{"openapi":"3.1.0","info":{"title":"Inth API","version":"1.0.0","description":"Control-plane API for Inth organizations, members, projects, and API keys. Consent settings live on the project.\n\nResource IDs are prefixed strings (`org_` organizations, `prj_` projects, `key_` API keys). Treat them as opaque; the prefix only tells you what kind of resource an ID refers to.\n\nProduct operations require a scope. Feedback intake only requires authentication. Organization API keys carry a fixed set; user tokens carry the scopes approved at sign-in. `GET /v1/me` lists them.\n\nResources are top-level and IDs are global. Lists and creates take an optional `organizationId` query parameter and default to the active organization of the credential; a resource fetched by ID resolves its own organization, and one outside your memberships answers 404.\n\nAuthenticated responses include `X-RateLimit-Limit`, `X-RateLimit-Remaining`, and `X-RateLimit-Reset` (Unix seconds) so clients can pace themselves before hitting 429s. Every response carries an `X-Request-Id` header; include it when reporting issues.\n\nWithin v1 changes are additive: new fields, new endpoints, and new enum values may appear at any time, and clients should ignore fields they do not recognize. Breaking changes ship under a new version prefix.\n\nDeprecation policy: https://inth.com/docs/rest-api#versioning-and-deprecation. Deprecation notices document affected versions or endpoints, replacements, migration instructions, and planned retirement dates. No retirement date is announced for v1 and no minimum notice period is guaranteed."},"servers":[{"url":"https://api.inth.com","description":"Configured API base URL"}],"tags":[{"name":"Feedback","description":"Report problems and suggestions to the Inth team."},{"name":"System","description":"Health and service metadata."},{"name":"Organizations","description":"Organizations the credential can reach."},{"name":"Members","description":"Organization members and pending invitations."},{"name":"Projects","description":"Projects and their consent settings. A project is the top-level container for Inth products such as Consent."},{"name":"API keys","description":"Organization API keys."},{"name":"Code Audit","description":"Repository scans and their findings. A scan runs on the production branch of a connected repository; the first scan of a repository is a free preview that can be unlocked with credits."},{"name":"Inbox","description":"The organization queue of findings across Code Audit and other sources, with the status a person sets on each."},{"name":"Billing","description":"Plan and credit balance, read only."},{"name":"MCP","description":"Model Context Protocol endpoint for agent clients. Unlike the REST routes it speaks JSON-RPC and authenticates with a user-delegated OAuth access token."}],"paths":{"/v1/feedback":{"post":{"tags":["Feedback"],"summary":"Submit agent feedback","operationId":"submitAgentFeedback","description":"Report unexpected Inth failures, misleading documentation, missing capabilities, or workarounds. Include expected and actual behavior and an optional request ID. Submit once per distinct issue and continue the original task if reporting fails. Do not report routine validation errors or include credentials, personal data, customer payloads, or full transcripts. Reports go to the Inth team; follow the user's permission to send feedback. Accepts an API key or OAuth bearer without a product scope or organization role. No credits charged. Ten new reports per caller per UTC clock hour. Resubmitting identical content within a UTC day returns the existing reference with 200 and does not consume that quota.","security":[{"bearerAuth":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AgentFeedbackSubmission"},"examples":{"default":{"value":{"category":"docs_mismatch","surface":"api","message":"The documented example returns a validation error.","operation":"POST /v1/projects","expected":"The documented example creates a project.","actual":"The API rejects the example payload."}}}}}},"responses":{"200":{"description":"Identical report already accepted today. alreadySubmitted is true.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/AgentFeedbackResult"}}}}}},"201":{"description":"Report saved to the Inth feedback inbox.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/AgentFeedbackResult"}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"413":{"description":"Request exceeds 64 KB.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"},"503":{"description":"Feedback submissions are temporarily paused.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}}}}},"/health":{"get":{"tags":["System"],"summary":"Health check","operationId":"getHealth","responses":{"200":{"description":"API service is healthy.