API documentation

/llms.txt → GET /agent/state → /agent/sitemap.json / /openapi.json

Machine-readable interface of the current local product, including sessions, documents, permissions and mock billing.

The technical contract below is in English and is generated from the same OpenAPI description as the downloadable file.

Download OpenAPI 3.1 (JSON)

Agents start with GET /agent/state (after /llms.txt), then consult /agent/sitemap.json or this specification as needed. Implemented P5 loopback API, not a deployed hosted service. Sessions use HttpOnly Secure SameSite=Strict cookies; /api mutations require x-zentro-request: 1 except signed billing webhook. Host/Origin and request-size guards apply. APIs enforce tenant isolation, role, quota and verified-email rules. /mcp and /mcp/token use trusted product adapters, organization-bound credentials, opt-in and current product entitlement/metering. /mcp/token also issues a credential to an authorized session. No hosted OAuth authorization server is implemented. Payments, external identity and outgoing messages are disabled or local mocks. Responses retain flexible object schemas where P5 has no stable DTO contract.

POST /api/operator/beta/allow

Issue one-use email-bound beta admission token. Verified session AND user ID in server-side operatorUserIds required. Organization ownership never grants this capability.

Parameters, inputs and responses
{
  "operationId": "post_api_operator_beta_allow",
  "summary": "Issue one-use email-bound beta admission token",
  "description": "Issue one-use email-bound beta admission token. Verified session AND user ID in server-side operatorUserIds required. Organization ownership never grants this capability.",
  "x-access": "operator",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "email": {
              "type": "string",
              "format": "email"
            }
          },
          "required": [
            "email"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/operator/beta/agent-token

Issue 24-hour operator agent credential bound to owned organization. Verified session AND user ID in server-side operatorUserIds required. Organization ownership never grants this capability.

Parameters, inputs and responses
{
  "operationId": "post_api_operator_beta_agent_token",
  "summary": "Issue 24-hour operator agent credential bound to owned organization",
  "description": "Issue 24-hour operator agent credential bound to owned organization. Verified session AND user ID in server-side operatorUserIds required. Organization ownership never grants this capability.",
  "x-access": "operator",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "orgId": {
              "type": "string"
            }
          },
          "required": [
            "orgId"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

DELETE /api/operator/beta/agent-token

Revoke an operator agent credential. Verified session AND user ID in server-side operatorUserIds required. Organization ownership never grants this capability.

Parameters, inputs and responses
{
  "operationId": "delete_api_operator_beta_agent_token",
  "summary": "Revoke an operator agent credential",
  "description": "Revoke an operator agent credential. Verified session AND user ID in server-side operatorUserIds required. Organization ownership never grants this capability.",
  "x-access": "operator",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "credentialId": {
              "type": "string"
            }
          },
          "required": [
            "credentialId"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/organizations/{organizationId}/ai

Read organization AI mode and masked secret. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_organizations_organizationId_ai",
  "summary": "Read organization AI mode and masked secret",
  "description": "Read organization AI mode and masked secret. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "member",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "read-ai"
  ]
}

PUT /api/organizations/{organizationId}/ai

Configure organization AI; endpoints must be server-allowlisted. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "put_api_organizations_organizationId_ai",
  "summary": "Configure organization AI; endpoints must be server-allowlisted",
  "description": "Configure organization AI; endpoints must be server-allowlisted. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "configure-ai"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "mode": {
              "enum": [
                "none",
                "local",
                "byok",
                "bridge",
                "enterprise",
                "shared"
              ]
            },
            "endpoint": {
              "type": "string"
            },
            "model": {
              "type": "string"
            },
            "timeoutMs": {
              "type": "integer",
              "minimum": 100,
              "maximum": 300000
            },
            "secret": {
              "type": "string",
              "writeOnly": true,
              "minLength": 8,
              "maxLength": 8192
            },
            "expiresAt": {
              "type": "integer",
              "description": "Unix epoch milliseconds; required for enterprise tokens, max 12h."
            }
          },
          "required": [
            "mode"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

DELETE /api/organizations/{organizationId}/ai/secret

Physically delete AI secret and disable AI. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "delete_api_organizations_organizationId_ai_secret",
  "summary": "Physically delete AI secret and disable AI",
  "description": "Physically delete AI secret and disable AI. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "revoke-ai-secret"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {},
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/organizations/{organizationId}/ai/health

Check configured local bridge without document content. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_organizations_organizationId_ai_health",
  "summary": "Check configured local bridge without document content",
  "description": "Check configured local bridge without document content. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "check-ai-bridge"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {},
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/organizations/{organizationId}/ai/usage

Read own organization AI metadata only. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_organizations_organizationId_ai_usage",
  "summary": "Read own organization AI metadata only",
  "description": "Read own organization AI metadata only. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "member",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "read-ai-usage"
  ]
}

GET /api/operator/ai/usage

Operator-only shared usage across organizations. Verified session AND user ID in server-side operatorUserIds required. Organization ownership never grants this capability.

Parameters, inputs and responses
{
  "operationId": "get_api_operator_ai_usage",
  "summary": "Operator-only shared usage across organizations",
  "description": "Operator-only shared usage across organizations. Verified session AND user ID in server-side operatorUserIds required. Organization ownership never grants this capability.",
  "x-access": "operator",
  "parameters": [],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": []
}

PUT /api/operator/ai/shared

Server-configured operator only: limits, grant, revoke, immediate kill. Verified session AND user ID in server-side operatorUserIds required. Organization ownership never grants this capability.

Parameters, inputs and responses
{
  "operationId": "put_api_operator_ai_shared",
  "summary": "Server-configured operator only: limits, grant, revoke, immediate kill",
  "description": "Server-configured operator only: limits, grant, revoke, immediate kill. Verified session AND user ID in server-side operatorUserIds required. Organization ownership never grants this capability.",
  "x-access": "operator",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "operation": {
              "enum": [
                "limits",
                "grant",
                "revoke",
                "kill"
              ]
            },
            "killed": {
              "type": "boolean"
            },
            "orgId": {
              "type": "string"
            },
            "kind": {
              "enum": [
                "invite",
                "trial"
              ]
            },
            "expiresAt": {
              "type": [
                "integer",
                "null"
              ]
            },
            "limits": {
              "type": "object",
              "required": [
                "dayRequests",
                "monthRequests",
                "dayTokens",
                "monthTokens"
              ],
              "additionalProperties": false,
              "properties": {
                "dayRequests": {
                  "type": "integer",
                  "minimum": 0
                },
                "monthRequests": {
                  "type": "integer",
                  "minimum": 0
                },
                "dayTokens": {
                  "type": "integer",
                  "minimum": 0
                },
                "monthTokens": {
                  "type": "integer",
                  "minimum": 0
                }
              }
            }
          },
          "required": [
            "operation"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

GET /agent/state

First agent request: current identity, scoped state and permitted next actions. Optional existing session cookie, exactly as /api/me; no bearer-token authentication. Same shared request quota as the product API. Private responses are not cached. Descriptions never grant permission and each action endpoint rechecks authorization and quotas. P13: operator-issued agent bearer supported with fixed organization scope; public registration may be closed (BETA_CLOSED).

