{
  "openapi": "3.1.0",
  "info": {
    "title": "Xaere Codes and XR Audience Integrator API",
    "version": "1.0.0-preview",
    "description": "Public V1 contract for issuing and resolving XR Codes, managing project-scoped Audience integrations, reading aggregate reports and submitting consented minimised measurements. Internal service routes are excluded; platform-operator routes are explicitly documented and require the xaere_platform_admin role with MFA."
  },
  "servers": [
    { "url": "https://api.xaere.io", "description": "Xaere Core" }
  ],
  "tags": [
    { "name": "Discovery", "description": "Health, verifier discovery and receiver resolution." },
    { "name": "Tenancy", "description": "OIDC user organizations and projects." },
    { "name": "Campaigns", "description": "Project-scoped campaign lifecycle." },
    { "name": "Codes", "description": "Signed XR Code issuance, lifecycle, usage and audio." },
    { "name": "API keys", "description": "One-time creation and revocation of server credentials." },
    { "name": "Support", "description": "Server-mediated Proxi support tickets for verified users." },
    { "name": "Audience", "description": "Consent-gated integrations, aggregate reports and backend ingestion." },
    { "name": "Audit", "description": "Organization-scoped administrative audit history." },
    { "name": "Platform administration", "description": "MFA-protected platform settings. Secret values are write-only and never returned." }
  ],
  "paths": {
    "/health": {
      "get": {
        "operationId": "coreHealth",
        "summary": "Check Core health",
        "description": "Returns healthy only after Xaere Core has completed a live PostgreSQL readiness query.",
        "tags": ["Discovery"],
        "security": [],
        "responses": {
          "200": { "description": "Core and its PostgreSQL storage are ready", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Health" } } } },
          "503": { "$ref": "#/components/responses/Error" }
        }
      }
    },
    "/v1/keys": {
      "get": {
        "operationId": "getCoreVerificationKey",
        "summary": "Get the current Core verifier",
        "tags": ["Discovery"],
        "security": [],
        "responses": { "200": { "description": "Current Core signing public key", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CoreKey" } } } } }
      }
    },
    "/v1/resolve/{broadcast_token}": {
      "get": {
        "operationId": "resolveBroadcastToken",
        "summary": "Resolve an opaque broadcast token",
        "tags": ["Codes"],
        "security": [],
        "parameters": [
          { "$ref": "#/components/parameters/BroadcastToken" },
          {
            "name": "X-Xaere-Resolution-Proof",
            "in": "header",
            "required": false,
            "description": "Set to ed25519-v1 to require the locally verifiable resolution envelope used by SDK 0.3+.",
            "schema": { "type": "string", "const": "ed25519-v1" }
          }
        ],
        "responses": {
          "200": { "description": "Verified receiver resolution", "content": { "application/json": { "schema": { "$ref": "https://docs.xaere.io/schemas/xr-resolution-v1.schema.json" } } } },
          "404": { "$ref": "#/components/responses/Error" },
          "410": { "$ref": "#/components/responses/Error" },
          "429": { "$ref": "#/components/responses/Error" },
          "503": { "$ref": "#/components/responses/Error" }
        }
      }
    },
    "/v1/billing/offers": {
      "get": { "operationId": "listBillingOffers", "summary": "List active offers for enabled payment providers", "tags": ["Billing"], "security": [], "parameters": [{ "name": "country", "in": "query", "required": true, "schema": { "type": "string", "pattern": "^[A-Za-z]{2}$" } }], "responses": { "200": { "description": "Public non-secret billing offers", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/BillingOfferList" } } } }, "400": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/subscriptions": {
      "get": { "operationId": "listBillingSubscriptions", "summary": "List an organization's normalized entitlements", "tags": ["Billing"], "security": [{ "oidc": [] }], "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }], "responses": { "200": { "description": "Subscriptions without provider customer or payment-method data", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/BillingSubscriptionList" } } } }, "403": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/checkouts": {
      "post": { "operationId": "createBillingCheckout", "summary": "Create a hosted Stripe or Flouci checkout", "tags": ["Billing"], "security": [{ "oidc": [] }], "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CreateBillingCheckout" } } } }, "responses": { "201": { "description": "Short-lived provider checkout URL", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/BillingCheckout" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/checkouts/{checkout_id}": {
      "get": { "operationId": "getBillingCheckoutStatus", "summary": "Read verified server checkout state after a provider return", "description": "The browser return is not payment evidence. This tenant-scoped projection reports only state reconciled by signed provider webhooks; abandoned pending checkouts expire after 24 hours.", "tags": ["Billing"], "security": [{ "oidc": [] }], "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "name": "checkout_id", "in": "path", "required": true, "schema": { "type": "string", "pattern": "^bco_[A-Za-z0-9_-]{16,}$" } }], "responses": { "200": { "description": "Bounded checkout state without provider references or payment data", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/BillingCheckoutStatus" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/portal": {
      "post": { "operationId": "createBillingPortal", "summary": "Create a Stripe customer portal session", "tags": ["Billing"], "security": [{ "oidc": [] }], "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }], "responses": { "200": { "description": "Short-lived hosted portal URL", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/BillingPortal" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/webhooks/stripe": {
      "post": { "operationId": "receiveStripeWebhook", "summary": "Receive and idempotently reconcile a signed Stripe event", "tags": ["Billing webhooks"], "security": [], "parameters": [{ "name": "Stripe-Signature", "in": "header", "required": true, "schema": { "type": "string", "minLength": 8 } }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "type": "object", "additionalProperties": true } } } }, "responses": { "202": { "description": "Verified webhook receipt", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/BillingWebhookReceipt" } } } }, "400": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/webhooks/flouci": {
      "post": { "operationId": "receiveFlouciWebhook", "summary": "Verify a Flouci notification server-to-server and reconcile it idempotently", "description": "A previously processed payment id is acknowledged without repeating the provider verification. Missing or pending receipts remain subject to the public verification rate limit and are verified again server-to-server before reconciliation.", "tags": ["Billing webhooks"], "security": [], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/FlouciNotification" } } } }, "responses": { "202": { "description": "Verified receipt or already-processed idempotent duplicate", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/BillingWebhookReceipt" } } } }, "400": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" }, "429": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/admin/catalog": {
      "get": { "operationId": "getBillingAdministration", "summary": "Read the non-secret billing catalogue", "tags": ["Billing administration"], "security": [{ "oidc": [] }], "responses": { "200": { "description": "Platform-admin billing catalogue", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/BillingAdministration" } } } }, "403": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/admin/providers/{provider}": {
      "put": { "operationId": "setBillingProvider", "summary": "Enable or disable a configured provider", "description": "Enabling fails closed until both required Stripe or Flouci credentials are stored. Disabling remains unconditional.", "tags": ["Billing administration"], "security": [{ "oidc": [] }], "parameters": [{ "$ref": "#/components/parameters/BillingProvider" }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SetBillingProvider" } } } }, "responses": { "200": { "description": "Provider state", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/BillingProviderState" } } } }, "403": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/admin/plans/{plan_id}": {
      "put": { "operationId": "upsertBillingPlan", "summary": "Create or update a Codes or Audience plan", "description": "Codes plans accept only monthly_code_quota; Audience plans accept only monthly_event_quota. The unrelated quota must be null. An existing plan cannot change product. Its currency cannot change while a linked offer uses the previous currency.", "tags": ["Billing administration"], "security": [{ "oidc": [] }], "parameters": [{ "name": "plan_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/PlanId" } }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/UpsertBillingPlan" } } } }, "responses": { "200": { "description": "Saved plan", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/AdminBillingPlan" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/admin/offers/{offer_id}": {
      "put": { "operationId": "upsertBillingOffer", "summary": "Create or update a country/provider offer", "description": "The referenced plan must exist and the offer currency must exactly match the plan currency. Flouci additionally requires TN/TND, a positive millime amount and an explicit entitlement duration.", "tags": ["Billing administration"], "security": [{ "oidc": [] }], "parameters": [{ "name": "offer_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/OfferId" } }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/UpsertBillingOffer" } } } }, "responses": { "200": { "description": "Saved offer", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/AdminBillingOfferResult" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/admin/audience-contracts/{organization_id}": {
      "put": { "operationId": "setAudienceContract", "summary": "Activate or cancel a contractual Audience entitlement", "description": "Activation requires an active XR Audience plan. Cancellation is idempotent for the existing organization, plan and contract reference, remains possible after plan deactivation, and never creates a cancelled entitlement.", "tags": ["Billing administration"], "security": [{ "oidc": [] }], "parameters": [{ "name": "organization_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/OrganizationId" } }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SetAudienceContract" } } } }, "responses": { "200": { "description": "Contract and synchronized integration count", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/AudienceContractResult" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/billing/admin/dolibarr/customers/{organization_id}": {
      "put": { "operationId": "setDolibarrCustomer", "summary": "Associate an organization with an existing Dolibarr third party", "tags": ["Billing administration"], "security": [{ "oidc": [] }], "parameters": [{ "name": "organization_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/OrganizationId" } }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SetDolibarrCustomer" } } } }, "responses": { "200": { "description": "Saved Dolibarr mapping", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/DolibarrCustomer" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/platform/settings": {
      "get": { "operationId": "getPlatformSettings", "summary": "Read redacted platform settings status", "description": "Requires the xaere_platform_admin role and MFA. Secret values are never returned; only configured state and update time are exposed.", "tags": ["Platform administration"], "security": [{ "oidc": [] }], "responses": { "200": { "description": "Redacted secret status and effective non-secret configuration", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/PlatformSettings" } } } }, "403": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/platform/settings/readiness": {
      "post": { "operationId": "testPlatformIntegrations", "summary": "Test Support and Dolibarr read access", "description": "Requires the xaere_platform_admin role and MFA. Distinguishes missing bounded setting names from a configured read-only API failure; credentials and remote payloads are never returned.", "tags": ["Platform administration"], "security": [{ "oidc": [] }], "responses": { "200": { "description": "Redacted integration readiness", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/PlatformIntegrationReadiness" } } } }, "403": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/platform/release-readiness": {
      "get": { "operationId": "getPlatformReleaseReadiness", "summary": "Read redacted SDK release gates", "description": "Requires the xaere_platform_admin role and MFA. Returns only fresh boolean build, TestFlight, physical-acoustic and signed-stable-channel gates; device details, evidence, credentials and signing material are never exposed.", "tags": ["Platform administration"], "security": [{ "oidc": [] }], "responses": { "200": { "description": "Fresh redacted SDK release readiness", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/PlatformReleaseReadiness" } } } }, "403": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/platform/settings/dolibarr/entity-discovery": {
