AIP (Agent Interface Protocol) is an open protocol that lets a website describe its state and actions to AI agents in a machine-readable manifest. Today, an agent that wants to use a website has to drive a browser: take screenshots, guess which button is which, click, and hope the layout didn’t change. AIP replaces that with a contract. The page publishes an Agent Interface Manifest (AIM) listing what it currently shows and which actions it accepts, each with an input schema. The agent reads the manifest and invokes actions over plain HTTP. Think of AIP like an API that a web page grows automatically: the same handlers that power the buttons a human clicks also power the actions an agent invokes.

An agent approves a request through AIP: discover, read, act.

AIP is at version 0.1-demo. The reference implementation is a prototype, not a production authorization system. See Security before using real data.

What can AIP enable?

  • An agent approves or rejects items in an admin queue by calling approve_request with an ID instead of hunting for the right row on screen.
  • An agent searches a store, adds a product variant to a cart and prepares checkout, then tells you the total without placing the order.
  • A human keeps the page open and watches every change happen live, because actions run in their own browser tab.

Why does AIP matter?

  • Website builders: expose what agents can do with a few hooks around code you already have. No separate agent API to maintain.
  • Agents: get exact state and typed actions instead of pixels. Fewer turns, fewer tokens, fewer mis-clicks. See the benchmark.
  • End users: delegate tasks on the sites they already use, with the page as the visible source of truth.

How it looks to an agent

Start building

Quickstart

Run the demo and let an agent drive it in five minutes

Add AIP to a React app

Expose state and actions with two hooks

Plain HTML / vanilla JS

No framework required

Build an agent client

Discover, read, invoke and verify

Learn more

Architecture

How the page, the bridge and the agent fit together

Security

Tokens, consequential actions and unknown outcomes