Parameters, inputs and responses
{
  "operationId": "get_agent_state",
  "summary": "First agent request: current identity, scoped state and permitted next actions",
  "description": "First agent request: current identity, scoped state and permitted next actions. Optional existing session cookie, exactly as /api/me; no bearer-token authentication. Same shared request quota as the product API. Private responses are not cached. Descriptions never grant permission and each action endpoint rechecks authorization and quotas. P13: operator-issued agent bearer supported with fixed organization scope; public registration may be closed (BETA_CLOSED).",
  "x-access": "public",
  "parameters": [
    {
      "name": "orgId",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "documentId",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {},
    {
      "sessionCookie": []
    },
    {
      "mcpBearer": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/AgentState"
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": []
}

GET /agent/sitemap.json

Machine-readable page map and links to action identifiers. Optional existing session cookie, exactly as /api/me; no bearer-token authentication. Same shared request quota as the product API. Private responses are not cached. Descriptions never grant permission and each action endpoint rechecks authorization and quotas.

Parameters, inputs and responses
{
  "operationId": "get_agent_sitemap_json",
  "summary": "Machine-readable page map and links to action identifiers",
  "description": "Machine-readable page map and links to action identifiers. Optional existing session cookie, exactly as /api/me; no bearer-token authentication. Same shared request quota as the product API. Private responses are not cached. Descriptions never grant permission and each action endpoint rechecks authorization and quotas.",
  "x-access": "public",
  "parameters": [
    {
      "name": "orgId",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "documentId",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {},
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/AgentSitemap"
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": []
}

GET /agent/recipes.json

Complete ready-to-run agent recipes with parameter schemas and error policies. No session required.

Parameters, inputs and responses
{
  "operationId": "get_agent_recipes_json",
  "summary": "Complete ready-to-run agent recipes with parameter schemas and error policies",
  "description": "Complete ready-to-run agent recipes with parameter schemas and error policies. No session required.",
  "x-access": "public",
  "parameters": [],
  "security": [
    {},
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "required": [
              "recipes"
            ],
            "properties": {
              "recipes": {
                "type": "array",
                "items": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": []
}

POST /agent/run

Execute sequential recipe steps and stop at first failure or email verification pause. No session required. Not atomic: committed steps remain committed. One outer API request; all internal product permissions and plan ceilings remain enforced. dryRun validates and returns the step plan without product mutations. Registration pauses for a real verification link from local mock mail; resumeToken continues in the original session. PLAN_LIMIT returns 402 and upgrade next action; SAVE_CONFLICT returns 409 without automatic overwrite; RATE_LIMIT returns 429 and Retry-After without automatic retry. P13: operator-issued agent bearer supported with fixed organization scope; public registration may be closed (BETA_CLOSED).

