threadId and the last consumed cursor outside the agent transcript so a later run can recover work with get_thread.
Use Darwin’s first-party webLink for connection and payment interactions rather than proxying sensitive provider credentials through the agent.
Runtime state
Keep the selected Searchagent, optional nested capability, threadId, last consumed cursor, retry identifiers, and latest Darwin response in session or workflow state. Give the model the current state it needs, but keep secrets and sensitive browser data in the application layer.