AISEA Developers

Builder Record API

AISEA can be a builder's portable record: profile facts, skills, links, and the work behind them. A trusted assistant or platform can use that record to help complete a resume, bio, application, team page, or other profile without starting from a blank form.

One record, used with permission

This API supplies structured facts; it does not write back to AISEA or decide what belongs in a resume. The member creates a token for each trusted connection and can revoke it at any time. Coding assistants can call the endpoint from a local command or adapter; an MCP wrapper can expose the same record without changing its data contract.

1. Ask the member to create a connection

The member signs in to AISEA, opens Builder record in Settings, names the connection, and copies the token once. AISEA stores only its hash. The member may revoke the connection at any time.

Store the token in backend secrets or a local agent's secret store. Never paste it into a prompt or put it in frontend JavaScript, a mobile bundle, analytics, logs, or a URL. Cross-origin browser requests are rejected.

2. Fetch the builder record

curl https://www.aisea.builders/api/v1/profile \
  -H "Authorization: Bearer $AISEA_PROFILE_TOKEN"
const response = await fetch(
  "https://www.aisea.builders/api/v1/profile",
  {
    headers: {
      Authorization: `Bearer ${process.env.AISEA_PROFILE_TOKEN}`,
    },
  }
);

if (!response.ok) throw new Error(`AISEA returned ${response.status}`);
const { data: builderRecord } = await response.json();

There is no username parameter. The bearer token determines which profile is returned, including when that member's AISEA profile is private.

Response

The response contains identity, location, skills, collaboration preferences, member-provided links, and up to 50 public projects, accepted challenges, and published articles in each category. Counts remain complete even when a list reaches that limit. It never contains email, internal IDs, roles, drafts, private projects, Discord identity, or administrative data.

When the AISEA profile is private, visibility is private and links.aisea_profile_url is null. Other profile-card fields remain available because the member authorized this connection separately.

Limits and errors

  • Each token permits 300 requests per 15 minutes.
  • 401 means the token is missing, invalid, or revoked.
  • 403 means a browser-origin request was rejected.
  • 404 means the connected builder profile no longer exists.
  • 429 includes rate-limit and retry headers.
  • 500 or 503 should be retried with backoff.

Responses use Cache-Control: private, no-store. Retain the record only as long as the member's task requires, and stop using it when the member disconnects. Revocation prevents future reads but cannot recall copies already made.

OpenAPI 3.1 specification ↗