agent-os and the database is agentos-db. Every command in scripts/render/ drives the Render API and needs RENDER_API_KEY in your environment or env file.
Manage
Auto-deploy on merge
autoDeploy: true is on in render.yaml, so every push to your deploy branch triggers a build and deploy. Render builds the pushed branch; local uncommitted changes never deploy. ./scripts/render/env-sync.sh is still how you sync env changes.
Production auth
Token-Based Authorization is on by default. Production startup requiresJWT_VERIFICATION_KEY or a readable JWKS file at the container path in JWT_JWKS_FILE; otherwise the process exits.
Token-Based Auth gives you three things:
- Protected AgentOS routes require a token. The operational and docs routes
/,/health,/info,/docs,/redoc,/openapi.json, and/docs/oauth2-redirectremain public. - Per-request identity. Middleware validates the token and exposes its
user_id, optionalsession_id, scopes, and claims to the request. - Scope-based permissions. Token scopes control access to AgentOS routes and resources.
authorization_config=AuthorizationConfig(user_isolation=True) to AgentOS. See User Isolation.
To disable JWT authentication, set authorization=False in app/main.py, remove JWT_VERIFICATION_KEY and JWT_JWKS_FILE from the Render service, and push. Use this only inside a private VPC behind another auth layer. authorization=False disables AgentOS scope enforcement, while configured JWT environment variables still enable JWT validation. MCP OAuth remains active when MCP_CONNECT_SECRET is set.
Customize
Add an agent
Add an agent
Ask your coding agent to run Register it in Add its UI metadata beneath the existing Local containers hot-reload on save. For production, commit and push; Render rebuilds automatically.
/create-agent, or do it by hand. Create agents/my_agent.py:app/main.py:manifest: key in app/config.yaml:Change the model
Change the model
app/settings.py defines default_model(), used by every agent. Change it in one place:anthropic to pyproject.toml, set the provider key in your env, and regenerate pins:docker compose up -d --build. For production, sync the env and push:Add tools
Add tools
Agno ships 100+ toolkits. See Toolkits.
Add dependencies
Add dependencies
- Edit
pyproject.toml. - Regenerate pins:
./scripts/generate_requirements.sh(addupgradeto refresh every pin). - Rebuild locally with
docker compose up -d --build, or commit and push to redeploy.
Enable Slack
Enable Slack
Set both variables in your env file:Sync with
./scripts/render/env-sync.sh. The interface activates automatically and routes messages to Agent Builder; change the agent= argument in app/main.py to point at another agent. See Slack setup.Toggle scheduled workflows
Toggle scheduled workflows
The deployment check runs daily by default (
ENABLE_DEPLOY_CHECK=True); it is deterministic and free. The run-evals schedule is always registered but starts disabled because it uses model calls. Enable it from the AgentOS UI. Both workflows remain runnable on demand.Format, validate, and run evals
The format, validate, and eval scripts run on the host and need a venv. Set it up once:./scripts/mcp_check.sh runs inside the container, so it needs no venv.
Environment variables
Troubleshooting
up.sh reports no agent-os service
up.sh reports no agent-os service
Expected before the first Blueprint launch. Open dashboard.render.com → New + → Blueprint, connect your copy of the repo, and apply. The script prints these steps and polls every 15 seconds for up to 30 minutes, so you can leave it running while you launch.
RENDER_API_KEY not set
RENDER_API_KEY not set
Create one in the dashboard under Account Settings → API Keys, then export it or add it to
.env.production. The scripts read it from either place.up.sh pauses asking for a JWT key
up.sh pauses asking for a JWT key
Expected. At os.agno.com, choose Connect OS → Live, enter your onrender.com URL, name it Live AgentOS, turn on Token-Based Authorization (JWT) on the connection panel, and connect. The UI generates the public key. If the OS is already connected, enable the setting under Settings → OS & Security. Paste the full PEM into the script prompt. To add a PEM later, set
JWT_VERIFICATION_KEY and run ./scripts/render/env-sync.sh. To use JWKS, commit and push the file into the image build context, or configure a mount. Set JWT_JWKS_FILE to its container path, then let auto-deploy rebuild or roll the service. Env sync alone only updates the path.App fails to start in production
App fails to start in production
JWT scope enforcement is on whenever
RUNTIME_ENV is not dev. Set JWT_VERIFICATION_KEY and sync. For JWKS, verify the file exists inside the container at JWT_JWKS_FILE; changing the variable alone does not deliver it. To disable JWT inside a private VPC behind another auth layer, set authorization=False in app/main.py and remove both JWT environment variables from the Render service. MCP OAuth remains active when MCP_CONNECT_SECRET is set.My code changes didn't deploy
My code changes didn't deploy
Render builds the pushed branch, so local uncommitted changes stay on your machine. Commit, push to your deploy branch, and let
autoDeploy rebuild. redeploy.sh warns when it finds uncommitted changes.Scheduled jobs never fire
Scheduled jobs never fire
AGENTOS_URL is still the localhost default. up.sh pins it to your onrender.com URL automatically, and env-sync.sh pins it when your env file has none; for a custom domain or tunnel, set it by hand and run ./scripts/render/env-sync.sh.Scheduler or MCP streams stop working
Scheduler or MCP streams stop working
The service is likely on the
free plan, which sleeps between requests; the in-process scheduler and MCP streams stop when it does. Set plan: starter (or higher) in render.yaml and push.