> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usehasp.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create or update the current draft version for an agent

> PUT /v1/agents/{agent_id}/draft

If no draft exists, a new version is inserted (v1 or max+1 after a prior
publish). If a draft already exists, its fields are updated in place.
Cannot be called on a published version — creates a new draft instead.

Invariants enforced:
  - model must be in org.allowed_model_ids when provided.
  - persona is stored encrypted; the org's PHI mode governs runtime handling.



## OpenAPI

````yaml /openapi/v1.json put /agents/{agentId}/draft
openapi: 3.1.0
info:
  title: HASP AI API
  version: '2026-07-12'
  description: >-
    The HASP Public AI API is the regulated-AI substrate for healthcare and
    other

    regulated industries — identity, policy, audit, compliance, and PHI handling

    for AI inference, exposed via two surfaces:


    - **Native (`/v1/ai/*`)**: HASP-native chat with full event taxonomy, run
    lifecycle,
      and PHI metadata.
    - **Anthropic-compat (`/v1/messages`)**: Drop-in replacement for
    `@anthropic-ai/sdk` —
      change only `baseURL`. All Gateway compliance checks (BAA, credits, PHI policy) apply.

    All requests require an API key (`Authorization: Bearer
    hasp_api_live_<key>`). See

    [Authentication](https://docs.usehasp.com/ai-api/authentication) for key
    management.
servers:
  - url: https://api.usehasp.com/v1
    description: Production
security:
  - http: []
paths:
  /agents/{agentId}/draft:
    put:
      tags:
        - AgentVersions
      summary: Create or update the current draft version for an agent
      description: |-
        PUT /v1/agents/{agent_id}/draft

        If no draft exists, a new version is inserted (v1 or max+1 after a prior
        publish). If a draft already exists, its fields are updated in place.
        Cannot be called on a published version — creates a new draft instead.

        Invariants enforced:
          - model must be in org.allowed_model_ids when provided.
          - persona is stored encrypted; the org's PHI mode governs runtime handling.
      operationId: v1.agents.draft.upsert
      parameters:
        - name: agentId
          in: path
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                persona:
                  type:
                    - string
                    - 'null'
                  maxLength: 16000
                model:
                  type:
                    - string
                    - 'null'
                  maxLength: 128
                input_schema:
                  type:
                    - object
                    - 'null'
                  additionalProperties: {}
                output_schema:
                  type:
                    - object
                    - 'null'
                  additionalProperties: {}
                default_scope_grants:
                  type: array
                  items:
                    type: object
                    additionalProperties: {}
                tool_allowlist:
                  type:
                    - array
                    - 'null'
                  items:
                    type: string
                    maxLength: 64
      responses:
        '200':
          description: Created or updated draft version.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  data:
                    type: object
                    properties:
                      version:
                        type: object
                        properties:
                          id:
                            type: string
                          agent_id:
                            type: string
                          version:
                            type: integer
                          is_draft:
                            type: boolean
                          is_deprecated:
                            type: boolean
                          is_retired:
                            type: boolean
                          persona:
                            type:
                              - string
                              - 'null'
                          model:
                            type:
                              - string
                              - 'null'
                          tool_allowlist:
                            type:
                              - array
                              - 'null'
                            items:
                              type: string
                          default_scope_grants:
                            type: array
                            items:
                              type: object
                              additionalProperties: {}
                          input_schema:
                            type:
                              - object
                              - 'null'
                            additionalProperties: {}
                          output_schema:
                            type:
                              - object
                              - 'null'
                            additionalProperties: {}
                          behavior_constraints:
                            type:
                              - object
                              - 'null'
                            additionalProperties: {}
                          invocation_limits:
                            type:
                              - object
                              - 'null'
                            additionalProperties: {}
                          schema_hash:
                            type:
                              - string
                              - 'null'
                          visibility:
                            type: string
                          released_at:
                            type:
                              - string
                              - 'null'
                          released_by:
                            type:
                              - string
                              - 'null'
                          deprecated_at:
                            type:
                              - string
                              - 'null'
                          retired_at:
                            type:
                              - string
                              - 'null'
                          created_at:
                            type: string
                          updated_at:
                            type: string
                        required:
                          - id
                          - agent_id
                          - version
                          - is_draft
                          - is_deprecated
                          - is_retired
                          - persona
                          - model
                          - tool_allowlist
                          - default_scope_grants
                          - input_schema
                          - output_schema
                          - behavior_constraints
                          - invocation_limits
                          - schema_hash
                          - visibility
                          - released_at
                          - released_by
                          - deprecated_at
                          - retired_at
                          - created_at
                          - updated_at
                    required:
                      - version
                required:
                  - success
                  - data
        '401':
          description: Bearer token is missing, malformed, or revoked.
          content:
            application/json:
              schema:
                type: object
                example:
                  success: false
                  error:
                    type: authentication
                    code: INVALID_API_KEY
                    message: Bearer token is missing, malformed, or revoked.
                    param: null
                    details: null
                    retryable: false
                    request_id: 01JQREQ7XZQK5N6PZ1VVXHYB8T
                  meta:
                    request_id: 01JQREQ7XZQK5N6PZ1VVXHYB8T
        '403':
          description: >-
            The caller is authenticated but lacks the scope or capability this
            route requires.
          content:
            application/json:
              schema:
                type: object
                example:
                  success: false
                  error:
                    type: permission
                    code: MISSING_SCOPE
                    message: >-
                      The caller is authenticated but lacks the scope or
                      capability this route requires.
                    param: null
                    details: null
                    retryable: false
                    request_id: 01JQREQ7XZQK5N6PZ1VVXHYB8T
                  meta:
                    request_id: 01JQREQ7XZQK5N6PZ1VVXHYB8T
        '422':
          $ref: '#/components/responses/ValidationException'
components:
  responses:
    ValidationException:
      description: Validation error
      content:
        application/json:
          schema:
            type: object
            properties:
              message:
                type: string
                description: Errors overview.
              errors:
                type: object
                description: A detailed description of each field that failed validation.
                additionalProperties:
                  type: array
                  items:
                    type: string
            required:
              - message
              - errors
  securitySchemes:
    http:
      type: http
      scheme: bearer

````