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/Health"}}},"examples":{"default":{"value":{"success":true,"data":{"ok":true}}}}}}},"503":{"description":"API service is unavailable.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"default":{"value":{"success":false,"error":{"code":"SERVICE_UNAVAILABLE","message":"Service unavailable"}}}}}}}}}},"/mcp":{"post":{"tags":["MCP"],"summary":"Send MCP message","description":"Streamable HTTP endpoint for the Model Context Protocol. It serves the 2026-07-28 revision natively and falls back to stateless 2025-era Streamable HTTP for older clients.\n\nEach POST carries one JSON-RPC message; batch arrays are not part of either served transport revision.\n\nThe bearer must be a user-delegated OAuth access token issued by the Inth authorization server; organization API keys are rejected. Clients discover the authorization server through `/.well-known/oauth-protected-resource/mcp`, advertised on the `WWW-Authenticate` challenge of a 401.\n\nServing is stateless, so there are no sessions: `GET` and `DELETE` answer `405`.","operationId":"postMcp","security":[{"mcpOAuthBearer":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","additionalProperties":true}}}},"responses":{"200":{"description":"JSON-RPC response. Tool failures are reported in the result body, not as an HTTP status.","content":{"application/json":{"schema":{"type":"object","additionalProperties":true}},"text/event-stream":{"schema":{"type":"string"}}}},"202":{"description":"JSON-RPC notification accepted."},"400":{"description":"Malformed JSON-RPC request, invalid protocol envelope, or request/header mismatch."},"401":{"description":"Missing or invalid OAuth access token. The `WWW-Authenticate` header points to protected-resource discovery."},"403":{"description":"Valid OAuth access token without the required `mcp:tools` scope."},"429":{"description":"MCP request limit exceeded for this user and OAuth client pair.","headers":{"Retry-After":{"description":"Seconds to wait before retrying.","schema":{"type":"integer","minimum":1}}}},"500":{"description":"Internal JSON-RPC server error."}}}},"/v1/me":{"get":{"tags":["System"],"summary":"Get the calling credential","description":"Describes the credential behind the bearer token: what kind of principal it is, the scopes it carries, and the organizations it can reach.","operationId":"getMe","security":[{"bearerAuth":[]}],"responses":{"200":{"description":"The calling credential and its organizations.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/Me"}}},"examples":{"default":{"value":{"success":true,"data":{"principal":{"type":"api_key","keyId":"key_123","organizationId":"org_123","createdBy":"usr_123"},"activeOrganizationId":"org_123","scopes":["api-keys.read","organizations.read","projects.read","projects.write"],"organizations":[{"id":"org_123","slug":"acme","name":"Acme","role":"owner"}]}}}}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/organizations":{"get":{"tags":["Organizations"],"summary":"List organizations","description":"Lists the organizations the credential can reach, with its role in each. Requires organizations.read.","operationId":"listOrganizations","security":[{"bearerAuth":[]}],"parameters":[{"name":"limit","in":"query","required":true,"description":"Page size, between 1 and 100.","schema":{"type":"integer","minimum":1,"maximum":100,"default":50},"example":50},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the previous page’s pagination.nextCursor.","schema":{"type":"string","minLength":1}}],"responses":{"200":{"description":"Organizations the credential can reach.","content":{"application/json":{"schema":{"type":"object","required":["success","data","pagination"],"properties":{"success":{"type":"boolean","const":true},"data":{"type":"array","items":{"$ref":"#/components/schemas/Organization"}},"pagination":{"$ref":"#/components/schemas/Pagination"}}},"examples":{"default":{"value":{"success":true,"data":[{"id":"org_123","slug":"acme","name":"Acme","role":"owner"}],"pagination":{"nextCursor":null,"hasMore":false}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}},"post":{"tags":["Organizations"],"summary":"Create organization","description":"Creates an organization owned by the caller, on the free plan. Requires organizations.write and a user token; organization API keys belong to one organization and are refused with 403.","operationId":"createOrganization","security":[{"bearerAuth":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateOrganizationRequest"},"examples":{"default":{"value":{"name":"Acme","slug":"acme"}}}}}},"responses":{"201":{"description":"Created organization.