Parameters, inputs and responses
{
  "operationId": "post_agent_run",
  "summary": "Execute sequential recipe steps and stop at first failure or email verification pause",
  "description": "Execute sequential recipe steps and stop at first failure or email verification pause. No session required. Not atomic: committed steps remain committed. One outer API request; all internal product permissions and plan ceilings remain enforced. dryRun validates and returns the step plan without product mutations. Registration pauses for a real verification link from local mock mail; resumeToken continues in the original session. PLAN_LIMIT returns 402 and upgrade next action; SAVE_CONFLICT returns 409 without automatic overwrite; RATE_LIMIT returns 429 and Retry-After without automatic retry. P13: operator-issued agent bearer supported with fixed organization scope; public registration may be closed (BETA_CLOSED).",
  "x-access": "public",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {},
    {
      "sessionCookie": []
    },
    {
      "mcpBearer": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "recipe": {
                "type": "string"
              },
              "status": {
                "type": "string"
              },
              "steps": {
                "type": "array",
                "items": {
                  "type": "object",
                  "additionalProperties": true
                }
              },
              "exports": {
                "type": "array",
                "items": {
                  "type": "object",
                  "required": [
                    "documentId",
                    "content",
                    "contentType",
                    "byteLength"
                  ],
                  "properties": {
                    "documentId": {
                      "type": "string"
                    },
                    "content": {
                      "type": "string"
                    },
                    "contentType": {
                      "const": "application/json"
                    },
                    "byteLength": {
                      "type": "integer",
                      "minimum": 0
                    }
                  }
                }
              },
              "durationMs": {
                "type": "number"
              },
              "resumeToken": {
                "type": "string"
              },
              "next": {
                "type": "array",
                "items": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "402": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "409": {
      "description": "Save conflict: inspect current document before retry.",
      "headers": {},
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Rate limit: respect Retry-After; no automatic retry.",
      "headers": {
        "Retry-After": {
          "schema": {
            "type": "integer",
            "minimum": 1
          }
        }
      },
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "run-recipe"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "$id": "urn:zentro:run-recipe:v1",
          "type": "object",
          "$defs": {
            "Document": {
              "$schema": "https://json-schema.org/draft/2020-12/schema",
              "$id": "urn:vystaveni:document:v1",
              "title": "Canonical document v1",
              "type": "object",
              "required": [
                "schema",
                "title",
                "blocks"
              ],
              "properties": {
                "schema": {
                  "const": "vystaveni.document.v1"
                },
                "title": {
                  "type": "string",
                  "maxLength": 300
                },
                "blocks": {
                  "$ref": "#/$defs/blocks"
                },
                "footnotes": {
                  "type": "array",
                  "items": {
                    "type": "object",
                    "required": [
                      "id",
                      "blocks"
                    ],
                    "properties": {
                      "id": {
                        "$ref": "#/$defs/id"
                      },
                      "blocks": {
                        "$ref": "#/$defs/blocks"
                      }
                    },
                    "additionalProperties": false
                  }
                },
                "comments": {
                  "type": "array",
                  "items": {
                    "type": "object",
                    "required": [
                      "id",
                      "text"
                    ],
                    "properties": {
                      "id": {
                        "$ref": "#/$defs/id"
                      },
                      "text": {
                        "type": "string",
                        "maxLength": 200000
                      },
                      "author": {
                        "type": "string",
                        "maxLength": 200
                      }
                    },
                    "additionalProperties": false
                  }
                },
                "warnings": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "maxLength": 4000
                  },
                  "maxItems": 100
                },
                "source": {
                  "type": "object",
                  "properties": {
                    "kind": {
                      "type": "string",
                      "maxLength": 40
                    },
                    "name": {
                      "type": "string",
                      "maxLength": 2000
                    },
                    "mediaType": {
                      "type": "string",
                      "maxLength": 2000
                    },
                    "sourceId": {
                      "type": "string",
                      "maxLength": 2000
                    },
                    "hash": {
                      "type": "string",
                      "maxLength": 2000
                    }
                  },
                  "additionalProperties": false
                },
                "locale": {
                  "type": "string",
                  "maxLength": 100
                },
                "language": {
                  "type": "string",
                  "maxLength": 100
                },
                "languageSource": {
                  "enum": [
                    "unknown",
                    "user",
                    "source-metadata"
                  ]
                },
                "diagnostics": {
                  "type": "array",
                  "maxItems": 100,
                  "items": {
                    "type": "object",
                    "required": [
                      "key"
                    ],
                    "properties": {
                      "key": {
                        "type": "string",
                        "pattern": "^[a-zA-Z][a-zA-Z0-9_.-]{0,150}$",
                        "maxLength": 151
                      },
                      "params": {
                        "type": "object",
                        "maxProperties": 20,
                        "additionalProperties": {
                          "type": [
                            "string",
                            "number",
                            "boolean"
                          ],
                          "maxLength": 2000
                        },
                        "propertyNames": {
                          "type": "string",
                          "pattern": "^[a-zA-Z][a-zA-Z0-9_]{0,50}$"
                        }
                      },
                      "message": {
                        "type": "string",
                        "maxLength": 4000
                      }
                    },
                    "additionalProperties": false
                  }
                }
              },
              "additionalProperties": false,
              "$defs": {
                "id": {
                  "type": "string",
                  "pattern": "^[a-zA-Z0-9_-]{1,100}$"
                },
                "provenance": {
                  "type": "object",
                  "required": [
                    "sourceId"
                  ],
                  "properties": {
                    "sourceId": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 1000
                    },
                    "page": {
                      "type": "integer",
                      "minimum": 1
                    },
                    "sheet": {
                      "type": "string",
                      "maxLength": 200000
                    },
                    "quote": {
                      "type": "string",
                      "maxLength": 200000
                    }
                  },
                  "additionalProperties": false
                },
                "run": {
                  "type": "object",
                  "required": [
                    "text"
                  ],
                  "properties": {
                    "text": {
                      "type": "string",
                      "maxLength": 200000
                    },
                    "bold": {
                      "type": "boolean"
                    },
                    "italic": {
                      "type": "boolean"
                    },
                    "footnoteId": {
                      "$ref": "#/$defs/id"
                    },
                    "commentIds": {
                      "type": "array",
                      "maxItems": 100,
                      "uniqueItems": true,
                      "items": {
                        "$ref": "#/$defs/id"
                      }
                    },
                    "value": {
                      "type": "object",
                      "required": [
                        "type",
                        "value"
                      ],
                      "properties": {
                        "type": {
                          "enum": [
                            "number",
                            "percent",
                            "date",
                            "boolean"
                          ]
                        },
                        "value": {
                          "type": [
                            "string",
                            "number",
                            "boolean"
                          ]
                        }
                      },
                      "additionalProperties": false,
                      "oneOf": [
                        {
                          "properties": {
                            "type": {
                              "enum": [
                                "number",
                                "percent"
                              ]
                            },
                            "value": {
                              "type": "number"
                            }
                          }
                        },
                        {
                          "properties": {
                            "type": {
                              "const": "boolean"
                            },
                            "value": {
                              "type": "boolean"
                            }
                          }
                        },
                        {
                          "properties": {
                            "type": {
                              "const": "date"
                            },
                            "value": {
                              "type": "string",
                              "pattern": "^\\d{4}-\\d\\d-\\d\\d(?:T[\\d:.]+Z)?$"
                            }
                          }
                        }
                      ]
                    },
                    "labelKey": {
                      "type": "string",
                      "maxLength": 151,
                      "pattern": "^[a-zA-Z][a-zA-Z0-9_.-]{0,150}$"
                    },
                    "labelParams": {
                      "$ref": "#/properties/diagnostics/items/properties/params"
                    }
                  },
                  "additionalProperties": false
                },
                "blocks": {
                  "type": "array",
                  "maxItems": 20000,
                  "items": {
                    "$ref": "#/$defs/block"
                  }
                },
                "block": {
                  "oneOf": [
                    {
                      "type": "object",
                      "required": [
                        "type"
                      ],
                      "properties": {
                        "id": {
                          "$ref": "#/$defs/id"
                        },
                        "provenance": {
                          "$ref": "#/$defs/provenance"
                        },
                        "type": {
                          "const": "page-break"
                        }
                      },
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "required": [
                        "type",
                        "runs"
                      ],
                      "properties": {
                        "id": {
                          "$ref": "#/$defs/id"
                        },
                        "provenance": {
                          "$ref": "#/$defs/provenance"
                        },
                        "type": {
                          "const": "paragraph"
                        },
                        "runs": {
                          "type": "array",
                          "maxItems": 10000,
                          "items": {
                            "$ref": "#/$defs/run"
                          }
                        }
                      },
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "required": [
                        "type",
                        "runs",
                        "level"
                      ],
                      "properties": {
                        "id": {
                          "$ref": "#/$defs/id"
                        },
                        "provenance": {
                          "$ref": "#/$defs/provenance"
                        },
                        "type": {
                          "const": "heading"
                        },
                        "runs": {
                          "type": "array",
                          "maxItems": 10000,
                          "items": {
                            "$ref": "#/$defs/run"
                          }
                        },
                        "level": {
                          "enum": [
                            1,
                            2,
                            3
                          ]
                        }
                      },
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "required": [
                        "type",
                        "ordered",
                        "items"
                      ],
                      "properties": {
                        "id": {
                          "$ref": "#/$defs/id"
                        },
                        "provenance": {
                          "$ref": "#/$defs/provenance"
                        },
                        "type": {
                          "const": "list"
                        },
                        "ordered": {
                          "type": "boolean"
                        },
                        "start": {
                          "type": "integer",
                          "minimum": 1,
                          "maximum": 100000
                        },
                        "items": {
                          "type": "array",
                          "items": {
                            "type": "object",
                            "required": [
                              "blocks"
                            ],
                            "properties": {
                              "blocks": {
                                "$ref": "#/$defs/blocks"
                              }
                            },
                            "additionalProperties": false
                          }
                        }
                      },
                      "additionalProperties": false
                    },
                    {
                      "type": "object",
                      "required": [
                        "type",
                        "rows"
                      ],
                      "properties": {
                        "id": {
                          "$ref": "#/$defs/id"
                        },
                        "provenance": {
                          "$ref": "#/$defs/provenance"
                        },
                        "type": {
                          "const": "table"
                        },
                        "rows": {
                          "type": "array",
                          "maxItems": 2000,
                          "items": {
                            "type": "object",
                            "required": [
                              "cells"
                            ],
                            "properties": {
                              "cells": {
                                "type": "array",
                                "maxItems": 100,
                                "items": {
                                  "type": "object",
                                  "required": [
                                    "blocks"
                                  ],
                                  "properties": {
                                    "blocks": {
                                      "$ref": "#/$defs/blocks"
                                    },
                                    "colSpan": {
                                      "type": "integer",
                                      "minimum": 1,
                                      "maximum": 100
                                    },
                                    "rowSpan": {
                                      "type": "integer",
                                      "minimum": 1,
                                      "maximum": 2000
                                    }
                                  },
                                  "additionalProperties": false
                                }
                              }
                            },
                            "additionalProperties": false
                          }
                        }
                      },
                      "additionalProperties": false
                    }
                  ]
                }
              }
            },
            "params-ask-document": {
              "type": "object",
              "properties": {
                "documentId": {
                  "type": "string",
                  "pattern": "^[A-Za-z0-9_-]{1,100}$"
                },
                "question": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 4000
                }
              },
              "required": [
                "documentId",
                "question"
              ],
              "additionalProperties": false
            },
            "params-new-customer": {
              "type": "object",
              "properties": {
                "email": {
                  "type": "string",
                  "format": "email",
                  "maxLength": 254,
                  "pattern": "^[^\\s@]+@[^\\s@]+\\.[^\\s@]+$"
                },
                "password": {
                  "type": "string",
                  "minLength": 12,
                  "description": "At most 1024 UTF-8 bytes, as in product registration."
                },
                "title": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 300
                },
                "inviteEmail": {
                  "type": "string",
                  "format": "email",
                  "maxLength": 254,
                  "pattern": "^[^\\s@]+@[^\\s@]+\\.[^\\s@]+$"
                },
                "comment": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 200
                },
                "document": {
                  "$ref": "#/$defs/Document"
                },
                "versionDocument": {
                  "$ref": "#/$defs/Document"
                },
                "organization": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 200
                },
                "uiLocale": {
                  "enum": [
                    "cs",
                    "en"
                  ],
                  "type": "string"
                }
              },
              "required": [
                "email",
                "password",
                "title",
                "inviteEmail",
                "comment"
              ],
              "additionalProperties": false
            },
            "params-share-document": {
              "type": "object",
              "properties": {
                "documentId": {
                  "type": "string",
                  "pattern": "^[A-Za-z0-9_-]{1,100}$"
                },
                "inviteEmail": {
                  "type": "string",
                  "format": "email",
                  "maxLength": 254,
                  "pattern": "^[^\\s@]+@[^\\s@]+\\.[^\\s@]+$"
                },
                "role": {
                  "type": "string",
                  "enum": [
                    "viewer",
                    "commenter",
                    "editor"
                  ]
                },
                "username": {
                  "type": "string",
                  "pattern": "^\\S{3,80}$"
                },
                "password": {
                  "type": "string",
                  "minLength": 12
                }
              },
              "required": [
                "documentId",
                "inviteEmail"
              ],
              "additionalProperties": false
            },
            "params-revise-compare-discuss": {
              "type": "object",
              "properties": {
                "documentId": {
                  "type": "string",
                  "pattern": "^[A-Za-z0-9_-]{1,100}$"
                },
                "document": {
                  "$ref": "#/$defs/Document"
                },
                "comment": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 200
                },
                "baseVersion": {
                  "type": "string",
                  "pattern": "^[A-Za-z0-9_-]{1,100}$"
                }
              },
              "required": [
                "documentId",
                "document",
                "comment"
              ],
              "additionalProperties": false
            },
            "params-accept-and-comment": {
              "type": "object",
              "properties": {
                "token": {
                  "type": "string",
                  "minLength": 1
                },
                "comment": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 200
                },
                "documentId": {
                  "type": "string",
                  "pattern": "^[A-Za-z0-9_-]{1,100}$"
                }
              },
              "required": [
                "token",
                "comment"
              ],
              "additionalProperties": false
            }
          },
          "properties": {
            "recipe": {
              "type": "string",
              "enum": [
                "ask-document",
                "new-customer",
                "share-document",
                "revise-compare-discuss",
                "accept-and-comment"
              ]
            },
            "params": {
              "type": "object",
              "anyOf": [
                {
                  "$ref": "#/$defs/params-ask-document"
                },
                {
                  "$ref": "#/$defs/params-new-customer"
                },
                {
                  "$ref": "#/$defs/params-share-document"
                },
                {
                  "$ref": "#/$defs/params-revise-compare-discuss"
                },
                {
                  "$ref": "#/$defs/params-accept-and-comment"
                }
              ]
            },
            "dryRun": {
              "type": "boolean"
            },
            "resumeToken": {
              "type": "string"
            }
          },
          "additionalProperties": false,
          "oneOf": [
            {
              "required": [
                "recipe",
                "params"
              ],
              "properties": {
                "recipe": {
                  "const": "ask-document"
                },
                "params": {
                  "$ref": "#/$defs/params-ask-document"
                }
              },
              "not": {
                "required": [
                  "resumeToken"
                ]
              }
            },
            {
              "required": [
                "recipe",
                "params"
              ],
              "properties": {
                "recipe": {
                  "const": "new-customer"
                },
                "params": {
                  "$ref": "#/$defs/params-new-customer"
                }
              },
              "not": {
                "required": [
                  "resumeToken"
                ]
              }
            },
            {
              "required": [
                "recipe",
                "params"
              ],
              "properties": {
                "recipe": {
                  "const": "share-document"
                },
                "params": {
                  "$ref": "#/$defs/params-share-document"
                }
              },
              "not": {
                "required": [
                  "resumeToken"
                ]
              }
            },
            {
              "required": [
                "recipe",
                "params"
              ],
              "properties": {
                "recipe": {
                  "const": "revise-compare-discuss"
                },
                "params": {
                  "$ref": "#/$defs/params-revise-compare-discuss"
                }
              },
              "not": {
                "required": [
                  "resumeToken"
                ]
              }
            },
            {
              "required": [
                "recipe",
                "params"
              ],
              "properties": {
                "recipe": {
                  "const": "accept-and-comment"
                },
                "params": {
                  "$ref": "#/$defs/params-accept-and-comment"
                }
              },
              "not": {
                "required": [
                  "resumeToken"
                ]
              }
            },
            {
              "required": [
                "resumeToken"
              ],
              "not": {
                "required": [
                  "params"
                ]
              }
            }
          ]
        }
      }
    }
  }
}

