Median API
Everything the widget does, over HTTP: read a visitor’s thread, send messages, attach files, and signal typing. The tool endpoint routes point the agent at the tools you serve. Server to server only. No CORS headers are sent, so a browser cannot call it directly.
The thread, message and typing endpoints take a session: a token you choose, 8 to 128 characters after trimming, naming one visitor. Use your own user id for signed in people so their conversation follows them across devices, and a random id in a cookie for everyone else. The API trusts whatever session your server sends, so never let the browser choose it.
Errors are JSON with a code and a message. Every code, the rate limits per plan and the size limits are in Errors and limits.
https://api.median.sh/v1Conversations
Read a visitor’s thread and write to it.
Files
Upload what a message carries.
Presence
What the team sees while a visitor types.
Tool endpoint
Point the agent at the routes you serve, and re-read their manifests. These routes accept a Median key or an OAuth access token.