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/Organization"}}},"examples":{"default":{"summary":"Created organization","value":{"success":true,"data":{"id":"org_123","slug":"acme","name":"Acme","role":"owner"}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"413":{"$ref":"#/components/responses/PayloadTooLarge"},"422":{"$ref":"#/components/responses/PlanLimitReached"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/organizations/{organizationId}":{"get":{"tags":["Organizations"],"summary":"Get organization","description":"Gets one organization the credential can reach. Requires organizations.read.","operationId":"getOrganization","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"path","required":true,"description":"Organization ID.","schema":{"type":"string","minLength":1},"example":"org_123"}],"responses":{"200":{"description":"Requested organization.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/Organization"}}},"examples":{"default":{"value":{"success":true,"data":{"id":"org_123","slug":"acme","name":"Acme","role":"owner"}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/members":{"get":{"tags":["Members"],"summary":"List members","description":"Lists the members of an organization with their roles. Requires members.read. Any member of the organization can read the roster.","operationId":"listMembers","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"query","required":false,"description":"Organization to act in. Defaults to the active organization of the credential; organization API keys always act in their own.","schema":{"type":"string","minLength":1},"example":"org_123"},{"name":"limit","in":"query","required":true,"description":"Page size, between 1 and 100.","schema":{"type":"integer","minimum":1,"maximum":100,"default":50},"example":50},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the previous page’s pagination.nextCursor.","schema":{"type":"string","minLength":1}}],"responses":{"200":{"description":"Members of the organization.","content":{"application/json":{"schema":{"type":"object","required":["success","data","pagination"],"properties":{"success":{"type":"boolean","const":true},"data":{"type":"array","items":{"$ref":"#/components/schemas/Member"}},"pagination":{"$ref":"#/components/schemas/Pagination"}}},"examples":{"default":{"value":{"success":true,"data":[{"id":"mem_123","role":"admin","joinedAt":"2026-01-05T09:30:00.000Z","user":{"id":"usr_123","name":"Sam Rivera","email":"sam@acme.example","image":null}}],"pagination":{"nextCursor":null,"hasMore":false}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/members/{memberId}":{"patch":{"tags":["Members"],"summary":"Update member role","description":"Changes the role of a member. Requires members.write, a user token, and an admin or owner role. Only owners can grant or take the owner role, a member cannot change their own role, and the last owner cannot be demoted.","operationId":"updateMember","security":[{"bearerAuth":[]}],"parameters":[{"name":"memberId","in":"path","required":true,"description":"Member ID.","schema":{"type":"string","minLength":1},"example":"mem_123"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateMemberRequest"},"examples":{"default":{"value":{"role":"admin"}}}}}},"responses":{"200":{"description":"Member role was updated.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/UpdateResult"}}},"examples":{"default":{"value":{"success":true,"data":{"updated":true}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"413":{"$ref":"#/components/responses/PayloadTooLarge"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}},"delete":{"tags":["Members"],"summary":"Remove member","description":"Removes a member from the organization. Requires members.write, a user token, and an admin or owner role. Only owners can remove owners, a member cannot remove themselves, and the last owner cannot be removed.","operationId":"removeMember","security":[{"bearerAuth":[]}],"parameters":[{"name":"memberId","in":"path","required":true,"description":"Member ID.","schema":{"type":"string","minLength":1},"example":"mem_123"}],"responses":{"200":{"description":"Member was removed.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/DeleteResult"}}},"examples":{"default":{"value":{"success":true,"data":{"deleted":true}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/invitations":{"get":{"tags":["Members"],"summary":"List invitations","description":"Lists pending invitations. Requires members.read and an admin or owner role.","operationId":"listInvitations","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"query","required":false,"description":"Organization to act in. Defaults to the active organization of the credential; organization API keys always act in their own.","schema":{"type":"string","minLength":1},"example":"org_123"},{"name":"limit","in":"query","required":true,"description":"Page size, between 1 and 