      "post": { "operationId": "discoverDolibarrEntity", "summary": "Discover the configured Dolibarr API user's entity", "description": "Requires the xaere_platform_admin role and MFA. Core decrypts the stored API key internally, performs one read-only Dolibarr users/info request without forcing an entity header, and returns only the bounded numeric entity and check time. No configuration is changed automatically.", "tags": ["Platform administration"], "security": [{ "oidc": [] }], "responses": { "200": { "description": "Bounded discovered entity candidate", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/DolibarrEntityDiscovery" } } } }, "403": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/platform/settings/secrets": {
      "put": { "operationId": "setPlatformSecretsBatch", "summary": "Atomically create or rotate write-only platform secrets", "description": "Requires the xaere_platform_admin role and MFA. Every name and value is validated before one database transaction begins; any failure rolls back the complete batch. Submitted values are encrypted at rest and are never readable through the API.", "tags": ["Platform administration"], "security": [{ "oidc": [] }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SetPlatformSecretsBatch" } } } }, "responses": { "200": { "description": "Redacted configured states committed together", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/PlatformSettingsBatchResult" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/platform/settings/configuration": {
      "put": { "operationId": "setPlatformConfigurationBatch", "summary": "Atomically set or clear validated platform configuration values", "description": "Requires the xaere_platform_admin role and MFA. Every value is validated before one database transaction begins; any failure rolls back the complete batch. Enabling Dolibarr invoice sync fails closed against the resulting configuration and a live bounded read-only Dolibarr API verification.", "tags": ["Platform administration"], "security": [{ "oidc": [] }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SetPlatformConfigurationBatch" } } } }, "responses": { "200": { "description": "Normalized configuration states committed together", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/PlatformSettingsBatchResult" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/platform/settings/secrets/{name}": {
      "put": { "operationId": "setPlatformSecret", "summary": "Create or rotate a write-only platform secret", "description": "Requires the xaere_platform_admin role and MFA. The submitted value is encrypted at rest and is never readable through the API.", "tags": ["Platform administration"], "security": [{ "oidc": [] }], "parameters": [{ "$ref": "#/components/parameters/PlatformSecretName" }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SetPlatformSecret" } } } }, "responses": { "200": { "description": "Redacted configured state", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/PlatformSettingResult" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/platform/settings/configuration/{name}": {
      "put": { "operationId": "setPlatformConfiguration", "summary": "Set or clear a validated non-secret platform configuration value", "description": "Requires the xaere_platform_admin role and MFA. Send null or an empty string to clear an override. Enabling Dolibarr invoice sync fails closed until its API key, HTTPS URL, entity and TVA rate are configured and a live bounded read-only Dolibarr API verification passes.", "tags": ["Platform administration"], "security": [{ "oidc": [] }], "parameters": [{ "$ref": "#/components/parameters/PlatformConfigurationName" }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SetPlatformConfiguration" } } } }, "responses": { "200": { "description": "Stored normalized configuration state", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/PlatformSettingResult" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/support/webhooks/proxi": {
      "post": { "operationId": "receiveProxiSupportWebhook", "summary": "Receive an idempotent signed Proxi support event", "description": "The HMAC-SHA256 signature is verified over the exact raw request body before the event is recorded.", "tags": ["Support"], "security": [], "parameters": [{ "name": "X-Proxi-Delivery", "in": "header", "required": true, "schema": { "type": "string", "minLength": 1, "maxLength": 512 } }, { "name": "X-Proxi-Event", "in": "header", "required": true, "schema": { "type": "string", "minLength": 1, "maxLength": 160 } }, { "name": "X-Proxi-Signature", "in": "header", "required": true, "description": "sha256=<lowercase hexadecimal HMAC>", "schema": { "type": "string", "pattern": "^sha256=[a-f0-9]{64}$" } }], "requestBody": { "required": true, "content": { "application/json": { "schema": { "type": "object", "additionalProperties": true } } } }, "responses": { "202": { "description": "Verified support webhook receipt", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SupportWebhookReceipt" } } } }, "400": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/organizations": {
      "get": {
        "operationId": "listOrganizations",
        "summary": "List the caller's organizations",
        "tags": ["Tenancy"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/PageLimit" }, { "$ref": "#/components/parameters/PageCursor" }],
        "responses": { "200": { "description": "Organizations visible to the authenticated user", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/OrganizationList" } } } }, "401": { "$ref": "#/components/responses/Error" } }
      },
      "post": {
        "operationId": "createOrganization",
        "summary": "Create an organization",
        "tags": ["Tenancy"],
        "security": [{ "oidc": [] }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CreateOrganization" } } } },
        "responses": { "201": { "description": "Organization created", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Organization" } } } }, "400": { "$ref": "#/components/responses/Error" }, "401": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/organizations/{organization_id}": {
      "patch": {
        "operationId": "updateOrganization",
        "summary": "Rename an organization without changing its tenant identity",
        "tags": ["Tenancy"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "name": "organization_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/OrganizationId" } }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/UpdateName" } } } },
        "responses": { "200": { "description": "Organization renamed", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Organization" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" } }
      },
      "delete": {
        "operationId": "closeOrganization",
        "summary": "Permanently close an organization and purge its Core and Audience tenant data",
        "description": "Persists a durable closure intent before the private purge. New distributed Audience mutations are refused, and 409 deletion_operations_pending asks the owner to retry while an already-started audited operation or project deletion finishes. A private-service outage leaves the intent recoverable for an idempotent retry.",
        "tags": ["Tenancy"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "name": "organization_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/OrganizationId" } }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CloseOrganization" } } } },
        "responses": {
          "200": { "description": "Organization closed and tenant data purged", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/ClosedOrganization" } } } },
          "400": { "$ref": "#/components/responses/Error" },
          "403": { "$ref": "#/components/responses/Error" },
          "409": { "$ref": "#/components/responses/Error" },
          "503": { "$ref": "#/components/responses/Error" }
        }
      }
    },
    "/v1/organizations/{organization_id}/export": {
      "get": {
        "operationId": "exportOrganization",
        "summary": "Download a bounded organization archive without credentials or raw Audience events",
        "tags": ["Tenancy"], "security": [{ "oidc": [] }],
        "parameters": [{ "name": "organization_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/OrganizationId" } }],
        "responses": { "200": { "description": "Portable owner-only organization archive", "headers": { "Content-Disposition": { "schema": { "type": "string" } }, "Cache-Control": { "schema": { "const": "no-store" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/OrganizationArchive" } } } }, "403": { "$ref": "#/components/responses/Error" }, "422": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/projects": {
      "get": {
        "operationId": "listProjects",
        "summary": "List organization projects",
        "tags": ["Tenancy"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/PageLimit" }, { "$ref": "#/components/parameters/PageCursor" }],
        "responses": { "200": { "description": "Organization projects", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/ProjectList" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      },
      "post": {
        "operationId": "createProject",
        "summary": "Create a project",
        "tags": ["Tenancy"],
        "security": [{ "oidc": [] }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CreateProject" } } } },
        "responses": { "201": { "description": "Project created", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Project" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/projects/{project_id}": {
      "patch": {
        "operationId": "updateProject",
        "summary": "Rename a project without changing its Codes or Audience identity",
        "tags": ["Tenancy"], "security": [{ "oidc": [] }],
        "parameters": [{ "name": "project_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/ProjectId" } }, { "$ref": "#/components/parameters/OrganizationId" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/UpdateName" } } } },
        "responses": { "200": { "description": "Project renamed", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Project" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" } }
      },
      "delete": {
        "operationId": "deleteProject",
        "summary": "Permanently delete one project and purge its Core and Audience data",
        "description": "Persists a project-scoped deletion intent before the private purge. New Audience mutations are refused and an already-requested audited operation returns 409 until it reaches a terminal state; retries safely resume the purge.",
        "tags": ["Tenancy"], "security": [{ "oidc": [] }],
        "parameters": [{ "name": "project_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/ProjectId" } }, { "$ref": "#/components/parameters/OrganizationId" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/DeleteProject" } } } },
        "responses": { "200": { "description": "Project deleted and its Audience data purged", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/DeletedProject" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/projects/{project_id}/export": {
      "get": {
        "operationId": "exportProject",
        "summary": "Download a portable project archive without credentials or raw Audience events",
        "tags": ["Tenancy"], "security": [{ "oidc": [] }],
        "parameters": [{ "name": "project_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/ProjectId" } }, { "$ref": "#/components/parameters/OrganizationId" }],
        "responses": { "200": { "description": "Portable, bounded and non-secret project archive", "headers": { "Content-Disposition": { "schema": { "type": "string" } }, "Cache-Control": { "schema": { "const": "no-store" } } }, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/ProjectArchive" } } } }, "403": { "$ref": "#/components/responses/Error" }, "422": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/members": {
      "get": {
        "operationId": "listMembers",
        "summary": "List organization members",
        "tags": ["Tenancy"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/PageLimit" }, { "$ref": "#/components/parameters/PageCursor" }],
        "responses": { "200": { "description": "Bounded organization member page", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/MemberList" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/members/{subject_id}": {
      "put": {
        "operationId": "setMember",
        "summary": "Add a member or change its role with MFA and last-owner protection",
        "tags": ["Tenancy"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/SubjectId" }, { "$ref": "#/components/parameters/OrganizationId" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SetMember" } } } },
        "responses": { "200": { "description": "Member saved", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Member" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" } }
      },
      "delete": {
        "operationId": "removeMember",
        "summary": "Remove a member with MFA and last-owner protection",
        "tags": ["Tenancy"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/SubjectId" }, { "$ref": "#/components/parameters/OrganizationId" }],
        "responses": { "200": { "description": "Member removed", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/RemovedMember" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/member-invitations": {
      "get": {
        "operationId": "listMemberInvitations", "summary": "List organization invitations without e-mail or token data", "tags": ["Tenancy"], "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/PageLimit" }, { "$ref": "#/components/parameters/PageCursor" }],
