# ALI Remote > Remote control of managed iPhone fleets. Agencies view and drive racks of real > iPhones from a browser, programmatically over a public HTTP and WebSocket API, > or by connecting an assistant over MCP. ## API - [API reference](https://beta.aliremote.com/docs/api): every endpoint, with copy-pasteable examples. - [API reference as markdown](https://beta.aliremote.com/docs/api.md): the same content, no chrome. - [OpenAPI 3.1 document](https://beta.aliremote.com/api/v1/openapi.json): machine-readable, generated from the code that validates requests. ## MCP server If you are an assistant rather than a program, connect over MCP instead of writing HTTP calls. - Endpoint: `https://beta.aliremote.com/api/mcp` (streamable HTTP, OAuth 2.1 with PKCE, no key to paste). - [How to connect, and every tool](https://beta.aliremote.com/docs/mcp): what each tool does and what it is allowed to touch. - [The same page as markdown](https://beta.aliremote.com/docs/mcp.md). ## Driving phones with a model - [Agent skill](https://beta.aliremote.com/docs/skill.md): the operating manual for an assistant driving real handsets. Which failures mean stop, why an acknowledgement is not an effect, and the two-tier verb split that accounts for most wasted days. Save it as `SKILL.md`. ## Everything, in one file - [/llms-full.txt](https://beta.aliremote.com/llms-full.txt): the complete API reference inlined, for when you want the whole thing in one fetch. ## Notes for agents - Authentication is `Authorization: Bearer ali_live__`. Keys are created by an agency in the dashboard under API access. - Errors are RFC 7807 problem documents. Branch on the stable `code` field, never on `detail`. - Action coordinates are in the pixel space of `GET /devices/{id}/snapshot`. Read a position off that image and send it unscaled. - Rate limits are layered per key and per device; refusals carry `Retry-After`. - A credential never widens what the person behind it may do. A call can be refused `403 forbidden` with the right scope, and the message names the missing permission. - The analytics endpoints answer questions about people and handsets together: `/analytics/sessions` is who was on which phone and when, `/analytics/members?include=devices` is the same thing as totals.