{"openapi":"3.1.0","info":{"title":"Thru API","version":"1.0.0","description":"A credential-holding proxy for AI agents. Agents create a public proxy configuration and send the user a one-use browser setup link. The user enters provider credentials directly into Thru. Agents use a separate access capability to call a fixed public HTTPS API with headers or AWS SigV4 authentication injected by Thru. Credentials are encrypted at rest and never returned by setup or status APIs. Responses containing known credential echoes are blocked. A trusted destination and scoped provider credentials are essential: echo detection cannot guarantee protection from a malicious upstream."},"servers":[{"url":"https://thru.snd.one"}],"tags":[{"name":"Proxies"},{"name":"Browser setup"},{"name":"Owner management"},{"name":"Proxy requests"},{"name":"Documentation"}],"paths":{"/api/proxies":{"post":{"operationId":"createProxy","summary":"Create a proxy and a one-use browser setup link","tags":["Proxies"],"security":[],"description":"Unauthenticated creation. Configuration contains credential field definitions and template references, never provider credential values. Maximum JSON body: 64 KiB. Keep access_token privately and give the user auth_url unchanged, including the fragment. Setup is one-use and expires within one hour. The proxy expires 24 hours after creation by default, at most 7 days.","requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateProxy"},"examples":{"github":{"value":{"name":"GitHub","description":"Read your GitHub profile and repositories.","target_url":"https://api.github.com","credential_url":"https://github.com/settings/personal-access-tokens/new","credentials":[{"key":"api_key","label":"GitHub personal access token","description":"Use a token with only the repository permissions needed for this task.","placeholder":"github_pat_…"}],"headers":{"Authorization":"Bearer {{api_key}}","Accept":"application/vnd.github+json","X-GitHub-Api-Version":"2022-11-28"},"allowed_methods":["GET","HEAD"],"expires_in":86400}},"multipleCredentials":{"value":{"name":"Acme API","description":"Use the project API with a key and a separate project identifier.","target_url":"https://api.example.com/v1","credentials":[{"key":"api_key","label":"API key"},{"key":"project_id","label":"Project ID"}],"headers":{"Authorization":"Bearer {{api_key}}","X-Project-ID":"{{project_id}}"},"allowed_methods":["GET","HEAD"]}},"aws":{"value":{"name":"AWS Lambda","description":"Invoke the Lambda functions needed for this task.","target_url":"https://lambda.us-east-1.amazonaws.com/2015-03-31/functions","credential_url":"https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html","credentials":[{"key":"access_key_id","label":"AWS access key ID"},{"key":"secret_access_key","label":"AWS secret access key"},{"key":"session_token","label":"AWS session token","description":"This example requires temporary credentials, including a session token."}],"headers":{},"auth":{"type":"aws-sigv4","service":"lambda","region":"us-east-1","access_key_id":"access_key_id","secret_access_key":"secret_access_key","session_token":"session_token"},"allowed_methods":["POST"],"expires_in":3600}}}}}},"responses":{"201":{"description":"Proxy configuration with the one-use setup URL and an agent access token returned only on creation.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreatedProxy"}}}},"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Configuration JSON body exceeds 64 KiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}}}}},"/api/proxies/{id}":{"get":{"operationId":"getProxyStatus","summary":"Read public configuration and current status","tags":["Proxies"],"description":"Poll gently with the agent access token. Provider credentials, the setup token, and the owner token are never returned.","security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"responses":{"200":{"description":"Safe proxy metadata and current status.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Proxy"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}}}},"delete":{"operationId":"revokeProxy","summary":"Revoke the proxy and erase stored credentials","tags":["Owner management"],"description":"Requires the owner token from the management URL issued to the user after setup. The agent access token cannot revoke a proxy.","security":[{"ownerAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"responses":{"200":{"description":"The proxy is revoked.","content":{"application/json":{"schema":{"type":"object","properties":{"status":{"const":"revoked"}},"required":["status"]}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}}}}},"/api/proxies/{id}/setup":{"get":{"operationId":"getSetupMetadata","summary":"Read metadata for the user credential form","tags":["Browser setup"],"description":"Browser-only capability obtained from the auth_url fragment. Never returns credentials.","security":[{"setupAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"responses":{"200":{"description":"Safe proxy metadata.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Proxy"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}}}}},"/api/proxies/{id}/credentials":{"post":{"operationId":"submitCredentials","summary":"User submits credentials directly from the Thru form","tags":["Browser setup"],"security":[{"setupAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"description":"Consumes the one-use setup token. All declared credential fields are required. Maximum JSON body: 64 KiB. The user can narrow allowed_methods to a nonempty subset of the configured methods. Agents must never collect or submit provider credentials on the user's behalf. Authenticated means saved, not verified by the provider.","requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CredentialSubmission"}}}},"responses":{"200":{"description":"Credentials saved. The management URL carries a separate owner capability in its fragment; save it privately.