100.","schema":{"type":"integer","minimum":1,"maximum":100,"default":50},"example":50},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the previous page’s pagination.nextCursor.","schema":{"type":"string","minLength":1}}],"responses":{"200":{"description":"Pending invitations of the organization.","content":{"application/json":{"schema":{"type":"object","required":["success","data","pagination"],"properties":{"success":{"type":"boolean","const":true},"data":{"type":"array","items":{"$ref":"#/components/schemas/Invitation"}},"pagination":{"$ref":"#/components/schemas/Pagination"}}},"examples":{"default":{"value":{"success":true,"data":[{"id":"inv_123","email":"kim@acme.example","role":"member","status":"pending","createdAt":"2026-01-05T09:30:00.000Z","expiresAt":"2026-01-07T09:30:00.000Z","invitedBy":{"id":"usr_123","name":"Sam Rivera","email":"sam@acme.example"}}],"pagination":{"nextCursor":null,"hasMore":false}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}},"post":{"tags":["Members"],"summary":"Invite member","description":"Emails an invitation to join the organization. The invitation expires after 48 hours. Requires members.write, a user token, and an admin or owner role; only owners can invite owners. An address that is already a member or already invited answers 409.","operationId":"createInvitation","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"query","required":false,"description":"Organization to act in. Defaults to the active organization of the credential; organization API keys always act in their own.","schema":{"type":"string","minLength":1},"example":"org_123"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateInvitationRequest"},"examples":{"default":{"value":{"email":"kim@acme.example","role":"member"}}}}}},"responses":{"201":{"description":"Created invitation.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/Invitation"}}},"examples":{"default":{"value":{"success":true,"data":{"id":"inv_123","email":"kim@acme.example","role":"member","status":"pending","createdAt":"2026-01-05T09:30:00.000Z","expiresAt":"2026-01-07T09:30:00.000Z","invitedBy":{"id":"usr_123","name":"Sam Rivera","email":"sam@acme.example"}}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"413":{"$ref":"#/components/responses/PayloadTooLarge"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"},"503":{"$ref":"#/components/responses/ServiceUnavailable"}}}},"/v1/invitations/{invitationId}":{"delete":{"tags":["Members"],"summary":"Cancel invitation","description":"Cancels only a still-pending invitation. A concurrent acceptance or deletion returns 409. Requires members.write, a user token, and an admin or owner role.","operationId":"cancelInvitation","security":[{"bearerAuth":[]}],"parameters":[{"name":"invitationId","in":"path","required":true,"description":"Invitation ID.","schema":{"type":"string","minLength":1},"example":"inv_123"}],"responses":{"200":{"description":"Invitation was cancelled.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/DeleteResult"}}},"examples":{"default":{"value":{"success":true,"data":{"deleted":true}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/billing":{"get":{"tags":["Billing"],"summary":"Get billing","description":"Plan, tier, credit balance, and automatic top-up settings. Read only; purchases and plan changes stay in the dashboard. Requires billing.read.","operationId":"getBilling","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"query","required":false,"description":"Organization to act in. Defaults to the active organization of the credential; organization API keys always act in their own.","schema":{"type":"string","minLength":1},"example":"org_123"}],"responses":{"200":{"description":"Billing summary.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/Billing"}}},"examples":{"default":{"value":{"success":true,"data":{"organizationId":"org_123","tier":"starter","plan":{"name":"Startup","family":"startup","billingInterval":"month","pastDue":false},"credits":{"remaining":120,"unlimited":false},"autoTopUp":{"enabled":true,"thresholdCredits":50,"quantityCredits":100}}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/code-audit/repositories":{"get":{"tags":["Code Audit"],"summary":"List connected repositories","description":"GitHub repositories the Inth App can reach, with the projects each is linked to. Requires code-audit.read.","operationId":"listCodeAuditRepositories","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"query","required":false,"description":"Organization to act in. Defaults to the active organization of the credential; organization API keys always act in their own.","schema":{"type":"string","minLength":1},"example":"org_123"},{"name":"limit","in":"query","required":true,"description":"Page size, between 1 and 