> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agno.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Per-User Component Isolation

> Demonstrates serving components with per-user isolation, so each caller only sees and manages the agents, teams, and workflows they created.

```python user_isolation_os.py theme={null}
"""
Per-User Component Isolation
============================

Demonstrates serving components with per-user isolation, so each caller only
sees and manages the agents, teams, and workflows they created.

Components created over POST /components are stamped with the caller's JWT
subject, and the component, list, and run routes are scoped to that owner.
Admins (agent_os:admin scope) keep seeing everything.

Generate a token for a user with:

    python -c "import jwt, datetime as d; print(jwt.encode({'sub': 'alice', \
'scopes': ['components:read', 'components:write', 'components:delete', \
'agents:read', 'agents:run'], 'exp': d.datetime.now(d.UTC) + \
d.timedelta(hours=1)}, 'my-jwt-secret', algorithm='HS256'))"

Then create a component as that user:

    curl -X POST http://localhost:7777/components \
        -H "Authorization: Bearer $ALICE_TOKEN" -H "Content-Type: application/json" \
        -d '{"name": "Alice Agent", "component_type": "agent", "stage": "published",
             "config": {"name": "Alice Agent", "instructions": "You are Alice private agent."}}'

A token for a different user sees none of it:

    curl http://localhost:7777/components -H "Authorization: Bearer $BOB_TOKEN"
    curl http://localhost:7777/agents -H "Authorization: Bearer $BOB_TOKEN"
"""

from agno.db.postgres import PostgresDb
from agno.os import AgentOS
from agno.os.config import AuthorizationConfig

# ---------------------------------------------------------------------------
# Setup
# ---------------------------------------------------------------------------
db = PostgresDb(db_url="postgresql+psycopg://ai:ai@localhost:5532/ai", id="postgres_db")

# ---------------------------------------------------------------------------
# Create AgentOS App
# ---------------------------------------------------------------------------
# No agents are registered in code: only components created over the API live in
# the database and can be owned. Components passed to AgentOS(agents=[...]) are shared.
agent_os = AgentOS(
    id="user-isolation-os",
    db=db,
    authorization=True,
    authorization_config=AuthorizationConfig(
        verification_keys=["my-jwt-secret"],
        algorithm="HS256",
        user_isolation=True,
    ),
)

app = agent_os.get_app()

# ---------------------------------------------------------------------------
# Run AgentOS App
# ---------------------------------------------------------------------------
if __name__ == "__main__":
    agent_os.serve(app="user_isolation_os:app", reload=True)
```

## Run the Example

<Steps>
  <Snippet file="create-venv-step.mdx" />

  <Step title="Install dependencies">
    ```bash theme={null}
    uv pip install -U "agno[os]" "psycopg[binary]"
    ```
  </Step>

  <Snippet file="run-pgvector-step.mdx" />

  <Step title="Run the example">
    Save the code above as `user_isolation_os.py`, then run:

    ```bash theme={null}
    python user_isolation_os.py
    ```
  </Step>
</Steps>

Full source: [cookbook/93\_components/user\_isolation\_os.py](https://github.com/agno-agi/agno/blob/v3.0.4/cookbook/93_components/user_isolation_os.py)
