openapi: 3.1.0
info:
  title: HE Signs integration API
  version: 0.7.0
  description: Database-backed v2 integration runtime with a separate
    authenticated sender workspace. Locally validated; public deployment and
    independent production review remain pending. Up to 10 PDFs, 25 signers and
    200 fields. Optional email-code authentication, service PDF seals and
    RFC3161 timestamps. No claim of qualified signatures or verified legal
    identity.
servers:
  - url: https://hesigns.homeequal.ai
    description: Intended production origin; deployment pending
security:
  - apiKey: []
components:
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: X-API-Key
    scimBearer:
      type: http
      scheme: bearer
      description: Expiring HE Signs key with provisioning:manage scope
  parameters:
    requestId:
      in: path
      name: id
      required: true
      schema:
        type: string
        pattern: ^hs_[a-f0-9-]{36}$
    idempotencyKey:
      in: header
      name: Idempotency-Key
      required: true
      schema:
        type: string
        maxLength: 200
  schemas:
    AgreementTemplateInput:
      type: object
      required:
        - name
        - roles
        - routing
        - fields
      description: Reusable preparation with no personal recipient assignments. PDF
        and field validation matches agreement creation.
      properties:
        name:
          type: string
          minLength: 1
          maxLength: 120
        description:
          type: string
          maxLength: 300
        base_version:
          type: integer
          minimum: 1
          description: Required for PUT; must equal the latest stored version
        document:
          type: object
          required:
            - name
            - base64
          properties:
            name:
              type: string
              maxLength: 200
            base64:
              type: string
              description: PDF up to 8 MiB decoded and 100 pages
        roles:
          type: array
          minItems: 1
          maxItems: 25
          items:
            type: object
            required:
              - key
              - name
            properties:
              key:
                type: string
                pattern: ^[a-z][a-z0-9_]{0,39}$
                description: Unique stable key used for recipient assignments
              name:
                type: string
                minLength: 1
                maxLength: 60
                description: Unique display name such as Client or Provider
              locale:
                type: string
                enum:
                  - en
                  - es
                  - fr
                  - ar
                default: en
              authentication:
                type: string
                enum:
                  - private_link
                  - email_otp
                default: private_link
                description: Email codes require configured mail and the database runtime.
                  Mailbox access does not independently establish legal
                  identity.
              allow_delegation:
                type: boolean
                default: false
              routing_order:
                type: integer
                minimum: 1
                maximum: 25
                description: Required with groups routing. All people in earlier groups must
                  finish.
              attachment_requests:
                type: array
                maxItems: 3
                items:
                  $ref: "#/components/schemas/AttachmentRequest"
        routing:
          type: string
          enum:
            - parallel
            - sequential
            - groups
        fields:
          type: array
          minItems: 1
          maxItems: 200
          items:
            $ref: "#/components/schemas/EnvelopeField"
        documents:
          type: array
          minItems: 1
          maxItems: 10
          items:
            type: object
            required:
              - name
              - base64
            properties:
              name:
                type: string
                maxLength: 200
              base64:
                type: string
                description: PDF up to 8 MiB decoded and 100 pages
          description: "PDFs in final order. Combined decoded sources: 8 MiB and 100
            pages. Fields use page numbers in the combined packet."
      oneOf:
        - required:
            - document
          not:
            required:
              - documents
        - required:
            - documents
          not:
            required:
              - document
    AgreementTemplate:
      type: object
      properties:
        id:
          type: string
        version:
          type: integer
        latest_version:
          type: integer
        name:
          type: string
        description:
          type: string
        archived:
          type: boolean
        document_name:
          type: string
        sha256:
          type: string
        page_count:
          type: integer
        roles:
          type: array
          items:
            type: object
            properties:
              key:
                type: string
              name:
                type: string
        routing:
          type: string
        fields:
          type: array
          items:
            $ref: "#/components/schemas/EnvelopeField"
        created_at:
          type: string
          format: date-time
        saved_at:
          type: string
          format: date-time
        versions:
          type: array
          description: Present on single-template reads
          items:
            type: object
            properties:
              version:
                type: integer
              name:
                type: string
              saved_at:
                type: string
                format: date-time
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
            message:
              type: string
    Field:
      type: object
      required:
        - page
        - x
        - y
        - width
        - height
      description: Coordinates in PDF points from the bottom left of an unrotated page.
      properties:
        page:
          type: integer
          minimum: 1
        x:
          type: number
          minimum: 0
        y:
          type: number
          minimum: 0
        width:
          type: number
          minimum: 180
        height:
          type: number
          minimum: 48
    CreateRequest:
      type: object
      required:
        - client_reference
        - document
        - participant
        - field
      properties:
        client_reference:
          type: string
          maxLength: 200
        document:
          type: object
          required:
            - name
            - base64
          properties:
            name:
              type: string
              maxLength: 200
            base64:
              type: string
              description: Base64 PDF bytes
              maximum 8 MiB decoded: null
        participant:
          type: object
          required:
            - name
            - email
          properties:
            name:
              type: string
              maxLength: 120
            email:
              type: string
              format: email
        field:
          $ref: "#/components/schemas/Field"
        sender_authorization:
          type: object
          description: Required when a tenant has enrolled a customer Ed25519 public key.
