Expand description
/api/v1: the REST API over the user’s monitored sites. Every route is a thin layer over
AgentService, which the cloud MCP tools share, so both return the same JSON and count
against the same daily quota.
Authentication is Authorization: Bearer <key> and nothing else (no cookies). Errors are
{"error":{"code","message"}}; every keyed response carries X-RateLimit-Limit and
X-RateLimit-Remaining (calls left today, UTC), both left out on plans without a limit, and
a 429 adds Retry-After (seconds to the next 00:00 UTC). The routes are exempt from the
Origin check, since no browser session reaches them.
Constants§
- PREFIX
- Where the API lives; the
Origincheck exempts everything under it.