hosting

POST /v1/sites/{siteId}/ide-assist

Ask the AI assistant about one file in the site's web editor.

All hosting endpoints

Authentication

This endpoint is public. It takes no credential and no organisation — it is what our own marketing site and AI answer engines read.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/ide-assist \
  -H "Content-Type: application/json" \
  -d '{ "context": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Answers one request about one file, from inside the site's browser editor, and bills the model call to that site's organisation on the same AI meter as every other surface (their own provider key if they have added one, their Zinn® credit if not). **This is the one site endpoint family with no user session behind it, and that is deliberate.** Its caller is a VS Code extension running inside the customer's own CageFS jail on a hosting box, which cannot hold a Keycloak session. It authenticates with a **signed, site-bound, expiring grant** minted when the editor is opened and presented as `Authorization: Bearer <grant>`. The grant names the site, the organisation and the person who opened the editor; the site in it must match the site in the path, and the organisation is read from the grant and never from the request body, so a grant for one site can neither ask about another nor bill another tenant. The grant never reaches the customer's browser: it is held in a root-owned file on the hosting box and attached by the editor gate, which runs outside every jail. A missing or unreadable grant is a `404`, never a `401`, so this cannot be used to discover that a site exists. An **editing** action (`fix`, `refactor`, `complete`, `generate`) returns a `proposal`: the complete replacement for the region that was sent. It is a suggestion and nothing on this side applies it — the editor shows it as a diff and writes it only after the customer approves. A **read-only** action (`ask`, `explain`) never returns one, however code-shaped its answer. A refusal the customer should read — an exhausted allowance, a revoked provider key, a question that is too long, a file too large to rewrite safely — is a `422` carrying the sentence to show them and a code in `details[].code`, because "you are out of credit" and "we could not reach the model" are different facts and only one of them is theirs to fix.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
actionstring<ask, explain, fix, refactor, complete, generate>NoWhat to do. `ask` and `explain` are read-only and answer in prose. `fix`, `refactor`, `complete` and `generate` return a `proposal` the editor shows as a diff for the customer t…
questionstringNoWhat the developer wants. Required for `ask` and `generate`; optional for the rest. Longer than 4,000 characters is a `422` asking them to select the part of the file they mean.
pathstringNoThe file's path relative to the site, shown to the model so it can reason about what kind of file it is. Optional — an unsaved buffer has none.
contextstringYesThe file, or the selected region of it. Truncated to 24,000 characters for a read-only action, and the answer says so rather than silently answering about a fragment. An **editi…
modelstringNoA model from `/ide-assist/models`. Omit for the automatic choice, which is the cheapest model that can do the job, computed from our price list.

Response

NameTypeRequiredWhat it is
actionstringYesThe action this answers, echoed so the editor can render it correctly.
answerstringYesThe assistant's answer, as markdown. Never blank on a `200` — an empty answer is a `422`, because the call was paid for either way and a blank panel in an editor is indistinguis…
proposalstringYesThe complete replacement for the region that was sent, or empty. Non-empty only for an editing action, and only when the model returned exactly one well-formed code block with n…
modelstringYesThe model that answered, so the editor can show what the customer paid for.
fundingstringYesWhich route paid — the customer's own provider key, their Zinn® credit, or their included allowance. The same decision the AI page renders, never a second one.

Errors this endpoint can return

404 · 422 · 429