# RPC protocol (https://optakt.ai/docs/rpc)

Optakt One exposes Cap'n Proto RPC interfaces. The admin app uses these interfaces too: a custom client can manage the same deployment without writing directly to its database.

This is a typed RPC protocol, not a REST or HTTP JSON API. A client needs the matching schemas and bindings. To obtain the protocol for your integration, write to [max@optakt.io](mailto:max@optakt.io).

## Management [#management]

The **Capabilities** interface is the management surface. It covers login, your profile and linked identities, users, agent scopes, members, spaces, credentials, providers, integrations and model settings.

A client first obtains the authentication interface, logs in, then obtains a session using the token. The session grants operations according to the user's role. A custom interface does not bypass membership or admin permissions.

The built-in admin app connects locally by default. For a remote client, use an SSH tunnel or enable the TLS listener and verify its certificate. See [Admin app](/docs/admin-app#from-another-computer).

## Service interfaces [#service-interfaces]

Three other interfaces serve the system's components:

| Interface | What it carries |
| --- | --- |
| **Engine** | Workloads, results, streaming tokens, tool calls and model/provider configuration |
| **Messenger** | Messages, files, reactions, bot configuration and chat updates |
| **Events** | Workload accepted/completed notifications for observers |

The Engine and Messenger interfaces are two-sided: each service supplies capabilities to the other during a handshake. They are component contracts, not an unauthenticated endpoint for submitting chat messages.

## Compatibility [#compatibility]

Use schemas that match the version of the deployment you connect to. Before building a new client or connector, agree which interface it needs; the management API, a chat connector and an execution component serve different purposes.
