> ## Documentation Index
> Fetch the complete documentation index at: https://docs.continuouslabs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Send requests to a Simulation

> Send the simulated API's own requests to the Simulation endpoint with a Simulation token.

Send the simulated API's own requests to `{endpoint}/{path}` with the `X-Continuous-Simulation-Token` header. `endpoint` comes from the create, fork, get, and list responses. The Simulation serves the Simulator's full API, so an existing client of that API can address the Simulation without speaking the Continuous control-plane API.

Replace only the vendor's host with `endpoint`, and keep the vendor's base path. An OpenAPI Simulator serves each operation under the path of the spec's first server URL; for `https://api.vendor.com/v2`, send `{endpoint}/v2/articles`. A WSDL Simulator serves at the path of `soap:address`.

Replace `<endpoint>` and `<token>` with the endpoint and token from the [quickstart](/quickstart#create-a-simulation):

```bash theme={null}
curl "<endpoint>/v1/customers" \
  -H "X-Continuous-Simulation-Token: <token>" \
  --data-urlencode "name=Ada Lovelace" \
  --data-urlencode "email=ada@example.com"
```

The same Simulation returns the same response bytes for the same requests from the same state. Each request marks the Simulation active and wakes a paused Simulation.

`Cookie`, `Proxy-Authorization`, and the token header are removed before the request reaches the Simulation.

## Read-only requests

Set `Continuous-Read-Only: true` to inspect data without permitting that request to write:

```bash theme={null}
curl "<endpoint>/v1/customers" \
  -H "X-Continuous-Simulation-Token: <token>" \
  -H "Continuous-Read-Only: true"
```

The Simulation checks the operation's capabilities, so SOAP and POST reads can pass. Write operations fail before execution, including retries with a saved idempotency response. Reads with declared write effects also fail. The header is a platform control and is not passed to authored vendor behavior.

Use exactly one value: `true` or `false`. Header names are case-insensitive. An absent header or `false` keeps ordinary behavior. Invalid, empty, or repeated values return `400`. A rejected write returns `403` with code `simulation_read_only`, including on SOAP endpoints.

This feature requires an updated Simulation runtime. Older running runtimes ignore the header; rebuilding a Simulator alone does not update them. After the runtime update, older Simulator artifacts reject requests with `true` because they cannot prove read-only support. Rebuild the Simulator and create a new Simulation to use the header.

This restriction applies to one request. Other requests can still write, and activity tracking and automatic wake continue. It does not grant restricted token permissions or change Simulation lifecycle controls.

## Errors

Platform refusals use the [error envelope](/api-reference/errors). A rejected Simulation token carries `X-Continuous-Simulation-Token-Rejected: true`. A stopped Simulation must be started before it accepts requests. Read-only refusals keep the platform JSON shape, including on SOAP endpoints.

The simulated API also returns its own responses. [Quotas and limits](/api-reference/quotas#size-limits) owns the transport caps for ordinary, multipart, and SOAP requests.

<Columns cols={2}>
  <Card title="Simulations" icon="play" href="/concepts/simulations">
    Lifecycle, credentials, steps, and forks.
  </Card>

  <Card title="Authentication" icon="key" href="/api-reference/authentication">
    API keys for `/v1` routes and Simulation tokens for the data plane.
  </Card>
</Columns>