          required:
            - signature
          properties:
            signature:
              type: string
              description: Base64 Ed25519 signature over canonical manifest UTF-8 bytes
    RequestStatus:
      type: object
      required:
        - id
        - client_reference
        - status
        - document_name
        - participant
        - created_at
        - expires_at
      properties:
        id:
          type: string
        client_reference:
          type: string
        status:
          type: string
          enum:
            - ready_for_delivery
            - sent
            - in_progress
            - completed
            - declined
            - voided
            - expired
        document_name:
          type: string
        page_count:
          type: integer
        participant:
          type: object
          properties:
            name:
              type: string
            email:
              type: string
        created_at:
          type: string
          format: date-time
        expires_at:
          type: string
          format: date-time
        completed_at:
          type:
            - string
            - "null"
          format: date-time
        declined_at:
          type:
            - string
            - "null"
          format: date-time
        voided_at:
          type:
            - string
            - "null"
          format: date-time
        expired_at:
          type:
            - string
            - "null"
          format: date-time
        terminal_reason:
          type:
            - string
            - "null"
        signer_path:
          type:
            - string
            - "null"
          description: Private link path; customer delivers it to signer
        invitation_delivery:
          type:
            - object
            - "null"
          description: Provider acceptance
          failure: null
          or attempt state: null
        completion_delivery:
          type:
            - object
            - "null"
          description: Signed-copy email state
        reminder_delivery:
          type:
            - object
            - "null"
          description: Bounded reminder attempts and provider acceptance
    EnvelopeField:
      type: object
      required:
        - signer
        - type
        - page
        - x
        - y
        - width
        - height
      description: Coordinates are PDF points from the bottom left of an unrotated
        page. Fields must not overlap. Full name and email are filled from
        recipient data; signed_date is the signing date in UTC. Date is entered
        by the signer. Minimum widths are signature 180, initials 90, full_name
        180, email 180, signed_date 110, date 110, text 180, checkbox 150
        points.
      properties:
        signer:
          type: integer
          minimum: 0
          maximum: 24
        type:
          type: string
          enum:
            - signature
            - initials
            - full_name
            - email
            - signed_date
            - date
            - text
            - checkbox
        label:
          type: string
          maxLength: 80
          description: Prompt for a date
          text: null
          or required checkbox field: null
        page:
          type: integer
          minimum: 1
        x:
          type: number
          minimum: 0
        y:
          type: number
          minimum: 0
        width:
          type: number
          minimum: 90
        height:
          type: number
          minimum: 44
        required:
          type: boolean
          default: true
          description: Only text, date and checkbox fields may be optional.
        condition:
          type: object
          required:
            - field
            - equals
          properties:
            field:
              type: integer
              minimum: 0
              maximum: 199
            equals:
              type:
                - string
                - boolean
          description: Show when an unconditional checkbox/text/date field of the same
            signer has this exact answer. At least one unconditional signature
            per signer remains required.
    CreateEnvelope:
      type: object
      required:
        - client_reference
        - participants
        - routing
        - fields
      properties:
        client_reference:
          type: string
          maxLength: 200
        document:
          type: object
          required:
            - name
            - base64
          properties:
            name:
              type: string
              maxLength: 200
            base64:
              type: string
              description: Base64 PDF bytes
              maximum 8 MiB decoded: null
        routing:
          type: string
          enum:
            - parallel
            - sequential
            - groups
        participants:
          type: array
          minItems: 1
          maxItems: 25
          items:
            type: object
            required:
              - name
              - email
            properties:
              name:
                type: string
                maxLength: 120
              email:
                type: string
                format: email
              locale:
                type: string
                enum:
                  - en
                  - es
                  - fr
                  - ar
                default: en
              authentication:
                type: string
                enum:
                  - private_link
                  - email_otp
                default: private_link
                description: Email codes require configured mail and the database runtime.
                  Mailbox access does not independently establish legal
                  identity.
              allow_delegation:
                type: boolean
                default: false
              routing_order:
                type: integer
                minimum: 1
                maximum: 25
                description: Required with groups routing. All people in earlier groups must
                  finish.
              attachment_requests:
                type: array
                maxItems: 3
                items:
                  $ref: "#/components/schemas/AttachmentRequest"
        fields:
          type: array
          minItems: 1
          maxItems: 200
          items:
            $ref: "#/components/schemas/EnvelopeField"
        sender_authorization:
          type: object
          description: Required when this tenant has enrolled a customer Ed25519 public key.
          required:
            - signature
          properties:
            signature:
              type: string
              description: Base64 signature over the canonical v2 manifest
        documents:
          type: array
          minItems: 1
          maxItems: 10
          items:
            type: object
            required:
              - name
              - base64
            properties:
              name:
                type: string
                maxLength: 200
              base64:
                type: string
                description: Base64 PDF bytes
                maximum 8 MiB decoded: null
          description: "PDFs in final order. Combined decoded sources: 8 MiB and 100
            pages. Fields use page numbers in the combined packet."
      oneOf:
        - required:
            - document
          not:
            required:
              - documents
        - required:
            - documents
          not:
            required:
              - document
    EnvelopeStatus:
      type: object
      properties:
        id:
          type: string
        kind:
          type: string
          const: envelope
        status:
          type: string
          enum:
            - ready_for_delivery
            - in_progress
            - completed
            - declined
            - voided
            - expired
        customer_authorized:
          type: boolean
        routing:
          type: string
          enum:
            - parallel
            - sequential
        client_reference:
          type: string
        document_name:
          type: string
        page_count:
          type: integer
        fields:
          type: array
          items:
            $ref: "#/components/schemas/EnvelopeField"
        participants:
          type: array
          items:
            type: object
            properties:
              index:
                type: integer
              name:
                type: string
              email:
                type: string
                format: email
              status:
                type: string
                enum:
                  - ready
                  - waiting
                  - sent
                  - opened
                  - signed
                  - declined
              signer_path:
                type:
                  - string
                  - "null"
                description: Private path for this signer
              invitation_delivery:
                type:
                  - object
                  - "null"
              reminder_delivery:
                type:
                  - object
                  - "null"
                description: Attempts and accepted reminders for this signer
              completion_delivery:
                type:
                  - object
                  - "null"
        created_at:
          type: string
          format: date-time
        expires_at:
          type: string
          format: date-time
        completed_at:
          type:
            - string
            - "null"
          format: date-time
    AttachmentRequest:
      type: object
      required:
        - label
      properties:
        label:
          type: string
          minLength: 1
          maxLength: 100
        required:
          type: boolean
          default: true
    BulkRow:
      type: object
      required:
        - client_reference
        - assignments
      properties:
        client_reference:
          type: string
          maxLength: 200
        assignments:
          type: object
          additionalProperties:
            type: object
            required:
              - name
              - email
            properties:
              name:
                type: string
              email:
                type: string
                format: email
        sender_authorization:
          type: object
          description: Required when this tenant has enrolled a customer Ed25519 public key.
