How it works
How Agent Studio works
Updated September 25, 2026 · by Nishanthan Janarthanarajah (Nishy), founder of Agent Studio
POST /v1/agents/{slug}/invoke.Step 1: Design on the canvas
Every agent starts with one Orchestrator: the node that talks to the caller and decides what to do. Give it a name, a model, and a system prompt. Then drag in Sub-agents for specialised work such as looking up an order, drafting a reply, or classifying a ticket. Connect a sub-agent to the orchestrator and it becomes a tool the orchestrator can call, with its own model and prompt.
Prompts can be rough. Press Polish and Agent Studio rewrites a one-line idea into a structured prompt with identity, responsibilities, delegation rules, boundaries, and tone. You preview the result and accept or discard it.
Step 2: Add protection
Guardrails are policies written in plain language, such as “only answer questions about our products” or “never quote a refund amount”. Each guardrail runs on input or on output and either blocks with your own message or rewrites the text to comply.
The Injection shield sits in front of everything. It combines fast pattern rules, Meta's Llama Prompt Guard 2 classifier, and a general LLM check, and it can harden the orchestrator so user text is treated as data rather than instructions. Attempts to override your prompt are blocked before any model call.
Step 3: Test with a trace
The playground runs your current draft. Each reply comes with a trace that lists every stage: shield verdict and score, each guardrail decision with its reason, every delegation with the task and result, and the orchestrator's step and token counts. Try a normal request, then try to break it.
Step 4: Deploy as an API
Press Deploy. The canvas compiles into an immutable versioned deployment. You get an endpoint, a bearer API key you can rotate, and a curl example. Call it from any language:
curl -X POST https://create-your-agent.nishy.space/v1/agents/support-copilot/invoke \
-H "Authorization: Bearer ak_…" \
-H "Content-Type: application/json" \
-d '{"input": "Where is my order #A1234?"}'The response includes the answer, whether it was blocked and by which stage, the version that served it, and the full trace. Full API reference →
What happens on every request
Requests always run the same pipeline: injection shield → input guardrails → orchestrator (delegating to sub-agents) → output guardrails → response. Every stage is recorded in the trace and stored in the Runs tab of the builder.
Frequently asked questions
Do I need to write code to build an agent?+
No. You design on a canvas and write prompts in plain language. The only code is the one HTTP call you make to your deployed agent, and Agent Studio generates that curl command for you.
How long does it take to deploy an agent?+
About ten minutes for a first agent: create it, write the orchestrator prompt, connect a sub-agent, add a guardrail and the shield, test once, and press Deploy.
Which models power the agents?+
GPT-OSS 120B and 20B, Llama 3.3 70B, Llama 4 Maverick, and Kimi K2, all served by Groq for low latency. You choose a model per node.
What happens when I change a deployed agent?+
Edit the design and press Deploy again. A new immutable version goes live behind the same endpoint and API key, so callers never change anything.
Can the agent call my own tools or APIs?+
Today the orchestrator delegates to sub-agents you define. Custom tool calling to external APIs is on the roadmap; the public endpoint already accepts full conversations so you can orchestrate from your side.