Docs / Guides

Any HTTP API

Broker calls to any HTTPS API for AI agents: the token is injected by the broker and never returned, with an optional host allowlist.

For APIs without a dedicated adapter, the generic HTTP provider calls any HTTPS endpoint with your token injected broker-side. The agent sends the request shape; it never sees the token.

Actions and parameters

Actions are HTTP methods: GET, POST, PUT, PATCH, DELETE. The resource is the absolute HTTPS base URL. Parameters:

pathAppended to the base URL
queryObject of query parameters
bodyJSON body
headersExtra non-secret headers
{"provider": "http", "resource": "https://api.example.com", "action": "GET",
 "parameters": {"path": "/v1/status", "query": {"verbose": "true"}}}

Locking it down

  • Only https resources are accepted.
  • Set HTTP_ALLOWED_HOSTS (comma-separated) on the broker to refuse any other host.
  • Use policy constraints on path (for example a prefix) so an agent can only reach the routes you intend.

The token itself is long-lived, since a generic API cannot be asked to mint a narrower one. It still never leaves the broker.