          required:
            - signature
          properties:
            signature:
              type: string
              description: Base64 signature over the canonical v2 manifest
paths:
  /v2/templates:
    get:
      summary: List the latest version of each owned agreement template, including
        archived templates
      responses:
        "200":
          description: Template library
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: "#/components/schemas/AgreementTemplate"
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: templates:read
    post:
      summary: Save an agreement template with reusable recipient roles
      description: Stores version 1 without creating an agreement or sending email.
        Supports 100 templates per local workspace.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: "#/components/schemas/AgreementTemplateInput"
      responses:
        "201":
          description: Template saved
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/AgreementTemplate"
        "400":
          description: Invalid roles
          PDF or fields: null
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: templates:write
  "/v2/templates/{id}":
    parameters:
      - in: path
        name: id
        required: true
        schema:
          type: string
    get:
      summary: Read an owned template version and version history
      parameters:
        - in: query
          name: version
          schema:
            type: integer
            minimum: 1
          description: Defaults to latest
      responses:
        "200":
          description: Template metadata
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/AgreementTemplate"
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Template or version not found for this customer
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: templates:read
    put:
      summary: Save a new immutable version of an owned template
      description: Requires base_version equal to the latest version. Earlier versions
        and created agreements remain unchanged. Up to 50 versions per template.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: "#/components/schemas/AgreementTemplateInput"
      responses:
        "200":
          description: New version saved
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/AgreementTemplate"
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Version conflict or archived template
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: templates:write
  "/v2/templates/{id}/pdf":
    get:
      summary: Download the exact PDF for an owned template version
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
        - in: query
          name: version
          schema:
            type: integer
            minimum: 1
      responses:
        "200":
          description: PDF bytes after hash verification
          content:
            application/pdf:
              schema:
                type: string
                format: binary
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Template or version not found for this customer
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: templates:read
  "/v2/templates/{id}/archive":
    post:
      summary: Archive or restore an owned template without deleting its versions
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - archived
              properties:
                archived:
                  type: boolean
      responses:
        "200":
          description: Archive state updated
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Template not found for this customer
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: templates:write
  "/v2/templates/{id}/prepare":
    post:
      summary: Resolve an exact template version and role assignments into an
        agreement creation body
      description: Does not create or send. Review the returned envelope, then use the
        existing envelope manifest or creation endpoint. Template id/version are
        preparation metadata, not additional signer-identity evidence.
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - version
                - client_reference
                - assignments
              properties:
                version:
                  type: integer
                  minimum: 1
                client_reference:
                  type: string
                  maxLength: 200
                assignments:
                  type: object
                  description: Exactly one entry per role key
                  additionalProperties:
                    type: object
                    required:
                      - name
                      - email
                    properties:
                      name:
                        type: string
                        maxLength: 120
                      email:
                        type: string
                        format: email
      responses:
        "200":
          description: Reviewed input for the existing envelope creation API
          content:
            application/json:
              schema:
                type: object
                properties:
                  template:
                    type: object
                    properties:
                      id:
                        type: string
                      version:
                        type: integer
                      name:
                        type: string
                  envelope:
                    $ref: "#/components/schemas/CreateEnvelope"
        "400":
          description: Missing version or invalid role assignments
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Template is archived
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: templates:write
  /v2/envelopes/placement-preview:
    post:
      summary: Preview automatic field placements without creating or sending an
        agreement
      description: Reads PDF text, literal anchors, or repeated page footers. Up to 8
        MiB, 100 pages, and 200 suggestions. Review each returned field and
        issue before submitting explicit fields to the creation endpoint.
        Scanned-image OCR is not supported.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - document
              properties:
                document:
                  type: object
                  required:
                    - base64
                  properties:
                    base64:
                      type: string
                mode:
                  type: string
                  enum:
                    - labels
                    - anchor
                    - initials
                  default: labels
                anchor:
                  type: string
                  maxLength: 120
                  description: Required for anchor mode; literal case-insensitive text
                field_type:
                  type: string
                  enum:
                    - signature
                    - initials
                    - full_name
                    - email
                    - signed_date
                    - date
                    - text
                    - checkbox
                  default: signature
                signer:
                  type: integer
                  minimum: 0
                  maximum: 24
                  default: 0
                recipient_count:
                  type: integer
                  minimum: 1
                  maximum: 25
                  default: 2
                ocr:
                  type: boolean
                  default: false
                  description: Use the bundled English OCR model for up to 10 scanned pages. Runs
                    locally; suggestions always require sender review.
                pages:
                  type: array
                  maxItems: 10
                  items:
                    type: integer
                    minimum: 1
                    maximum: 100
      responses:
        "200":
          description: Placement candidates with source text, reason, warning, and
            blocking issue; review_required is true
          content:
            application/json:
              schema:
                type: object
                properties:
                  review_required:
                    type: boolean
                    const: true
                  page_count:
                    type: integer
                  data:
                    type: array
                    items:
                      type: object
                      properties:
                        field:
                          $ref: "#/components/schemas/EnvelopeField"
                        source:
                          type: string
                        reason:
                          type: string
                        warning:
                          type: string
                        issue:
                          type:
                            - string
                            - "null"
        "400":
          description: Invalid PDF
          mode: null
          field type: null
          recipient: null
          anchor: null
          or page count: null
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:write
  /v2/envelopes:
    get:
      summary: List up to 100 recent customer-owned agreements
      responses:
        "200":
          description: Newest-first cursor page. Follow next_cursor as cursor; includes
            data, has_more and next_cursor.
