NexusAGI API
Sign in once for a session token and send it as the X-NexusAgi-Session
header on every call. Create an account at
/account/signup.html.
Sign in
Signs you in and returns a session token. Registration is separate:
POST /api/nexusagi/register; GET /api/nexusagi/register/policy
says whether new accounts are accepted. Max 2 active sessions.
Two-factor. With it on, sign-in answers
401 {"reason":"totp-required"} until the body carries totpCode; a
recovery code works in that field. No password yet? You get
409 {"reason":"set-password-required"}; set one on the machine NexusAGI runs on.
Device verification. A browser not approved from the NexusAGI app gets a
reduced surface. See /api/nexusagi/device/* and
/account/verify-device.html.
Rate limiting. One sign-in attempt per client per 60 s, a per-minute ceiling,
backoff after failures. A 429 carries
retryAfterSeconds and a Retry-After header.
curl -X POST /api/nexusagi/auth -d '{"username":"alice","password":"...","totpCode":null}'
Ends the session and frees its slot.
Chat
Sends one message and returns the reply.
curl -X POST /api/nexusagi/chat -H "X-NexusAgi-Session: <token>" -d '{"message":"hello"}'
Marks a reply right or wrong. Good ratings reinforce a reply; bad ones do not.
curl -X POST /api/nexusagi/feedback -H "X-NexusAgi-Session: <token>" \
-d '{"userMessage":"...","agiReply":"...","rating":"positive","note":null}'
Usage
Your token use: current session, lifetime total, a 30-day breakdown, last 10 sessions.
Shows what the assistant has learned so far.