Key design choices
Actions run in the browser, not on the server. The bridge never reimplements business logic. It forwards the invocation to the handler the page registered, the same one a button click calls. That keeps the agent’s view and the human’s view identical, and means adding AIP to a page doesn’t require a parallel API. The manifest is live. The page re-syncs its snapshot whenever registered state or actions change. A signed-out page only exposeslogin; after login it exposes the real actions. Agents should always read the manifest before acting.
One invocation at a time per session. A second invocation while one is in flight gets 409. This keeps ordering simple and predictable.
The human stays in the loop. A session requires a live, visible browser tab. Closing the tab stops processing.
Serializations
Every manifest is available as JSON (/page.json) and TOON (/page.toon). TOON is a compact, token-efficient encoding of the same data. It is a serialization, not a separate schema.