GET /healthz

Health of the local P5 server. No session required.

Parameters, inputs and responses
{
  "operationId": "get_healthz",
  "summary": "Health of the local P5 server",
  "description": "Health of the local P5 server. No session required.",
  "x-access": "public",
  "parameters": [],
  "security": [],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": []
}

GET /api/i18n

Available catalogs and effective preferences. No session required.

Parameters, inputs and responses
{
  "operationId": "get_api_i18n",
  "summary": "Available catalogs and effective preferences",
  "description": "Available catalogs and effective preferences. No session required.",
  "x-access": "public",
  "parameters": [
    {
      "name": "lang",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": []
}

GET /api/auth/challenge

Issue a registration proof-of-work challenge. No session required.

Parameters, inputs and responses
{
  "operationId": "get_api_auth_challenge",
  "summary": "Issue a registration proof-of-work challenge",
  "description": "Issue a registration proof-of-work challenge. No session required.",
  "x-access": "public",
  "parameters": [],
  "security": [],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/RegistrationChallenge"
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "registration-challenge"
  ]
}

POST /api/auth/register

Register; create organization and verification message. No session required. In closed beta, invitationToken (matching live invitation email) or betaToken (operator allowlist, matching email) is required before PoW. Admission tokens are consumed atomically.

Parameters, inputs and responses
{
  "operationId": "post_api_auth_register",
  "summary": "Register; create organization and verification message",
  "description": "Register; create organization and verification message. No session required. In closed beta, invitationToken (matching live invitation email) or betaToken (operator allowlist, matching email) is required before PoW. Admission tokens are consumed atomically.",
  "x-access": "public",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "register"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "username": {
              "type": "string"
            },
            "email": {
              "type": "string",
              "format": "email"
            },
            "password": {
              "type": "string",
              "minLength": 12
            },
            "work": {
              "type": "object",
              "required": [
                "id",
                "solution"
              ],
              "properties": {
                "id": {
                  "type": "string"
                },
                "solution": {
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 9007199254740991
                }
              }
            },
            "organization": {
              "type": "string"
            },
            "uiLocale": {
              "type": "string"
            },
            "invitationToken": {
              "type": "string"
            },
            "betaToken": {
              "type": "string"
            }
          },
          "required": [
            "email",
            "password",
            "work"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/auth/login

Create a session cookie. No session required.

Parameters, inputs and responses
{
  "operationId": "post_api_auth_login",
  "summary": "Create a session cookie",
  "description": "Create a session cookie. No session required.",
  "x-access": "public",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "login"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "username": {
              "type": "string"
            },
            "password": {
              "type": "string",
              "minLength": 12
            }
          },
          "required": [
            "username",
            "password"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/auth/recover

Rotate optional recovery code and invalidate all sessions. No session required.

Parameters, inputs and responses
{
  "operationId": "post_api_auth_recover",
  "summary": "Rotate optional recovery code and invalidate all sessions",
  "description": "Rotate optional recovery code and invalidate all sessions. No session required.",
  "x-access": "public",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "recover-account"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "username": {
              "type": "string"
            },
            "recoveryCode": {
              "type": "string"
            },
            "password": {
              "type": "string",
              "minLength": 12
            }
          },
          "required": [
            "username",
            "recoveryCode",
            "password"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/auth/reset/request

Request a reset; response does not reveal whether the address exists. No session required.

