Developer documentation
Fast path
Last reviewed 31 August 2026
All docs
Every decision CAIN records is normally ordered by a 4-replica PBFT cluster before your agent gets its answer. That round trip is most of a decision's time: about 600 ms end to end from the public internet.
The fast path takes that round off the hot path for an agent you trust with specific tools. The cluster commits the agent's authorization once, as a signed snapshot. After that, the agent's calls to those tools are answered in about 70 ms, measured on production on 1 October 2026 (20 of 20 calls on the fast path, p50 72 ms, against p50 587 ms for the same agent on a tool without a grant).
What does not change#
- Every check still runs on every call: identity, policy, your tool rules, aggregate budgets, the injection
screen, trust, approvals. Only a call those checks already ALLOWED skips the consensus round.
- A held, denied or degraded call goes through the normal path, as before.
- Evidence: each fast-path decision is still signed, and its commitment is anchored into a Merkle root that the
cluster quorum-commits a few seconds later. Check it at /api/v1/governance/anchor/<decision_id>.
- Revocation bites on the next call: revoking the agent key, removing the grant, or a change to the agent's
identity all end the fast path immediately.
Turn it on#
In the console: Agents → Agent keys & fast path, list the tools, Enable.
Or with your account's own key (an agent key can never grant itself):
curl -X POST https://cainstudio.online/fabric/agent-keys/<agent_key_id>/fast-path \
-H "X-API-Key: $CAIN_API_KEY" -H "content-type: application/json" \
-d '{"tools": ["/tools/read_file", "/tools/search/"]}'
tools: exact paths, or a folder with a trailing/. Wildcards,..and//are refused.service: leave it out for your own tools; set it to a catalog slug for a proxied service.ttl_s: snapshot lifetime, 5–900 s (default 120). The cluster renews it while the grant lasts.
The agent must have made at least one call. Turn it off with DELETE on the same URL. GET /fabric/agent-keys shows each key's fast_path.
When a call still takes the slow path#
You see in the decision's consensus stage | Why |
ordered by 2f+1 of 4 replicas … | The call was not ALLOWED before consensus (held, denied), the tool is not in the grant, or the snapshot is renewing. |
mode: authorization_snapshot | Fast path. |
A new agent's first calls are held for a human until it has earned trust: the held decision says how many approvals are left ("2 of 5 approved actions so far. After 3 more, …"). Only then can its calls be ALLOWED, and so use the fast path.