The endpoint should accept a POST request with JSON body:{"query": "user message", "text": "selected document text"}
Response: JSON with a "content" field, or plain text.
If this add-in page is loaded via HTTPS, the API endpoint must also be HTTPS.