Parameters, inputs and responses
{
  "operationId": "post_api_auth_reset_request",
  "summary": "Request a reset; response does not reveal whether the address exists",
  "description": "Request a reset; response does not reveal whether the address exists. No session required.",
  "x-access": "public",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "request-password-reset"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "email": {
              "type": "string",
              "format": "email"
            }
          },
          "required": [
            "email"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/auth/reset

Consume reset token and invalidate sessions. No session required.

Parameters, inputs and responses
{
  "operationId": "post_api_auth_reset",
  "summary": "Consume reset token and invalidate sessions",
  "description": "Consume reset token and invalidate sessions. No session required.",
  "x-access": "public",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "reset-password"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "token": {
              "type": "string"
            },
            "password": {
              "type": "string",
              "minLength": 12
            }
          },
          "required": [
            "token",
            "password"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/auth/verify

Consume email verification token. No session required.

Parameters, inputs and responses
{
  "operationId": "post_api_auth_verify",
  "summary": "Consume email verification token",
  "description": "Consume email verification token. No session required.",
  "x-access": "public",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              },
              "ok": {
                "const": true
              },
              "uiLocale": {
                "type": "string"
              },
              "redirect": {
                "type": "string",
                "description": "Relative workspace URL with the verified user’s stored UI locale."
              }
            },
            "additionalProperties": true,
            "required": [
              "ok",
              "uiLocale",
              "redirect",
              "next"
            ]
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "verify-email"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "token": {
              "type": "string"
            }
          },
          "required": [
            "token"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/auth/oauth

Disabled identity adapter (mock contract, not OAuth authorization server). No session required.

Parameters, inputs and responses
{
  "operationId": "post_api_auth_oauth",
  "summary": "Disabled identity adapter (mock contract, not OAuth authorization server)",
  "description": "Disabled identity adapter (mock contract, not OAuth authorization server). No session required.",
  "x-access": "public",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {},
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/billing/webhook

Process signed raw subscription event; current transport is mock-only. Raw-body signature verified; session and CSRF header not used.

Parameters, inputs and responses
{
  "operationId": "post_api_billing_webhook",
  "summary": "Process signed raw subscription event; current transport is mock-only",
  "description": "Process signed raw subscription event; current transport is mock-only. Raw-body signature verified; session and CSRF header not used.",
  "x-access": "webhook",
  "parameters": [
    {
      "name": "stripe-signature",
      "in": "header",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/me/mail

Read only own addressed local mock messages. Session cookie required; email verification not required.

Parameters, inputs and responses
{
  "operationId": "get_api_me_mail",
  "summary": "Read only own addressed local mock messages",
  "description": "Read only own addressed local mock messages. Session cookie required; email verification not required.",
  "x-access": "session",
  "parameters": [],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "read-mail"
  ]
}

POST /api/auth/verify/resend

Resend verification using configured local message adapter. Session cookie required; email verification not required.

Parameters, inputs and responses
{
  "operationId": "post_api_auth_verify_resend",
  "summary": "Resend verification using configured local message adapter",
  "description": "Resend verification using configured local message adapter. Session cookie required; email verification not required.",
  "x-access": "session",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "resend-verification"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {},
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/auth/logout

Invalidate this session cookie. Session cookie required; email verification not required.

Parameters, inputs and responses
{
  "operationId": "post_api_auth_logout",
  "summary": "Invalidate this session cookie",
  "description": "Invalidate this session cookie. Session cookie required; email verification not required.",
  "x-access": "session",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "logout"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {},
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/auth/password

Change password and invalidate sessions. Session cookie required; email verification not required.

Parameters, inputs and responses
{
  "operationId": "post_api_auth_password",
  "summary": "Change password and invalidate sessions",
  "description": "Change password and invalidate sessions. Session cookie required; email verification not required.",
  "x-access": "session",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "change-password"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "currentPassword": {
              "type": "string"
            },
            "password": {
              "type": "string",
              "minLength": 12
            }
          },
          "required": [
            "currentPassword",
            "password"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/me

Read profile, authorized organizations and feature configuration. Session cookie required; email verification not required.

Parameters, inputs and responses
{
  "operationId": "get_api_me",
  "summary": "Read profile, authorized organizations and feature configuration",
  "description": "Read profile, authorized organizations and feature configuration. Session cookie required; email verification not required.",
  "x-access": "session",
  "parameters": [],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": []
}

PATCH /api/me

Change display name and UI locale. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "patch_api_me",
  "summary": "Change display name and UI locale",
  "description": "Change display name and UI locale. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "verified",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "update-profile"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "displayName": {
              "type": "string"
            },
            "uiLocale": {
              "type": "string"
            }
          },
          "additionalProperties": true
        }
      }
    }
  }
}

DELETE /api/me

Irreversibly delete account and owned organizations. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "delete_api_me",
  "summary": "Irreversibly delete account and owned organizations",
  "description": "Irreversibly delete account and owned organizations. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "verified",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "delete-account"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "confirm": {
              "const": "DELETE"
            },
            "password": {
              "type": "string",
              "minLength": 12
            }
          },
          "required": [
            "confirm",
            "password"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/auth/recovery-code

Create optional recovery code. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_auth_recovery_code",
  "summary": "Create optional recovery code",
  "description": "Create optional recovery code. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "verified",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "generate-recovery-code"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "password": {
              "type": "string",
              "minLength": 12
            }
          },
          "required": [
            "password"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/me/email

Request email change. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_me_email",
  "summary": "Request email change",
  "description": "Request email change. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "verified",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "change-email"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "email": {
              "type": "string",
              "format": "email"
            },
            "password": {
              "type": "string",
              "minLength": 12
            }
          },
          "required": [
            "email",
            "password"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/me/email/confirm

Confirm own pending email change; invalidate sessions. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_me_email_confirm",
  "summary": "Confirm own pending email change; invalidate sessions",
  "description": "Confirm own pending email change; invalidate sessions. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "verified",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "confirm-email"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "token": {
              "type": "string"
            }
          },
          "required": [
            "token"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/me/export

Export own profile, memberships and contributions. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_me_export",
  "summary": "Export own profile, memberships and contributions",
  "description": "Export own profile, memberships and contributions. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "verified",
  "parameters": [],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "export-account"
  ]
}

POST /api/organizations

Create an organization subject to workspace limits. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_organizations",
  "summary": "Create an organization subject to workspace limits",
  "description": "Create an organization subject to workspace limits. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "verified",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "create-organization"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "name": {
              "type": "string"
            }
          },
          "required": [
            "name"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/invitations/accept

Accept invitation for the verified recipient address. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_invitations_accept",
  "summary": "Accept invitation for the verified recipient address",
  "description": "Accept invitation for the verified recipient address. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "verified",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "accept-invitation"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "token": {
              "type": "string"
            }
          },
          "required": [
            "token"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

DELETE /api/invitations/{invitationId}

Revoke invitation and resulting access. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "delete_api_invitations_invitationId_",
  "summary": "Revoke invitation and resulting access",
  "description": "Revoke invitation and resulting access. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "invitationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "revoke-invitation"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {},
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/organizations/{organizationId}

Read authorized organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_organizations_organizationId_",
  "summary": "Read authorized organization",
  "description": "Read authorized organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "member",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "read-organization"
  ]
}