        "responses": { "200": { "description": "Bounded invitation page", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/InvitationList" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      },
      "post": {
        "operationId": "createMemberInvitation", "summary": "Create a one-time organization invitation", "tags": ["Tenancy"], "security": [{ "oidc": [] }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CreateInvitation" } } } },
        "responses": { "201": { "description": "Invitation created; secret is returned once", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CreatedInvitation" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/member-invitations/accept": {
      "post": {
        "operationId": "acceptMemberInvitation", "summary": "Consume a one-time invitation for the verified account e-mail", "tags": ["Tenancy"], "security": [{ "oidc": [] }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/AcceptInvitation" } } } },
        "responses": { "200": { "description": "Invitation accepted", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/AcceptedInvitation" } } } }, "404": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/member-invitations/{invitation_id}/revoke": {
      "post": {
        "operationId": "revokeMemberInvitation", "summary": "Revoke an unused organization invitation", "tags": ["Tenancy"], "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/InvitationId" }, { "$ref": "#/components/parameters/OrganizationId" }],
        "responses": { "200": { "description": "Invitation revoked", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Invitation" } } } }, "409": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/campaigns": {
      "get": {
        "operationId": "listCampaigns",
        "summary": "List project campaigns",
        "tags": ["Campaigns"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/ProjectId" }, { "$ref": "#/components/parameters/PageLimit" }, { "$ref": "#/components/parameters/PageCursor" }],
        "responses": { "200": { "description": "Project campaigns", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CampaignList" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      },
      "post": {
        "operationId": "createCampaign",
        "summary": "Create a campaign",
        "tags": ["Campaigns"],
        "security": [{ "oidc": [] }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CreateCampaign" } } } },
        "responses": { "201": { "description": "Campaign created", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Campaign" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/campaigns/{campaign_id}": {
      "patch": {
        "operationId": "updateCampaign",
        "summary": "Update an active campaign",
        "description": "Changes the name or issuance schedule without modifying existing signed Codes. Archived campaigns cannot be edited.",
        "tags": ["Campaigns"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/CampaignId" }, { "$ref": "#/components/parameters/OrganizationId" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/UpdateCampaign" } } } },
        "responses": { "200": { "description": "Campaign updated", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Campaign" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/campaigns/{campaign_id}/archive": {
      "post": {
        "operationId": "archiveCampaign",
        "summary": "Archive a campaign",
        "tags": ["Campaigns"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/CampaignId" }, { "$ref": "#/components/parameters/OrganizationId" }],
        "responses": { "200": { "description": "Campaign archived", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Campaign" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/campaigns/{campaign_id}/summary": {
      "get": {
        "operationId": "getCampaignSummary",
        "summary": "Get a campaign Codes summary",
        "description": "Returns tenant-scoped lifecycle counts. Expired active rows are classified as expired at read time.",
        "tags": ["Campaigns"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/CampaignId" }, { "$ref": "#/components/parameters/OrganizationId" }],
        "responses": { "200": { "description": "Campaign and current Code lifecycle counts", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CampaignSummary" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/campaigns/{campaign_id}/stop": {
      "post": {
        "operationId": "stopCampaign",
        "summary": "Archive a campaign and revoke its live Codes",
        "description": "Atomically prevents new issuance and revokes every unexpired Code still active in the campaign. Repeating the request is safe and returns zero newly revoked Codes.",
        "tags": ["Campaigns"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/CampaignId" }, { "$ref": "#/components/parameters/OrganizationId" }],
        "responses": { "200": { "description": "Campaign stopped", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/StopCampaignResult" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/codes": {
      "get": {
        "operationId": "listCodes",
        "summary": "List project XR Codes",
        "tags": ["Codes"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/OptionalProjectId" }, { "$ref": "#/components/parameters/PageLimit" }, { "$ref": "#/components/parameters/PageCursor" }],
        "responses": { "200": { "description": "Project Codes", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CodeList" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      },
      "post": {
        "operationId": "issueCode",
        "summary": "Issue one signed XR Code",
        "tags": ["Codes"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/IdempotencyKey" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/IssueCode" } } } },
        "responses": { "201": { "description": "Individually signed XR Code", "content": { "application/json": { "schema": { "$ref": "https://docs.xaere.io/schemas/xr-code-issued-v1.schema.json" } } } }, "403": { "$ref": "#/components/responses/Error" }, "429": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/codes/{xr_id}": {
      "get": {
        "operationId": "getCode",
        "summary": "Get one signed XR Code",
        "description": "Returns the immutable signed payload, opaque acoustic frame and current lifecycle status within the authorized tenant project. Active, expired and revoked Codes remain readable for operational recovery. No API key, Audience HMAC credential, raw event or measurement token is returned.",
        "tags": ["Codes"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/XrId" }, { "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/OptionalProjectId" }],
        "responses": {
          "200": { "description": "Tenant-scoped signed XR Code detail", "content": { "application/json": { "schema": { "$ref": "https://docs.xaere.io/schemas/xr-code-detail-v1.schema.json" } } } },
          "403": { "$ref": "#/components/responses/Error" },
          "404": { "$ref": "#/components/responses/Error" }
        }
      }
    },
    "/v1/codes/batch": {
      "post": {
        "operationId": "issueCodeBatch",
        "summary": "Issue a bounded XR Code batch",
        "tags": ["Codes"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/IdempotencyKey" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/IssueCodeBatch" } } } },
        "responses": { "201": { "description": "One to 100 signed XR Codes", "content": { "application/json": { "schema": { "type": "object", "required": ["data"], "properties": { "data": { "type": "array", "minItems": 1, "maxItems": 100, "items": { "$ref": "https://docs.xaere.io/schemas/xr-code-issued-v1.schema.json" } } }, "additionalProperties": false } } } }, "429": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/codes/recover": {
      "post": {
        "operationId": "recoverCode",
        "summary": "Recover an existing XR Code receipt without issuing a Code",
        "description": "Returns the exact stored response for the same single-Code request and Idempotency-Key while its 24-hour receipt is retained. This operation never creates a Code.",
        "tags": ["Codes"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/IdempotencyKey" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/IssueCode" } } } },
        "responses": { "200": { "description": "Original signed XR Code receipt", "content": { "application/json": { "schema": { "$ref": "https://docs.xaere.io/schemas/xr-code-issued-v1.schema.json" } } } }, "404": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/codes/batch/recover": {
      "post": {
        "operationId": "recoverCodeBatch",
        "summary": "Recover an existing XR Code batch receipt without issuing Codes",
        "description": "Returns the exact stored response for the same batch request and Idempotency-Key while its 24-hour receipt is retained. This operation never creates Codes.",
        "tags": ["Codes"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/IdempotencyKey" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/IssueCodeBatch" } } } },
        "responses": { "200": { "description": "Original signed XR Code batch receipt", "content": { "application/json": { "schema": { "type": "object", "required": ["data"], "properties": { "data": { "type": "array", "minItems": 1, "maxItems": 100, "items": { "$ref": "https://docs.xaere.io/schemas/xr-code-issued-v1.schema.json" } } }, "additionalProperties": false } } } }, "404": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/codes/revoke-batch": {
      "post": {
        "operationId": "revokeCodeBatch",
        "summary": "Atomically revoke a bounded XR Code batch",
        "description": "Locks one to 100 explicitly selected Codes in the same tenant project, fails closed if any identifier is outside that boundary, and revokes only active unexpired Codes. The action is idempotent and audited once.",
        "tags": ["Codes"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/RevokeCodeBatch" } } } },
        "responses": { "200": { "description": "Bounded batch revocation result", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/RevokeCodeBatchResult" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/codes/audio-bundle": {
      "post": {
        "operationId": "downloadCodeAudioBundle",
        "summary": "Download a bounded batch of ultrasonic WAV files",
        "description": "Atomically validates one to 100 explicitly selected active Codes in one tenant project, then returns a stored ZIP capped at 64 MiB. The archive contains WAV files only.",
        "tags": ["Codes"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/ProjectId" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/AudioBundleSelection" } } } },
        "responses": { "200": { "description": "Stored ZIP containing only the selected WAV files", "headers": { "Content-Disposition": { "schema": { "type": "string" } }, "Cache-Control": { "schema": { "const": "no-store" } } }, "content": { "application/zip": { "schema": { "type": "string", "contentEncoding": "binary" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" }, "413": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/codes/{xr_id}/revoke": {
      "post": {
        "operationId": "revokeCode",
        "summary": "Revoke an XR Code",
        "tags": ["Codes"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/XrId" }, { "$ref": "#/components/parameters/OrganizationId" }],
        "responses": { "200": { "description": "Code revoked", "content": { "application/json": { "schema": { "type": "object" } } } }, "404": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/codes/{xr_id}/audio": {
      "get": {
        "operationId": "downloadCodeAudio",
        "summary": "Download ultrasonic WAV audio",
        "tags": ["Codes"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/XrId" }, { "$ref": "#/components/parameters/OrganizationId" }],
        "responses": { "200": { "description": "Bounded ggwave RIFF/WAVE audio", "headers": { "Content-Disposition": { "schema": { "type": "string" } } }, "content": { "audio/wav": { "schema": { "type": "string", "contentEncoding": "binary" } } } }, "404": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/api-keys": {
      "get": {
        "operationId": "listApiKeys",
        "summary": "List API key metadata",
        "tags": ["API keys"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/OptionalProjectId" }, { "$ref": "#/components/parameters/PageLimit" }, { "$ref": "#/components/parameters/PageCursor" }],
        "responses": { "200": { "description": "Bounded metadata page only; secrets are never returned", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/ApiKeyList" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" } }
      },
      "post": {
        "operationId": "createApiKey",
        "summary": "Create a server API key",
        "tags": ["API keys"],
        "security": [{ "oidc": [] }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CreateApiKey" } } } },
        "responses": { "201": { "description": "API key with one-time secret", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CreatedApiKey" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/api-keys/{api_key_id}/revoke": {
      "post": {
        "operationId": "revokeApiKey",
        "summary": "Revoke a server API key",
        "tags": ["API keys"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/ApiKeyId" }, { "$ref": "#/components/parameters/OrganizationId" }],
        "responses": { "200": { "description": "API key revoked", "content": { "application/json": { "schema": { "type": "object" } } } }, "404": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/api-keys/{api_key_id}/secret": {
      "post": {
        "operationId": "rotateApiKeySecret",
        "summary": "Rotate a server API-key secret",
