curl --request POST \
--url https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"url": "https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...",
"label": "Local app"
}
'import requests
url = "https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links"
payload = {
"url": "https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...",
"label": "Local app"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
url: 'https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...',
label: 'Local app'
})
};
fetch('https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'url' => 'https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...',
'label' => 'Local app'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links"
payload := strings.NewReader("{\n \"url\": \"https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...\",\n \"label\": \"Local app\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...\",\n \"label\": \"Local app\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...\",\n \"label\": \"Local app\"\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"reference": "<string>",
"label": "<string>",
"origin": "<string>",
"status": "active",
"created_by_user_id": "<string>",
"created_at": "<string>",
"expires_at": "<string>",
"opened_at": "<string>",
"revoked_at": "<string>"
}{
"error": "prompt_required"
}{
"error": "missing_bearer",
"message": "Authorization required"
}{
"error": "missing_scope",
"required_scope": "sessions:read"
}{
"error": "session_not_found"
}{
"error": {
"type": "rate_limited",
"message": "This API key exceeded its request-rate limit"
}
}Share a link with the agent
Registers an https URL with the session. The agent sees only the returned reference and can open it once in the session’s cloud browser by passing the reference to browser_use open_tab; the URL itself is stored encrypted and never returned. Mention the reference in a message to ask the agent to open it.
runcurl --request POST \
--url https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"url": "https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...",
"label": "Local app"
}
'import requests
url = "https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links"
payload = {
"url": "https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...",
"label": "Local app"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
url: 'https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...',
label: 'Local app'
})
};
fetch('https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'url' => 'https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...',
'label' => 'Local app'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links"
payload := strings.NewReader("{\n \"url\": \"https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...\",\n \"label\": \"Local app\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...\",\n \"label\": \"Local app\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.reasonmachines.com/v3/organizations/{orgId}/sessions/{sessionId}/shared-links")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://quiet-river.trycloudflare.com/agents?ara_preview_cap=...\",\n \"label\": \"Local app\"\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"reference": "<string>",
"label": "<string>",
"origin": "<string>",
"status": "active",
"created_by_user_id": "<string>",
"created_at": "<string>",
"expires_at": "<string>",
"opened_at": "<string>",
"revoked_at": "<string>"
}{
"error": "prompt_required"
}{
"error": "missing_bearer",
"message": "Authorization required"
}{
"error": "missing_scope",
"required_scope": "sessions:read"
}{
"error": "session_not_found"
}{
"error": {
"type": "rate_limited",
"message": "This API key exceeded its request-rate limit"
}
}Authorizations
Your Reason API key from Settings > API. New keys use reason_; legacy ara_ keys remain accepted. Keys are capability-scoped: run, mcp:read, mcp:write, secrets:read, secrets:write, sessions:read, sessions:debug, knowledge:read, memory:read, memory:write, skills:read, skills:write, repos:read, repos:write, reviews:read, reviews:write, deployment:read, analytics:read, org:read, org:write, attachments:read, attachments:write, guardrails:read, guardrails:write, automations:read, automations:write, agent_auth:read. mcp:write manages MCP server configuration only; it does not authorize remote MCP-tool execution. sessions:debug is privileged: it expands diagnostic session events only for organization owners/admins.
Path Parameters
Organization id or slug. Resolve it with GET /v3/self.
The session id.
Body
Response
The shared link.
The only form the agent sees: pass it to browser_use open_tab as the url.
Scheme and host of the stored URL.
active, opened, revoked, expired 