100.","schema":{"type":"integer","minimum":1,"maximum":100,"default":50},"example":50},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the previous page’s pagination.nextCursor.","schema":{"type":"string","minLength":1}}],"responses":{"200":{"description":"Connected repositories.","content":{"application/json":{"schema":{"type":"object","required":["success","data","pagination"],"properties":{"success":{"type":"boolean","const":true},"data":{"type":"array","items":{"$ref":"#/components/schemas/CodeAuditRepository"}},"pagination":{"$ref":"#/components/schemas/Pagination"}}},"examples":{"default":{"value":{"success":true,"data":[{"id":"repo_123","organizationId":"org_123","owner":"acme","name":"website","htmlUrl":"https://github.com/acme/website","defaultBranch":"main","visibility":"private","connectedAt":"2026-01-05T09:30:00.000Z","projects":[{"projectId":"prj_123","projectSlug":"website","projectName":"Website","productionBranch":"main","rootDirectory":"/","pullRequestScansEnabled":true}]}],"pagination":{"nextCursor":null,"hasMore":false}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/code-audit/scans":{"get":{"tags":["Code Audit"],"summary":"List scans","description":"Scans of the organization, newest first. Requires code-audit.read.","operationId":"listCodeAuditScans","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"query","required":false,"description":"Organization to act in. Defaults to the active organization of the credential; organization API keys always act in their own.","schema":{"type":"string","minLength":1},"example":"org_123"},{"name":"repositoryId","in":"query","required":false,"description":"Only scans of this repository.","schema":{"type":"string","minLength":1},"example":"repo_123"},{"name":"status","in":"query","required":false,"description":"Only scans in this status.","schema":{"type":"string","minLength":1},"example":"completed"},{"name":"limit","in":"query","required":true,"description":"Page size, between 1 and 100.","schema":{"type":"integer","minimum":1,"maximum":100,"default":50},"example":50},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the previous page’s pagination.nextCursor.","schema":{"type":"string","minLength":1}}],"responses":{"200":{"description":"Scans.","content":{"application/json":{"schema":{"type":"object","required":["success","data","pagination"],"properties":{"success":{"type":"boolean","const":true},"data":{"type":"array","items":{"$ref":"#/components/schemas/CodeAuditScan"}},"pagination":{"$ref":"#/components/schemas/Pagination"}}},"examples":{"default":{"value":{"success":true,"data":[{"id":"scan_123","organizationId":"org_123","repositoryId":"repo_123","repositoryName":"website","branch":"main","headCommitSha":"9fceb02d0ae598e95dc970b74767f19372d61af8","pullRequestNumber":null,"scope":"repository","trigger":"manual","status":"completed","access":"free-preview","unlockCredits":25,"findingCount":14,"issueCount":9,"progress":null,"createdAt":"2026-01-05T09:30:00.000Z","startedAt":"2026-01-05T09:30:05.000Z","completedAt":"2026-01-05T09:41:12.000Z"}],"pagination":{"nextCursor":null,"hasMore":false}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}},"post":{"tags":["Code Audit"],"summary":"Start scan","description":"Starts a scan of the production branch of a connected repository. The first scan of a repository is a free preview. Answers 202 with the scan once the workflow has created it, or with the scan request to poll when that takes longer than a few seconds. Requires code-audit.write, a user token, and an admin or owner role.","operationId":"startCodeAuditScan","security":[{"bearerAuth":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/StartCodeAuditScanRequest"},"examples":{"default":{"value":{"repositoryId":"repo_123"}}}}}},"responses":{"202":{"description":"The scan was accepted.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/CodeAuditScanStart"}}},"examples":{"started":{"summary":"Scan created","value":{"success":true,"data":{"status":"started","scan":{"id":"scan_123","organizationId":"org_123","repositoryId":"repo_123","repositoryName":"website","branch":"main","headCommitSha":"9fceb02d0ae598e95dc970b74767f19372d61af8","pullRequestNumber":null,"scope":"repository","trigger":"manual","status":"queued","access":"free-preview","unlockCredits":25,"findingCount":null,"issueCount":null,"progress":null,"createdAt":"2026-01-05T09:30:00.000Z","startedAt":"2026-01-05T09:30:05.000Z","completedAt":null}}}},"starting":{"summary":"Still dispatching","value":{"success":true,"data":{"status":"starting","preparationId":"prep_123","repositoryId":"repo_123"}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"402":{"$ref":"#/components/responses/InsufficientCredits"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"description":"A scan is already running (`SCAN_IN_PROGRESS`), the