Machine discovery
Public API catalog.
ProductClient publishes a small set of public APIs for agents and integrations. Machines find them through a well-known catalog document (RFC 9727); people can read this page instead.
Discovering the catalog
Fetch /.well-known/api-catalog. The response is a
Linkset document (application/linkset+json) listing every published API with its spec, docs and status links:
{ "linkset": [
{
"anchor": "https://productclient.com/api/agent/chat",
"service-desc": [{ "href": "https://productclient.com/api/openapi.json", "type": "application/openapi+json" }],
"service-doc": [{ "href": "https://productclient.com/api-docs", "type": "text/html" }],
"status": [{ "href": "https://productclient.com/api/health", "type": "application/json" }]
}
]} Per RFC 9727 §2 the endpoint also answers HEAD with a Link header advertising the relation.
The APIs
Agent Chat
POST → SSEAsk a product’s agent a question and stream the reply as Server-Sent Events (token / done / error events). The same panel that answers visitors on every product page.
Public, rate limited
Notes
GET, POST, PUT, DELETEThe 24-hour status bubbles on product pages. Visitors tap a live note (PUT); makers read, post and end notes from the dashboard with a 10-minute cooldown between posts.
PUT public · maker routes need a Supabase JWT
Product MCP Server
GET, POST, DELETE (MCP transport)Streamable HTTP MCP endpoint exposing the public product graph — products, launches, releases — for Cursor, Claude and other MCP clients. Drafts never leave the building.
Public, read-only
Agent Config
GETPanel setup for a product agent: greeting, pinned tools and avatar type. The first call an embedder makes before mounting the chat panel.
Public
Machine-readable surfaces
- /.well-known/api-catalog API catalog — Linkset format per RFC 9727
- /api/openapi.json OpenAPI 3.1 description of every endpoint above
- /api/health Health probe — the
statuslink for each API - /.well-known/oauth-protected-resource OAuth protected resource metadata (RFC 9728) — how agents authenticate with a Supabase JWT
- /llms.txt Site index for AI agents, including these API surfaces
Fair use
Public endpoints are rate limited and cache friendly. The chat stream is capped at 30 seconds per turn; note taps are deduplicated per viewer. Report abuse or credential issues to [email protected].