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConnectionResult"}}}},"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Credential submission JSON body exceeds 64 KiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}}}}},"/api/proxies/{id}/manage":{"get":{"operationId":"getManagementMetadata","summary":"Read metadata for the owner management page","tags":["Owner management"],"security":[{"ownerAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"responses":{"200":{"description":"Safe proxy metadata.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Proxy"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}}}}},"/p/{id}":{"get":{"operationId":"proxyGETBase","summary":"Forward GET to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"head":{"operationId":"proxyHEADBase","summary":"Forward HEAD to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"post":{"operationId":"proxyPOSTBase","summary":"Forward POST to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"requestBody":{"required":false,"description":"The exact upstream API request body; maximum 1 MiB.","content":{"*/*":{"schema":{}}}},"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"put":{"operationId":"proxyPUTBase","summary":"Forward PUT to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"requestBody":{"required":false,"description":"The exact upstream API request body; maximum 1 MiB.","content":{"*/*":{"schema":{}}}},"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"patch":{"operationId":"proxyPATCHBase","summary":"Forward PATCH to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"requestBody":{"required":false,"description":"The exact upstream API request body; maximum 1 MiB.","content":{"*/*":{"schema":{}}}},"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"delete":{"operationId":"proxyDELETEBase","summary":"Forward DELETE to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"requestBody":{"required":false,"description":"The exact upstream API request body; maximum 1 MiB.","content":{"*/*":{"schema":{}}}},"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"options":{"operationId":"proxyOPTIONSBase","summary":"Forward OPTIONS to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}}],"requestBody":{"required":false,"description":"The exact upstream API request body; maximum 1 MiB.","content":{"*/*":{"schema":{}}}},"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}}},"/p/{id}/{path}":{"get":{"operationId":"proxyGETPath","summary":"Forward GET to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}},{"name":"path","in":"path","required":true,"description":"API path suffix, which can contain slashes. Appended below the fixed target base path. Forward arbitrary API query parameters as usual.","schema":{"type":"string"}}],"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"head":{"operationId":"proxyHEADPath","summary":"Forward HEAD to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}},{"name":"path","in":"path","required":true,"description":"API path suffix, which can contain slashes. Appended below the fixed target base path. Forward arbitrary API query parameters as usual.","schema":{"type":"string"}}],"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"post":{"operationId":"proxyPOSTPath","summary":"Forward POST to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}},{"name":"path","in":"path","required":true,"description":"API path suffix, which can contain slashes. Appended below the fixed target base path. Forward arbitrary API query parameters as usual.","schema":{"type":"string"}}],"requestBody":{"required":false,"description":"The exact upstream API request body; maximum 1 MiB.","content":{"*/*":{"schema":{}}}},"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"put":{"operationId":"proxyPUTPath","summary":"Forward PUT to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}},{"name":"path","in":"path","required":true,"description":"API path suffix, which can contain slashes. Appended below the fixed target base path. Forward arbitrary API query parameters as usual.","schema":{"type":"string"}}],"requestBody":{"required":false,"description":"The exact upstream API request body; maximum 1 MiB.","content":{"*/*":{"schema":{}}}},"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"patch":{"operationId":"proxyPATCHPath","summary":"Forward PATCH to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}},{"name":"path","in":"path","required":true,"description":"API path suffix, which can contain slashes. Appended below the fixed target base path. Forward arbitrary API query parameters as usual.","schema":{"type":"string"}}],"requestBody":{"required":false,"description":"The exact upstream API request body; maximum 1 MiB.","content":{"*/*":{"schema":{}}}},"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"delete":{"operationId":"proxyDELETEPath","summary":"Forward DELETE to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}},{"name":"path","in":"path","required":true,"description":"API path suffix, which can contain slashes. Appended below the fixed target base path. Forward arbitrary API query parameters as usual.","schema":{"type":"string"}}],"requestBody":{"required":false,"description":"The exact upstream API request body; maximum 1 MiB.","content":{"*/*":{"schema":{}}}},"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}},"options":{"operationId":"proxyOPTIONSPath","summary":"Forward OPTIONS to the configured API","description":"Requires the agent access token. The target host and base path are fixed. The path suffix and query are forwarded, configured credential headers replace matching client headers, and the Thru Authorization header is consumed. AWS configurations receive a SigV4 signature of the complete body. Redirects are rejected with HTTP 502 and never followed. Only supported UTF-8 text, JSON, and XML responses up to 1 MiB are returned; responses containing known credential echoes are blocked. Proxy rate limit: 60 requests per minute. Timeout: 30 seconds.","tags":["Proxy requests"],"security":[{"agentAccess":[]}],"parameters":[{"name":"id","in":"path","required":true,"description":"Proxy identifier returned on creation.","schema":{"type":"string"}},{"name":"path","in":"path","required":true,"description":"API path suffix, which can contain slashes. Appended below the fixed target base path. Forward arbitrary API query parameters as usual.","schema":{"type":"string"}}],"requestBody":{"required":false,"description":"The exact upstream API request body; maximum 1 MiB.","content":{"*/*":{"schema":{}}}},"responses":{"400":{"description":"Invalid request or configuration.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"401":{"description":"Missing or invalid capability token.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"403":{"description":"Cross-origin browser request is forbidden.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"404":{"description":"Proxy does not exist.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"405":{"description":"HTTP method is not permitted.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"409":{"description":"Proxy is not authenticated, or setup has already completed.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"410":{"description":"Proxy is expired or revoked, or the setup capability has expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"413":{"description":"Request or response body exceeds 1 MiB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"415":{"description":"Configuration or credentials submission requires Content-Type: application/json.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"429":{"description":"Rate limit exceeded. Wait before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"502":{"description":"Upstream request failed, or the response cannot safely be returned.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"503":{"description":"Required Thru server configuration is missing.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"504":{"description":"Upstream request timed out.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}}},"default":{"description":"Upstream status and supported response body for responses that pass safety checks. Upstream redirects are rejected with HTTP 502. The proxy may also return a JSON error.","content":{"application/json":{"schema":{}},"text/plain":{"schema":{"type":"string"}},"application/xml":{"schema":{"type":"string"}}}}}}},"/llms.txt":{"get":{"operationId":"getAgentInstructions","summary":"Read the full agent setup and usage guide","tags":["Documentation"],"security":[],"responses":{"200":{"description":"Plain-text agent instructions and examples.","content":{"text/plain":{"schema":{"type":"string"}}}}}}},"/openapi.json":{"get":{"operationId":"getOpenApi","summary":"Read this OpenAPI document","tags":["Documentation"],"security":[],"responses":{"200":{"description":"OpenAPI 3.1 document.","content":{"application/json":{"schema":{"type":"object"}}}}}}}},"components":{"securitySchemes":{"agentAccess":{"type":"http","scheme":"bearer","description":"Agent access_token returned only at creation. Grants proxy use and status access, never provider credential disclosure or owner revocation."},"setupAccess":{"type":"apiKey","in":"header","name":"X-Thru-Setup-Token","description":"One-use browser setup token from the auth_url fragment. Expires after one hour or at proxy expiry."},"ownerAccess":{"type":"http","scheme":"bearer","description":"Owner token from the management_url fragment issued to the browser after setup. Grants owner metadata and revocation."}},"schemas":{"CredentialField":{"type":"object","additionalProperties":false,"required":["key","label"],"properties":{"key":{"type":"string","pattern":"^[a-z][a-z0-9_]{0,39}$","description":"Unique lowercase identifier referenced by header templates or AWS auth config. Every declared credential must be used. constructor and prototype are reserved."},"label":{"type":"string","minLength":1,"maxLength":100},"description":{"type":"string","minLength":1,"maxLength":500},"placeholder":{"type":"string","minLength":1,"maxLength":100}}},"AwsAuth":{"type":"object","additionalProperties":false,"required":["type","service","region","access_key_id","secret_access_key"],"properties":{"type":{"const":"aws-sigv4"},"service":{"type":"string","pattern":"^[a-z0-9-]+$","maxLength":63,"examples":["lambda","s3","execute-api"]},"region":{"type":"string","pattern":"^[a-z0-9-]+$","maxLength":63,"examples":["us-east-1"]},"access_key_id":{"type":"string","description":"Declared credential key containing the access key ID."},"secret_access_key":{"type":"string","description":"Declared credential key containing the secret access key."