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: query
          name: limit
          required: false
          schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 100
        - in: query
          name: cursor
          required: false
          schema:
            type: string
      x-required-scope: envelopes:read
    post:
      summary: Create an agreement for 1 to 5 signers
      description: Requires at least one signature field for each signer. No
        invitations are sent by creation.
      parameters:
        - $ref: "#/components/parameters/idempotencyKey"
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: "#/components/schemas/CreateEnvelope"
      responses:
        "201":
          description: Created or idempotently replayed
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/EnvelopeStatus"
        "400":
          description: Invalid signer
          PDF: null
          routing: null
          or fields: null
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "402":
          description: "SUBSCRIPTION_REQUIRED or SUBSCRIPTION_INACTIVE: workspace owner
            must activate or restore the subscription. Existing signing and
            downloads remain available."
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Idempotency key conflict
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:write
  /v2/envelopes/manifest:
    post:
      summary: Prepare the exact agreement manifest for a customer Ed25519 signature
      parameters:
        - $ref: "#/components/parameters/idempotencyKey"
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: "#/components/schemas/CreateEnvelope"
      responses:
        "200":
          description: Canonical manifest to sign
          content:
            application/json:
              schema:
                type: object
                properties:
                  manifest:
                    type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:write
  "/v2/envelopes/{id}":
    get:
      summary: Read a customer-owned agreement
      parameters:
        - $ref: "#/components/parameters/requestId"
      responses:
        "200":
          description: Agreement status
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/EnvelopeStatus"
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Agreement not found for this customer
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:read
  "/v2/envelopes/{id}/send/{signer}":
    post:
      summary: Email an active signer; ordered successors are invited automatically
        after the previous signature
      parameters:
        - $ref: "#/components/parameters/requestId"
        - in: path
          name: signer
          required: true
          schema:
            type: integer
            minimum: 0
            maximum: 4
      responses:
        "202":
          description: Delivery durably queued; inspect recipient and delivery status.
            SMTP acceptance is not inbox receipt.
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Delivery unavailable or reminder not due
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
        "503":
          description: Email not configured
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:send
  "/v2/envelopes/{id}/remind/{signer}":
    post:
      summary: Remind an invited, unsigned signer after at least 24 hours; at most
        three accepted reminders
      parameters:
        - $ref: "#/components/parameters/requestId"
        - in: path
          name: signer
          required: true
          schema:
            type: integer
            minimum: 0
            maximum: 4
      responses:
        "202":
          description: Delivery durably queued; inspect recipient and delivery status.
            SMTP acceptance is not inbox receipt.
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Delivery unavailable or reminder not due
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
        "503":
          description: Email not configured
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:send
  "/v2/envelopes/{id}/deliver-completed/{signer}":
    post:
      summary: Retry a failed completed-copy email without asking the signer to sign
        again
      parameters:
        - $ref: "#/components/parameters/requestId"
        - in: path
          name: signer
          required: true
          schema:
            type: integer
            minimum: 0
            maximum: 4
      responses:
        "202":
          description: Delivery durably queued; inspect recipient and delivery status.
            SMTP acceptance is not inbox receipt.
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Delivery unavailable or reminder not due
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
        "503":
          description: Email not configured
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:send
  "/v2/envelopes/{id}/void":
    post:
      summary: Void an open agreement with a reason
      parameters:
        - $ref: "#/components/parameters/requestId"
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - reason
              properties:
                reason:
                  type: string
                  maxLength: 500
      responses:
        "200":
          description: Agreement voided
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Agreement already closed
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:write
  "/v2/envelopes/{id}/events":
    get:
      summary: Read recorded agreement and signer events
      parameters:
        - $ref: "#/components/parameters/requestId"
      responses:
        "200":
          description: Event history
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: events:read
  "/v2/envelopes/{id}/original.pdf":
    get:
      summary: Download the original agreement PDF
      parameters:
        - $ref: "#/components/parameters/requestId"
      responses:
        "200":
          description: Original PDF
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:read
  "/v2/envelopes/{id}/completed.pdf":
    get:
      summary: Download the visibly marked PDF after all signers finish
      parameters:
        - $ref: "#/components/parameters/requestId"
      responses:
        "200":
          description: Completed PDF
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Agreement not completed
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:read
  "/v2/envelopes/{id}/proof.json":
    get:
      summary: Download the detached signed evidence for all signers
      parameters:
        - $ref: "#/components/parameters/requestId"
      responses:
        "200":
          description: Evidence JSON
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Agreement not completed
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:read
  "/v2/envelopes/{id}/proof-kit.zip":
    get:
      summary: Download both PDFs, evidence, public key, and offline verifier
      parameters:
        - $ref: "#/components/parameters/requestId"
      responses:
        "200":
          description: Portable proof kit ZIP
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Agreement not completed
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      x-required-scope: envelopes:read
  "/esign/{token}":
    get:
      security: []
      summary: Private signer page; waiting signers see their place in the order
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Signer HTML page
  "/esign/{token}/document.pdf":
    get:
      security: []
      summary: Open the original PDF and record that this signer opened it
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Original PDF
        "409":
          description: Signer is waiting or already signed
  "/esign/{token}/complete":
    post:
      security: []
      summary: Record this signer's assigned field values, review, consent, typed
        name, and intent
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - name
                - reviewed_document
                - consent_to_electronic_signing
                - intent_to_sign
              properties:
                name:
                  type: string
                reviewed_document:
                  type: boolean
                  const: true
                consent_to_electronic_signing:
                  type: boolean
                  const: true
                intent_to_sign:
                  type: boolean
                  const: true
                field_values:
                  type: object
                  description: Required values keyed by zero-based index in the agreement's fields
                    array. Date uses YYYY-MM-DD, text is a short printable
                    answer, and each required checkbox must be true. Signature,
                    initials, and full_name are derived from the signer's name;
                    email comes from recipient data, and signed_date from the
                    UTC signing time. These automatic fields cannot be
                    overridden.
