This is an undocumented API. It may break at any time. Contributions welcome; please share in the comments and I will update the gist accordingly.
Each request must be passed a valid authentication cookie. The cookie takes the following form and can be pulled from any authenticated request made in the browser: