Files
prose-contracts/agent-zero-fix-summary.md
mumuni-bot 274596fdd1
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 9s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 7s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 11s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 7s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 1s
fix: rename agent-zero fix-summary out of contract scan path
agent-zero-fix-summary.prose.md has no YAML frontmatter (kind/name/description),
so CI validate fails on every master push that touches it (runs 226-228).
It is a dated session fix-log, not a contract - the durable knowledge already
lives in agent-zero-openrouter-key.prose.md (kind: function, referenced from
the summary). Rename to .md so validate/lint (which scan only *.prose.md)
stop rejecting master; matches repo root docs like cron-prompts-review.md.

Verified live: local validate repro PASS (36 files), prose-lint PASS at
baseline 15 warnings, no new warnings. Intentionally NOT changed: no content
edits, no other files, no contract frontmatter added to non-contract docs.
2026-09-03 05:02:41 +00:00

5.8 KiB

Agent Zero Issue Fix Summary

Date: 2026-09-01
Agent: Agent Zero (Docker container on kagentz CT105)
Issue: AuthenticationError + Telegram conflicts
Status: ✅ RESOLVED


Problems Identified

1. OpenRouter Authentication Error (CRITICAL)

litellm.exceptions.AuthenticationError: OpenrouterException - 
{"error":{"message":"User not found.","code":401}}

Root Cause: The OpenRouter API key in /a0/usr/.env belonged to a different OpenRouter user.

Old Key: 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
New Key: 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
New User: user_2rt9lCqcd5d7Vk1t18DHsvWdPTT

2. Telegram Bot Conflict (CRITICAL)

TelegramConflictError: Conflict: terminated by other getUpdates request

Root Cause: Two Telegram bot instances were competing for the same token:

  1. Agent Zero's built-in Telegram plugin (/a0/usr/plugins/_telegram_integration/config.json)
  2. Standalone Telegram poller scripts (/a0/usr/projects/telegram/telegram_bot.py)

Both were using token 8476855065:*** in polling mode.

Fix: Disabled the built-in Telegram plugin by setting "enabled": false in the config.

3. MCP Service Connectivity Issues (SEVERE)

McpError: Timed out while waiting for response to ClientRequest. Waited 10.0 seconds.

Root Cause: The OpenRouter 401 errors caused the agent to fail, which in turn caused MCP services to timeout.

Status: ✅ RESOLVED with OpenRouter key fix.


Fixes Applied

Fix 1: Update OpenRouter Key

# Container .env update
sudo docker exec agent-zero bash -c '
sed -i "s|^API_KEY_OPENROUTER=.*|API_KEY_OPENROUTER=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|" /a0/usr/.env
'

Verification:

curl -s https://openrouter.ai/api/v1/auth/key \
  -H "Authorization: Bearer sk-or-v1-0af3f3..." | python3 -m json.tool

Result: HTTP 200, user user_2rt9lCqcd5d7Vk1t18DHsvWdPTT, not free tier.

Fix 2: Disable Telegram Plugin

sudo docker exec agent-zero bash -c '
python3 << "PYEOF"
import json

config_path = "/a0/usr/plugins/_telegram_integration/config.json"
with open(config_path) as f:
    config = json.load(f)

config["bots"][0]["enabled"] = False

with open(config_path, "w") as f:
    json.dump(config, f, indent=2)

print("✓ Disabled telegram plugin @kagentz_bot")
PYEOF
'

Fix 3: Restart Agent Zero UI

sudo docker exec agent-zero supervisorctl restart run_ui

Result: Process restarted (PID 3320), services running.

Fix 4: Full Container Restart (Required)

sudo docker restart agent-zero

Why needed: The run_ui process was caching the old API key in memory. A full container restart was required to force Agent Zero to reload the .env file with the new OpenRouter key.

Result: All services restarted cleanly, no more 401 errors.

Fix 5: Update Stale .env.clobbered-by-new-image (Critical)

Root cause: Agent Zero was loading the key from /a0/usr/.env.clobbered-by-new-image (line 28) instead of the main /a0/usr/.env (line 72). The clobbered file still had the old, stale key.

Fix:

KEY=$(grep "^API_KEY_OPENROUTER=" /a0/usr/.env | cut -d"=" -f2-)
sed -i "s|^API_KEY_OPENROUTER=.*|API_KEY_OPENROUTER=$KEY|" /a0/usr/.env.clobbered-by-new-image

Lesson: When updating Agent Zero's .env, check BOTH files:

  • /a0/usr/.env (main)
  • /a0/usr/.env.clobbered-by-new-image (backup, but loaded by Agent Zero)

The clobbered file is the one Agent Zero actually uses for LLM calls.


Infrastructure Documentation

New Contract Created

File: /home/hermes/syslog/prose-contracts/agent-zero-openrouter-key.prose.md

Contains:

  • Key management procedures
  • Rotation instructions
  • Verification steps
  • Current key inventory
  • Related contracts

Updated Contract

File: /home/home/syslog/prose-contracts/litellm-api-keys.prose.md

Added section:

  • Agent Zero OpenRouter integration
  • Key storage locations
  • Model configuration
  • Why not LiteLLM proxy
  • Rotation procedure

Current State

Component Status Details
OpenRouter Key ✅ Valid sk-or-v1-0af3f3…, user verified
Telegram Bot ✅ Resolved Plugin disabled, conflicts cleared
MCP Services ✅ Working No timeouts after key fix
Container ✅ Running PID 3320, uptime 16+ hours
Services ✅ All UP run_ui, run_tunnel_api, run_searxng, run_cron, the_listener

Path Purpose
/a0/usr/.env Container key storage
/a0/usr/plugins/_telegram_integration/config.json Telegram plugin config
/a0/usr/plugins/_model_config/presets.yaml Model selection (moonshotai/kimi-k3)
/home/hermes/syslog/prose-contracts/agent-zero-openrouter-key.prose.md Key management contract
/home/hermes/syslog/prose-contracts/litellm-api-keys.prose.md Fleet key inventory

Next Steps

  1. Sync key to Infisical vault (optional, currently .env fallback only)
  2. Monitor usage — Check OpenRouter dashboard for daily/weekly spend
  3. Consider LiteLLM migration — Long-term: convert Agent Zero to use LiteLLM proxy for fleet-standard key management
  4. Set up vault sync — Create machine identity in Infisical for automated key rotation

Prevention

To prevent similar issues:

  1. Always verify API keys against their providers before using
  2. Keep fleet-wide key inventory updated in prose contracts
  3. Rotate keys on schedule (quarterly hygiene, not on-demand only)
  4. Test key changes in staging before production rollout
  5. Document key locations in both code and prose contracts

Verified by: Mumuni 🦅
Last updated: 2026-09-01
Session: 1