All POST requests must send Content-Type: application/json and, if an Origin header is present, it must match the site origin. Bodies are limited to 64 KiB. Authenticate with Authorization: Bearer <token> or the aim_session cookie.

Agent-facing

GET <page>.json · GET <page>.toon

Returns the manifest. Token optional; without it, public schema only.

POST /__aim/invoke

Request
200 Response
504 Response
string
required
An id from the manifest’s actions[].
any
required
A value matching that action’s input_schema. Not wrapped.

POST /__aim/disconnect

Revokes the token and clears the cookie. Same effect as invoking the disconnect action.

Page-facing

These are used by the page’s bridge client. Agents don’t call them.