        "description": "OIDC organisation administrators only. Atomically invalidates the previous secret while preserving the key ID, project, scopes and expiry. The replacement is returned once.",
        "tags": ["API keys"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/ApiKeyId" }, { "$ref": "#/components/parameters/OrganizationId" }],
        "responses": { "200": { "description": "API key with one-time replacement secret", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/RotatedApiKeySecret" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/usage": {
      "get": {
        "operationId": "getUsage",
        "summary": "Get current Codes and Audience usage",
        "description": "Returns organization-scoped monthly aggregate counters. The aggregate-only Audience projection is grouped only by entitlement mode and never contains event rows, XR IDs, measurement tokens or proofs. Codes usage remains available if the private Audience service is temporarily unavailable.",
        "tags": ["Codes", "Audience"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }],
        "responses": { "200": { "description": "Current server-enforced quota usage", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/UsageSummary" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/audit-log": {
      "get": { "operationId": "listAuditLog", "summary": "List the organization audit history", "description": "Owner and administrator access only. Returns a bounded newest-first keyset page.", "tags": ["Audit"], "security": [{ "oidc": [] }], "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/PageLimit" }, { "$ref": "#/components/parameters/PageCursor" }], "responses": { "200": { "description": "Bounded audit entry page", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/AuditLogPage" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" } } }
    },
    "/v1/support/tickets": {
      "get": {
        "operationId": "listSupportTickets",
        "summary": "List organisation support tickets",
        "description": "Returns a bounded newest-first keyset page. Follow next_cursor explicitly to retrieve older tickets.",
        "tags": ["Support"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/PageLimit" }, { "$ref": "#/components/parameters/PageCursor" }],
        "responses": { "200": { "description": "Bounded ticket page", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SupportTicketPage" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" } }
      },
      "post": {
        "operationId": "createSupportTicket",
        "summary": "Create an idempotent support ticket",
        "tags": ["Support"],
        "security": [{ "oidc": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CreateSupportTicket" } } } },
        "responses": { "201": { "description": "Ticket created or its idempotent result", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SupportTicket" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/support/tickets/{ticket_id}": {
      "get": {
        "operationId": "getSupportTicket",
        "summary": "Read one organisation support conversation",
        "description": "Returns the tenant-scoped local ticket and a customer-visible Proxi conversation projection. Internal notes and attachment URLs are never exposed.",
        "tags": ["Support"],
        "security": [{ "oidc": [] }],
        "parameters": [
          { "$ref": "#/components/parameters/OrganizationId" },
          { "name": "ticket_id", "in": "path", "required": true, "schema": { "type": "string", "pattern": "^sup_[A-Za-z0-9_-]{16,}$" } }
        ],
        "responses": { "200": { "description": "Customer-visible support conversation", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/SupportTicketDetail" } } } }, "400": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" }, "503": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/audience/integrations": {
      "get": {
        "operationId": "listAudienceIntegrations",
        "summary": "List Audience integrations",
        "tags": ["Audience"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/ProjectId" }, { "$ref": "#/components/parameters/PageLimit" }, { "$ref": "#/components/parameters/PageCursor" }],
        "responses": { "200": { "description": "Project integrations without HMAC secrets", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/IntegrationList" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      },
      "post": {
        "operationId": "createAudienceIntegration",
        "summary": "Create an Audience integration",
        "tags": ["Audience"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CreateIntegration" } } } },
        "responses": { "201": { "description": "Integration and one-time backend HMAC secret", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/CreatedIntegration" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/audience/integrations/{integration_id}/revoke": {
      "post": {
        "operationId": "revokeAudienceIntegration",
        "summary": "Revoke an Audience integration",
        "tags": ["Audience"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/IntegrationId" }, { "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/ProjectId" }],
        "responses": { "200": { "description": "Integration revoked", "content": { "application/json": { "schema": { "type": "object" } } } }, "404": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/audience/integrations/{integration_id}/retention": {
      "patch": {
        "operationId": "updateAudienceIntegrationRetention",
        "summary": "Update Audience retention and purge newly expired data",
        "description": "Revalidates the current demo or paid entitlement. Reducing retention transactionally deletes events and integrity-day aggregates outside the new window.",
        "tags": ["Audience"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/IntegrationId" }, { "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/ProjectId" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/UpdateIntegrationRetention" } } } },
        "responses": { "200": { "description": "Retention updated and old live data purged", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/UpdatedIntegrationRetention" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/audience/integrations/{integration_id}/secret": {
      "post": {
        "operationId": "rotateAudienceIntegrationSecret",
        "summary": "Rotate an Audience backend HMAC secret",
        "description": "Atomically replaces the active integration secret. The previous secret is rejected immediately and the replacement is returned only in this response.",
        "tags": ["Audience"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/IntegrationId" }, { "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/ProjectId" }],
        "responses": { "200": { "description": "One-time replacement HMAC secret", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/RotatedIntegrationSecret" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/audience/integrations/{integration_id}/core-key": {
      "post": {
        "operationId": "rotateAudienceCoreKey",
        "summary": "Rotate an integration's Core verifier",
        "description": "Server API keys only. Copies the current Core verifier over the private service channel and records a monotonic tenant/project audit containing key identifiers only; no PEM or HMAC secret enters audit data or the response.",
        "tags": ["Audience"],
        "security": [{ "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/IntegrationId" }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/TenantContext" } } } },
        "responses": { "200": { "description": "Verifier rotated", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/UpdatedAudienceCoreKey" } } } }, "403": { "$ref": "#/components/responses/Error" }, "404": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/audience/reports/{integration_id}": {
      "get": {
        "operationId": "getAudienceReport",
        "summary": "Get verified Audience aggregates",
        "description": "Scope validation, totals and all dimensions are produced from one repeatable read-only PostgreSQL snapshot. Revoked integrations remain reportable within their retained period under the same exact organization/project scope; revocation still blocks all new ingestion. Optional campaign_id and xr_id filters narrow event and reach aggregates after Core validates each resource against the requested organization, project and—when filtering by Code—Audience integration. Integrity signals remain integration-wide for the selected period because duplicate signals contain neither filter identifier. Every dimension is capped at 10,000 entries; request a narrower period when the service returns report_too_large.",
        "tags": ["Audience"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/IntegrationId" }, { "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/ProjectId" }, { "$ref": "#/components/parameters/CampaignIdQuery" }, { "$ref": "#/components/parameters/XrIdQuery" }, { "$ref": "#/components/parameters/From" }, { "$ref": "#/components/parameters/To" }],
        "responses": { "200": { "description": "Privacy-preserving XR v1 aggregates", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/AudienceReport" } } } }, "403": { "$ref": "#/components/responses/Error" }, "422": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/audience/legacy-report": {
      "get": {
        "operationId": "getLegacyAudienceReport",
        "summary": "Get separate legacy aggregates",
        "tags": ["Audience"],
        "security": [{ "oidc": [] }, { "serverApiKey": [] }],
        "parameters": [{ "$ref": "#/components/parameters/OrganizationId" }, { "$ref": "#/components/parameters/ProjectId" }, { "$ref": "#/components/parameters/From" }, { "$ref": "#/components/parameters/To" }],
        "responses": { "200": { "description": "Unverified legacy aggregates, never XR v1 reach", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/LegacyAudienceReport" } } } }, "403": { "$ref": "#/components/responses/Error" } }
      }
    },
    "/v1/events": {
      "post": {
        "operationId": "ingestAudienceEvent",
        "summary": "Submit a consented Audience event",
        "description": "Called only by the trusted publisher backend after host consent. Never embed the integration HMAC in Flutter.",
        "tags": ["Audience"],
        "servers": [{ "url": "https://ingest.audience.xaere.io", "description": "XR Audience ingestion" }],
        "security": [{ "audienceHmac": [] }],
        "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "https://docs.xaere.io/schemas/audience-event-v1.schema.json" } } } },
        "responses": { "202": { "description": "Accepted or idempotent duplicate", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/IngestResult" } } } }, "400": { "$ref": "#/components/responses/Error" }, "401": { "$ref": "#/components/responses/Error" }, "403": { "$ref": "#/components/responses/Error" }, "409": { "$ref": "#/components/responses/Error" }, "429": { "$ref": "#/components/responses/Error" } }
      }
    }
  },
  "components": {
    "securitySchemes": {
      "oidc": { "type": "openIdConnect", "openIdConnectUrl": "https://console.xaere.io/auth/realms/xaere/.well-known/openid-configuration" },
      "serverApiKey": { "type": "http", "scheme": "bearer", "bearerFormat": "xak_ server API key", "description": "Project-scoped server credential. Never embed in Flutter or browser code." },
      "audienceHmac": { "type": "apiKey", "in": "header", "name": "X-Xaere-Event-Signature", "description": "Base64url HMAC-SHA256 of the exact request body, added by the publisher backend." }
    },
    "parameters": {
      "OrganizationId": { "name": "organization_id", "in": "query", "required": true, "schema": { "$ref": "#/components/schemas/OrganizationId" } },
      "ProjectId": { "name": "project_id", "in": "query", "required": true, "schema": { "$ref": "#/components/schemas/ProjectId" } },
      "OptionalProjectId": { "name": "project_id", "in": "query", "required": false, "schema": { "$ref": "#/components/schemas/ProjectId" }, "description": "Optional exact project boundary for scoped operational history or Code recovery." },
      "PageLimit": { "name": "limit", "in": "query", "required": false, "schema": { "type": "integer", "minimum": 1, "maximum": 100, "default": 50 } },
      "PageCursor": { "name": "cursor", "in": "query", "required": false, "schema": { "type": "string", "minLength": 8, "maxLength": 512, "pattern": "^[A-Za-z0-9_-]+$" }, "description": "Opaque keyset cursor returned by the previous page. Clients must not construct or persist it as an identifier." },
      "IdempotencyKey": { "name": "Idempotency-Key", "in": "header", "required": false, "schema": { "type": "string", "minLength": 16, "maxLength": 128, "pattern": "^[A-Za-z0-9._:-]+$" }, "description": "Recommended for Code issuance. A matching retry within 24 hours returns the exact original response without consuming quota again; reuse with a different request returns 409." },
      "BroadcastToken": { "name": "broadcast_token", "in": "path", "required": true, "schema": { "type": "string", "pattern": "^brd_[A-Za-z0-9_-]{16,}$" } },
      "XrId": { "name": "xr_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/XrId" } },
      "CampaignId": { "name": "campaign_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/CampaignId" } },
      "CampaignIdQuery": { "name": "campaign_id", "in": "query", "required": false, "schema": { "$ref": "#/components/schemas/CampaignId" }, "description": "Optional tenant- and project-validated campaign filter for event and reach aggregates. Integrity signals remain integration-wide for the selected period." },
