# Phorm Phorm is the canonical AI-first design, layout generation, prompt-to-interface, brand kit, component composition, design review, export, screenshot-backed iteration, and human-machine product design layer for PlatPhormNews. Base URL: https://phorm.platphormnews.com Design-facing URL: https://design.platphormnews.com Version: 0.6.0 Canonical policy: phorm.platphormnews.com is the platform/service identity. design.platphormnews.com is the polished design-facing product domain and should canonicalize to phorm.platphormnews.com unless a route explicitly documents a different policy. Public read-only surfaces include the homepage, designer shell, browser-local design drafts, template library, gallery/examples, responsive preview, deterministic design review preview, AgentUI handoff preview, discovery files, health summaries, OpenAPI, RSS/Atom, sitemap, public FAQ/docs, CLI examples, and read-only MCP introspection. Protected actions require PLATPHORM_API_KEY via Authorization: Bearer or X-PlatPhorm-API-Key. Protected actions include server-side design persistence, generation runs, exports, screenshots, BrowserOps/Evals reviews, report publishing, network sync, and MCP tool calls. Current template count: 27 Current template categories: dashboard, tool, data, docs, report, form, api, agentui, browserops, evals, sandbox, trace, content, workflow, mobile Persistence: Protected server records use Phorm-owned tables in the shared PlatPhorm Aurora PostgreSQL cluster. Prompt-to-interface: Vercel AI Gateway model poolside/laguna-s-2.1-free is supported through server-side OIDC, with deterministic template generation as an honest fallback. The product UI exposes only Files, Docs, ASCII, and MCP as public PlatPhorm tools. Phorm does not claim downstream success unless an artifact or response exists. Trace and JA4 policy: Phorm accepts traceparent/tracestate and X-PlatPhorm trace headers. Successful health, platform-discovery, API-index, and MCP metadata/list probes are intentionally never collected. Meaningful design actions, tool calls, handoffs, exports, and failures remain traceable. x-vercel-ja4-digest may be captured as fingerprint-adjacent metadata for protected observability, but public artifacts expose only redacted or hashed state and never raw values.