Config API
The public endpoint that serves tool definitions to the snippet.
Endpoint
GET /api/sites/:publicId/config
:publicId is the public identifier from your site's snippet block. It's safe to expose in HTML and doesn't grant write access.
Query parameters
| Parameter | Type | Description |
|---|---|---|
path | string | Current page path, e.g. /products/shoes. Used for path pattern filtering. |
Response
{
"siteId": "uuid",
"tools": [
{
"id": "uuid",
"name": "addToCart",
"description": "Add a product to the shopping cart",
"inputSchema": { "type": "object", "properties": {} },
"executeJs": "return window.__aigentablyDemo.addToCartUI(args.productId, args.quantity)",
"exposedTo": [],
"title": "Add to cart",
"annotations": {}
}
],
"formTools": [
{
"id": "uuid",
"name": "subscribeNewsletter",
"description": "Subscribe an email address to this website's newsletter.",
"selector": "form#newsletter",
"autosubmit": false
}
],
"pollInterval": 300
}tools: only enabled tools matching the?path=pattern are returnedexposedTo: origins in the page's frame tree this tool is visible to, passed straight through toregisterTool()'s options. It scopes which documents can see the tool, not which agent is allowed to call it; an empty array means every document in the frame tree.title: a human-readable name derived fromname, passed toregisterTool()as the tool'stitleannotations: the WebMCPToolAnnotationsfor the tool, with only the hints that aretrue:readOnlyHint(changes nothing),consequentialHint(has an effect that can't be undone, so agents should confirm with the user first) anduntrustedContentHint(output includes content written by others, such as reviews). A hint set in the tool editor is served as set; one left on Auto is inferred from the tool's name, sosearchProductsis read-only,placeOrderis consequential, andaddToCartgets neither.formTools: enabled form tools whose page path matches?path=. For each one, the snippet finds the form withselectorand setstoolname,tooldescriptionand, whenautosubmitis true,toolautosubmiton it, which makes the browser register the form as a WebMCP tool with an input schema taken from the form's own fields. A form that already has atoolnameof its own is left alone. Withoutautosubmit, the agent fills the form in and the visitor presses submit.pollInterval: seconds between re-fetches (default: 300)
Caching
The endpoint uses ETag-based caching. The snippet sends If-None-Match on subsequent requests. If nothing has changed, the server returns 304 Not Modified and the snippet skips re-registration.
Cache-Control is set to public, max-age=60. Tool changes appear within 60 seconds.
Rate limiting
Requests are rate-limited per site. The snippet's polling interval keeps well within the limit under normal usage. Exceeded: 429 Too Many Requests.
CORS
The endpoint is open to all origins (Access-Control-Allow-Origin: *). This is intentional, as the snippet runs on third-party sites.
Error responses
| Status | Code | Meaning |
|---|---|---|
| 404 | NOT_FOUND | Invalid or deleted publicId |
| 429 | RATE_LIMITED | Too many requests |
| 500 | INTERNAL_ERROR | Server error |