Skip to content
Changelog

Serve agents to the public with PublicSurface

ContributorAshpreet BediFounder & CEO

September 8, 20261 min read

Pass public=PublicSurface(...) to Agno's AgentOS and list the components anonymous users may reach. AgentOS keeps everything you leave off that list private, and every public request runs against quotas and bounds.

Say you want a product assistant on your marketing site. Visitors aren't logged in, and you don't want them anywhere near your admin API, your internal teams or the workflow that re-syncs your docs. PublicSurface draws that line in the AgentOS constructor.

agent_os = AgentOS(
    id="product-assistant",
    db=db,
    agents=[assistant],
    public=PublicSurface(
        agents=[assistant],
        limits={
            "run": RateLimit(
                client_per_minute=10,
                global_per_minute=50,
                client_per_day=80,
                global_per_day=3000,
            )
        },
    ),
    cors_allowed_origins=["https://your-product.example"],
)

What PublicSurface exposes: anonymous clients reach only the selected agent, team and stateless MCP server, through shared quotas and request bounds. The sync workflow needs a service token, and team members and the admin API stay private.

How are public requests limited?

PublicSurface enforces per-client and global limits, per minute and per day. AgentOS counts them in PostgreSQL, so every replica enforces the same numbers. Request bodies, run time, output size and concurrent runs all have ceilings you can set.

What happens to teams and workflows?

A selected team is public over REST, with gzip. AgentOS reduces its roster, and its members' routes stay private unless you select them too.

A public workflow still needs service credentials, so knowing its URL doesn't let anyone trigger it.

Can I serve tools over MCP?

PublicSurface can serve explicit tools to anonymous clients over a native, stateless MCP server.

Learn more about Public Surface in the documentation. For a production example, see how we built the Agno Docs Agent.

Frequently asked questions

Pass public=PublicSurface(agents=[...]) to AgentOS and list only the components you want public. AgentOS serves those to anonymous clients and keeps the rest of the AgentOS private. See Public Surface in the documentation.

Pass limits to PublicSurface, for example {"run": RateLimit(client_per_minute=10, global_per_minute=50)}. Limits apply per client and globally, per minute and per day. AgentOS stores the counters in PostgreSQL, so all replicas share one set of numbers.

No. A workflow on a PublicSurface still needs service credentials, so a caller who knows its URL can't trigger it without them.

No. AgentOS serves a selected team over REST with a reduced roster. Its members' routes stay private unless you select those members too.

Shipped around the same time