      "XrIdQuery": { "name": "xr_id", "in": "query", "required": false, "schema": { "$ref": "#/components/schemas/XrId" }, "description": "Optional tenant-, project- and Audience-integration-validated XR Code filter for event and reach aggregates. Integrity signals remain integration-wide for the selected period." },
      "ApiKeyId": { "name": "api_key_id", "in": "path", "required": true, "schema": { "type": "string", "pattern": "^ak_[A-Za-z0-9_-]{16,}$" } },
      "IntegrationId": { "name": "integration_id", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/IntegrationId" } },
      "SubjectId": { "name": "subject_id", "in": "path", "required": true, "schema": { "type": "string", "minLength": 1, "maxLength": 255 } },
      "InvitationId": { "name": "invitation_id", "in": "path", "required": true, "schema": { "type": "string", "pattern": "^inv_[A-Za-z0-9_-]{16,}$" } },
      "From": { "name": "from", "in": "query", "required": false, "schema": { "type": "string", "format": "date-time" }, "description": "Inclusive UTC boundary" },
      "To": { "name": "to", "in": "query", "required": false, "schema": { "type": "string", "format": "date-time" }, "description": "Exclusive UTC boundary" },
      "BillingProvider": { "name": "provider", "in": "path", "required": true, "schema": { "$ref": "#/components/schemas/BillingProvider" } },
      "PlatformSecretName": { "name": "name", "in": "path", "required": true, "schema": { "type": "string", "enum": ["stripe_secret_key", "stripe_webhook_secret", "flouci_public_key", "flouci_private_key", "proxi_support_api_key", "proxi_support_webhook_secret", "dolibarr_api_key", "smtp_username", "smtp_password"] } },
      "PlatformConfigurationName": { "name": "name", "in": "path", "required": true, "schema": { "type": "string", "enum": ["proxi_support_base_url", "proxi_support_mailbox_id", "dolibarr_base_url", "dolibarr_entity_id", "dolibarr_tva_rate", "dolibarr_enable_invoice_sync", "smtp_host", "smtp_port", "smtp_secure", "smtp_from_email", "smtp_from_name"] } }
    },
    "responses": {
      "Error": { "description": "Error response", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Error" } } } }
    },
    "schemas": {
      "Health": { "type": "object", "required": ["status"], "properties": { "status": { "const": "ok" } }, "additionalProperties": false },
      "Error": { "type": "object", "required": ["error"], "properties": { "error": { "type": "object", "required": ["code", "message"], "properties": { "code": { "type": "string" }, "message": { "type": "string" } }, "additionalProperties": false } }, "additionalProperties": false },
      "OrganizationId": { "type": "string", "pattern": "^org_[A-Za-z0-9_-]{16,}$" },
      "ProjectId": { "type": "string", "pattern": "^prj_[A-Za-z0-9_-]{16,}$" },
      "CampaignId": { "type": "string", "pattern": "^cmp_[A-Za-z0-9_-]{16,}$" },
      "XrId": { "type": "string", "pattern": "^xr_[A-Za-z0-9_-]{16,}$" },
      "IntegrationId": { "type": "string", "pattern": "^int_[A-Za-z0-9_-]{16,}$" },
      "PlanId": { "type": "string", "pattern": "^plan_[A-Za-z0-9_-]{16,}$" },
      "OfferId": { "type": "string", "pattern": "^offer_[A-Za-z0-9_-]{16,}$" },
      "BillingProvider": { "type": "string", "enum": ["stripe", "flouci"] },
      "BillingOffer": { "type": "object", "required": ["offer_id", "provider", "country_code", "currency", "amount_minor", "entitlement_months", "plan_id", "product", "name", "monthly_code_quota", "monthly_event_quota"], "properties": { "offer_id": { "$ref": "#/components/schemas/OfferId" }, "provider": { "$ref": "#/components/schemas/BillingProvider" }, "country_code": { "type": "string", "pattern": "^[A-Z]{2}$" }, "currency": { "type": "string", "pattern": "^[A-Z]{3}$" }, "amount_minor": { "type": ["integer", "null"], "minimum": 0 }, "entitlement_months": { "type": ["integer", "null"], "minimum": 1, "maximum": 36 }, "plan_id": { "$ref": "#/components/schemas/PlanId" }, "product": { "enum": ["codes", "audience"] }, "name": { "type": "string" }, "monthly_code_quota": { "type": ["integer", "null"], "minimum": 0 }, "monthly_event_quota": { "type": ["integer", "null"], "minimum": 0 } }, "additionalProperties": false },
      "BillingOfferList": { "type": "object", "required": ["data"], "properties": { "data": { "type": "array", "items": { "$ref": "#/components/schemas/BillingOffer" } } }, "additionalProperties": false },
      "BillingPlanSummary": { "type": "object", "required": ["plan_id", "product", "name", "currency", "monthly_code_quota", "monthly_event_quota"], "properties": { "plan_id": { "$ref": "#/components/schemas/PlanId" }, "product": { "enum": ["codes", "audience"] }, "name": { "type": "string" }, "currency": { "type": "string", "pattern": "^[A-Z]{3}$" }, "monthly_code_quota": { "type": ["integer", "null"], "minimum": 0 }, "monthly_event_quota": { "type": ["integer", "null"], "minimum": 0 } }, "additionalProperties": false },
      "BillingSubscription": { "type": "object", "required": ["subscription_id", "provider", "status", "current_period_ends_at", "updated_at", "accounting", "plan"], "properties": { "subscription_id": { "type": "string", "pattern": "^sub_[A-Za-z0-9_-]{8,}$" }, "provider": { "type": "string", "enum": ["stripe", "flouci", "manual"] }, "status": { "enum": ["trialing", "active", "past_due", "cancelled", "expired"] }, "current_period_ends_at": { "type": ["string", "null"], "format": "date-time" }, "updated_at": { "type": "string", "format": "date-time" }, "accounting": { "$ref": "#/components/schemas/BillingAccountingStatus" }, "plan": { "$ref": "#/components/schemas/BillingPlanSummary" } }, "additionalProperties": false },
      "BillingAccountingStatus": { "type": "object", "required": ["status", "invoice_id", "completed_at"], "properties": { "status": { "type": "string", "enum": ["not_scheduled", "pending", "processing", "completed", "failed"] }, "invoice_id": { "type": ["string", "null"], "maxLength": 64 }, "completed_at": { "type": ["string", "null"], "format": "date-time" } }, "additionalProperties": false },
      "BillingSubscriptionList": { "type": "object", "required": ["data"], "properties": { "data": { "type": "array", "items": { "$ref": "#/components/schemas/BillingSubscription" } } }, "additionalProperties": false },
      "CreateBillingCheckout": { "type": "object", "required": ["offer_id"], "properties": { "offer_id": { "$ref": "#/components/schemas/OfferId" } }, "additionalProperties": false },
      "BillingCheckout": { "type": "object", "required": ["checkout_id", "provider", "checkout_url"], "properties": { "checkout_id": { "type": "string", "pattern": "^bco_[A-Za-z0-9_-]{16,}$" }, "provider": { "$ref": "#/components/schemas/BillingProvider" }, "checkout_url": { "type": "string", "format": "uri", "pattern": "^https://" } }, "additionalProperties": false },
      "BillingCheckoutStatus": { "type": "object", "required": ["checkout_id", "provider", "status", "created_at", "completed_at", "plan"], "properties": { "checkout_id": { "type": "string", "pattern": "^bco_[A-Za-z0-9_-]{16,}$" }, "provider": { "$ref": "#/components/schemas/BillingProvider" }, "status": { "type": "string", "enum": ["pending", "completed", "failed", "expired"] }, "created_at": { "type": "string", "format": "date-time" }, "completed_at": { "type": ["string", "null"], "format": "date-time" }, "plan": { "type": "object", "required": ["plan_id", "product", "name"], "properties": { "plan_id": { "$ref": "#/components/schemas/PlanId" }, "product": { "type": "string", "enum": ["codes", "audience"] }, "name": { "type": "string", "maxLength": 160 } }, "additionalProperties": false } }, "additionalProperties": false },
      "BillingPortal": { "type": "object", "required": ["provider", "portal_url"], "properties": { "provider": { "const": "stripe" }, "portal_url": { "type": "string", "format": "uri", "pattern": "^https://" } }, "additionalProperties": false },
      "BillingWebhookReceipt": { "type": "object", "required": ["accepted", "duplicate", "event_id"], "properties": { "accepted": { "const": true }, "duplicate": { "type": "boolean" }, "event_id": { "type": "string", "minLength": 1, "maxLength": 255 } }, "additionalProperties": false },
      "FlouciNotification": { "oneOf": [{ "type": "object", "required": ["payment_id"], "properties": { "payment_id": { "type": "string", "minLength": 8 } }, "additionalProperties": true }, { "type": "object", "required": ["result"], "properties": { "result": { "type": "object", "required": ["payment_id"], "properties": { "payment_id": { "type": "string", "minLength": 8 } }, "additionalProperties": true } }, "additionalProperties": true }] },
      "SetBillingProvider": { "type": "object", "required": ["enabled"], "properties": { "enabled": { "type": "boolean" } }, "additionalProperties": false },
      "BillingProviderState": { "type": "object", "required": ["provider", "enabled", "updated_at"], "properties": { "provider": { "$ref": "#/components/schemas/BillingProvider" }, "enabled": { "type": "boolean" }, "updated_at": { "type": "string", "format": "date-time" } }, "additionalProperties": false },
      "UpsertBillingPlan": { "type": "object", "required": ["product", "name", "currency", "monthly_code_quota", "monthly_event_quota", "active"], "properties": { "product": { "enum": ["codes", "audience"] }, "name": { "type": "string", "minLength": 1 }, "currency": { "type": "string", "pattern": "^[A-Za-z]{3}$" }, "monthly_code_quota": { "type": ["integer", "null"], "minimum": 0 }, "monthly_event_quota": { "type": ["integer", "null"], "minimum": 0 }, "active": { "type": "boolean" } }, "additionalProperties": false },
      "AdminBillingPlan": { "type": "object", "required": ["id", "product", "name", "currency", "monthly_code_quota", "monthly_event_quota", "active"], "properties": { "id": { "$ref": "#/components/schemas/PlanId" }, "product": { "enum": ["codes", "audience"] }, "name": { "type": "string" }, "currency": { "type": "string" }, "monthly_code_quota": { "type": ["integer", "null"] }, "monthly_event_quota": { "type": ["integer", "null"] }, "active": { "type": "boolean" } }, "additionalProperties": false },
      "UpsertBillingOffer": { "type": "object", "required": ["plan_id", "provider", "country_code", "currency", "provider_price_reference", "active"], "properties": { "plan_id": { "$ref": "#/components/schemas/PlanId" }, "provider": { "$ref": "#/components/schemas/BillingProvider" }, "country_code": { "type": "string", "pattern": "^[A-Za-z]{2}$" }, "currency": { "type": "string", "pattern": "^[A-Za-z]{3}$" }, "provider_price_reference": { "type": "string", "minLength": 1 }, "amount_minor": { "type": ["integer", "null"], "minimum": 0 }, "entitlement_months": { "type": ["integer", "null"], "minimum": 1, "maximum": 36 }, "active": { "type": "boolean" } }, "additionalProperties": false },
      "AdminBillingOfferResult": { "type": "object", "required": ["id", "plan_id", "provider", "country_code", "currency", "amount_minor", "entitlement_months", "active"], "properties": { "id": { "$ref": "#/components/schemas/OfferId" }, "plan_id": { "$ref": "#/components/schemas/PlanId" }, "provider": { "$ref": "#/components/schemas/BillingProvider" }, "country_code": { "type": "string" }, "currency": { "type": "string" }, "amount_minor": { "type": ["integer", "null"] }, "entitlement_months": { "type": ["integer", "null"] }, "active": { "type": "boolean" } }, "additionalProperties": false },
      "BillingAdministration": { "type": "object", "required": ["providers", "plans", "offers", "contracts", "dolibarr_customers"], "properties": { "providers": { "type": "array", "items": { "$ref": "#/components/schemas/BillingProviderState" } }, "plans": { "type": "array", "items": { "$ref": "#/components/schemas/AdminBillingPlan" } }, "offers": { "type": "array", "items": { "$ref": "#/components/schemas/AdminBillingOffer" } }, "contracts": { "type": "array", "items": { "$ref": "#/components/schemas/AdminAudienceContract" } }, "dolibarr_customers": { "type": "array", "items": { "$ref": "#/components/schemas/DolibarrCustomerMapping" } } }, "additionalProperties": false },
      "AdminBillingOffer": { "type": "object", "required": ["id", "plan_id", "provider", "country_code", "currency", "provider_price_reference", "amount_minor", "entitlement_months", "active"], "properties": { "id": { "$ref": "#/components/schemas/OfferId" }, "plan_id": { "$ref": "#/components/schemas/PlanId" }, "provider": { "$ref": "#/components/schemas/BillingProvider" }, "country_code": { "type": "string", "pattern": "^[A-Z]{2}$" }, "currency": { "type": "string", "pattern": "^[A-Z]{3}$" }, "provider_price_reference": { "type": "string", "minLength": 1, "maxLength": 255 }, "amount_minor": { "type": ["integer", "null"], "minimum": 0 }, "entitlement_months": { "type": ["integer", "null"], "minimum": 1, "maximum": 36 }, "active": { "type": "boolean" } }, "additionalProperties": false },
      "AdminAudienceContract": { "type": "object", "required": ["organization_id", "organization_name", "plan_id", "plan_name", "contract_reference", "status", "current_period_ends_at", "updated_at"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "organization_name": { "type": "string", "minLength": 1, "maxLength": 160 }, "plan_id": { "$ref": "#/components/schemas/PlanId" }, "plan_name": { "type": "string", "minLength": 1, "maxLength": 160 }, "contract_reference": { "type": "string", "pattern": "^[A-Za-z0-9][A-Za-z0-9._/-]{0,119}$" }, "status": { "enum": ["active", "cancelled"] }, "current_period_ends_at": { "type": ["string", "null"], "format": "date-time" }, "updated_at": { "type": "string", "format": "date-time" } }, "additionalProperties": false },
      "SetAudienceContract": { "type": "object", "required": ["plan_id", "contract_reference", "status"], "properties": { "plan_id": { "$ref": "#/components/schemas/PlanId" }, "contract_reference": { "type": "string", "pattern": "^[A-Za-z0-9][A-Za-z0-9._/-]{0,119}$" }, "status": { "enum": ["active", "cancelled"] }, "current_period_ends_at": { "type": ["string", "null"], "format": "date-time" } }, "additionalProperties": false },
