Create an Executable
Before creating an executable, upload an active release, complete a profile's setup in the same project, and create any required secrets. Use Console → Executables → Create, or the equivalent management CLI and API operations.
1. Select code and args
Choose the function and immutable version tag. Enter args using the generated Fields form or raw JSON. Check address arguments carefully because a permission manifest may use them to resolve the profile scope required by this release.
2. Set a schedule
Choose an interval or cron expression. The console offers presets and a human-readable schedule preview. An interval can specify a future start time. Manual runs and webhooks are additional invocation channels; an executable still stores a cron or interval schedule.
Choose a cadence that leaves room for chain confirmation and external API limits. Overlapping calls do not provide an unlimited work queue.
3. Bind secrets
Select only the project secrets this task reads. The runtime resolves those values on each invocation and exposes them through ctx.secrets. A local .env file is not uploaded or automatically bound.
4. Select account, gas, and runtime
Choose an active profile on the intended chain. Review the permission-coverage result. Missing scope allows creation, but the executable stays paused until coverage is resolved. Invalid or unavailable permission checks still block creation.
Roles profiles require sponsored gas. Legacy profiles may use sponsored or wallet-paid execution, with optional insufficient-balance fallback. See gas modes.
Select an available sandbox runtime when offered. Daytona is the compatibility default; gVisor is available only on deployments with that runtime configured. Durable state belongs in ctx.storage in either case.
Provision and verify
Creation enters provisioning; once the sandbox is ready and permissions are covered, the executable becomes active and its schedule starts. Missing coverage leaves it paused without registering the schedule. Inspect the execution detail page, use Simulate for a preview, and run Execute now when ready for an actual submission.
A simulation ends as skipped, does not commit storage, and does not establish that all later sponsorship or on-chain checks will pass.
An owner or admin can explicitly attempt one manual run with missing call permissions from the detail page, including while paused. Check Override missing permissions for one manual run, then Attempt one run. This skips the manifest-coverage preflight for that attempt only; runtime call checks and on-chain permissions remain enforced. Allowed calls can execute and incur fees. Invalid policies, forbidden calls, and incomplete or changing profiles cannot be overridden. The attempt does not activate the schedule.
Later changes
You can change args, schedule, secrets, gas settings, and the profile within the same chain, subject to permissions and migration guards. Pause before switching the function release. A completed switch remains paused until explicitly activated.
For operation and recovery, see executable lifecycle, monitoring, and release management.