A valid request URL is required to generate request examples{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "not_found",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "service_unavailable",
"message": "<string>"
}
}Ask the copilot
A valid request URL is required to generate request examples{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "not_found",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "service_unavailable",
"message": "<string>"
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.
Headers
List application/vnd.phonebase.ui-message-stream to be answered with the UI message stream. Anything else, or no header, selects the older event stream. The response is text/event-stream either way.
Body
What to ask, in the shape of the protocol selected by Accept.
- PromptBody
- ChatTransportBody
What you want, in a sentence. A turn is a message, not a document. The older protocol's body.
1 - 4000What the console knows and the sentence does not say. Every device id here must be one your session can address, or the request is 400 naming the field. Resolution order for which phone a turn is about: pinned, then mentions, then context.device, then the device this thread last acted on, then the only device you have, then a data-device-choice card. THIS BLOCK IS NOT REPLAYED: it describes where somebody is now, so it is read from this request only and never from the stored thread.
Show child attributes
Show child attributes
Device ids the person named with an @ in this message. The id travels, never the typed name, so renaming a phone cannot re-point a message. Exactly one names the turn's device; two or more raise the chooser.
10Response
The stream. It stays open until the turn ends. Which protocol it speaks is in the header below.