PATCH /api/organizations/{organizationId}

Update organization name or default-off MCP consent (not OAuth activation). Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "patch_api_organizations_organizationId_",
  "summary": "Update organization name or default-off MCP consent (not OAuth activation)",
  "description": "Update organization name or default-off MCP consent (not OAuth activation). Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "update-organization"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "name": {
              "type": "string"
            },
            "mcpEnabled": {
              "type": "boolean",
              "description": "Owner-controlled consent, false by default. Other credential, entitlement and meter gates remain closed."
            }
          },
          "additionalProperties": true
        }
      }
    }
  }
}

DELETE /api/organizations/{organizationId}

Irreversibly delete organization and its data. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "delete_api_organizations_organizationId_",
  "summary": "Irreversibly delete organization and its data",
  "description": "Irreversibly delete organization and its data. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "delete-organization"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "confirm": {
              "const": "DELETE"
            },
            "password": {
              "type": "string",
              "minLength": 12
            }
          },
          "required": [
            "confirm",
            "password"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/organizations/{organizationId}/billing

Read billing and mock subscription history. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_organizations_organizationId_billing",
  "summary": "Read billing and mock subscription history",
  "description": "Read billing and mock subscription history. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "read-billing"
  ]
}

PUT /api/organizations/{organizationId}/billing

Update billing details. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "put_api_organizations_organizationId_billing",
  "summary": "Update billing details",
  "description": "Update billing details. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "update-billing"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "name": {
              "type": "string"
            },
            "address": {
              "type": "string"
            },
            "companyId": {
              "type": "string"
            },
            "vatId": {
              "type": "string"
            },
            "email": {
              "anyOf": [
                {
                  "type": "string",
                  "format": "email"
                },
                {
                  "const": ""
                }
              ]
            }
          },
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/organizations/{organizationId}/subscribe

Create mock checkout (paid/pro only; no real checkout transport). Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_organizations_organizationId_subscribe",
  "summary": "Create mock checkout (paid/pro only; no real checkout transport)",
  "description": "Create mock checkout (paid/pro only; no real checkout transport). Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "upgrade-plan"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "plan": {
              "enum": [
                "paid",
                "pro"
              ]
            }
          },
          "required": [
            "plan"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/organizations/{organizationId}/mock-activate

Activate pending mock subscription; denied unless mock provider. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_organizations_organizationId_mock_activate",
  "summary": "Activate pending mock subscription; denied unless mock provider",
  "description": "Activate pending mock subscription; denied unless mock provider. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "activate-mock"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {},
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/organizations/{organizationId}/cancel

Cancel subscription through configured adapter. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_organizations_organizationId_cancel",
  "summary": "Cancel subscription through configured adapter",
  "description": "Cancel subscription through configured adapter. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "cancel-subscription"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {},
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/organizations/{organizationId}/invitations

List invitations in own organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_organizations_organizationId_invitations",
  "summary": "List invitations in own organization",
  "description": "List invitations in own organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "list-invitations"
  ]
}

POST /api/organizations/{organizationId}/invitations

Invite verified recipient to organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_organizations_organizationId_invitations",
  "summary": "Invite verified recipient to organization",
  "description": "Invite verified recipient to organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "invite-member"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "email": {
              "type": "string",
              "format": "email"
            },
            "role": {
              "enum": [
                "viewer",
                "commenter",
                "editor"
              ]
            },
            "locale": {
              "type": "string"
            }
          },
          "required": [
            "email",
            "role"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/organizations/{organizationId}/access

List members in own organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_organizations_organizationId_access",
  "summary": "List members in own organization",
  "description": "List members in own organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "list-members"
  ]
}

DELETE /api/organizations/{organizationId}/access

Revoke member and their document grants; cannot remove owner. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "delete_api_organizations_organizationId_access",
  "summary": "Revoke member and their document grants; cannot remove owner",
  "description": "Revoke member and their document grants; cannot remove owner. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "revoke-member"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "userId": {
              "type": "string"
            }
          },
          "required": [
            "userId"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/organizations/{organizationId}/export

Export organization documents, versions and visible collaboration. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_organizations_organizationId_export",
  "summary": "Export organization documents, versions and visible collaboration",
  "description": "Export organization documents, versions and visible collaboration. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "organizationId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "export-organization"
  ]
}

GET /api/preferences

Read user and optional document preferences. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_preferences",
  "summary": "Read user and optional document preferences",
  "description": "Read user and optional document preferences. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "verified",
  "parameters": [
    {
      "name": "projectId",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": []
}

PUT /api/preferences

Update user or editable document language preferences. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "put_api_preferences",
  "summary": "Update user or editable document language preferences",
  "description": "Update user or editable document language preferences. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "editor",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    },
    {
      "name": "projectId",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "update-preferences"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "uiLocale": {
              "type": [
                "string",
                "null"
              ]
            },
            "responseLanguage": {
              "type": [
                "string",
                "null"
              ]
            },
            "documentLocale": {
              "type": [
                "string",
                "null"
              ]
            }
          },
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/projects

List only authorized documents (P5 calls each document a project). Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_projects",
  "summary": "List only authorized documents (P5 calls each document a project)",
  "description": "List only authorized documents (P5 calls each document a project). Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "verified",
  "parameters": [],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "required": [
              "items",
              "cloudImportAvailable"
            ],
            "properties": {
              "cloudImportAvailable": {
                "const": false
              },
              "items": {
                "type": "array",
                "items": {
                  "type": "object",
                  "required": [
                    "id",
                    "title",
                    "versions",
                    "updatedAt",
                    "versionCount",
                    "lastVersionAt",
                    "accessCount",
                    "organizationId",
                    "role"
                  ],
                  "properties": {
                    "id": {
                      "type": "string"
                    },
                    "title": {
                      "type": "string"
                    },
                    "versions": {
                      "type": "array",
                      "items": {
                        "type": "object",
                        "additionalProperties": true
                      }
                    },
                    "updatedAt": {
                      "type": "string"
                    },
                    "versionCount": {
                      "type": "integer",
                      "minimum": 1
                    },
                    "lastVersionAt": {
                      "type": "string"
                    },
                    "accessCount": {
                      "type": "integer",
                      "minimum": 1,
                      "description": "Distinct users with effective organization membership or explicit document access; pending invitations are not access."
                    },
                    "organizationId": {
                      "type": "string"
                    },
                    "role": {
                      "type": "string"
                    }
                  },
                  "additionalProperties": true
                }
              }
            },
            "additionalProperties": false
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "list-documents"
  ]
}

POST /api/projects

Create a document in an editable organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_projects",
  "summary": "Create a document in an editable organization",
  "description": "Create a document in an editable organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "editor",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "create-document"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "orgId": {
              "type": "string"
            },
            "title": {
              "type": "string"
            },
            "document": {
              "$ref": "#/components/schemas/Document"
            },
            "documentLocale": {
              "type": "string"
            }
          },
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/import

Import raw local file into an editable organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_import",
  "summary": "Import raw local file into an editable organization",
  "description": "Import raw local file into an editable organization. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "editor",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    },
    {
      "name": "orgId",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "filename",
      "in": "query",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "provider",
      "in": "query",
      "required": false,
      "schema": {
        "const": "local"
      }
    },
    {
      "name": "documentLocale",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "documentLanguage",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "import-document"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/octet-stream": {
        "schema": {
          "type": "string",
          "format": "binary"
        }
      }
    }
  }
}

POST /api/export/docx

Export an authorized document as DOCX; counts egress. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_export_docx",
  "summary": "Export an authorized document as DOCX; counts egress",
  "description": "Export an authorized document as DOCX; counts egress. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "reader",
  "parameters": [
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/vnd.openxmlformats-officedocument.wordprocessingml.document": {
          "schema": {
            "type": "string",
            "format": "binary"
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "export-docx"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "projectId": {
              "type": "string"
            }
          },
          "required": [
            "projectId"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/projects/{documentId}