previous free preview must be unlocked first (`UNLOCK_REQUIRED`), or the repository is not linked to a project (`REPOSITORY_NOT_LINKED`).","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"inProgress":{"value":{"success":false,"error":{"code":"SCAN_IN_PROGRESS","message":"A scan of this repository is already running","details":{"scanId":"scan_122","scanStatus":"running"}}}},"unlockRequired":{"value":{"success":false,"error":{"code":"UNLOCK_REQUIRED","message":"Unlock the previous free preview before starting another scan","details":{"scanId":"scan_122","unlockCredits":25}}}}}}}},"413":{"$ref":"#/components/responses/PayloadTooLarge"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"},"503":{"$ref":"#/components/responses/ServiceUnavailable"}}}},"/v1/code-audit/scan-requests/{preparationId}":{"get":{"tags":["Code Audit"],"summary":"Get scan request","description":"Polls a scan request that answered `starting`. Requires code-audit.read or code-audit.write.","operationId":"getCodeAuditScanRequest","security":[{"bearerAuth":[]}],"parameters":[{"name":"preparationId","in":"path","required":true,"description":"Scan request ID from the start response.","schema":{"type":"string","minLength":1},"example":"prep_123"},{"name":"repositoryId","in":"query","required":true,"description":"Repository the scan was requested for.","schema":{"type":"string","minLength":1},"example":"repo_123"}],"responses":{"200":{"description":"The scan request state.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/CodeAuditScanRequestState"}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/code-audit/scans/{scanId}":{"get":{"tags":["Code Audit"],"summary":"Get scan","description":"One scan with its status, progress, counts, and whether its report is locked. Requires code-audit.read.","operationId":"getCodeAuditScan","security":[{"bearerAuth":[]}],"parameters":[{"name":"scanId","in":"path","required":true,"description":"Scan ID.","schema":{"type":"string","minLength":1},"example":"scan_123"}],"responses":{"200":{"description":"Requested scan.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/CodeAuditScan"}}},"examples":{"default":{"value":{"success":true,"data":{"id":"scan_123","organizationId":"org_123","repositoryId":"repo_123","repositoryName":"website","branch":"main","headCommitSha":"9fceb02d0ae598e95dc970b74767f19372d61af8","pullRequestNumber":null,"scope":"repository","trigger":"manual","status":"completed","access":"free-preview","unlockCredits":25,"findingCount":14,"issueCount":9,"progress":null,"createdAt":"2026-01-05T09:30:00.000Z","startedAt":"2026-01-05T09:30:05.000Z","completedAt":"2026-01-05T09:41:12.000Z"}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/code-audit/scans/{scanId}/issues":{"get":{"tags":["Code Audit"],"summary":"Get scan issues","description":"The findings of a scan. A free preview returns the visible subset with `lockedCount` and `unlockCredits`; a locked report returns counts only. Requires code-audit.read.","operationId":"getCodeAuditScanIssues","security":[{"bearerAuth":[]}],"parameters":[{"name":"scanId","in":"path","required":true,"description":"Scan ID.","schema":{"type":"string","minLength":1},"example":"scan_123"}],"responses":{"200":{"description":"Scan findings.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/CodeAuditReport"}}},"examples":{"default":{"value":{"success":true,"data":{"scanId":"scan_123","access":"free-preview","totalCount":9,"lockedCount":6,"unlockCredits":25,"priorityCounts":{"P0":0,"P1":2,"P2":5,"P3":2},"issues":[{"id":"issue_123","title":"Email addresses written to application logs","description":"The checkout handler logs the full request body, which includes the customer email.","priority":"P1","reviewPriority":"high","potentialImpact":"high","recommendation":"Redact personal data before logging the request body.","files":["apps/web/src/checkout/handler.ts"],"category":"pii-in-logs","resolution":"active","evidence":{"filePath":"apps/web/src/checkout/handler.ts","lineNumbers":[42]}}]}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/code-audit/scans/{scanId}/unlock":{"post":{"tags":["Code Audit"],"summary":"Unlock scan report","description":"Spends credits to unlock the full report of a free preview. Idempotent: an unlocked report answers `already-unlocked`. Requires code-audit.write, a user token, and an owner role.","operationId":"unlockCodeAuditScan","security":[{"bearerAuth":[]}],"parameters":[{"name":"scanId","in":"path","required":true,"description":"Scan ID.","schema":{"type":"string","minLength":1},"example":"scan_123"}],"responses":{"200":{"description":"The report is unlocked.