                  additionalProperties:
                    oneOf:
                      - type: string
                      - type: boolean
                        const: true
                locale:
                  type: string
                  enum:
                    - en
                    - es
                    - fr
                    - ar
                  default: en
                attachments:
                  type: array
                  maxItems: 3
                  items:
                    type: object
                    required:
                      - request
                      - name
                      - base64
                    properties:
                      request:
                        type: integer
                        minimum: 0
                        maximum: 2
                      name:
                        type: string
                      base64:
                        type: string
                  description: PDF/PNG/JPEG; 4 MiB each, 8 MiB total across the agreement. Matched
                    to attachment request indices and included in the proof kit
                    for all recipients.
      responses:
        "200":
          description: Signature recorded; final artifact created after the last signer
        "409":
          description: Signer is waiting
          already signed: null
          or agreement is closed: null
  "/esign/{token}/decline":
    post:
      security: []
      summary: Decline and close the whole agreement
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Decline recorded
  "/esign/{token}/completed.pdf":
    get:
      security: []
      summary: Download signed PDF after all signers finish
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Completed PDF
        "409":
          description: Agreement not completed
  "/esign/{token}/proof.json":
    get:
      security: []
      summary: Download detached evidence after completion
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Evidence JSON
  "/esign/{token}/proof-kit.zip":
    get:
      security: []
      summary: Download portable proof kit after completion
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Proof kit ZIP
  /v2/envelopes/assemble:
    post:
      summary: Preview an ordered PDF packet without creating or sending
      x-required-scope: envelopes:write
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                documents:
                  type: array
                  minItems: 1
                  maxItems: 10
                  items:
                    type: object
                    required:
                      - name
                      - base64
                    properties:
                      name:
                        type: string
                        maxLength: 200
                      base64:
                        type: string
                        description: Base64 PDF bytes
                        maximum 8 MiB decoded: null
                  description: "PDFs in final order. Combined decoded sources: 8 MiB and 100
                    pages. Fields use page numbers in the combined packet."
              required:
                - documents
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  "/v2/templates/{id}/documents":
    get:
      summary: Read immutable source PDF bytes for an exact template version
      x-required-scope: templates:read
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
        - in: query
          name: version
          required: false
          schema:
            type: integer
  "/v2/envelopes/{id}/source-{index}.pdf":
    get:
      summary: Download one original packet PDF
      x-required-scope: envelopes:read
      responses:
        "200":
          description: PDF
          content:
            application/pdf:
              schema:
                type: string
                format: binary
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Unavailable
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
        - in: path
          name: index
          required: true
          schema:
            type: integer
            minimum: 0
            maximum: 9
  "/v2/envelopes/{id}/signed-{index}.pdf":
    get:
      summary: Download one completed packet PDF
      x-required-scope: envelopes:read
      responses:
        "200":
          description: PDF
          content:
            application/pdf:
              schema:
                type: string
                format: binary
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Unavailable
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
        - in: path
          name: index
          required: true
          schema:
            type: integer
            minimum: 0
            maximum: 9
  "/esign/{token}/source-{index}.pdf":
    get:
      summary: Download one original packet PDF
      responses:
        "200":
          description: PDF
          content:
            application/pdf:
              schema:
                type: string
                format: binary
        "404":
          description: Unavailable
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
        - in: path
          name: index
          required: true
          schema:
            type: integer
            minimum: 0
            maximum: 9
      security: []
  "/esign/{token}/signed-{index}.pdf":
    get:
      summary: Download one completed packet PDF
      responses:
        "200":
          description: PDF
          content:
            application/pdf:
              schema:
                type: string
                format: binary
        "404":
          description: Unavailable
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
        - in: path
          name: index
          required: true
          schema:
            type: integer
            minimum: 0
            maximum: 9
      security: []
  "/esign/{token}/delegate":
    post:
      summary: Transfer signing when explicitly permitted; revokes old access and
        queues a new invitation
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  maxLength: 120
                email:
                  type: string
                  format: email
                confirm:
                  const: true
              required:
                - name
                - email
                - confirm
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
      security: []
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
  "/v2/envelopes/{id}/embedded-sessions":
    post:
      summary: Create a 15-minute signing session for an enrolled application origin
      x-required-scope: sessions:write
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - signer
                - parent_origin
              properties:
                signer:
                  type: integer
                  minimum: 0
                  maximum: 24
                parent_origin:
                  type: string
                  format: uri
      responses:
        "201":
          description: Short-lived session
          content:
            application/json:
              schema:
                type: object
                required:
                  - session_id
                  - session_url
                  - expires_at
                properties:
                  session_id:
                    type: string
                  session_url:
                    type: string
                    format: uri
                  expires_at:
                    type: string
                    format: date-time
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Origin not enrolled
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Agreement or signer already finished
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  "/v2/embedded-sessions/{sessionId}":
    delete:
      summary: Revoke an embedded session
      x-required-scope: sessions:write
      parameters:
        - in: path
          name: sessionId
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Revoked
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Session not found
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  /v2/credentials:
    get:
      summary: List your credential metadata; never returns secrets
      x-required-scope: credentials:manage
      responses:
        "200":
          description: Credential metadata
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
    post:
      summary: Issue a scoped expiring key; cannot exceed the caller’s scopes
      x-required-scope: credentials:manage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - label
                - scopes
              properties:
                label:
                  type: string
                  maxLength: 100
                scopes:
                  type: array
                  items:
                    type: string
                expires_in_days:
                  type: integer
                  minimum: 1
                  maximum: 365
                  default: 90
      responses:
        "201":
          description: Store api_key securely; it is returned only once
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid or excessive scope
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: 20 active credentials limit reached
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  "/v2/credentials/{id}":
    delete:
      summary: Immediately revoke a credential
      x-required-scope: credentials:manage
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Revoked
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Credential not found
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  /v2/events:
    get:
      summary: Read the durable event stream, including events created before webhook
        enrollment
      x-required-scope: events:read
      parameters:
        - in: query
          name: after
          required: false
          schema:
            type: string
      responses:
        "200":
          description: Up to 100 events, has_more and next_cursor. Persist next_cursor
            only after durable processing.