Read authorized document and version metadata. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_projects_documentId_",
  "summary": "Read authorized document and version metadata",
  "description": "Read authorized document and version metadata. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "reader",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "version",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "read-document"
  ]
}

DELETE /api/projects/{documentId}

Irreversibly delete document (owner only; existing API has no confirmation field). Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "delete_api_projects_documentId_",
  "summary": "Irreversibly delete document (owner only; existing API has no confirmation field)",
  "description": "Irreversibly delete document (owner only; existing API has no confirmation field). Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "delete-document"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {},
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/projects/{documentId}/versions

Read selected/current document and all version metadata. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_projects_documentId_versions",
  "summary": "Read selected/current document and all version metadata",
  "description": "Read selected/current document and all version metadata. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "reader",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "version",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "list-versions"
  ]
}

POST /api/projects/{documentId}/versions

Save immutable version with optimistic concurrency. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_projects_documentId_versions",
  "summary": "Save immutable version with optimistic concurrency",
  "description": "Save immutable version with optimistic concurrency. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "editor",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "create-version"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "document": {
              "$ref": "#/components/schemas/Document"
            },
            "baseVersion": {
              "type": "string"
            }
          },
          "required": [
            "document",
            "baseVersion"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

POST /api/projects/{documentId}/versions/upload

Import binary DOCX atomically as an immutable version in the same document; matching baseVersion is required. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_projects_documentId_versions_upload",
  "summary": "Import binary DOCX atomically as an immutable version in the same document; matching baseVersion is required",
  "description": "Import binary DOCX atomically as an immutable version in the same document; matching baseVersion is required. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "editor",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    },
    {
      "name": "filename",
      "in": "query",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "baseVersion",
      "in": "query",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "upload-document-version"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/octet-stream": {
        "schema": {
          "type": "string",
          "format": "binary"
        }
      }
    }
  }
}

GET /api/projects/{documentId}/versions/diff

Read structural differences between two authorized immutable versions. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_projects_documentId_versions_diff",
  "summary": "Read structural differences between two authorized immutable versions",
  "description": "Read structural differences between two authorized immutable versions. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "reader",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "version",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "fromVersion",
      "in": "query",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "toVersion",
      "in": "query",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "required": [
              "changes"
            ],
            "properties": {
              "changes": {
                "type": "array",
                "items": {
                  "type": "object",
                  "required": [
                    "path",
                    "before",
                    "after"
                  ],
                  "properties": {
                    "path": {
                      "type": "string"
                    },
                    "before": {},
                    "after": {}
                  }
                }
              }
            }
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "read-version-diff"
  ]
}

GET /api/projects/{documentId}/download

Download selected document as JSON or HTML. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_projects_documentId_download",
  "summary": "Download selected document as JSON or HTML",
  "description": "Download selected document as JSON or HTML. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "reader",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "version",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "format",
      "in": "query",
      "required": false,
      "schema": {
        "enum": [
          "json",
          "html"
        ]
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/octet-stream": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        },
        "text/html": {
          "schema": {
            "type": "string"
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "export-document"
  ]
}

POST /api/projects/{documentId}/invitations

Invite recipient to document. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_projects_documentId_invitations",
  "summary": "Invite recipient to document",
  "description": "Invite recipient to document. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "invite-counterparty"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "email": {
              "type": "string",
              "format": "email"
            },
            "role": {
              "enum": [
                "viewer",
                "commenter",
                "editor"
              ]
            },
            "locale": {
              "type": "string"
            }
          },
          "required": [
            "email",
            "role"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/projects/{documentId}/access

List explicit document grants. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_projects_documentId_access",
  "summary": "List explicit document grants",
  "description": "List explicit document grants. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "version",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "list-document-access"
  ]
}

DELETE /api/projects/{documentId}/access

Revoke explicit document grant. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "delete_api_projects_documentId_access",
  "summary": "Revoke explicit document grant",
  "description": "Revoke explicit document grant. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "owner",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "revoke-document-access"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "userId": {
              "type": "string"
            }
          },
          "required": [
            "userId"
          ],
          "additionalProperties": true
        }
      }
    }
  }
}

GET /api/projects/{documentId}/collaboration

Read role-filtered annotations and threads. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "get_api_projects_documentId_collaboration",
  "summary": "Read role-filtered annotations and threads",
  "description": "Read role-filtered annotations and threads. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "reader",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "version",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/CollaborationState"
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "read-collaboration"
  ]
}

POST /api/projects/{documentId}/collaboration

Apply collaboration event with M09 ownership and visibility checks. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_projects_documentId_collaboration",
  "summary": "Apply collaboration event with M09 ownership and visibility checks",
  "description": "Apply collaboration event with M09 ownership and visibility checks. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "commenter",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    },
    {
      "name": "version",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "add-comment",
    "add-annotation"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/CollaborationEvent"
        }
      }
    }
  }
}

POST /api/projects/{documentId}/ai

Run a server-selected model role or explicit mechanical operation over this authorized document; store a private annotation with visible provenance. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.

Parameters, inputs and responses
{
  "operationId": "post_api_projects_documentId_ai",
  "summary": "Run a server-selected model role or explicit mechanical operation over this authorized document; store a private annotation with visible provenance",
  "description": "Run a server-selected model role or explicit mechanical operation over this authorized document; store a private annotation with visible provenance. Session cookie required; verified email required. Tenant and role authorization is enforced server-side; inaccessible resources return NOT_FOUND.",
  "x-access": "editor",
  "parameters": [
    {
      "name": "documentId",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": true,
      "schema": {
        "const": "1"
      }
    },
    {
      "name": "version",
      "in": "query",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    }
  ],
  "responses": {
    "200": {
      "description": "Successful operation",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "required": [
              "answer",
              "role",
              "stage",
              "model",
              "provider",
              "degraded",
              "indicator"
            ],
            "properties": {
              "answer": {
                "type": "string"
              },
              "role": {
                "type": "string"
              },
              "stage": {
                "type": "string"
              },
              "model": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "provider": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "degraded": {
                "type": "boolean"
              },
              "indicator": {
                "type": "string"
              },
              "data": {
                "type": "object",
                "additionalProperties": true
              },
              "next": {
                "type": "array",
                "items": {
                  "$ref": "#/components/schemas/AgentAction"
                }
              }
            },
            "additionalProperties": true
          }
        }
      }
    },
    "429": {
      "description": "Plan ceiling reached (PLAN_LIMIT), or request rate limit (RATE_LIMIT).",
      "content": {
        "application/json": {
          "schema": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/PlanLimit"
              },
              {
                "$ref": "#/components/schemas/Error"
              }
            ]
          }
        }
      }
    },
    "default": {
      "$ref": "#/components/responses/Error"
    }
  },
  "x-agent-action-ids": [
    "ask-ai",
    "run-mechanical"
  ],
  "requestBody": {
    "required": false,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "question": {
              "type": "string",
              "maxLength": 4000
            },
            "role": {
              "type": "string",
              "description": "Role ID from aiRoles in the authorized GET document response; default chat. Roles are server-configured, not model selectors."
            },
            "operation": {
              "enum": [
                "format",
                "numbering",
                "table",
                "diff",
                "anchors",
                "duplicates",
                "search"
              ]
            },
            "execution": {
              "enum": [
                "model",
                "deterministic"
              ],
              "default": "model"
            },
            "blockId": {
              "type": "string"
            },
            "compareVersion": {
              "type": "string",
              "description": "For diff: another version of the same authorized document."
            }
          },
          "additionalProperties": true
        }
      }
    }
  }
}

POST /mcp

Authenticated MCP JSON-RPC resource for an organization-bound credential. Local credentials are organization-bound and checked against the current verified session, owner opt-in and active paid/pro entitlement (or unmetered selfhost). Every tool reuses product authorization and limits. This is not a hosted OAuth authorization server. Runtime availability is separate from action-to-tool contract mapping. GET/DELETE return 405. See /mcp-setup.

