API Reference
Everything you need to integrate with your Paperclip agent's API endpoint.
Base URL
Authentication
All requests require a Bearer token in the authorization header. Generate API keys in your agent dashboard under Settings → API Keys.
- Scoped to specific agents
- Configurable expiration
- Individual revocation
- Usage audit log
All keys start with ha_ for easy identification in logs and configurations.
Send a Message
Request Body
Response
Example
Streaming
Returns Server-Sent Events (SSE) for real-time partial responses. Each event contains a chunk of the agent's response as it is generated.
Rate Limits
| Plan | Requests/min | Requests/day |
|---|---|---|
| Starter | 60 | 10,000 |
| Pro | 300 | 100,000 |
| Scale | Custom | Unlimited |
Rate limit headers: X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset
Error Codes
200 400 401 429 500 503 API FAQ
How do I authenticate with the HostAgentes agent API?
Every request requires a Bearer token in the Authorization header. Generate API keys in your agent dashboard under Settings → API Keys. Keys are scoped to specific agents, support configurable expiration and individual revocation, and every use is recorded in a usage audit log.
What is the base URL for the Paperclip agent API?
Each deployed agent gets its own endpoint at https://your-agent.hostagentes.com/api/v1. Send messages with POST /chat and stream responses with POST /chat/stream.
Does the HostAgentes API support streaming responses?
Yes. POST /chat/stream returns Server-Sent Events (SSE) for real-time partial responses — each event contains a chunk of the agent's response as it is generated.
What are the API rate limits?
Starter: 60 requests/min and 10,000 requests/day. Pro: 300 requests/min and 100,000 requests/day. Scale: custom limits with unlimited daily requests. Responses include X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset headers.
What does a 429 error code mean?
429 means you exceeded the rate limit — wait for the time given in the Retry-After header and try again. A 401 means your API key is missing or invalid; 500 and 503 are server-side and should be retried after a few seconds or with exponential backoff.