thread, messageType, and messageContent.
accepted response means Darwin saved the message. It does not mean the
target received it, answered it, or completed work.
Message types you can send
start_thread requires messageType and messageContent for its first message. It accepts message or action_request. send_message accepts all six types below. Darwin validates the matching content shape and assigns sender authority from the authenticated request.
Do not send authentication or payment confirmations. Use Authenticate and Pay; Darwin records verified outcomes in thread state.
Target and runtime updates you can receive
The canonical durable history also contains the target/runtime-only types below. They are exhaustive and are generated from the internal thread event schema. Callers cannot submit or forge them. Get thread exposes their safe current projection, not the private raw event.What Get thread returns
messages contains safe text/media message and result projections. actions contains current action status. requests is a strict discriminated review union. It includes exact safe action arguments and account selection, approval reason and action terms, authentication target/type/resource/scopes/account when available, payment amount/currency/payee/methods/expiry, or the result ID for completion review.
Request review terms come from the immutable originating event, independent of the current cursor page. Darwin fails closed if those terms are missing, corrupt, or contain credential-shaped fields. Public objects omit internal revisions, request digests, credentials and provider receipts.
For a confirmation, copy the request ID from the matching Get thread request. Use the action ID only for cancellation_request. Never treat ordinary text such as “approved” as structured authority.
Attachments
Ordinarymessage sends text in messageContent. Optional attachments can reference validated image, audio, video or file assets. Each attachment uses { type, asset }; it never contains inline base64, credentials or an arbitrary download URL. Media still requires an available upload validator and compatible route.
Recover history and status
Call Get thread with the last processedcursor. Continue while hasMore is
true; once caught up, set wait: true for one bounded read. A quiet result is
an idle wait, not completion. MCP does not expose a separate stream tool.
The first-party Web experience may use its authenticated SSE transport and resume from
Last-Event-ID; that private transport does not add an eighth Act operation. Stream
disconnects do not cancel or complete work.
Use messages for safe conversation/result content, actions for current work
state, and requests for pending or resolved decisions. Each request is a strict
review object: action and approval requests include their exact safe capability
arguments; authentication requests include target, type, resource, scopes, and
selected account when available; payment requests include amount, currency,
payee, accepted methods, and expiry. Completion requests identify the result.
Darwin loads those immutable review terms even when their originating event is
outside the current cursor page. Missing, corrupt, or credential-shaped review
data fails closed. Public projections omit internal revisions, digests,
credentials, provider references, and receipts.
Retry rules
- Retry a timed-out mutation only with the same idempotency key and identical input.
- On authorization denial, stop and reconnect with the required scope.
- On rate limits, respect
Retry-After. - Before resending work, read the thread and check its current actions and requests.