---
title: Restart attribution (no restart is ever anonymous)
---

# Restart attribution (no restart is ever anonymous)

## What it is

In a dev (`npm run dev`) install, agents and automations can restart Omniscio over the
command-line API (`POST /app/restart`) — for example to pick up freshly merged code. A restart
tears the window down for the ~2-minute supervisor rebuild, so from the user's chair an
**unattributed** restart is indistinguishable from a crash. On 2026-08-02 three anonymous
restarts (global CLI token, no source session) read as a "mystery crash" and cost a full
investigation to explain.

## Where to find it

### Where you see it

- The notice appears in your Inbox after an agent/supervisor-triggered restart, deduped under
  one card that refreshes to the latest restart.
- A refused anonymous caller sees the `400` body naming the exact headers to send.

Contract: `restart-amc-invariants-mechanism-contract.md` (`I10`; the separate owner off-switch `allowAgentAppRestart` is `I9`).

## How it behaves

### What Omniscio does

Two halves, both dev-only (a packaged build has no dev restart at all):

1. **Anonymous restart commands are refused.** Every `POST /app/restart` caller must identify
   itself — a validated `X-AMC-Source-Session-Id` (AMC-spawned agents already have it in
   `$AMC_SESSION_ID`), a validated active `X-AMC-Source-Cron-Job-Id`, or the dev supervisor's
   own `X-AMC-Restart-Origin` header (a closed set the supervisor sends on its automatic
   relaunches, e.g. after a build-configuration change). A caller with none of these gets a
   clear `400` explaining exactly how to comply, and **no restart happens**. The provenance
   requirement has no off-switch. This is attribution, not authorization — the bearer token
   still gates access, and a separate owner switch (`allowAgentAppRestart`, default OFF)
   403-blocks ALL headless restarts until you enable it at Settings → CLI Control; the point
   here is that any restart that IS allowed can always be traced to a requester.

2. **The relaunch says who did it.** When an agent, scheduled job, or the supervisor restarts
   Omniscio, the next boot raises one persistent inbox notice — *"Omniscio was restarted at
   \<time\> at the request of the session \"\<name\>\" … this was a deliberate restart, not a
   crash."* — with the requesting session attached as its provenance. Restarts you trigger
   yourself with the header **Restart** button stay silent (you already know). A stale record
   (the relaunch didn't follow within 6 hours) or a genuine crash produces no notice, so the
   card can never cry wolf.

## Related

No other library page covers this ground directly. [INDEX.md](INDEX.md) is the library index, and it is the quickest way to find the surrounding pages on sessions, the inbox, and CLI control that a restart touches.
