Browse docs · Guides
Get started
Concepts
Guides
Security
Reference
Docs / Guides
Any HTTP API
Broker calls to any HTTPS API for AI agents: the token is injected by the broker and never returned, with an optional host allowlist.
For APIs without a dedicated adapter, the generic HTTP provider calls any HTTPS endpoint with your token injected broker-side. The agent sends the request shape; it never sees the token.
Actions and parameters
Actions are HTTP methods: GET, POST, PUT, PATCH, DELETE. The resource is the absolute HTTPS base URL. Parameters:
path | Appended to the base URL |
query | Object of query parameters |
body | JSON body |
headers | Extra non-secret headers |
{"provider": "http", "resource": "https://api.example.com", "action": "GET",
"parameters": {"path": "/v1/status", "query": {"verbose": "true"}}}
Locking it down
- Only
httpsresources are accepted. - Set
HTTP_ALLOWED_HOSTS(comma-separated) on the broker to refuse any other host. - Use policy constraints on
path(for example aprefix) so an agent can only reach the routes you intend.
The token itself is long-lived, since a generic API cannot be asked to mint a narrower one. It still never leaves the broker.