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  /v2/usage:
    get:
      summary: Read UTC calendar-month agreement usage, allowance and delivery backlog
      x-required-scope: usage:read
      responses:
        "200":
          description: Usage; idempotent replays are not counted again
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  /v2/webhooks:
    get:
      summary: Read your webhook endpoint metadata
      x-required-scope: webhooks:manage
      responses:
        "200":
          description: Endpoint metadata; no secret
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
    put:
      summary: Enroll or rotate an HTTPS webhook endpoint and secret
      x-required-scope: webhooks:manage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - url
              properties:
                url:
                  type: string
                  format: uri
                  maxLength: 2048
      responses:
        "200":
          description: Secret returned once. Existing queued events retain their old
            destination and secret.
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Private or invalid endpoint
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
    delete:
      summary: Disable new callbacks and cancel queued deliveries; an in-flight
        attempt may finish
      x-required-scope: webhooks:manage
      responses:
        "200":
          description: Disabled
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  /v2/webhooks/deliveries:
    get:
      summary: Inspect the most recent 100 webhook and email jobs
      x-required-scope: webhooks:manage
      responses:
        "200":
          description: Delivery state, attempts, next attempt, and sanitized failure code
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  "/v2/webhooks/deliveries/{id}/replay":
    post:
      summary: Replay a dead, retrying or delivered job using its original event ID
        and destination snapshot
      x-required-scope: webhooks:manage
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
      responses:
        "202":
          description: Queued
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Unavailable or currently processing
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  /v2/retention:
    get:
      summary: List retention state for the most recent 100 agreements
      x-required-scope: retention:manage
      responses:
        "200":
          description: Agreement metadata, legal holds, deletion dates and a seven-day
            grace period
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  "/v2/retention/{id}/hold":
    put:
      summary: Place or release a legal hold; placing a hold cancels scheduled deletion
      x-required-scope: retention:manage
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - enabled
              properties:
                enabled:
                  type: boolean
      responses:
        "200":
          description: Updated hold
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Agreement unavailable
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  "/v2/retention/{id}/deletion":
    post:
      summary: Schedule deletion of a closed agreement after seven days
      x-required-scope: retention:manage
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - confirm_document_name
              properties:
                confirm_document_name:
                  type: string
                  description: Must exactly match the document name
      responses:
        "202":
          description: Scheduled; cancellable before processing
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Agreement unavailable
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Agreement active or held
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
    delete:
      summary: Cancel scheduled deletion
      x-required-scope: retention:manage
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
      responses:
        "200":
          description: Cancelled
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Agreement unavailable
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  /verification-keys:
    get:
      summary: List active and historical public proof keys; establish trust through a
        separate channel
      security: []
      responses:
        "200":
          description: Public key metadata
          content:
            application/json:
              schema:
                type: object
  /v2/exports/completed:
    get:
      summary: List completed agreements eligible for bulk export, with cursor
        pagination
      x-required-scope: exports:read
      parameters:
        - in: query
          name: after
          required: false
          schema:
            type: string
      responses:
        "200":
          description: Up to 50 records, has_more and next_cursor. This is a live listing,
            not a frozen export snapshot.
