Production
In shortDeploy, configure and secure the 10xGraph API server in production: endpoints, config, auth, rate limiting, storage and environment variables.
- 2 min read
- 7 sections
- Updated
- v0.9.2
- Markdown
The 10xgraph api command starts a FastAPI + Uvicorn server that exposes your compiled graph as a fully-featured REST + WebSocket API. This section is the single source of truth for everything you need to run 10xGraph in production.
What the server exposes
| Group | Prefix | What it does |
|---|---|---|
| Health | /ping |
Unauthenticated health check |
| Graph | /v1/graph/... |
Invoke, stream, stop, fix, inspect the graph |
| Threads | /v1/threads/... |
CRUD for thread state and messages (requires checkpointer) |
| Store | /v1/store/... |
Semantic memory CRUD and search (requires store backend) |
| Files | /v1/files/... |
Multimodal file upload and retrieval |
| Config | /v1/config/... |
Read server configuration (e.g. multimodal settings) |
| Observability | /v1/observability/... |
Reconstructed run traces. Development only; returns an empty payload in production. |
| Evals | /v1/evals/... |
Eval report viewer. Unauthenticated, so it is not mounted when MODE=production. |
Full endpoint reference: REST API reference, starting with the shared conventions, auth model, and permission table.
Sending images and documents to an agent: Multimodal and vision
Configuration
All server behavior is controlled by two inputs:
10xgraph.json, which graph to load, which auth backend, which checkpointer, rate limiting, etc. Production guidance: 10xgraph.json in production. Complete field reference: configuration reference- Environment variables, secrets and runtime tunables (
JWT_SECRET_KEY,ORIGINS,MODE,LOG_LEVEL, etc.). Complete reference: Environment variables
Authentication and authorization
All endpoints except /ping pass through an auth + authorization layer:
- No auth (
"auth": null), all requests are allowed without credentials. Safe for internal networks or local dev. - JWT (
"auth": "jwt"), Bearer token checked againstJWT_SECRET_KEY. Standard stateless auth. - Custom (
"auth": {"method": "custom", "path": "..."}), subclassBaseAuthfor any identity provider. - Authorization (
"authorization": "module:Class"), subclassAuthorizationBackendfor per-resource RBAC.
Guide: Auth and Authorization
Rate limiting
Configured under the rate_limit key in 10xgraph.json. Three backends: memory (dev), redis (production), custom.
Guide: Rate limiting
Checkpointing
Thread state persistence. Without a checkpointer, every request is stateless. With PgCheckpointer, state survives across restarts and can be shared across multiple server instances.
Guide: Checkpointing
Deployment
For Dockerfile generation run 10xgraph build. For multi-worker, Kubernetes, and reverse-proxy deployments see the Deployment guide.
Quick start
pip install 10xgraph-api
10xgraph init # scaffold a project
cp .env.example .env # fill in API keys
10xgraph api # start the serverAccess:
- API:
http://127.0.0.1:8000 - Swagger:
http://127.0.0.1:8000/docs - ReDoc:
http://127.0.0.1:8000/redocs - Health:
http://127.0.0.1:8000/ping