Rosuite secure generation handoff
This public handoff page is a browser client for securely submitting, tracking, and downloading shared generation jobs. A capability token, when provided in the URL fragment, stays in the browser and is not sent with the initial page request.
Executable agent handoff. This page submits, polls, and downloads generations itself; curl, a terminal, and custom HTTP tools are optional.
The public handoff page is available without a token. Add the owner-provided capability only in the URL fragment to enable authenticated actions.
GET-only agent execution (no headers, POST, terminal, or form control)
Agent-only handoff: open the owner-provided /s/TOKEN/agent-handoff capability URL for the authenticated execution document.
If your agent can open URLs but cannot send custom HTTP requests, it can still generate. Extract TOKEN from this handoff link's #access_token=TOKEN, then open:
https://THIS-HOST/agent?action=instructions&access_token=TOKEN
That response gives a GET-only generation template. The agent URL-encodes its prompt, opens the generation URL once, follows the returned status_url, then opens the returned one-time download_url. It must not report that an Authorization header or POST tool is required.
Tradeoff: this fallback places the bearer capability in query URLs, so it is less private than fragment/header authentication. It cannot upload local files; use existing Higgsfield media IDs or the interactive form below for references.
Generate
Advanced fields
Optional JSON object merged into the request. Use for existing media IDs, parent_id, is_first_gen, or another supported schema field. UI values win for prompt, Unlimited, resolution, and uploaded files.
Unlimited only. The gateway refuses credit fallback. Reference videos usually reduce UGC quality; use one only when the workflow truly requires it. Reference images are fine.
Job
No job submitted.
Agent instructions
- If your environment only opens URLs, use
/agentas described above. It requires no custom headers or POST body. - If your environment supports authenticated HTTP, use
/v1/instructionsand the API directly. - If it can operate this page, enter the prompt/settings, attach any reference files, and press Submit.
- Keep the tab open while it polls. When complete, use the download button to receive the actual binary file.
- For Wilbo UGC, read the creative skills below before writing. A human must choose any Pinterest inspiration and approve the distinct GPT-Image-2 character before that generated image is used here.
Select a skill and load it here.
Drawbacks
- One provider generation runs at a time; later jobs queue.
- The host's authenticated Higgsfield tab and Unlimited state must remain healthy.
- A first-party verification challenge requires a human on the host. This page does not bypass it.
- Downloads are one-time and job status is lost if the gateway restarts.
- The link is a bearer capability. Anyone holding it can consume generation capacity until it is rotated or revoked.