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  /v2/exports/proof-kits.zip:
    post:
      summary: Export 1–10 completed proof kits in one archive, up to 32 MiB of
        artifact data
      x-required-scope: exports:read
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - ids
              properties:
                ids:
                  type: array
                  minItems: 1
                  maxItems: 10
                  uniqueItems: true
                  items:
                    type: string
      responses:
        "200":
          description: ZIP containing individual proof kits, a filename mapping and
            checksums
          content:
            application/zip:
              schema:
                type: string
                format: binary
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: One or more completed agreements unavailable
          content:
            application/json:
              schema:
                type: object
        "413":
          description: Choose a smaller batch
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
        "503":
          description: Export busy, or artifact/historical key unavailable
          content:
            application/json:
              schema:
                type: object
  /verification-key.pem:
    get:
      summary: Download a public proof key by key_id; defaults to the active key
      security: []
      parameters:
        - in: query
          name: key_id
          required: false
          schema:
            type: string
      responses:
        "200":
          description: Ed25519 public PEM
          content:
            application/x-pem-file:
              schema:
                type: string
        "404":
          description: Unknown key
          content:
            application/json:
              schema:
                type: object
  "/esign/{token}/challenge":
    post:
      summary: Queue a short-lived email verification code
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties: {}
              required: []
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
      security: []
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
  "/esign/{token}/verify-code":
    post:
      summary: Exchange an email code for a 30-minute private signing session
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                code:
                  type: string
                  pattern: ^[0-9]{6}$
              required:
                - code
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
      security: []
      parameters:
        - in: path
          name: token
          required: true
          schema:
            type: string
  /v2/deployment:
    get:
      summary: Read the configured region; physical infrastructure requires operator
        verification
      x-required-scope: usage:read
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  /v2/bulk/prepare-row:
    post:
      summary: Prepare one stable row manifest before submitting a customer-authorized
        bulk batch
      x-required-scope: envelopes:write
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                template_id:
                  type: string
                version:
                  type: integer
                row_index:
                  type: integer
                  minimum: 0
                  maximum: 999
                row:
                  $ref: "#/components/schemas/BulkRow"
              required:
                - template_id
                - version
                - row_index
                - row
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - $ref: "#/components/parameters/idempotencyKey"
  /v2/bulk:
    get:
      summary: List durable batches
      x-required-scope: envelopes:write
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: query
          name: after
          required: false
          schema:
            type: string
    post:
      summary: Queue reviewed independent agreements; send_invitations additionally
        requires envelopes:send
      x-required-scope: envelopes:write
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                template_id:
                  type: string
                version:
                  type: integer
                  minimum: 1
                rows:
                  type: array
                  minItems: 1
                  maxItems: 1000
                  items:
                    $ref: "#/components/schemas/BulkRow"
                confirm:
                  const: true
                send_invitations:
                  type: boolean
              required:
                - template_id
                - version
                - rows
                - confirm
                - send_invitations
      responses:
        "202":
          description: Durably queued. Up to three active jobs per workspace; payloads and
            downloads expire after 24 hours.
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid rows or selection
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Idempotency conflict, active-job limit or unavailable template
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - $ref: "#/components/parameters/idempotencyKey"
  "/v2/bulk/{id}":
    get:
      summary: Read progress and up to 100 row results; continue using next_cursor as
        after
      x-required-scope: envelopes:write
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
        - in: query
          name: after
          required: false
          schema:
            type: integer
    delete:
      summary: Cancel pending rows; completed agreements remain
      x-required-scope: envelopes:write
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
  /v2/exports/jobs:
    get:
      summary: List durable batches
      x-required-scope: exports:read
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: query
          name: after
          required: false
          schema:
            type: string
    post:
      summary: Freeze up to 10,000 completed agreements for background export
      x-required-scope: exports:read
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                all:
                  type: boolean
                ids:
                  type: array
                  minItems: 1
                  maxItems: 10000
                  uniqueItems: true
                  items:
                    type: string
              required: []
      responses:
        "202":
          description: Durably queued. Up to three active jobs per workspace; payloads and
            downloads expire after 24 hours.
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid rows or selection
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Idempotency conflict, active-job limit or unavailable template
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - $ref: "#/components/parameters/idempotencyKey"
  "/v2/exports/jobs/{id}":
    get:
      summary: Read progress and up to 100 row results; continue using next_cursor as
        after
      x-required-scope: exports:read
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
        - in: query
          name: after
          required: false
          schema:
            type: integer
    delete:
      summary: Cancel pending rows; completed agreements remain
      x-required-scope: exports:read
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
  "/v2/exports/jobs/{id}/parts/{item}":
    get:
      summary: Download one completed proof ZIP; validate against the manifest SHA-256
      x-required-scope: exports:read
      responses:
        "200":
          description: One agreement ZIP, at most 64 MiB
          content:
            application/zip:
              schema:
                type: string
                format: binary
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "404":
          description: Unavailable or deleted agreement
          content:
            application/json:
              schema:
                type: object
        "410":
          description: Expired export
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
        - in: path
          name: item
          required: true
          schema:
            type: integer
  /v2/privacy:
    get:
      summary: List workspace privacy requests
      x-required-scope: privacy:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: query
          name: after
          required: false
          schema:
            type: string
    post:
      summary: Register a privacy request with an operator-selected due date
      x-required-scope: privacy:manage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                email:
                  type: string
                  format: email
                kind:
                  enum:
                    - access
                    - erasure
                    - correction
                due_at:
                  type: string
                  format: date
              required:
                - email
                - kind
                - due_at
      responses:
        "201":
          description: Registered
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
  "/v2/privacy/{id}":
    get:
      summary: Read request and action history
      x-required-scope: privacy:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
        - in: query
          name: after
          required: false
          schema:
            type: string
  "/v2/privacy/{id}/inventory":
    get:
      summary: Read related workspace records after authority review
      x-required-scope: privacy:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
        - in: query
          name: after
          required: false
          schema:
            type: string
  "/v2/privacy/{id}/export.json":
    get:
      summary: Export requester data without other recipients or private PDF contents
      x-required-scope: privacy:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
        - in: query
          name: after
          required: false
          schema:
            type: string
  "/v2/privacy/{id}/verify":
    post:
      summary: "Review and perform privacy action: verify"
      x-required-scope: privacy:manage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                note:
                  type: string
                  minLength: 10
                  maxLength: 2000
              required:
                - note
      responses:
        "200":
          description: Action recorded; held agreements and retention periods remain
            enforced
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Review required, protected data remains or request already closed
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
  "/v2/privacy/{id}/restriction":