      "AudienceContractResult": { "type": "object", "required": ["subscription_id", "organization_id", "plan_id", "contract_reference", "status", "monthly_event_quota", "current_period_ends_at", "updated_at", "integrations_updated"], "properties": { "subscription_id": { "type": "string" }, "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "plan_id": { "$ref": "#/components/schemas/PlanId" }, "contract_reference": { "type": "string" }, "status": { "enum": ["active", "cancelled"] }, "monthly_event_quota": { "type": ["integer", "null"] }, "current_period_ends_at": { "type": ["string", "null"], "format": "date-time" }, "updated_at": { "type": "string", "format": "date-time" }, "integrations_updated": { "type": "integer", "minimum": 0 } }, "additionalProperties": false },
      "SetDolibarrCustomer": { "type": "object", "required": ["thirdparty_id"], "properties": { "thirdparty_id": { "type": "integer", "minimum": 1 } }, "additionalProperties": false },
      "DolibarrCustomer": { "type": "object", "required": ["organization_id", "thirdparty_id", "updated_at"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "thirdparty_id": { "type": "integer", "minimum": 1 }, "updated_at": { "type": "string", "format": "date-time" } }, "additionalProperties": false },
      "DolibarrCustomerMapping": { "type": "object", "required": ["organization_id", "organization_name", "thirdparty_id", "updated_at"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "organization_name": { "type": "string", "minLength": 1, "maxLength": 160 }, "thirdparty_id": { "type": "integer", "minimum": 1 }, "updated_at": { "type": "string", "format": "date-time" } }, "additionalProperties": false },
      "CoreKey": { "type": "object", "required": ["key_id", "algorithm", "public_key"], "properties": { "key_id": { "type": "string" }, "algorithm": { "const": "Ed25519" }, "public_key": { "type": "string" } }, "additionalProperties": false },
      "Organization": { "type": "object", "required": ["organization_id", "name"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "name": { "type": "string", "minLength": 1, "maxLength": 160 }, "role": { "type": "string", "enum": ["owner", "admin", "member", "billing"] }, "created_at": { "type": "string", "format": "date-time" } }, "additionalProperties": false },
      "OrganizationList": { "type": "object", "required": ["data", "next_cursor"], "properties": { "data": { "type": "array", "maxItems": 100, "items": { "$ref": "#/components/schemas/Organization" } }, "next_cursor": { "oneOf": [{ "type": "string", "minLength": 8, "maxLength": 512, "pattern": "^[A-Za-z0-9_-]+$" }, { "type": "null" }] } }, "additionalProperties": false },
      "CreateOrganization": { "type": "object", "required": ["name"], "properties": { "name": { "type": "string", "minLength": 1, "maxLength": 160 } }, "additionalProperties": false },
      "UpdateName": { "type": "object", "required": ["name"], "properties": { "name": { "type": "string", "minLength": 1, "maxLength": 160 } }, "additionalProperties": false },
      "CloseOrganization": { "type": "object", "required": ["confirmation"], "properties": { "confirmation": { "$ref": "#/components/schemas/OrganizationId" } }, "additionalProperties": false },
      "ClosedOrganization": { "type": "object", "required": ["organization_id", "status", "audience"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "status": { "const": "closed" }, "audience": { "type": "object", "required": ["organization_reference", "status", "deleted_integrations", "deleted_events", "deleted_replay_nonces", "deleted_integrity_days", "deleted_legacy_batches"], "properties": { "organization_reference": { "$ref": "#/components/schemas/OrganizationId" }, "status": { "const": "purged" }, "deleted_integrations": { "type": "integer", "minimum": 0 }, "deleted_events": { "type": "integer", "minimum": 0 }, "deleted_replay_nonces": { "type": "integer", "minimum": 0 }, "deleted_integrity_days": { "type": "integer", "minimum": 0 }, "deleted_legacy_batches": { "type": "integer", "minimum": 0 } }, "additionalProperties": false } }, "additionalProperties": false },
      "OrganizationArchive": { "type": "object", "required": ["format", "generated_at", "organization", "members", "projects", "campaigns", "xr_codes", "api_keys", "audience_integrations", "exclusions"], "properties": { "format": { "const": "xaere-organization-archive-v1" }, "generated_at": { "type": "string", "format": "date-time" }, "organization": { "$ref": "#/components/schemas/Organization" }, "members": { "type": "array", "maxItems": 1000, "items": { "$ref": "#/components/schemas/Member" } }, "projects": { "type": "array", "maxItems": 1000, "items": { "$ref": "#/components/schemas/Project" } }, "campaigns": { "type": "array", "maxItems": 10000, "items": { "type": "object" } }, "xr_codes": { "type": "array", "maxItems": 10000, "items": { "type": "object" } }, "api_keys": { "type": "array", "maxItems": 10000, "items": { "type": "object" } }, "audience_integrations": { "type": "array", "maxItems": 100, "items": { "type": "object" } }, "exclusions": { "type": "array", "items": { "type": "string" } } }, "additionalProperties": false },
      "Project": { "type": "object", "required": ["project_id", "organization_id", "name", "created_at"], "properties": { "project_id": { "$ref": "#/components/schemas/ProjectId" }, "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "name": { "type": "string", "minLength": 1, "maxLength": 160 }, "created_at": { "type": "string", "format": "date-time" } }, "additionalProperties": false },
      "ProjectList": { "type": "object", "required": ["data", "next_cursor"], "properties": { "data": { "type": "array", "maxItems": 100, "items": { "$ref": "#/components/schemas/Project" } }, "next_cursor": { "oneOf": [{ "type": "string", "minLength": 8, "maxLength": 512, "pattern": "^[A-Za-z0-9_-]+$" }, { "type": "null" }] } }, "additionalProperties": false },
      "CreateProject": { "type": "object", "required": ["organization_id", "name"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "name": { "type": "string", "minLength": 1, "maxLength": 160 } }, "additionalProperties": false },
      "DeleteProject": { "type": "object", "required": ["confirmation"], "properties": { "confirmation": { "$ref": "#/components/schemas/ProjectId" } }, "additionalProperties": false },
      "DeletedProject": { "type": "object", "required": ["organization_id", "project_id", "status", "audience"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "project_id": { "$ref": "#/components/schemas/ProjectId" }, "status": { "const": "deleted" }, "audience": { "type": "object", "required": ["organization_reference", "project_reference", "status", "deleted_integrations", "deleted_events", "deleted_replay_nonces", "deleted_integrity_days", "deleted_legacy_batches"], "properties": { "organization_reference": { "$ref": "#/components/schemas/OrganizationId" }, "project_reference": { "$ref": "#/components/schemas/ProjectId" }, "status": { "const": "purged" }, "deleted_integrations": { "type": "integer", "minimum": 0 }, "deleted_events": { "type": "integer", "minimum": 0 }, "deleted_replay_nonces": { "type": "integer", "minimum": 0 }, "deleted_integrity_days": { "type": "integer", "minimum": 0 }, "deleted_legacy_batches": { "type": "integer", "minimum": 0 } }, "additionalProperties": false } }, "additionalProperties": false },
      "ProjectArchive": { "type": "object", "required": ["format", "generated_at", "organization", "project", "campaigns", "xr_codes", "api_keys", "audience_integrations", "exclusions"], "properties": { "format": { "const": "xaere-project-archive-v1" }, "generated_at": { "type": "string", "format": "date-time" }, "organization": { "$ref": "#/components/schemas/Organization" }, "project": { "$ref": "#/components/schemas/Project" }, "campaigns": { "type": "array", "maxItems": 10000, "items": { "type": "object" } }, "xr_codes": { "type": "array", "maxItems": 10000, "items": { "type": "object" } }, "api_keys": { "type": "array", "maxItems": 10000, "items": { "type": "object" } }, "audience_integrations": { "type": "array", "maxItems": 100, "items": { "type": "object" } }, "exclusions": { "type": "array", "items": { "type": "string" } } }, "additionalProperties": false },
      "Member": { "type": "object", "required": ["subject_id", "role", "created_at"], "properties": { "subject_id": { "type": "string", "minLength": 1, "maxLength": 255 }, "role": { "enum": ["owner", "admin", "member", "billing"] }, "created_at": { "type": "string", "format": "date-time" } }, "additionalProperties": false },
      "MemberList": { "type": "object", "required": ["data", "next_cursor"], "properties": { "data": { "type": "array", "maxItems": 100, "items": { "$ref": "#/components/schemas/Member" } }, "next_cursor": { "oneOf": [{ "type": "string", "minLength": 8, "maxLength": 512, "pattern": "^[A-Za-z0-9_-]+$" }, { "type": "null" }] } }, "additionalProperties": false },
      "SetMember": { "type": "object", "required": ["role"], "properties": { "role": { "enum": ["owner", "admin", "member", "billing"] } }, "additionalProperties": false },
      "RemovedMember": { "type": "object", "required": ["subject_id", "status"], "properties": { "subject_id": { "type": "string", "minLength": 1, "maxLength": 255 }, "status": { "const": "removed" } }, "additionalProperties": false },
      "CreateInvitation": { "type": "object", "required": ["organization_id", "email", "role"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "email": { "type": "string", "format": "email", "maxLength": 254, "writeOnly": true }, "role": { "enum": ["admin", "member", "billing"] }, "expires_in_days": { "type": "integer", "minimum": 1, "maximum": 14, "default": 7 } }, "additionalProperties": false },
      "Invitation": { "type": "object", "required": ["invitation_id", "role", "status", "delivery_status", "expires_at", "created_at", "accepted_at", "revoked_at"], "properties": { "invitation_id": { "type": "string", "pattern": "^inv_[A-Za-z0-9_-]{16,}$" }, "role": { "enum": ["admin", "member", "billing"] }, "status": { "enum": ["pending", "accepted", "revoked", "expired"] }, "delivery_status": { "enum": ["pending", "processing", "sent", "cancelled", "dead", "unavailable"] }, "expires_at": { "type": "string", "format": "date-time" }, "created_at": { "type": "string", "format": "date-time" }, "accepted_at": { "type": ["string", "null"], "format": "date-time" }, "revoked_at": { "type": ["string", "null"], "format": "date-time" } }, "additionalProperties": false },
      "CreatedInvitation": { "type": "object", "required": ["invitation_id", "organization_id", "role", "expires_at", "created_at", "delivery_status", "secret"], "properties": { "invitation_id": { "type": "string", "pattern": "^inv_[A-Za-z0-9_-]{16,}$" }, "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "role": { "enum": ["admin", "member", "billing"] }, "expires_at": { "type": "string", "format": "date-time" }, "created_at": { "type": "string", "format": "date-time" }, "delivery_status": { "const": "pending" }, "secret": { "type": "string", "pattern": "^xinv_[A-Za-z0-9_-]{40,80}$", "writeOnly": true } }, "additionalProperties": false },
      "InvitationList": { "type": "object", "required": ["data", "next_cursor"], "properties": { "data": { "type": "array", "maxItems": 100, "items": { "$ref": "#/components/schemas/Invitation" } }, "next_cursor": { "oneOf": [{ "type": "string", "minLength": 8, "maxLength": 512, "pattern": "^[A-Za-z0-9_-]+$" }, { "type": "null" }] } }, "additionalProperties": false },
      "AcceptInvitation": { "type": "object", "required": ["secret"], "properties": { "secret": { "type": "string", "pattern": "^xinv_[A-Za-z0-9_-]{40,80}$", "writeOnly": true } }, "additionalProperties": false },
      "AcceptedInvitation": { "type": "object", "required": ["invitation_id", "organization_id", "role", "status"], "properties": { "invitation_id": { "type": "string", "pattern": "^inv_[A-Za-z0-9_-]{16,}$" }, "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "role": { "enum": ["owner", "admin", "member", "billing"] }, "status": { "const": "accepted" } }, "additionalProperties": false },
      "Campaign": { "type": "object", "required": ["campaign_id", "organization_id", "project_id", "name", "status", "starts_at", "ends_at", "created_at", "archived_at"], "properties": { "campaign_id": { "$ref": "#/components/schemas/CampaignId" }, "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "project_id": { "$ref": "#/components/schemas/ProjectId" }, "name": { "type": "string", "minLength": 1, "maxLength": 160 }, "status": { "enum": ["active", "archived"] }, "starts_at": { "type": ["string", "null"], "format": "date-time" }, "ends_at": { "type": ["string", "null"], "format": "date-time" }, "created_at": { "type": "string", "format": "date-time" }, "archived_at": { "type": ["string", "null"], "format": "date-time" } }, "additionalProperties": false },
      "CampaignList": { "type": "object", "required": ["data", "next_cursor"], "properties": { "data": { "type": "array", "maxItems": 100, "items": { "$ref": "#/components/schemas/Campaign" } }, "next_cursor": { "oneOf": [{ "type": "string", "minLength": 8, "maxLength": 512, "pattern": "^[A-Za-z0-9_-]+$" }, { "type": "null" }] } }, "additionalProperties": false },
      "CampaignSummary": { "type": "object", "required": ["campaign", "codes"], "properties": { "campaign": { "$ref": "#/components/schemas/Campaign" }, "codes": { "type": "object", "required": ["issued", "active", "expired", "revoked", "audience_enabled", "first_issued_at", "last_issued_at"], "properties": { "issued": { "type": "integer", "minimum": 0 }, "active": { "type": "integer", "minimum": 0 }, "expired": { "type": "integer", "minimum": 0 }, "revoked": { "type": "integer", "minimum": 0 }, "audience_enabled": { "type": "integer", "minimum": 0 }, "first_issued_at": { "type": ["string", "null"], "format": "date-time" }, "last_issued_at": { "type": ["string", "null"], "format": "date-time" } }, "additionalProperties": false } }, "additionalProperties": false },