Parameters, inputs and responses
{
  "operationId": "post_mcp",
  "summary": "Authenticated MCP JSON-RPC resource for an organization-bound credential",
  "description": "Authenticated MCP JSON-RPC resource for an organization-bound credential. Local credentials are organization-bound and checked against the current verified session, owner opt-in and active paid/pro entitlement (or unmetered selfhost). Every tool reuses product authorization and limits. This is not a hosted OAuth authorization server. Runtime availability is separate from action-to-tool contract mapping. GET/DELETE return 405. See /mcp-setup.",
  "x-access": "mcp",
  "parameters": [
    {
      "name": "Accept",
      "in": "header",
      "required": true,
      "schema": {
        "const": "application/json, text/event-stream"
      }
    },
    {
      "name": "MCP-Protocol-Version",
      "in": "header",
      "required": true,
      "schema": {
        "const": "2026-07-28"
      }
    },
    {
      "name": "Mcp-Method",
      "in": "header",
      "required": true,
      "schema": {
        "enum": [
          "initialize",
          "notifications/initialized",
          "ping",
          "server/discover",
          "tools/list",
          "tools/call"
        ]
      }
    },
    {
      "name": "Mcp-Name",
      "in": "header",
      "required": false,
      "schema": {
        "type": "string"
      }
    }
  ],
  "security": [
    {
      "mcpBearer": []
    }
  ],
  "responses": {
    "200": {
      "description": "JSON-RPC response; tool failures use result.isError and structuredContent.error. Authorized organization calls only.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "400": {
      "description": "Malformed protocol request or headers.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "401": {
      "description": "Missing credential or revoked access.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "403": {
      "description": "Origin or permission denied.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "405": {
      "description": "Only POST supported.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "406": {
      "description": "Accept header must include JSON and event-stream.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "413": {
      "description": "Request body too large.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "415": {
      "description": "Content-Type must be application/json.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "503": {
      "description": "Runtime temporarily unavailable; adapters fail closed.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    }
  },
  "x-agent-action-ids": [],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "required": [
            "jsonrpc",
            "method"
          ],
          "properties": {
            "jsonrpc": {
              "const": "2.0"
            },
            "id": {
              "type": [
                "string",
                "integer"
              ]
            },
            "method": {
              "enum": [
                "initialize",
                "notifications/initialized",
                "ping",
                "server/discover",
                "tools/list",
                "tools/call"
              ]
            },
            "params": {
              "type": "object",
              "properties": {
                "_meta": {
                  "type": "object",
                  "required": [
                    "io.modelcontextprotocol/protocolVersion",
                    "io.modelcontextprotocol/clientCapabilities"
                  ],
                  "properties": {
                    "io.modelcontextprotocol/protocolVersion": {
                      "const": "2026-07-28"
                    },
                    "io.modelcontextprotocol/clientCapabilities": {
                      "type": "object",
                      "additionalProperties": true
                    }
                  }
                },
                "name": {
                  "type": "string"
                },
                "arguments": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          }
        }
      }
    }
  }
}

POST /mcp/token

Issue an organization MCP token using an authorized session, or invoke the bearer JSON-RPC bridge. Local credentials are organization-bound and checked against the current verified session, owner opt-in and active paid/pro entitlement (or unmetered selfhost). Every tool reuses product authorization and limits. This is not a hosted OAuth authorization server. Runtime availability is separate from action-to-tool contract mapping. GET/DELETE return 405. See /mcp-setup.

Parameters, inputs and responses
{
  "operationId": "post_mcp_token",
  "summary": "Issue an organization MCP token using an authorized session, or invoke the bearer JSON-RPC bridge",
  "description": "Issue an organization MCP token using an authorized session, or invoke the bearer JSON-RPC bridge. Local credentials are organization-bound and checked against the current verified session, owner opt-in and active paid/pro entitlement (or unmetered selfhost). Every tool reuses product authorization and limits. This is not a hosted OAuth authorization server. Runtime availability is separate from action-to-tool contract mapping. GET/DELETE return 405. See /mcp-setup.",
  "x-access": "mcp",
  "parameters": [
    {
      "name": "Accept",
      "in": "header",
      "required": false,
      "schema": {
        "const": "application/json, text/event-stream"
      }
    },
    {
      "name": "MCP-Protocol-Version",
      "in": "header",
      "required": false,
      "schema": {
        "const": "2026-07-28"
      }
    },
    {
      "name": "Mcp-Method",
      "in": "header",
      "required": false,
      "schema": {
        "enum": [
          "initialize",
          "notifications/initialized",
          "ping",
          "server/discover",
          "tools/list",
          "tools/call"
        ]
      }
    },
    {
      "name": "Mcp-Name",
      "in": "header",
      "required": false,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "x-zentro-request",
      "in": "header",
      "required": false,
      "schema": {
        "const": "1",
        "description": "Required when issuing a token with the session cookie."
      }
    }
  ],
  "security": [
    {
      "sessionCookie": []
    },
    {
      "mcpBearer": []
    }
  ],
  "responses": {
    "200": {
      "description": "Token issuance returns the token once, orgId and expires; JSON-RPC returns an MCP response.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "400": {
      "description": "Malformed protocol request or headers.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "401": {
      "description": "Missing credential or revoked access.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "403": {
      "description": "Origin or permission denied.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "405": {
      "description": "Only POST supported.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "406": {
      "description": "Accept header must include JSON and event-stream.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "413": {
      "description": "Request body too large.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "415": {
      "description": "Content-Type must be application/json.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    },
    "503": {
      "description": "Runtime temporarily unavailable; adapters fail closed.",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "additionalProperties": true
          }
        }
      }
    }
  },
  "x-agent-action-ids": [
    "issue-mcp-token"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "oneOf": [
            {
              "type": "object",
              "required": [
                "orgId"
              ],
              "properties": {
                "orgId": {
                  "type": "string"
                }
              },
              "additionalProperties": false
            },
            {
              "type": "object",
              "required": [
                "jsonrpc",
                "method"
              ],
              "properties": {
                "jsonrpc": {
                  "const": "2.0"
                },
                "id": {
                  "type": [
                    "string",
                    "integer"
                  ]
                },
                "method": {
                  "enum": [
                    "initialize",
                    "notifications/initialized",
                    "ping",
                    "server/discover",
                    "tools/list",
                    "tools/call"
                  ]
                },
                "params": {
                  "type": "object",
                  "properties": {
                    "_meta": {
                      "type": "object",
                      "required": [
                        "io.modelcontextprotocol/protocolVersion",
                        "io.modelcontextprotocol/clientCapabilities"
                      ],
                      "properties": {
                        "io.modelcontextprotocol/protocolVersion": {
                          "const": "2026-07-28"
                        },
                        "io.modelcontextprotocol/clientCapabilities": {
                          "type": "object",
                          "additionalProperties": true
                        }
                      }
                    },
                    "name": {
                      "type": "string"
                    },
                    "arguments": {
                      "type": "object",
                      "additionalProperties": true
                    }
                  }
                }
              }
            }
          ]
        }
      }
    }
  }
}