NOIR
Get started

Production checklist

The concrete gates between a local demo and a restart-safe, observable production agent.

A local agent can use the in-memory store and the CLI polling worker. A production agent needs deliberate choices for persistence, provider access, authorization, and operations.

Before deployment

  • Use Node.js 22.18 or newer.
  • Give the agent a stable id; changing it changes namespaced state.
  • Replace memoryStore() with a durable RuntimeStore for restarts or multiple replicas.
  • Run every capability store migration during controlled startup.
  • Keep webhook request bodies intact until channel signature verification completes.
  • Configure channel event subscriptions, scopes, interactions, and public webhook URLs.
  • Pin connector permissions to the narrowest accounts and resources needed.
  • Mark write and destructive tools with accurate effect, approval, and retry metadata.
  • Pass stable idempotency keys to external write APIs.
  • Set limits for model steps, run time, delivery time, history, and tool result bytes.
  • Attach onEvent or an observability capability before debugging real traffic.
  • Test one duplicate webhook, one process restart, one denied approval, and one provider timeout.

Durable processing

The core store must persist the inbound queue, leases, conversation history, tool checkpoints, approvals, and outbox. Run agent.start() only after migrations and dependencies are ready. Call agent.close() during shutdown so polling stops and owned resources flush.

For fetch-native hosts, call agent.fetch(request) from the route and use the host's background work primitive to trigger agent.drain() and agent.flushOutbox(). Do not assume the webhook request remains alive for model generation.

Security boundary

Treat message text, remote repository contents, MCP results, and model output as untrusted input. Authorization belongs in code. A system prompt stating that a user owns a repository is not a repository grant; verify the exact installation, actor, repository, operation, and branch in a connector callback.

Operational checks

npx noir doctor ./dist/agent.js
npx noir inspect ./dist/agent.js

Monitor run failures, repeated tool failures, output failures, delivery retries, queue age, and approval expiry. Preserve runtime event data without logging full secrets or unbounded tool results.

Release gate

Ship only after the application passes type checking, tests, a cold start against the production store, and a live webhook round trip. Then verify that a duplicate provider delivery produces one user-visible response and that a restarted worker completes queued output.

On this page