# Concepts (/docs/concepts)



<ArchitectureFlow />

Clients — Studio, the Agents SDK, HTTP, the CLI, and the Admin SDK — call the
Runtime API. The Runtime runs sessions, stores state, keeps artifacts,
provisions sandboxes, and records durable execution and streams. Outbound
calls to a model provider, MCP, HTTP tools, and the web go through the
Gateway.

## Words [#words]

| Term                | Meaning                                                                                                                                                                                                                                                         |
| ------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Tenant**          | One Nylorun installation: a Runtime with its own database, Studio, and data. Nothing is shared between Tenants. A project gets its own local Tenant; several run side by side on one machine. Requests never name a Tenant — the Runtime's URL is the Tenant's. |
| **Runtime**         | The service that runs sessions, calls the model, runs sandboxes, and stores history and files. Ships as `ghcr.io/nylorun/runtime`.                                                                                                                              |
| **Agent**           | A definition: an id, instructions, and the tools the model may call. Built with `@nylorun/agents`.                                                                                                                                                              |
| **Flow agent**      | An agent whose body is a flow: your code decides what runs next. Saved and opened like any agent.                                                                                                                                                               |
| **Action endpoint** | An HTTP route the Runtime calls for each tool call, hook, or flow function. Your tools run in your app.                                                                                                                                                         |
| **Session**         | One durable conversation or flow run, owned by `ownerUserId`.                                                                                                                                                                                                   |
| **Turn**            | One input and everything the agent does until it completes, pauses, fails, or is cancelled.                                                                                                                                                                     |
| **Sandbox**         | A workspace given to a session. Virtual by default; pod sandboxes run on Kubernetes after you enable them.                                                                                                                                                      |
| **Artifact**        | A file the Runtime stores: uploads, versions, and short-lived download links.                                                                                                                                                                                   |
| **Studio**          | The operator dashboard for one Tenant, served on loopback.                                                                                                                                                                                                      |
| **Action**          | One unit of your code the Runtime asks for: a tool call, a hook, or a flow `fn`, `verify`, or tool step.                                                                                                                                                        |
| **Project link**    | `.nylorun/link.json` and `credentials.json`, written by `nylorun start`.                                                                                                                                                                                        |
| **Scope**           | What a signed-in person may do when your app calls `client.as()`, for example `sessions:own`.                                                                                                                                                                   |

## Open source and Cloud [#open-source-and-cloud]

The Runtime, Studio, SDKs, and CLIs are open source. You can build, run, and
self-host everything on the Guides tab without a Nylorun account. The Runtime
verifies and enforces; it never signs people in or manages users. [Nylorun
Cloud](/docs/deploy/cloud) is the managed option: an isolated installation plus
sign-in, organisations, and billing, available by invitation.

## Next step [#next-step]

<Cards>
  <Card title="Your project" description="The generated tree, scripts, and where state lives." href="/docs/project" />

  <Card title="Studio" description="Sign in and run the starter agent." href="/docs/run/studio" />
</Cards>
