The contract
Authorization: Bearer <INGEST_TOKEN>. Same token for HTTP and MCP.
| Call | Purpose |
|---|---|
POST /api/ingest | Create or update a tile |
DELETE /api/ingest | Hide a tile |
GET /api/catalog | Tile types, locked flags, and json_schema |
POST /api/commands | Ask the operator (Command Tiles) |
GET /api/commands/{id} | Read the answer |
MCP /api/mcp | Same writes as tools: post_tile, ask_operator, and the rest |