> ## Documentation Index
> Fetch the complete documentation index at: https://docs.webless.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Bootstrap visitor access

> Exchange your index ID and a browser session ID for a Bearer access token. The token is bound to the Origin of the page that calls this route.

<script src="/agent-playground-reply.js?v=14" defer />

<div id="webless-agent-history" />

## Try it in this order

<Steps>
  <Step title="1. Bootstrap">
    Open [Bootstrap](/api-reference/latest/agent/bootstrap). Enter your index
    ID, click **Try it**, then **Send**. The playground saves your
    `accessToken` for the next two pages. You can only use it on this site, and
    it expires in about 15 minutes.
  </Step>

  <Step title="2. Send a message">
    Open [Send a message](/api-reference/latest/agent/create-session). This page
    fills in your token and index ID. Send `Hello`. The playground saves your
    `sessionId` (`wrun_…`).
  </Step>

  <Step title="3. Stream the reply">
    Open [Stream events](/api-reference/latest/agent/session-stream). This page
    fills in your token and that `sessionId`. Click **Send** to read the reply.
  </Step>
</Steps>

To send another message, go back to **Send a message** and click **Send**
again. Then open **Stream events** once more. The playground updates the
session id to that new turn.

Start here. This preview calls **`https://runtime.webless.ai`**. Use an index
that is published in Agentic mode on production.


## OpenAPI

````yaml api-reference/openapi-agent-runtime.json POST /webless/v1/bootstrap
openapi: 3.1.0
info:
  title: Webless Agent Runtime API
  description: >-
    Browser-facing endpoints for Agentic mode. Call these from the visitor's
    site; bootstrap returns a short-lived access token bound to that page's
    origin.
  version: v1
servers:
  - url: https://runtime.webless.ai
    description: Agent Runtime
security: []
paths:
  /webless/v1/bootstrap:
    post:
      tags:
        - Agent Runtime API
      summary: Bootstrap visitor access
      description: >-
        Exchange your index ID and a browser session ID for a Bearer access
        token. The token is bound to the Origin of the page that calls this
        route.
      operationId: agentRuntimeBootstrap
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/BootstrapRequest'
            examples:
              default:
                value:
                  clientSessionId: a1c2d3e4-1111-2222-3333-444455556666
                  indexId: YOUR_INDEX_ID
                  version: published
      responses:
        '200':
          description: Visitor capability issued
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BootstrapResponse'
              example:
                accessToken: <accessToken>
                tokenType: Bearer
                expiresAt: '2026-10-06T06:30:00.000Z'
                origin: http://localhost:3000
        '403':
          description: Agent unavailable or origin rejected
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentRuntimeError'
components:
  schemas:
    BootstrapRequest:
      type: object
      required:
        - clientSessionId
        - indexId
      properties:
        clientSessionId:
          type: string
          description: >-
            Stable ID for this browser session. Generate a fresh UUID per
            browser; do not reuse the docs example value.
          example: a1c2d3e4-1111-2222-3333-444455556666
        indexId:
          type: string
          description: Webless index ID from Setup.
          example: YOUR_INDEX_ID
        version:
          type: string
          enum:
            - published
            - unpublished
          default: published
          example: published
    BootstrapResponse:
      type: object
      properties:
        accessToken:
          type: string
        tokenType:
          type: string
          enum:
            - Bearer
        expiresAt:
          type: string
          format: date-time
        origin:
          type: string
          format: uri
        visitorSubject:
          type: string
        apiVersion:
          type: string
        identity:
          type: object
          properties:
            indexId:
              type: string
            revision:
              type: string
            tenantId:
              type: string
    AgentRuntimeError:
      type: object
      properties:
        ok:
          type: boolean
          enum:
            - false
        error:
          type: string
        code:
          type: string

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.