    post:
      summary: "Review and perform privacy action: restriction"
      x-required-scope: privacy:manage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                enabled:
                  type: boolean
              required:
                - enabled
      responses:
        "200":
          description: Action recorded; held agreements and retention periods remain
            enforced
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Review required, protected data remains or request already closed
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
  "/v2/privacy/{id}/erase-profile":
    post:
      summary: "Review and perform privacy action: erase-profile"
      x-required-scope: privacy:manage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                confirm_email:
                  type: string
                  format: email
              required:
                - confirm_email
      responses:
        "200":
          description: Action recorded; held agreements and retention periods remain
            enforced
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Review required, protected data remains or request already closed
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
  "/v2/privacy/{id}/deletions":
    post:
      summary: "Review and perform privacy action: deletions"
      x-required-scope: privacy:manage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                ids:
                  type: array
                  items:
                    type: string
              required:
                - ids
      responses:
        "202":
          description: Action recorded; held agreements and retention periods remain
            enforced
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Review required, protected data remains or request already closed
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
  "/v2/privacy/{id}/resolve":
    post:
      summary: "Review and perform privacy action: resolve"
      x-required-scope: privacy:manage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                outcome:
                  enum:
                    - fulfilled
                    - partially_fulfilled
                    - denied
                resolution:
                  type: string
                  minLength: 10
                  maxLength: 2000
                confirm_reviewed:
                  const: true
              required:
                - outcome
                - resolution
                - confirm_reviewed
      responses:
        "200":
          description: Action recorded; held agreements and retention periods remain
            enforced
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Review required, protected data remains or request already closed
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
  /v2/scim/ServiceProviderConfig:
    get:
      summary: Discover supported SCIM user provisioning capabilities
      x-required-scope: provisioning:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      security:
        - scimBearer: []
  /v2/scim/Schemas:
    get:
      summary: Discover supported SCIM user provisioning capabilities
      x-required-scope: provisioning:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      security:
        - scimBearer: []
  "/v2/scim/Schemas/{id}":
    get:
      summary: Discover supported SCIM user provisioning capabilities
      x-required-scope: provisioning:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      security:
        - scimBearer: []
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
  /v2/scim/ResourceTypes:
    get:
      summary: Discover supported SCIM user provisioning capabilities
      x-required-scope: provisioning:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      security:
        - scimBearer: []
  /v2/scim/ResourceTypes/User:
    get:
      summary: Discover supported SCIM user provisioning capabilities
      x-required-scope: provisioning:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      security:
        - scimBearer: []
  /v2/scim/Users:
    get:
      summary: List users; supports only userName eq "email" filter
      x-required-scope: provisioning:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      security:
        - scimBearer: []
      parameters:
        - in: query
          name: startIndex
          required: false
          schema:
            type: integer
            minimum: 1
        - in: query
          name: count
          required: false
          schema:
            type: integer
            minimum: 0
            maximum: 100
        - in: query
          name: filter
          required: false
          schema:
            type: string
    post:
      summary: Provision a sender or viewer under enrolled Google company policy
      x-required-scope: provisioning:manage
      responses:
        "201":
          description: Provisioned SCIM user
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Existing employee
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      security:
        - scimBearer: []
      requestBody:
        required: true
        content:
          application/scim+json:
            schema:
              type: object
              properties:
                schemas:
                  type: array
                  items:
                    type: string
                userName:
                  type: string
                  format: email
                displayName:
                  type: string
                active:
                  type: boolean
                externalId:
                  type: string
                name:
                  type: object
                  properties:
                    formatted:
                      type: string
              required:
                - userName
          application/json:
            schema:
              type: object
              properties:
                schemas:
                  type: array
                  items:
                    type: string
                userName:
                  type: string
                  format: email
                displayName:
                  type: string
                active:
                  type: boolean
                externalId:
                  type: string
                name:
                  type: object
                  properties:
                    formatted:
                      type: string
              required:
                - userName
  "/v2/scim/Users/{id}":
    get:
      summary: Read provisioned user
      x-required-scope: provisioning:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      security:
        - scimBearer: []
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
    put:
      summary: Update user; email changes and elevated role changes are refused
      x-required-scope: provisioning:manage
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      security:
        - scimBearer: []
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/scim+json:
            schema:
              type: object
              properties:
                schemas:
                  type: array
                  items:
                    type: string
                userName:
                  type: string
                  format: email
                displayName:
                  type: string
                active:
                  type: boolean
                externalId:
                  type: string
                name:
                  type: object
                  properties:
                    formatted:
                      type: string
              required:
                - userName
          application/json:
            schema:
              type: object
              properties:
                schemas:
                  type: array
                  items:
                    type: string
                userName:
                  type: string
                  format: email
                displayName:
                  type: string
                active:
                  type: boolean
                externalId:
                  type: string
                name:
                  type: object
                  properties:
                    formatted:
                      type: string
              required:
                - userName
    patch:
      summary: Apply add/replace to supported user attributes
      x-required-scope: provisioning:manage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                Operations:
                  type: array
                  minItems: 1
                  maxItems: 20
                  items:
                    type: object
                    properties:
                      op:
                        enum:
                          - add
                          - replace
                      path:
                        type: string
                      value: {}
                    required:
                      - op
                      - value
              required:
                - Operations
      responses:
        "200":
          description: Success
          content:
            application/json:
              schema:
                type: object
        "400":
          description: Invalid request
          content:
            application/json:
              schema:
                type: object
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: Action unavailable in the current state
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      security:
        - scimBearer: []
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
    delete:
      summary: Deactivate employee and revoke workspace sessions
      x-required-scope: provisioning:manage
      responses:
        "204":
          description: Removed
        "401":
          description: Missing, expired or revoked API key
          content:
            application/json:
              schema:
                type: object
        "403":
          description: Insufficient credential scope
          content:
            application/json:
              schema:
                type: object
        "409":
          description: An owner must first remove elevated responsibilities
          content:
            application/json:
              schema:
                type: object
        "429":
          description: Rate or monthly agreement limit; inspect Retry-After for request
            limits
          content:
            application/json:
              schema:
                type: object
      security:
        - scimBearer: []
      parameters:
        - in: path
          name: id
          required: true
          schema:
            type: string
