tui — Request Lifecycle

tui — Request Lifecycle A workflow diagram generated by Archify. 01 / Client 02 / Gateway 03 / Credential 04 / Backend + Zen EX / Rejects Intake Gate Proxy + stream Phone · POST + JWT · Client › Intake Phone POST + JWT JWT gate · wrap-jwt-auth · Gateway › Intake · HS256 JWT gate wrap-jwt-auth HS256 Build proxy req · inject Bearer · Gateway › Gate Build proxy req inject Bearer Resolve credential · OAuth to fallback · Credential › Gate Resolve credential OAuth to fallback opencode web · :4096 sessions · Backend + Zen › Proxy + stream opencode web :4096 sessions Zen Responses · SSE stream · Backend + Zen › Proxy + stream Zen Responses SSE stream 401 · unauthorized · Rejects › Intake 401 unauthorized 503 · no credential · Rejects › Gate 503 no credential bad JWT claims ok POST /responses nothing found SSE chunks Legend Agent logic Policy Cloud service External system

Fail closed

  • • No JWT -> 401 before anything else runs
  • • No credential -> 503 before any upstream call

Streaming

  • • SSE passes through untouched (:as :stream)
  • • Gateway adds auth, never buffers the body