# Run the Control Plane and a public agent on one AgentOS

> An Agno AgentOS with both PublicSurface and JWT authorization now serves anonymous users on its public routes and the full API to authorized tokens on one URL, so the Control Plane can manage it.

- Published: 2026-09-08
- Author: Ashpreet Bedi
- Categories: Changelog
- Canonical: https://www.agno.com/articles/run-the-control-plane-and-a-public-agent-on-one-agentos
- Markdown: https://www.agno.com/articles/run-the-control-plane-and-a-public-agent-on-one-agentos.md

You can now set `authorization=True` on an AgentOS that uses `PublicSurface`, and manage that AgentOS from the Control Plane. The combination used to break in both directions. A valid admin token got a `404` from `/config` and the component routes, and AgentOS rejected anonymous chat.

```python
from agno.os import AgentOS, MCPConfig
from agno.os.public import PublicSurface

agent_os = AgentOS(
    id="public-support",
    db=db,
    agents=[support],
    authorization=True,
    public=PublicSurface(agents=[support], mcp=True),
    mcp=MCPConfig(tools=[service_description], default_tools=False, stateless=True),
)
```

Set `JWT_VERIFICATION_KEY` to the Control Plane's public key so AgentOS can verify its tokens.

![One AgentOS URL with authorization=True and a PublicSurface. Anonymous callers reach only the selected chat and MCP routes, with public input checks and quotas. Verified JWTs, such as the Control Plane's, reach the full REST API, checked against their scopes and never cached. Invalid credentials are rejected and never treated as anonymous.](https://www.agno.com/images/v3-0-9-one-url-routing.png)

On one runtime URL, AgentOS now handles each caller by its credentials.

- Anonymous callers reach only the chat and MCP routes you selected, with the same input checks and quotas as before.
- Verified JWTs reach the full REST API, subject to their scopes. AgentOS marks those responses private and never caches them.
- AgentOS rejects invalid credentials. A bad token never falls back to anonymous access.

![The same AgentOS, with authorization=True and a PublicSurface, before and now. An admin JWT on /config got 404 and now gets 200. An anonymous request for the agent list got 401 and now gets 200. An anonymous request for /config gets 401 either way.](https://www.agno.com/images/v3-0-9-public-surface-with-jwt.png)

Public workflow WebSockets on this AgentOS now reach their authentication handler. AgentOS applies a shared connection quota, a cap on pending connections per worker, a fixed authentication deadline and a limit on failed attempts.

If you already combine `authorization=True` with `PublicSurface`, AgentOS now accepts anonymous requests to your selected public routes. Public MCP keeps its explicit tool list and quotas even for admin tokens. Use `mcp_auth` if MCP itself should require sign-in. Without `authorization=True`, a public deployment still closes its management routes.

See the [cookbook](https://github.com/agno-agi/agno/blob/main/cookbook/05_agent_os/27_public_pages/public_control_plane.py), and learn more about [Public Surface](https://docs.agno.com/agent-os/public-surface) and the [Control Plane](https://docs.agno.com/agent-os/control-plane) in the documentation.