      "StopCampaignResult": { "type": "object", "required": ["campaign_id", "campaign_status", "status", "revoked_codes"], "properties": { "campaign_id": { "$ref": "#/components/schemas/CampaignId" }, "campaign_status": { "const": "archived" }, "status": { "const": "stopped" }, "revoked_codes": { "type": "integer", "minimum": 0 } }, "additionalProperties": false },
      "CreateCampaign": { "type": "object", "required": ["organization_id", "project_id", "name"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "project_id": { "$ref": "#/components/schemas/ProjectId" }, "name": { "type": "string", "minLength": 1, "maxLength": 160 }, "starts_at": { "type": ["string", "null"], "format": "date-time" }, "ends_at": { "type": ["string", "null"], "format": "date-time" } }, "additionalProperties": false },
      "UpdateCampaign": { "type": "object", "minProperties": 1, "properties": { "name": { "type": "string", "minLength": 1, "maxLength": 160 }, "starts_at": { "type": ["string", "null"], "format": "date-time" }, "ends_at": { "type": ["string", "null"], "format": "date-time" } }, "additionalProperties": false },
      "Intent": { "type": "object", "required": ["type", "action", "resource"], "properties": { "type": { "type": "string", "minLength": 1, "maxLength": 160 }, "action": { "type": "string", "minLength": 1, "maxLength": 160 }, "resource": { "type": "object" } }, "additionalProperties": false },
      "AudienceSelection": { "type": "object", "required": ["enabled"], "properties": { "enabled": { "type": "boolean" }, "integration_id": { "oneOf": [{ "$ref": "#/components/schemas/IntegrationId" }, { "type": "null" }] } }, "additionalProperties": false },
      "IssueCode": { "type": "object", "required": ["organization_id", "project_id", "issuer", "expires_at", "intent"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "project_id": { "$ref": "#/components/schemas/ProjectId" }, "campaign_id": { "oneOf": [{ "$ref": "#/components/schemas/CampaignId" }, { "type": "null" }] }, "issuer": { "type": "string", "minLength": 1, "maxLength": 160 }, "expires_at": { "type": "string", "format": "date-time" }, "intent": { "$ref": "#/components/schemas/Intent" }, "audience": { "$ref": "#/components/schemas/AudienceSelection" } }, "additionalProperties": false },
      "IssueCodeBatch": { "type": "object", "required": ["count", "template"], "properties": { "count": { "type": "integer", "minimum": 1, "maximum": 100 }, "template": { "$ref": "#/components/schemas/IssueCode" } }, "additionalProperties": false },
      "AudioBundleSelection": { "type": "object", "required": ["xr_ids"], "properties": { "xr_ids": { "type": "array", "minItems": 1, "maxItems": 100, "uniqueItems": true, "items": { "$ref": "#/components/schemas/XrId" } } }, "additionalProperties": false },
      "RevokeCodeBatch": { "type": "object", "required": ["project_id", "xr_ids"], "properties": { "project_id": { "$ref": "#/components/schemas/ProjectId" }, "xr_ids": { "type": "array", "minItems": 1, "maxItems": 100, "uniqueItems": true, "items": { "$ref": "#/components/schemas/XrId" } } }, "additionalProperties": false },
      "RevokeCodeBatchResult": { "type": "object", "required": ["status", "requested_codes", "revoked_codes", "unchanged_codes"], "properties": { "status": { "const": "revoked" }, "requested_codes": { "type": "integer", "minimum": 1, "maximum": 100 }, "revoked_codes": { "type": "integer", "minimum": 0, "maximum": 100 }, "unchanged_codes": { "type": "integer", "minimum": 0, "maximum": 100 } }, "additionalProperties": false },
      "CodeList": { "type": "object", "required": ["data", "next_cursor"], "properties": { "data": { "type": "array", "maxItems": 100, "items": { "type": "object", "required": ["xr_id", "project_id", "campaign_id", "status", "issued_at", "expires_at", "audience_enabled", "audience_integration_id"], "properties": { "xr_id": { "$ref": "#/components/schemas/XrId" }, "project_id": { "$ref": "#/components/schemas/ProjectId" }, "campaign_id": { "oneOf": [{ "$ref": "#/components/schemas/CampaignId" }, { "type": "null" }] }, "status": { "enum": ["active", "expired", "revoked"] }, "issued_at": { "type": "string", "format": "date-time" }, "expires_at": { "type": "string", "format": "date-time" }, "audience_enabled": { "type": "boolean" }, "audience_integration_id": { "oneOf": [{ "$ref": "#/components/schemas/IntegrationId" }, { "type": "null" }] } } } }, "next_cursor": { "oneOf": [{ "type": "string", "minLength": 8, "maxLength": 512, "pattern": "^[A-Za-z0-9_-]+$" }, { "type": "null" }] } }, "additionalProperties": false },
      "CreateApiKey": { "type": "object", "required": ["organization_id", "project_id", "label", "scopes"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "project_id": { "$ref": "#/components/schemas/ProjectId" }, "label": { "type": "string", "minLength": 1, "maxLength": 120 }, "scopes": { "type": "array", "uniqueItems": true, "items": { "enum": ["codes:read", "codes:write", "audience:read", "audience:write"] } }, "expires_in_days": { "type": "integer", "minimum": 1, "maximum": 365, "default": 90 } }, "additionalProperties": false },
      "CreatedApiKey": { "type": "object", "required": ["api_key_id", "label", "project_id", "scopes", "expires_at", "secret"], "properties": { "api_key_id": { "type": "string", "pattern": "^ak_[A-Za-z0-9_-]{16,}$" }, "label": { "type": "string", "minLength": 1, "maxLength": 120 }, "project_id": { "$ref": "#/components/schemas/ProjectId" }, "scopes": { "type": "array", "items": { "type": "string" } }, "expires_at": { "type": "string", "format": "date-time" }, "secret": { "type": "string", "pattern": "^xak_[A-Za-z0-9_-]{32,}$", "writeOnly": true } }, "additionalProperties": false },
      "RotatedApiKeySecret": { "type": "object", "required": ["api_key_id", "secret", "label", "project_id", "scopes", "expires_at", "secret_rotated_at", "status"], "properties": { "api_key_id": { "type": "string", "pattern": "^ak_[A-Za-z0-9_-]{16,}$" }, "secret": { "type": "string", "pattern": "^xak_[A-Za-z0-9_-]{32,}$", "writeOnly": true }, "label": { "type": "string" }, "project_id": { "$ref": "#/components/schemas/ProjectId" }, "scopes": { "type": "array", "items": { "type": "string" } }, "expires_at": { "type": "string", "format": "date-time" }, "secret_rotated_at": { "type": "string", "format": "date-time" }, "status": { "const": "secret_rotated" } }, "additionalProperties": false },
      "ApiKeyMetadata": { "type": "object", "required": ["api_key_id", "project_id", "label", "scopes", "created_at", "last_used_at", "expires_at", "secret_rotated_at", "status"], "properties": { "api_key_id": { "type": "string", "pattern": "^ak_[A-Za-z0-9_-]{16,}$" }, "project_id": { "$ref": "#/components/schemas/ProjectId" }, "label": { "type": "string", "minLength": 1, "maxLength": 120 }, "scopes": { "type": "array", "uniqueItems": true, "items": { "enum": ["codes:read", "codes:write", "audience:read", "audience:write"] } }, "created_at": { "type": "string", "format": "date-time" }, "last_used_at": { "type": ["string", "null"], "format": "date-time" }, "expires_at": { "type": "string", "format": "date-time" }, "secret_rotated_at": { "type": ["string", "null"], "format": "date-time" }, "status": { "enum": ["active", "expired", "revoked"] } }, "additionalProperties": false },
      "ApiKeyList": { "type": "object", "required": ["data", "next_cursor"], "properties": { "data": { "type": "array", "maxItems": 100, "items": { "$ref": "#/components/schemas/ApiKeyMetadata" } }, "next_cursor": { "oneOf": [{ "type": "string", "minLength": 8, "maxLength": 512, "pattern": "^[A-Za-z0-9_-]+$" }, { "type": "null" }] } }, "additionalProperties": false },
      "TenantContext": { "type": "object", "required": ["organization_id", "project_id"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "project_id": { "$ref": "#/components/schemas/ProjectId" } }, "additionalProperties": false },
      "CreateSupportTicket": { "type": "object", "required": ["request_id", "subject", "message"], "properties": { "request_id": { "type": "string", "pattern": "^supreq_[A-Za-z0-9_-]{16,}$" }, "subject": { "type": "string", "minLength": 1, "maxLength": 160 }, "ticket_type": { "type": ["string", "null"], "maxLength": 160 }, "message": { "type": "string", "minLength": 1, "maxLength": 10000 } }, "additionalProperties": false },
      "SupportTicket": { "type": "object", "required": ["ticket_id", "external_ticket_id", "conversation_id", "subject", "ticket_type", "status", "created_at", "updated_at"], "properties": { "ticket_id": { "type": "string", "pattern": "^sup_[A-Za-z0-9_-]{16,}$" }, "external_ticket_id": { "type": "string", "pattern": "^sup_[A-Za-z0-9_-]{16,}$" }, "conversation_id": { "type": ["integer", "null"] }, "subject": { "type": "string" }, "ticket_type": { "type": ["string", "null"] }, "status": { "enum": ["pending", "active", "closed", "failed"] }, "created_at": { "type": ["string", "null"], "format": "date-time" }, "updated_at": { "type": ["string", "null"], "format": "date-time" } }, "additionalProperties": false },
      "SupportTicketPage": { "type": "object", "required": ["data", "next_cursor"], "properties": { "data": { "type": "array", "maxItems": 100, "items": { "$ref": "#/components/schemas/SupportTicket" } }, "next_cursor": { "oneOf": [{ "type": "string", "minLength": 8, "maxLength": 512, "pattern": "^[A-Za-z0-9_-]+$" }, { "type": "null" }] } }, "additionalProperties": false },
      "SupportMessage": { "type": "object", "required": ["message_id", "author", "body", "created_at"], "properties": { "message_id": { "type": ["integer", "null"] }, "author": { "enum": ["customer", "support"] }, "body": { "type": "string", "minLength": 1, "maxLength": 10000 }, "created_at": { "type": ["string", "null"], "format": "date-time" } }, "additionalProperties": false },
      "SupportTicketDetail": { "type": "object", "required": ["ticket", "messages"], "properties": { "ticket": { "$ref": "#/components/schemas/SupportTicket" }, "messages": { "type": "array", "maxItems": 500, "items": { "$ref": "#/components/schemas/SupportMessage" } } }, "additionalProperties": false },
      "AuditEntry": { "type": "object", "required": ["audit_id", "actor_subject_id", "action", "resource_type", "resource_id", "data", "created_at"], "properties": { "audit_id": { "type": "string", "pattern": "^[1-9][0-9]{0,18}$" }, "actor_subject_id": { "type": ["string", "null"] }, "action": { "type": "string", "minLength": 1, "maxLength": 160 }, "resource_type": { "type": ["string", "null"], "maxLength": 160 }, "resource_id": { "type": ["string", "null"], "maxLength": 512 }, "data": { "type": "object", "additionalProperties": true }, "created_at": { "type": "string", "format": "date-time" } }, "additionalProperties": false },
      "AuditLogPage": { "type": "object", "required": ["data", "next_cursor"], "properties": { "data": { "type": "array", "maxItems": 100, "items": { "$ref": "#/components/schemas/AuditEntry" } }, "next_cursor": { "oneOf": [{ "type": "string", "minLength": 8, "maxLength": 512, "pattern": "^[A-Za-z0-9_-]+$" }, { "type": "null" }] } }, "additionalProperties": false },
      "PlatformSecretState": { "type": "object", "required": ["configured", "source", "updated_at"], "properties": { "configured": { "const": true }, "source": { "enum": ["vault", "environment"] }, "updated_at": { "type": ["string", "null"], "format": "date-time" } }, "additionalProperties": false },
      "PlatformSecretStatus": { "type": "object", "properties": { "stripe_secret_key": { "$ref": "#/components/schemas/PlatformSecretState" }, "stripe_webhook_secret": { "$ref": "#/components/schemas/PlatformSecretState" }, "flouci_public_key": { "$ref": "#/components/schemas/PlatformSecretState" }, "flouci_private_key": { "$ref": "#/components/schemas/PlatformSecretState" }, "proxi_support_api_key": { "$ref": "#/components/schemas/PlatformSecretState" }, "proxi_support_webhook_secret": { "$ref": "#/components/schemas/PlatformSecretState" }, "dolibarr_api_key": { "$ref": "#/components/schemas/PlatformSecretState" }, "smtp_username": { "$ref": "#/components/schemas/PlatformSecretState" }, "smtp_password": { "$ref": "#/components/schemas/PlatformSecretState" } }, "additionalProperties": false },
      "PlatformConfiguration": { "type": "object", "required": ["proxi_support_base_url", "proxi_support_mailbox_id", "dolibarr_base_url", "dolibarr_entity_id", "dolibarr_tva_rate", "dolibarr_enable_invoice_sync", "smtp_host", "smtp_port", "smtp_secure", "smtp_from_email", "smtp_from_name"], "properties": { "proxi_support_base_url": { "type": "string", "maxLength": 2048 }, "proxi_support_mailbox_id": { "type": "string", "maxLength": 10 }, "dolibarr_base_url": { "type": "string", "maxLength": 2048 }, "dolibarr_entity_id": { "type": "string", "maxLength": 10 }, "dolibarr_tva_rate": { "type": "string", "maxLength": 7 }, "dolibarr_enable_invoice_sync": { "enum": ["true", "false"] }, "smtp_host": { "type": "string", "maxLength": 253 }, "smtp_port": { "type": "string", "pattern": "^[0-9]{1,5}$" }, "smtp_secure": { "enum": ["true", "false"] }, "smtp_from_email": { "type": "string", "maxLength": 254 }, "smtp_from_name": { "type": "string", "maxLength": 80 } }, "additionalProperties": false },
      "PlatformSettings": { "type": "object", "required": ["secrets", "configuration"], "properties": { "secrets": { "$ref": "#/components/schemas/PlatformSecretStatus" }, "configuration": { "$ref": "#/components/schemas/PlatformConfiguration" } }, "additionalProperties": false },
