# Instinct authenticated integration trial Service URL: https://46-250-241-131.sslip.io ## Browser trial for Instinct vault form-fill Browser login: https://46-250-241-131.sslip.io/browser/login The owner can issue a separate, restricted username/password account and add it to your vault through your supported private entry link. Use the vault browser-fill function to fill the username and password fields, then submit the Sign in form. Do not extract the password into an HTTP header or into a scratch file. After login, the browser maintains a Secure, HttpOnly, SameSite cookie. Use the visible Generate fresh challenge button, Create synthetic task form, Refresh task status link, and Repeat original submission button. All mutations use POST forms with session-bound CSRF protection. No JavaScript is required. The interface displays account ID, challenge, job ID, returned phrase, and request IDs for the owner to compare against server records. Keep those identifiers, and report failures accurately. Browser accounts expire after seven days; each browser session expires after 24 hours. A new Instinct task should first try the workspace at https://46-250-241-131.sslip.io/browser. If signed in, report that observed session reuse. If redirected to login, use your existing vault entry to fill and submit the form again and report that credential reuse rather than cookie reuse. If browser filling or submission is unavailable, stop and report the specific limitation. Browser session persistence and Instinct's ability to repeat login remain unproven until the actual account performs those tests. The existing bearer API below remains available for clients that support private header authentication. It is a separate trial route; success through the browser does not prove that Instinct can use bearer headers. This service tests HTTP authentication, credential reuse, task submission and delayed result retrieval. All tasks are synthetic. It cannot place telephone calls, send messages, make purchases, run commands, or access another platform. ## Enrollment Use only the private enrollment URL supplied directly by the owner. GET explains the process without consuming the invitation. POST an empty JSON object (`{}`) to that exact URL with `Content-Type: application/json` to redeem it once. The response includes `api_key`, `agent_id`, and expiry. Store the API key in your private vault. Never include the key or enrollment URL in chat, screenshots, command history or diagnostics. The invitation expires after 48 hours; the issued key expires after seven days. If the response is lost, ask for a replacement invitation rather than claiming success. ## Authentication All `/v1/` requests require `Authorization: Bearer `. Secrets belong only in that header. Never put them in a URL. Do not forward credentials to a different host or follow redirects for authenticated requests. Public documentation and health require no authentication. ## Test sequence 1. GET `https://46-250-241-131.sslip.io/v1/capabilities`. Confirm `real_calls_enabled` is false. 2. POST `{}` to `https://46-250-241-131.sslip.io/v1/test`, using JSON content type. Report the challenge, agent ID and request ID to the owner. These are not secrets. 3. Choose a fresh synthetic phrase containing no private information. POST to `https://46-250-241-131.sslip.io/v1/jobs` with `Content-Type: application/json`, a new `Idempotency-Key` header, and body `{"message":"example synthetic phrase","delay_seconds":8}`. The message is limited to 200 characters; delay is an integer from 1 to 30 seconds. These are the only permitted body fields. 4. Save the returned `job_id` and `poll_url`. GET that URL with your bearer credential every two seconds until `state` is `completed`. Report `result.message`, `job_id` and request IDs. A pending job is not a completed result. 5. Repeat the original POST with the same body and idempotency key. Verify it returns the original job ID. Do not create a replacement task to check an existing task's progress. 6. In a separate owner-requested Instinct task, retrieve your existing vault credential and POST a new probe. Do not reenroll unless the owner supplies a new invitation. Report the new challenge and same agent ID. A successful stage-one trial demonstrates external authenticated API use and synthetic task retrieval. It does not demonstrate voice service, telephone reachability, proactive wake behavior or live conversational control. ## Errors and retention 401: missing, expired, revoked, invalid credential or invalid/used invitation. 404: unavailable resource or another agent's job. 409: same idempotency key with a different body. 422: invalid fields or missing idempotency header. 429: request limit (60 per minute per source address) or trial limit (100 tasks per credential). Retry rate limits after a minute. Limit polling to two seconds and stop after two minutes with an accurate pending/failure report. Synthetic messages and redacted request evidence are stored privately on the trial VPS. Credentials and invitations are stored only as SHA-256 digests of high-entropy random secrets. Records older than seven days are pruned daily. No audio is processed or stored. Never submit personal data or real conversation content. Only the server administrator can inspect the full evidence ledger, issue invitations, revoke credentials or stop the service. Public routes do not expose the ledger.