What an open page offers
AICD API (aicdapi.com) serves source-linked Dallas-Fort Worth civic records over REST and a remote MCP server.
A page on aicdapi.com also offers a small tool set to the browser's own agent surface, through the browser's native document.modelContext API. Support is a property of the browser client and changes with it: where the API is absent, no tool is registered and the page behaves exactly as before. AICD API publishes no supported-client list.
The tools exist only while a page is open, and only in the top-level page — never inside a frame. They are withdrawn when the page navigates to another route or the signed-in identity changes.
Tools every visitor gets
- aicdapi_open_page opens one page from a fixed list of aicdapi.com routes. It takes a page id, never a URL from the caller.
- aicdapi_list_docs lists every document an agent can read: the agent index, the help topics, the API reference index, and the reference page of each HTTP operation.
- aicdapi_read_doc returns one of those documents as Markdown, at most 6000 characters per call, with the page's offset, nextOffset, end, totalChars, and notice. Repeat the call with nextOffset until end is true to read a whole document; an offset outside the document is refused rather than guessed.
- aicdapi_public_resources lists the anonymous, no-key surfaces with the caveat that applies to each, and points at the OpenAPI document, the agent index, and the sitemap.
- The public tools reach only what an anonymous visitor can already read. They return no account data, carry no credential, and cannot bypass authorization.
The no-key resources
- Public coverage catalog: GET https://aicdapi.com/api/v1/public/coverage. A dated research baseline whose meta carries catalogVersion, researchDate, scope, and ingestionVerified. At this review the pass is dated 2026-09-09, covers the 16 DFW counties, and carries ingestionVerified false. It is research evidence, not a live count of sources or records.
- Recent agenda hits: GET https://aicdapi.com/api/v1/public/agenda-hits. Up to three recent classified DFW hits, each with meetingAt and sourceUrl.
- Featured source status: GET https://aicdapi.com/api/v1/public/source-status. Live health for the featured DFW meeting sources only. It does not cover every catalog entry.
- All three need no key, no account, and no payment.
Tools signed-in visitors get
Opening the account console while signed in offers a second tool set for that session. These tools act as the signed-in user, under the same role, paid-access, plan-cap, and rate-limit checks as the console's own buttons, with the same audit trail, through the same server actions. There is no separate permission to grant for them.
- Read the account: aicdapi_account_status, aicdapi_list_keys, aicdapi_read_plan, aicdapi_subscription_state.
- Manage keys: aicdapi_create_key, aicdapi_rotate_key, aicdapi_revoke_key.
- Billing: aicdapi_start_checkout, aicdapi_open_billing.
- Creating or rotating a key needs an owner or admin role and current paid data access. Listing and revoking keys work without a paid period.
- The workspace API account itself is created by the account page when the workspace has none, so no tool covers it.
Secrets, sign-in, and payment
aicdapi_create_key and aicdapi_rotate_key return the new secret once, in the result of that call and in the same panel the buttons use. The page never logs it, stores it, or puts it in a URL. What the caller keeps is the caller's decision: an agent that receives the secret can retain it, so put it in a secret manager and treat it like any other key.
Ending a tool call or leaving the page stops late results: a cancelled call is answered "This tool call is no longer active.", it hands back no result, and it leaves the one-time panel and any Stripe navigation untouched. That cancels the call, not the change: a server action already sent is not undone, so the page can be behind — a key the call created can already exist while the list on screen is old. Refresh or reopen Account and read the account and key state before retrying an interrupted change. A one-time secret is never shown again.
aicdapi_start_checkout opens the hosted Stripe checkout, and aicdapi_open_billing opens the Stripe billing portal. A person completes any payment in the provider page; these tools never pay and cannot complete a purchase.
aicdapi_open_page can open the create-account or sign-in page, which starts the real sign-in flow. Reaching that page does not create an account or sign anyone in: a consent step or a challenge can still need the person, and the workspace API account is created afterwards from the account console.
Markdown, OpenAPI, and discovery metadata
Every readable document is also a plain URL: https://aicdapi.com/llms.txt for the agent index, https://aicdapi.com/llms-full.txt for the complete public help, https://aicdapi.com/help/llms.txt for the help section index, and https://aicdapi.com/api-reference/<operationId>/llms.txt for one HTTP operation. The OpenAPI document is at https://aicdapi.com/api/openapi.json, and the readable API reference is at https://aicdapi.com/api-reference.
The remote MCP server's metadata is published twice: https://aicdapi.com/server.json follows the official MCP registry server schema, and https://aicdapi.com/.well-known/mcp.json is a byte-identical alias. Both are convenience metadata. The well-known path is not a standards-defined discovery path, and AICD API does not claim that a registry lists the server; a client reads the live server contract from the MCP endpoint itself.