Skip to content

API & Integration

Connect to the right THOX service with the correct authentication, transport and permissions.

Use the correct THOX authentication

Match the service

EdgeLab requires a signed-in account with a confirmed email. The ThoxEmployee demo uses a guest session. A device runtime can have its own access configuration; these are separate credentials and permissions.

Keep credentials in the right place

Server provider keys belong on the server. Do not embed them in browser code, paste them into prompts or reuse website session cookies as device API credentials.

Read EdgeLab availability

From the THOX website while signed in, this read-only example checks the configured provider and model. It does not run inference or connect to a device.

Browser example

const response = await fetch('/api/edge-lab/status', {
  credentials: 'same-origin',
  cache: 'no-store',
});

if (!response.ok) {
  throw new Error('Sign in or retry the availability check.');
}

const status = await response.json();
console.log(status.configured, status.provider, status.model);

Streaming and interrupted requests

Use the service transport

Check the API documentation for the service you are integrating. The ThoxEmployee demo streams its run over HTTP; EdgeLab returns a bounded JSON receipt. This guide does not provide a universal THOX WebSocket endpoint.

Handle interruptions

If a connection stops, check the displayed run state before starting another request. The ThoxEmployee workspace can retain the run state and outputs even when the browser stream is interrupted.

Treat retries as new work

A cancelled or failed hosted request may already have used provider resources or demo allowance. Follow the displayed retry guidance rather than automatically replaying the prompt.

Choose a compatible client

Check the runtime contract

For a runtime that advertises an OpenAI-compatible API, confirm the exact base URL, authentication method, model identifier and supported endpoints before configuring a client library.

Check optional features separately

Streaming, structured output and tool-call formats depend on both the runtime and model. Do not assume a feature works because a basic text request succeeds.

Keep execution separate

A model response, tool-call suggestion or successful HTTP status is not authorization to execute an action. Validate the response and apply your own identity, permission and approval rules.

Respect the demo boundary

The website demos are supervised experiences, not general-purpose device-control APIs. Start through their interfaces to review the current provider, consent requirements and limits.

Connect tools with explicit access

Use a documented integration

When your application supports MCP, follow its connector configuration for the installed version. Confirm the transport, server address, credentials and supported tools.

Review what a tool can do

Grant access to the folders and services required for the task. Check whether a tool only reads information or can change files, send messages or run commands.

Understand profile exchange

The ThoxWork profile preview transfers profile information for review. It does not transfer provider credentials, register a backend or enable tools. ThoxWork remains Coming Soon.

Test without external effects

Use a small synthetic example and inspect the result before connecting an integration to real work. EdgeLab proposals and ThoxEmployee review decisions do not execute external actions.

More Resources