Answer the manifest
Median sends this right after a route is connected, on every sync from the dashboard, the CLI or the API, and before the agent’s first reply in every new conversation. Answer with every tool your config declares.
The signature covers the empty string as the body. A manifest may declare up to 20 tools and be up to 500 KB. version is checked, so a backend refuses a version it does not speak rather than half reading it.
A manifest Median cannot accept fails the sync. The endpoint shows Sync failed with the reason, and the agent keeps the last good tool set.
GET
/Authorization
median-signatureAPI key · headerrequired`t=<ms>,v1=<hex>`, where `v1` is the HMAC SHA-256 of `${t}.${body}` under the tool signing secret derived from `MEDIAN_KEY`. Compare in constant time and refuse timestamps more than five minutes from your clock.
Responses
200Every tool the config declares.
versionintegerrequiredThe protocol version. Median refuses versions it does not speak.
Allowed:
1toolsManifestTool[]requiredUp to 20 tools, and 20 across every endpoint in the organization.
max items 20
Show propertiesHide properties
Array of
ManifestToolnamestringrequiredThe model's function name. Unique across every endpoint in the organization. These are reserved: `searchKnowledgeBase`, `searchPastConversations`, `requestHandoff`, `saveVisitorDetails`, `resolveConversation`, `closeConversation`, `suggestKnowledge`, `suggestTool`, `reportBug`, `suggestImprovement`, `searchSignals`, `requestScreenshot`.
max length 64 · matches ^[a-zA-Z][a-zA-Z0-9_]{0,63}$
descriptionstringrequiredWhat the tool does. The agent decides when to call it by reading this.
min length 1 · max length 500
riskRiskrequired`low` runs when the agent calls it. `medium` runs when called, and the agent is told to get the customer's yes first. `reviewed` asks for that yes, then waits for an automated reviewer, which may hand the call to a teammate. `high` waits for a teammate's approval in the conversation.
Allowed:
lowmediumreviewedhighinputSchemaInputSchemarequiredA flat JSON Schema object of scalar fields, closed to extras. Up to 20 fields and 8,000 characters as JSON. Field names follow the tool name rule. The builder in `@mediansh/agent-tools` emits exactly this subset, and Median refuses anything else at sync.
Show propertiesHide properties
typestringrequiredAllowed:
objectpropertiesobjectrequiredrequiredstring[]Names from `properties`.
additionalPropertiesbooleanrequiredAllowed:
falsediagnosticsbooleanWhether this endpoint answers the diagnostics op. `median()` sets it when the config has a `diagnostics` function.
401The signature is missing, malformed, stale, or from a different Median key.
errorobjectrequiredShow propertiesHide properties
codestringrequiredAllowed:
execution_faileddiagnostics_unsupportedinvalid_bodyunknown_opinvalid_inputmissing_signaturemalformed_signaturestale_timestampinvalid_signatureunknown_toolmethod_not_allowedmissing_secretinvalid_median_keymessagestringrequiredWritten for whoever has to fix it. On `execution_failed` this is your thrown error's message, and the agent reads it.
405Only GET and POST are answered.
errorobjectrequiredShow propertiesHide properties
codestringrequiredAllowed:
execution_faileddiagnostics_unsupportedinvalid_bodyunknown_opinvalid_inputmissing_signaturemalformed_signaturestale_timestampinvalid_signatureunknown_toolmethod_not_allowedmissing_secretinvalid_median_keymessagestringrequiredWritten for whoever has to fix it. On `execution_failed` this is your thrown error's message, and the agent reads it.
500The server has no usable Median key to verify with.
errorobjectrequiredShow propertiesHide properties
codestringrequiredAllowed:
execution_faileddiagnostics_unsupportedinvalid_bodyunknown_opinvalid_inputmissing_signaturemalformed_signaturestale_timestampinvalid_signatureunknown_toolmethod_not_allowedmissing_secretinvalid_median_keymessagestringrequiredWritten for whoever has to fix it. On `execution_failed` this is your thrown error's message, and the agent reads it.
Request
curl -X GET "https://example.com/api/median/" \
-H "median-signature: YOUR_API_KEY"const response = await fetch("https://example.com/api/median/", {
method: "GET",
headers: {
"median-signature": "YOUR_API_KEY"
}
});Response
{
"version": 1,
"tools": [
{
"name": "orderStatus",
"description": "Look up the status of one of the customer's orders.",
"risk": "low",
"inputSchema": {
"type": "object",
"properties": {
"orderNumber": {
"type": "string",
"description": "The order number, like ORD-1042."
}
},
"required": [
"orderNumber"
],
"additionalProperties": false
}
}
],
"diagnostics": true
}{
"error": {
"code": "execution_failed",
"message": "string"
}
}{
"error": {
"code": "execution_failed",
"message": "string"
}
}{
"error": {
"code": "execution_failed",
"message": "string"
}
}