Skip to main content
GET
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Path Parameters

deviceId
string
required

The deviceId from a listing.

Response

Who is driving.

Who is driving one device: the lease's holder, the run on it, and the people who acted recently. One read for the question a Control view asks after every gesture.

lease
object | null
required

Your organisation's live lease on the device and who inside it holds the lease, or null when it holds none.

run
object | null
required

The run driving the device right now, or null. A finished run is not driving.

people
object[]
required

People other than you with an action on the device in the last sixty seconds, newest first. Ids, never names: resolve them through your own directory.

agentLastActionAt
string<date-time> | null
required

When an agent (a run, a key or a copilot) last acted on the device within the same window, or null.