AIP has three participants:

Key design choices

Actions run in the browser, not on the server. The bridge never reimplements business logic. It forwards the invocation to the handler the page registered, the same one a button click calls. That keeps the agent’s view and the human’s view identical, and means adding AIP to a page doesn’t require a parallel API. The manifest is live. The page re-syncs its snapshot whenever registered state or actions change. A signed-out page only exposes login; after login it exposes the real actions. Agents should always read the manifest before acting. One invocation at a time per session. A second invocation while one is in flight gets 409. This keeps ordering simple and predictable. The human stays in the loop. A session requires a live, visible browser tab. Closing the tab stops processing.

Serializations

Every manifest is available as JSON (/page.json) and TOON (/page.toon). TOON is a compact, token-efficient encoding of the same data. It is a serialization, not a separate schema.