Each agent-enabled page publishes an Agent Interface Manifest (AIM) at <page>.json and <page>.toon. It answers two questions: what does this page currently show? and what can I do here?
Example
State
state is whatever the page chose to publish: plain JSON, keyed by name. Pages decide what’s useful to an agent and what stays private. Passwords are never published.
Actions
Each action has:
id: the name you pass as actionId.
description: what it does, written for a model.
input_schema: the exact shape of input. Either a string, or a flat object of string fields.
input_example: a concrete valid input. When in doubt, copy its shape.
consequential: true if the action changes something that matters (money, orders, approvals). Agents should confirm with the user before invoking these.
Pass input exactly as the schema says. If the schema is a string, send "input": "req-3", not "input": {"id": "req-3"}.
Public vs session manifests
Without a token you get state_scope: "public_schema_only": the action catalog with empty state. It never contains another visitor’s data. With a valid session token you get state_scope: "session" and that session’s live state and registered actions. See Sessions & auth.
Full field reference: Manifest schema.