Connection(source_id="SOURCE_ID") to resolve it. Keep that URL and ReasonBlocks
key when you enable supported serving; no separate inference URL is needed. The source ID is part of the
URL. An Anthropic SDK base URL ends in /anthropic; its Messages request appends
/v1/messages.
Authentication and keys
REASONBLOCKS_API_KEY supplies the server credential. An rb_live_ key needs
Capture permission to record or resolve a source, and Inference permission to
use trained-model serving. A source restriction limits the key to that source.
The prefix alone does not identify its permissions. Existing rbcap_ source connection keys remain supported for capture and the
source’s existing proxy rollout. They remain separate from your provider credential.
New keys can have no scheduled expiration. Existing expiration dates still apply.
Rotate legacy source keys with a 24-hour overlap, or revoke them immediately when
needed. Manage rb_live_ credentials in API Keys.
Recording and training eligibility
Recording a request and admitting it to training are separate outcomes. The connection status shows Recorded requests, Training examples, Excluded from training, and Failed requests, with recent activity and exclusion reasons. Keep Manage connection open for automatic updates, or callrb.status().
Supported exchanges retain provider request and response information subject to
capture size, privacy and completeness limits. The recent index shows up to 256
recordings, while cumulative status continues to count new exchanges. Leaving
the recent index does not delete an exchange or stop new capture. Each backend
exchange has a 4 MiB serialized limit; the native SDK and HTTP gateway apply a
smaller 2 MiB request limit. Training examples retain their separate source limits.
See Recorded exchanges for
pagination and retrieval by ID. A request excluded from training
can still reach its original provider and be recorded. An interrupted response,
provider error or delivery failure appears separately; a training exclusion is
not proof that the original provider call failed.
An ordinary email address, including one in login tool arguments or results, is
personal data rather than a credential. It follows the source’s privacy setting
(off, redact or pseudonymize). Passwords, access tokens and other actual
secrets still block storage or training admission. An email supplied as a password
is still a secret. A historical exclusion reason alone does not establish whether
an exchange was recorded; check its recording status.
Connected confirms capture activity. It does not mean a model has been trained
or is awaiting approval. Training is a separate workflow; see
Train your complete agent when you are ready.
Anthropic request options
Provider and model restrictions still apply. Recording support does not imply
that every request is suitable for training or that a trained model reproduces
a provider feature. Top-level and block-level Anthropic cache annotations do not by themselves exclude
a supported request from training. Enabled thinking is recorded but excluded from
training with
thinking_not_trainable. The connection status reports this decision.
Bedrock and fallback
The SDK instruments the existing boto3 client locally. It keeps IAM signing, region and native AWS transport in place, then sends capture events to the source. An Anthropic API key is not required. For an approved rollout,serving=True
allows supported nonstreaming calls to ask the server for a candidate response.
Only an explicit upstream decision invokes the original Bedrock operation.
An uncertain or failed candidate dispatch is not silently replayed as a second
paid provider call.
rbtrace==1.3.1 adds safe dispatch diagnostics; 1.3.0 remains compatible.
The upgrade does not require changing the source URL, key or Bedrock client.
See Dispatch diagnostics.
InvokeModelWithResponseStream and ConverseStream remain native upstream
streams. Recording observes their consumption; it does not turn them into
candidate token streams. Incomplete consumption prevents a complete capture event;
check rb.diagnostics() for local delivery failures. Use serving=False for capture only.
The legacy hosted Bedrock relay still requires a bearer/API key. SigV4 is not
supported through that relay because it changes the signed host. Use the native
SDK integration for an existing IAM-authenticated client.
Boundaries
OpenAI Responses, Realtime, WebSockets and arbitrary compatible upstreams have separate integration requirements. A Python wrapper does not instrument calls made in JavaScript or native child processes. Hosted forwarding has request-size and authentication limits. Full-agent candidate serving has additional admission rules and uses nonstreaming requests; unsupported requests stay upstream before a candidate execution begins. Read the full-agent serving contract before enabling a release. Create one run per top-level user turn withrb.run(task_id), covering all model
calls, tool execution and the final answer. Use a new ID for the next turn in the
same conversation. Snapshots are optional for ordinary recording; full-agent training
requires a real repeatable starting state. Existing generated helpers and their
run_headers() interface remain supported; see the
migration guide.
