Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Path Parameters

deviceId
string
required

The deviceId from a listing.

Body

application/json

Optional. tracks and layer are accepted and not read yet: every view starts with the screen track on the high layer.

tracks
enum<string>[]
Available options:
screen,
overhead
layer
enum<string>
Available options:
auto,
low,
medium,
high

Response

How to show the device.

How to show one device live.

streamId
string
required

An opaque id for this view.

transport
enum<string>
required

Which player to use, and which entry of connect it reads.

Available options:
edge-webrtc,
provider-rtc,
snapshot
expiresAt
string<date-time> | null
required

When the viewing token stops admitting a new join, or null when there is none or it is not known. Ask again before it.

tracks
object[]
required

The video tracks on offer. Sizes and rates are nominal; the player reads the real ones from the stream.

connect
object
required

Connection details keyed by transport; exactly the entry named by transport is present, and none for snapshot. edge-webrtc is {url, token, room} with a receive-only token; provider-rtc is {token, baseUrl, padCode, userId, resolution}. Tokens are credentials.

clock
object
required
viewer
object
required
controls
object
required
capabilities
object
required

What a player may offer on this device.

fallback
object
required