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/CodeAuditUnlockResult"}}},"examples":{"default":{"value":{"success":true,"data":{"status":"unlocked"}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"402":{"$ref":"#/components/responses/InsufficientCredits"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"},"503":{"$ref":"#/components/responses/ServiceUnavailable"}}}},"/v1/inbox":{"get":{"tags":["Inbox"],"summary":"List Inbox items","description":"Findings in the Inbox, most recently updated first. Requires inbox.read.","operationId":"listInboxItems","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"query","required":false,"description":"Organization to act in. Defaults to the active organization of the credential; organization API keys always act in their own.","schema":{"type":"string","minLength":1},"example":"org_123"},{"name":"status","in":"query","required":false,"description":"Only items in this status.","schema":{"type":"string","enum":["open","accepted","dismissed","resolved"]},"example":"open"},{"name":"limit","in":"query","required":true,"description":"Page size, between 1 and 100.","schema":{"type":"integer","minimum":1,"maximum":100,"default":50},"example":50},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the previous page’s pagination.nextCursor.","schema":{"type":"string","minLength":1}}],"responses":{"200":{"description":"Inbox items.","content":{"application/json":{"schema":{"type":"object","required":["success","data","pagination"],"properties":{"success":{"type":"boolean","const":true},"data":{"type":"array","items":{"$ref":"#/components/schemas/InboxItem"}},"pagination":{"$ref":"#/components/schemas/Pagination"}}},"examples":{"default":{"value":{"success":true,"data":[{"id":"inbox_123","organizationId":"org_123","title":"Email addresses written to application logs","summary":"The checkout handler logs the full request body.","priority":"P1","status":"open","source":"code-audit","projectId":"prj_123","repositoryName":"website","githubIssue":null,"updatedAt":"2026-01-05T09:41:12.000Z","version":"3"}],"pagination":{"nextCursor":null,"hasMore":false}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/inbox/{itemId}":{"get":{"tags":["Inbox"],"summary":"Get Inbox item","description":"One finding with its code evidence. Requires inbox.read.","operationId":"getInboxItem","security":[{"bearerAuth":[]}],"parameters":[{"name":"itemId","in":"path","required":true,"description":"Inbox item ID.","schema":{"type":"string","minLength":1},"example":"inbox_123"}],"responses":{"200":{"description":"Requested item.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/InboxItemDetail"}}},"examples":{"default":{"value":{"success":true,"data":{"id":"inbox_123","organizationId":"org_123","title":"Email addresses written to application logs","summary":"The checkout handler logs the full request body.","priority":"P1","status":"open","source":"code-audit","projectId":"prj_123","repositoryName":"website","githubIssue":null,"updatedAt":"2026-01-05T09:41:12.000Z","version":"3","codeEvidence":{"filePath":"apps/web/src/checkout/handler.ts","lineNumbers":[42],"rule":"pii-in-logs","recommendation":"Redact personal data before logging the request body.","reportId":"scan_123","repositoryHtmlUrl":"https://github.com/acme/website","snippet":null}}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}},"patch":{"tags":["Inbox"],"summary":"Update Inbox item status","description":"Sets the status of a finding. Send the `version` from the item you read; a stale version answers 409 so two people cannot overwrite each other. Requires inbox.write, a user token, and an admin or owner role.","operationId":"updateInboxItem","security":[{"bearerAuth":[]}],"parameters":[{"name":"itemId","in":"path","required":true,"description":"Inbox item ID.","schema":{"type":"string","minLength":1},"example":"inbox_123"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateInboxItemRequest"},"examples":{"default":{"value":{"status":"resolved","version":"3"}}}}}},"responses":{"200":{"description":"Updated item.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/InboxItem"}}},"examples":{"default":{"value":{"success":true,"data":{"id":"inbox_123","organizationId":"org_123","title":"Email addresses written to application logs","summary":"The checkout handler logs the full request body.","priority":"P1","status":"resolved","source":"code-audit","projectId":"prj_123","repositoryName":"website","githubIssue":null,"updatedAt":"2026-01-05T09:41:12.000Z","version":"4"}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"413":{"$ref":"#/components/responses/PayloadTooLarge"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/inbox/{itemId}/github-issue":{"post":{"tags":["Inbox"],"summary":"Create GitHub issue","description":"Opens a GitHub issue in the connected repository for a code finding and records it on the item. Answers the existing issue when one was already created. An unresolved creation attempt returns 409 until reconciled. Requires inbox.write, a user token, and an admin or owner role.","operationId":"createInboxGithubIssue","security":[{"bearerAuth":[]}],"parameters":[{"name":"itemId","in":"path","required":true,"description":"Inbox item ID.","schema":{"type":"string","minLength":1},"example":"inbox_123"}],"responses":{"201":{"description":"The item with its GitHub issue.