG","\u002Fdocs\u002Fchangelog","docs\u002F5.changelog\u002F1.index",[134,136,140,144],{"title":135,"path":131,"stem":132},"Changelog",{"title":137,"path":138,"stem":139},"Roadmap","\u002Fdocs\u002Fchangelog\u002Froadmap","docs\u002F5.changelog\u002F2.roadmap",{"title":141,"path":142,"stem":143},"Release notes","\u002Fdocs\u002Fchangelog\u002Frelease-runbook","docs\u002F5.changelog\u002F3.release-runbook",{"title":145,"path":146,"stem":147},"Testing","\u002Fdocs\u002Fchangelog\u002Ftesting","docs\u002F5.changelog\u002F4.testing",false,{"id":150,"title":64,"body":151,"description":440,"extension":441,"meta":442,"navigation":266,"path":65,"seo":443,"stem":66,"__hash__":444},"docs\u002Fdocs\u002F2.fundamentals\u002F7.security.md",{"type":152,"value":153,"toc":434},"minimark",[154,158,162,167,208,212,221,357,361,364,403,406,410,413,430],[155,156,64],"h1",{"id":157},"security",[159,160,161],"p",{},"Neutron AI should be integrated as a server-side capability. Keep tokens, provider credentials, authorization decisions, and customer identity inside your platform boundary.",[163,164,166],"h2",{"id":165},"integration-checklist","Integration Checklist",[168,169,170,174,177,180,192,195,198,205],"ul",{},[171,172,173],"li",{},"Store Neutron tokens only in server-side environment variables or a managed secrets system.",[171,175,176],{},"Never expose Neutron tokens in browser code, mobile apps, public repositories, logs, or analytics.",[171,178,179],{},"Use workspace API keys for setup and Nucleus access tokens for runtime memory calls where possible.",[171,181,182,183,187,188,191],{},"Validate the current user before choosing ",[184,185,186],"code",{},"nucleusId"," and ",[184,189,190],{},"scopeId",".",[171,193,194],{},"Send only the minimum memory content needed for future tasks.",[171,196,197],{},"Avoid storing credentials, payment details, raw access tokens, or unnecessary personal data.",[171,199,200,201,204],{},"Use ",[184,202,203],{},"forget"," when users delete, revoke, or correct memory.",[171,206,207],{},"Log request IDs, status, duration, and safe scope labels. Do not log raw memory text by default.",[163,209,211],{"id":210},"tenant-and-scope-safety","Tenant and Scope Safety",[159,213,214,215,218,219,191],{},"Your app should treat Nucleus and scope IDs as authorization-sensitive. Do not accept arbitrary scope IDs from the browser without checking that the current user or agent may access them. ",[184,216,217],{},"tenantId"," remains a legacy alias for ",[184,220,186],{},[222,223,228],"pre",{"className":224,"code":225,"language":226,"meta":227,"style":227},"language-ts shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","const allowed_scope_ids = await getAllowedMemoryScopes(current_user);\n\nconst context_pack = await client.agentContext({\n  scopeIds: allowed_scope_ids,\n  agentId: \"agent_support\",\n  task: \"Prepare a customer support answer\"\n});\n","ts","",[184,229,230,261,268,294,310,330,346],{"__ignoreMap":227},[231,232,235,239,243,247,251,255,258],"span",{"class":233,"line":234},"line",1,[231,236,238],{"class":237},"spNyl","const",[231,240,242],{"class":241},"sTEyZ"," allowed_scope_ids ",[231,244,246],{"class":245},"sMK4o","=",[231,248,250],{"class":249},"s7zQu"," await",[231,252,254],{"class":253},"s2Zo4"," getAllowedMemoryScopes",[231,256,257],{"class":241},"(current_user)",[231,259,260],{"class":245},";\n",[231,262,264],{"class":233,"line":263},2,[231,265,267],{"emptyLinePlaceholder":266},true,"\n",[231,269,271,273,276,278,280,283,285,288,291],{"class":233,"line":270},3,[231,272,238],{"class":237},[231,274,275],{"class":241}," context_pack ",[231,277,246],{"class":245},[231,279,250],{"class":249},[231,281,282],{"class":241}," client",[231,284,191],{"class":245},[231,286,287],{"class":253},"agentContext",[231,289,290],{"class":241},"(",[231,292,293],{"class":245},"{\n",[231,295,297,301,304,307],{"class":233,"line":296},4,[231,298,300],{"class":299},"swJcz","  scopeIds",[231,302,303],{"class":245},":",[231,305,306],{"class":241}," allowed_scope_ids",[231,308,309],{"class":245},",\n",[231,311,313,316,318,321,325,328],{"class":233,"line":312},5,[231,314,315],{"class":299},"  agentId",[231,317,303],{"class":245},[231,319,320],{"class":245}," \"",[231,322,324],{"class":323},"sfazB","agent_support",[231,326,327],{"class":245},"\"",[231,329,309],{"class":245},[231,331,333,336,338,340,343],{"class":233,"line":332},6,[231,334,335],{"class":299},"  task",[231,337,303],{"class":245},[231,339,320],{"class":245},[231,341,342],{"class":323},"Prepare a customer support answer",[231,344,345],{"class":245},"\"\n",[231,347,349,352,355],{"class":233,"line":348},7,[231,350,351],{"class":245},"}",[231,353,354],{"class":241},")",[231,356,260],{"class":245},[163,358,360],{"id":359},"mcp-safety","MCP Safety",[159,362,363],{},"For MCP hosts, issue tokens with the narrowest useful access. Limit allowed tools when a host only needs context retrieval.",[222,365,367],{"className":224,"code":366,"language":226,"meta":227,"style":227},"const allowed_tools = [\"memory_agent_context\", \"memory_recall\"];\n",[184,368,369],{"__ignoreMap":227},[231,370,371,373,376,378,381,383,386,388,391,393,396,398,401],{"class":233,"line":234},[231,372,238],{"class":237},[231,374,375],{"class":241}," allowed_tools ",[231,377,246],{"class":245},[231,379,380],{"class":241}," [",[231,382,327],{"class":245},[231,384,385],{"class":323},"memory_agent_context",[231,387,327],{"class":245},[231,389,390],{"class":245},",",[231,392,320],{"class":245},[231,394,395],{"class":323},"memory_recall",[231,397,327],{"class":245},[231,399,400],{"class":241},"]",[231,402,260],{"class":245},[159,404,405],{},"Use write-capable MCP tools only when the host is trusted to store or delete memory.",[163,407,409],{"id":408},"user-controls","User Controls",[159,411,412],{},"Expose clear controls for:",[168,414,415,418,421,424,427],{},[171,416,417],{},"viewing saved memory",[171,419,420],{},"correcting memory",[171,422,423],{},"deleting memory",[171,425,426],{},"disabling memory for a workflow",[171,428,429],{},"exporting or auditing memory where your product requires it",[431,432,433],"style",{},"html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .s7zQu, html code.shiki .s7zQu{--shiki-light:#39ADB5;--shiki-light-font-style:italic;--shiki-default:#89DDFF;--shiki-default-font-style:italic;--shiki-dark:#89DDFF;--shiki-dark-font-style:italic}html pre.shiki code .s2Zo4, html code.shiki .s2Zo4{--shiki-light:#6182B8;--shiki-default:#82AAFF;--shiki-dark:#82AAFF}html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":227,"searchDepth":263,"depth":263,"links":435},[436,437,438,439],{"id":165,"depth":263,"text":166},{"id":210,"depth":263,"text":211},{"id":359,"depth":263,"text":360},{"id":408,"depth":263,"text":409},"Integration security guidance for public Neutron AI users.","md",{},{"title":64,"description":440},"XYr4GyY7ukoewvfdNwo6p1WjLWIJxH-hKwTbRCX_nPk",[446,447],{"title":60,"path":61,"stem":62,"children":-1},{"title":68,"path":69,"stem":70,"children":-1},1784317984170]