{endpoint}/{path} with the X-Continuous-Simulation-Token header. endpoint comes from the create, fork, get, and list responses. The Simulation serves the Simulator’s full API, so an existing client of that API can address the Simulation without speaking the Continuous control-plane API.
Replace only the vendor’s host with endpoint, and keep the vendor’s base path. An OpenAPI Simulator serves each operation under the path of the spec’s first server URL; for https://api.vendor.com/v2, send {endpoint}/v2/articles. A WSDL Simulator serves at the path of soap:address.
Replace <endpoint> and <token> with the endpoint and token from the quickstart:
Cookie, Proxy-Authorization, and the token header are removed before the request reaches the Simulation.
Read-only requests
SetContinuous-Read-Only: true to inspect data without permitting that request to write:
true or false. Header names are case-insensitive. An absent header or false keeps ordinary behavior. Invalid, empty, or repeated values return 400. A rejected write returns 403 with code simulation_read_only, including on SOAP endpoints.
This feature requires an updated Simulation runtime. Older running runtimes ignore the header; rebuilding a Simulator alone does not update them. After the runtime update, older Simulator artifacts reject requests with true because they cannot prove read-only support. Rebuild the Simulator and create a new Simulation to use the header.
This restriction applies to one request. Other requests can still write, and activity tracking and automatic wake continue. It does not grant restricted token permissions or change Simulation lifecycle controls.
Errors
Platform refusals use the error envelope. A rejected Simulation token carriesX-Continuous-Simulation-Token-Rejected: true. A stopped Simulation must be started before it accepts requests. Read-only refusals keep the platform JSON shape, including on SOAP endpoints.
The simulated API also returns its own responses. Quotas and limits owns the transport caps for ordinary, multipart, and SOAP requests.
Simulations
Lifecycle, credentials, steps, and forks.
Authentication
API keys for
/v1 routes and Simulation tokens for the data plane.