},"session_token":{"type":"string","description":"Optional declared credential key containing a temporary session token. When configured, it is required in the form."}}},"HttpMethods":{"type":"array","minItems":1,"uniqueItems":true,"items":{"type":"string","enum":["GET","HEAD","POST","PUT","PATCH","DELETE","OPTIONS"]},"description":"Permitted HTTP methods. The user can narrow this set during setup."},"CreateProxy":{"type":"object","additionalProperties":false,"required":["name","description","target_url","credentials"],"anyOf":[{"required":["auth"]},{"required":["headers"],"properties":{"headers":{"minProperties":1}}}],"properties":{"name":{"type":"string","minLength":1,"maxLength":100,"description":"A clear provider or task name displayed to the user."},"description":{"type":"string","minLength":1,"maxLength":1000,"description":"Explain the intended access so the user can review it."},"target_url":{"type":"string","format":"uri","pattern":"^https://","maxLength":2048,"description":"Fixed public HTTPS API origin and optional base path. Userinfo, query, and fragment are prohibited. Private, local, metadata, and IP literal targets are prohibited. Public DNS addresses are checked before each request."},"credential_url":{"type":"string","format":"uri","pattern":"^https://","maxLength":2048,"description":"Optional provider credential creation or documentation page. Embedded userinfo is prohibited."},"credentials":{"type":"array","minItems":1,"maxItems":8,"items":{"$ref":"#/components/schemas/CredentialField"},"description":"Schema only, never actual provider credential values. Each declared field is required and must be used in a header or AWS auth."},"headers":{"type":"object","maxProperties":16,"additionalProperties":{"type":"string","minLength":1,"maxLength":2048,"pattern":"^[ -~]+$"},"description":"Header names mapped to literal values or plain {{credential_key}} templates. Configured values replace matching client headers. No filters or expressions. Cookie, transport, and forwarding headers are reserved. At least one header is required for header authentication. AWS signing may omit this field or use an empty object; its signing headers are reserved."},"auth":{"$ref":"#/components/schemas/AwsAuth"},"allowed_methods":{"$ref":"#/components/schemas/HttpMethods","default":["GET","HEAD","POST","PUT","PATCH","DELETE","OPTIONS"]},"expires_in":{"type":"integer","minimum":60,"maximum":604800,"default":86400,"description":"Seconds from creation until expiry."}}},"Proxy":{"type":"object","required":["id","status","name","description","target_url","credentials","headers","allowed_methods","created_at","expires_at","setup_expires_at","proxy_url","status_url"],"properties":{"id":{"type":"string"},"status":{"type":"string","enum":["unauthenticated","authenticated","expired","revoked"]},"name":{"type":"string"},"description":{"type":"string"},"target_url":{"type":"string","format":"uri"},"credential_url":{"type":"string","format":"uri"},"credentials":{"type":"array","items":{"$ref":"#/components/schemas/CredentialField"},"description":"Public field definitions. Credential values are never included."},"headers":{"type":"object","additionalProperties":{"type":"string"},"description":"Public templates. Substituted credential values are never included."},"auth":{"$ref":"#/components/schemas/AwsAuth"},"allowed_methods":{"$ref":"#/components/schemas/HttpMethods"},"created_at":{"type":"string","format":"date-time"},"expires_at":{"type":"string","format":"date-time"},"setup_expires_at":{"type":"string","format":"date-time","description":"Deadline for the initial credential submission. Setup is also one-use."},"proxy_url":{"type":"string","format":"uri"},"status_url":{"type":"string","format":"uri"}}},"CreatedProxy":{"allOf":[{"$ref":"#/components/schemas/Proxy"},{"type":"object","required":["auth_url","access_token"],"properties":{"auth_url":{"type":"string","format":"uri","description":"One-use user setup URL. Preserve the fragment; it contains the setup token."},"access_token":{"type":"string","writeOnly":false,"description":"Thru agent capability returned only at creation. Keep private; distinct from the provider API key."}}}]},"CredentialSubmission":{"type":"object","additionalProperties":false,"required":["credentials"],"properties":{"credentials":{"type":"object","additionalProperties":{"type":"string","minLength":1,"maxLength":4096,"pattern":"^[ -~]+$","writeOnly":true},"description":"Printable ASCII values entered directly by the user in the Thru form. No line breaks. Keys must exactly match the declared fields."},"allowed_methods":{"$ref":"#/components/schemas/HttpMethods"}}},"ConnectionResult":{"type":"object","required":["status","management_url","expires_at"],"properties":{"status":{"const":"authenticated"},"management_url":{"type":"string","format":"uri","description":"Private owner management URL with #manage=<owner_token> fragment."},"expires_at":{"type":"string","format":"date-time"}}},"Error":{"type":"object","description":"An error response. Inspect the code, message, and HTTP status before retrying.","properties":{"error":{"type":"object","required":["code","message"],"properties":{"code":{"type":"string","examples":["validation_error","unsafe_destination","unauthorized","forbidden","not_found","conflict","not_authenticated","method_not_allowed","expired","revoked","rate_limited","payload_too_large","unsupported_media_type","upstream_error","upstream_redirect","upstream_timeout","credential_echo_blocked","unsupported_response","configuration_error","internal_error"]},"message":{"type":"string"}}}},"required":["error"]}}}}