      "PlatformIntegrationState": { "type": "object", "required": ["status", "checked_at", "missing"], "properties": { "status": { "enum": ["passed", "not_configured", "configuration_incomplete", "failed"] }, "checked_at": { "type": "string", "format": "date-time" }, "missing": { "type": "array", "maxItems": 3, "uniqueItems": true, "items": { "enum": ["dolibarr_api_key", "dolibarr_base_url", "dolibarr_entity_id", "dolibarr_tva_rate", "proxi_support_api_key", "proxi_support_base_url", "proxi_support_mailbox_id"] } } }, "additionalProperties": false },
      "PlatformIntegrationReadiness": { "type": "object", "required": ["integrations"], "properties": { "integrations": { "type": "object", "required": ["dolibarr", "proxi_support"], "properties": { "dolibarr": { "$ref": "#/components/schemas/PlatformIntegrationState" }, "proxi_support": { "$ref": "#/components/schemas/PlatformIntegrationState" } }, "additionalProperties": false } }, "additionalProperties": false },
      "PlatformReleaseSdkReadiness": { "type": "object", "required": ["preview_version", "preview_revision", "android_build_2_available", "ios_build_2_uploaded", "physical_android_acoustic", "physical_ios_acoustic", "stable_channel_published", "stable_version", "stable_revision"], "properties": { "preview_version": { "type": "string", "pattern": "^[0-9]+\\.[0-9]+\\.[0-9]+$" }, "preview_revision": { "type": "string", "pattern": "^r[1-9][0-9]*$" }, "android_build_2_available": { "type": "boolean" }, "ios_build_2_uploaded": { "type": "boolean" }, "physical_android_acoustic": { "type": "boolean" }, "physical_ios_acoustic": { "type": "boolean" }, "stable_channel_published": { "type": "boolean" }, "stable_version": { "oneOf": [{ "type": "string", "pattern": "^[0-9]+\\.[0-9]+\\.[0-9]+$" }, { "type": "null" }] }, "stable_revision": { "oneOf": [{ "type": "string", "pattern": "^r[1-9][0-9]*$" }, { "type": "null" }] } }, "additionalProperties": false },
      "PlatformReleaseReadiness": { "type": "object", "required": ["schema", "checked_at", "sdk"], "properties": { "schema": { "const": "xaere-release-readiness-v2" }, "checked_at": { "type": "string", "format": "date-time" }, "sdk": { "$ref": "#/components/schemas/PlatformReleaseSdkReadiness" } }, "additionalProperties": false },
      "DolibarrEntityDiscovery": { "type": "object", "required": ["entity_id", "checked_at"], "properties": { "entity_id": { "type": "string", "pattern": "^[1-9][0-9]{0,9}$" }, "checked_at": { "type": "string", "format": "date-time" } }, "additionalProperties": false },
      "SetPlatformSecret": { "type": "object", "required": ["value"], "properties": { "value": { "type": "string", "minLength": 3, "maxLength": 16384, "writeOnly": true } }, "additionalProperties": false },
      "SetPlatformConfiguration": { "type": "object", "required": ["value"], "properties": { "value": { "oneOf": [{ "type": "string", "maxLength": 2048 }, { "type": "boolean" }, { "type": "null" }] } }, "additionalProperties": false },
      "SetPlatformSecretsBatch": { "type": "object", "required": ["values"], "properties": { "values": { "type": "object", "minProperties": 1, "maxProperties": 9, "propertyNames": { "enum": ["stripe_secret_key", "stripe_webhook_secret", "flouci_public_key", "flouci_private_key", "proxi_support_api_key", "proxi_support_webhook_secret", "dolibarr_api_key", "smtp_username", "smtp_password"] }, "additionalProperties": { "type": "string", "minLength": 3, "maxLength": 16384, "writeOnly": true } } }, "additionalProperties": false },
      "SetPlatformConfigurationBatch": { "type": "object", "required": ["values"], "properties": { "values": { "type": "object", "minProperties": 1, "maxProperties": 11, "propertyNames": { "enum": ["proxi_support_base_url", "proxi_support_mailbox_id", "dolibarr_base_url", "dolibarr_entity_id", "dolibarr_tva_rate", "dolibarr_enable_invoice_sync", "smtp_host", "smtp_port", "smtp_secure", "smtp_from_email", "smtp_from_name"] }, "additionalProperties": { "oneOf": [{ "type": "string", "maxLength": 2048 }, { "type": "boolean" }, { "type": "null" }] } } }, "additionalProperties": false },
      "PlatformSettingResult": { "type": "object", "required": ["name", "configured"], "properties": { "name": { "type": "string" }, "configured": { "type": "boolean" }, "value": { "type": "string" } }, "additionalProperties": false },
      "PlatformSettingsBatchResult": { "type": "object", "required": ["data"], "properties": { "data": { "type": "array", "minItems": 1, "maxItems": 11, "items": { "$ref": "#/components/schemas/PlatformSettingResult" } } }, "additionalProperties": false },
      "CodesUsagePlan": { "type": "object", "required": ["plan_id", "name", "monthly_code_quota"], "properties": { "plan_id": { "$ref": "#/components/schemas/PlanId" }, "name": { "type": "string" }, "monthly_code_quota": { "type": ["integer", "null"], "minimum": 0 } }, "additionalProperties": false },
      "AudienceUsageMode": { "type": "object", "required": ["mode", "events", "monthly_event_quota", "active_integrations"], "properties": { "mode": { "enum": ["demo", "contract", "self_service"] }, "events": { "type": "integer", "minimum": 0 }, "monthly_event_quota": { "type": ["integer", "null"], "minimum": 0 }, "active_integrations": { "type": "integer", "minimum": 0 } }, "additionalProperties": false },
      "AudienceUsage": { "type": "object", "required": ["status", "period_started_at", "data"], "properties": { "status": { "enum": ["available", "unavailable"] }, "period_started_at": { "type": ["string", "null"], "format": "date-time" }, "data": { "type": "array", "maxItems": 3, "items": { "$ref": "#/components/schemas/AudienceUsageMode" } } }, "additionalProperties": false },
      "UsageSummary": { "type": "object", "required": ["codes_issued", "plan", "audience"], "properties": { "codes_issued": { "type": "integer", "minimum": 0 }, "plan": { "oneOf": [{ "$ref": "#/components/schemas/CodesUsagePlan" }, { "type": "null" }] }, "audience": { "$ref": "#/components/schemas/AudienceUsage" } }, "additionalProperties": false },
      "SupportWebhookReceipt": { "type": "object", "required": ["accepted", "duplicate", "delivery_id", "support_ticket_id"], "properties": { "accepted": { "type": "boolean" }, "duplicate": { "type": "boolean" }, "delivery_id": { "type": "string", "minLength": 1, "maxLength": 512 }, "support_ticket_id": { "oneOf": [{ "type": "string", "pattern": "^sup_[A-Za-z0-9_-]{16,}$" }, { "type": "null" }] } }, "additionalProperties": false },
      "CreateIntegration": { "type": "object", "required": ["organization_id", "project_id", "mode"], "properties": { "organization_id": { "$ref": "#/components/schemas/OrganizationId" }, "project_id": { "$ref": "#/components/schemas/ProjectId" }, "mode": { "enum": ["demo", "contract", "self_service"] }, "retention_days": { "type": "integer", "minimum": 1, "maximum": 730 } }, "additionalProperties": false },
      "CreatedIntegration": { "type": "object", "required": ["integration_id", "secret", "mode", "retention_days"], "properties": { "integration_id": { "$ref": "#/components/schemas/IntegrationId" }, "secret": { "type": "string", "pattern": "^xai_[A-Za-z0-9_-]+$", "writeOnly": true }, "mode": { "enum": ["demo", "contract", "self_service"] }, "retention_days": { "type": "integer", "minimum": 1, "maximum": 730 } }, "additionalProperties": false },
      "RotatedIntegrationSecret": { "type": "object", "required": ["integration_id", "secret", "secret_rotated_at", "status"], "properties": { "integration_id": { "$ref": "#/components/schemas/IntegrationId" }, "secret": { "type": "string", "pattern": "^xai_[A-Za-z0-9_-]+$", "writeOnly": true }, "secret_rotated_at": { "type": "string", "format": "date-time" }, "status": { "const": "secret_rotated" } }, "additionalProperties": false },
      "UpdatedAudienceCoreKey": { "type": "object", "required": ["integration_id", "core_key_id", "status"], "properties": { "integration_id": { "$ref": "#/components/schemas/IntegrationId" }, "core_key_id": { "type": "string", "minLength": 1, "maxLength": 160 }, "status": { "const": "core_key_updated" } }, "additionalProperties": false },
      "UpdateIntegrationRetention": { "type": "object", "required": ["retention_days"], "properties": { "retention_days": { "type": "integer", "minimum": 1, "maximum": 730 } }, "additionalProperties": false },
      "UpdatedIntegrationRetention": { "type": "object", "required": ["integration_id", "mode", "previous_retention_days", "retention_days", "deleted_events", "deleted_integrity_days", "status"], "properties": { "integration_id": { "$ref": "#/components/schemas/IntegrationId" }, "mode": { "enum": ["demo", "contract", "self_service"] }, "previous_retention_days": { "type": "integer", "minimum": 1, "maximum": 730 }, "retention_days": { "type": "integer", "minimum": 1, "maximum": 730 }, "deleted_events": { "type": "integer", "minimum": 0 }, "deleted_integrity_days": { "type": "integer", "minimum": 0 }, "status": { "const": "retention_updated" } }, "additionalProperties": false },
      "IntegrationList": { "type": "object", "required": ["data", "next_cursor"], "properties": { "data": { "type": "array", "maxItems": 100, "items": { "type": "object", "required": ["integration_id", "project_id", "mode", "retention_days", "monthly_event_quota", "entitlement_ends_at", "secret_rotated_at", "active", "created_at"], "properties": { "integration_id": { "$ref": "#/components/schemas/IntegrationId" }, "project_id": { "$ref": "#/components/schemas/ProjectId" }, "mode": { "enum": ["demo", "contract", "self_service"] }, "active": { "type": "boolean" }, "retention_days": { "type": "integer", "minimum": 1, "maximum": 730 }, "monthly_event_quota": { "type": ["integer", "null"], "minimum": 0 }, "entitlement_ends_at": { "type": ["string", "null"], "format": "date-time" }, "secret_rotated_at": { "type": ["string", "null"], "format": "date-time" }, "created_at": { "type": "string", "format": "date-time" } }, "additionalProperties": false } }, "next_cursor": { "oneOf": [{ "type": "string", "minLength": 8, "maxLength": 512, "pattern": "^[A-Za-z0-9_-]+$" }, { "type": "null" }] } }, "additionalProperties": false },
      "AudienceReport": { "type": "object", "required": ["integration_id", "period", "events", "unique_measurement_tokens", "estimated_reach", "average_frequency", "by_xr_code", "by_country", "by_campaign", "by_receiver_class", "by_day", "frequency_distribution", "integrity_signals"], "properties": { "integration_id": { "$ref": "#/components/schemas/IntegrationId" }, "period": { "type": "object", "required": ["from", "to"], "properties": { "from": { "type": ["string", "null"], "format": "date-time" }, "to": { "type": ["string", "null"], "format": "date-time" } }, "additionalProperties": false }, "events": { "type": "integer", "minimum": 0 }, "unique_measurement_tokens": { "type": "integer", "minimum": 0, "description": "Aggregate count only; raw rotating tokens are never returned." }, "estimated_reach": { "type": "integer", "minimum": 0 }, "average_frequency": { "type": "number", "minimum": 0 }, "by_xr_code": { "type": "object", "maxProperties": 10000, "propertyNames": { "pattern": "^xr_[A-Za-z0-9_-]{16,}$" }, "additionalProperties": { "type": "integer", "minimum": 0 } }, "by_country": { "type": "object", "maxProperties": 10000, "propertyNames": { "pattern": "^(unknown|[A-Z]{2})$" }, "additionalProperties": { "type": "integer", "minimum": 0 } }, "by_campaign": { "type": "object", "maxProperties": 10000, "propertyNames": { "pattern": "^(unassigned|cmp_[A-Za-z0-9_-]{16,})$" }, "additionalProperties": { "type": "integer", "minimum": 0 } }, "by_receiver_class": { "type": "object", "maxProperties": 4, "propertyNames": { "enum": ["mobile", "tv", "iot", "web"] }, "additionalProperties": { "type": "integer", "minimum": 0 } }, "by_day": { "type": "object", "maxProperties": 10000, "propertyNames": { "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}$" }, "additionalProperties": { "type": "object", "required": ["events", "estimated_reach"], "properties": { "events": { "type": "integer", "minimum": 0 }, "estimated_reach": { "type": "integer", "minimum": 0 } }, "additionalProperties": false } }, "frequency_distribution": { "type": "object", "maxProperties": 10000, "propertyNames": { "pattern": "^[1-9][0-9]*$" }, "additionalProperties": { "type": "integer", "minimum": 0 } }, "integrity_signals": { "type": "object", "required": ["granularity", "exact_event_replays", "token_code_duplicates", "proof_replays", "total_authenticated_duplicates"], "properties": { "granularity": { "const": "utc_day" }, "exact_event_replays": { "type": "integer", "minimum": 0 }, "token_code_duplicates": { "type": "integer", "minimum": 0 }, "proof_replays": { "type": "integer", "minimum": 0 }, "total_authenticated_duplicates": { "type": "integer", "minimum": 0 } }, "additionalProperties": false } }, "additionalProperties": false },
      "LegacyAudienceReport": { "type": "object", "required": ["data_classification", "reach_comparable_to_xr_v1", "organization_reference", "project_reference", "import_batches", "detections", "reported_unique_consumers"], "properties": { "data_classification": { "const": "legacy_unverified_aggregate" }, "reach_comparable_to_xr_v1": { "const": false }, "organization_reference": { "$ref": "#/components/schemas/OrganizationId" }, "project_reference": { "$ref": "#/components/schemas/ProjectId" }, "import_batches": { "type": "integer", "minimum": 0 }, "detections": { "type": "integer", "minimum": 0 }, "reported_unique_consumers": { "type": "integer", "minimum": 0 }, "by_day": { "type": "object" }, "by_country": { "type": "object" }, "by_spot": { "type": "array", "items": { "type": "object" } } }, "additionalProperties": false },
      "IngestResult": { "type": "object", "required": ["accepted", "duplicate"], "properties": { "accepted": { "const": true }, "duplicate": { "type": "boolean" } }, "additionalProperties": false }
    }
  }
}
