A valid request URL is required to generate request examples{
"frameId": "<string>",
"url": "<string>"
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Get a short-lived URL for one archived frame
Returns a presigned URL that renders one frame, good for about a minute. Fetch this with your credential, then use the url it returns as the image source: this route needs a bearer token and an img element cannot send one.
Where a frameId comes from: a run’s lastFrame.frameId, and the observedFrame an action receipt was bound to. On a finished run lastFrame is the frame the model’s report was written from, so this is how you show what the model said next to the screen it read that off.
ONE ANSWER FOR EVERY KIND OF UNAVAILABLE. A frame belonging to another org, an id that never existed, a frame whose bytes are not yet confirmed, one that was retired or has passed a finite retention expiry, an encrypted one, and a frame captured on a device your key cannot address all answer 404 frame_not_found. So this route cannot be used to discover which frames exist.
A deployment that archives no frames answers 404 for every id, because with no bucket the frame was never stored.
A valid request URL is required to generate request examples{
"frameId": "<string>",
"url": "<string>"
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.
Path Parameters
The frame's id, as a run's lastFrame.frameId or a receipt's observedFrame reports it.