fix: use X-Session-API-Key for local automation auth in prompts and RUNTIME_SERVICES (#999)

Fixes #980

The agent prompt in recommended-automations-launcher and the
RUNTIME_SERVICES block in agent-server-adapter both advertised
X-API-Key as the auth header for the local automation backend.
The automation service (openhands-automation) does not accept
X-API-Key — it accepts Authorization: Bearer and X-Session-API-Key.

X-Session-API-Key is the established local convention: the agent
server uses it, the frontend automation API client uses it (with an
explicit comment that both backends share the same header), and
auth.py describes it as matching that convention. Update both call
sites and the corresponding test assertion to use X-Session-API-Key.

Co-authored-by: openhands <openhands@all-hands.dev>
This commit is contained in:
Tim O'Farrell
2026-06-01 15:10:30 -06:00
committed by GitHub
co-authored by openhands
parent 449d1fc9e5
commit d0994a6fe1
5 changed files with 11 additions and 8 deletions
+1 -1
View File
@@ -782,7 +782,7 @@ export function buildRuntimeServicesInfo(options) {
description:
"OpenHands Automations service. All routes are mounted under " +
`'${apiPrefix}'. Authenticate with header ` +
`'X-API-Key: $${authEnvVar}'.`,
`'X-Session-API-Key: $${authEnvVar}'.`,
url_from_agent: baseUrl,
api_prefix: apiPrefix,
docs_url: `${baseUrl}${apiPrefix}/docs`,