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/InboxItem"}}},"examples":{"default":{"value":{"success":true,"data":{"id":"inbox_123","organizationId":"org_123","title":"Email addresses written to application logs","summary":"The checkout handler logs the full request body.","priority":"P1","status":"open","source":"code-audit","projectId":"prj_123","repositoryName":"website","githubIssue":{"number":42,"url":"https://github.com/acme/website/issues/42","createdAt":"2026-01-06T10:00:00.000Z"},"updatedAt":"2026-01-05T09:41:12.000Z","version":"3"}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"},"503":{"$ref":"#/components/responses/ServiceUnavailable"}}}},"/v1/regions":{"get":{"tags":["Projects"],"summary":"List regions","description":"Lists the regions a project can be created in. No scope required.","operationId":"listRegions","responses":{"200":{"description":"Regions available for new projects.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"type":"array","items":{"$ref":"#/components/schemas/Region"}}}},"examples":{"default":{"value":{"success":true,"data":[{"id":"us-east-1","label":"US East (N. Virginia)"}]}}}}}}}}},"/v1/projects":{"get":{"tags":["Projects"],"summary":"List projects","description":"Lists projects with their consent settings. Requires projects.read.","operationId":"listProjects","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"query","required":false,"description":"Restrict results to one organization the credential can reach.","schema":{"type":"string","minLength":1},"example":"org_123"},{"name":"limit","in":"query","required":true,"description":"Page size, between 1 and 100.","schema":{"type":"integer","minimum":1,"maximum":100,"default":50},"example":50},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the previous page’s pagination.nextCursor.","schema":{"type":"string","minLength":1}}],"responses":{"200":{"description":"Projects the credential can reach.","content":{"application/json":{"schema":{"type":"object","required":["success","data","pagination"],"properties":{"success":{"type":"boolean","const":true},"data":{"type":"array","items":{"$ref":"#/components/schemas/Project"}},"pagination":{"$ref":"#/components/schemas/Pagination"}}},"examples":{"default":{"value":{"success":true,"data":[{"id":"prj_123","slug":"website","name":"Website","description":null,"organizationId":"org_123","organizationSlug":"acme","dashboardUrl":"https://inth.com/dashboard/acme/website","consent":{"trustedOrigins":["example.com","*.example.com"],"branding":"inth","backendUrl":"https://website-acme.inth.app/","dashboardUrl":"https://inth.com/dashboard/acme/website/consent/overview","version":"v2"}}],"pagination":{"nextCursor":null,"hasMore":false}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}},"post":{"tags":["Projects"],"summary":"Create project","description":"Creates a project and its consent runtime in the chosen region. Requires projects.write and an admin or owner role.","operationId":"createProject","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"query","required":false,"description":"Organization to act in. Defaults to the active organization of the credential; organization API keys always act in their own.","schema":{"type":"string","minLength":1},"example":"org_123"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateProjectRequest"},"examples":{"default":{"value":{"name":"Website","region":"us-east-1","consent":{"trustedOrigins":["example.com","*.example.com"],"branding":"inth"}}}}}}},"responses":{"201":{"description":"Created project.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/Project"}}},"examples":{"default":{"summary":"Created project","value":{"success":true,"data":{"id":"prj_123","slug":"website","name":"Website","description":null,"organizationId":"org_123","organizationSlug":"acme","dashboardUrl":"https://inth.com/dashboard/acme/website","consent":{"trustedOrigins":["example.com","*.example.com"],"branding":"inth","backendUrl":"https://website-acme.inth.app/","dashboardUrl":"https://inth.com/dashboard/acme/website/consent/overview","version":"v2"}}}}}}}},"400":{"description":"Invalid payload, region, or trusted origin.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"invalidPayload":{"summary":"Validation failed","value":{"success":false,"error":{"code":"INVALID_PAYLOAD","message":"Invalid request payload","details":[{"code":"too_small","message":"Too small: expected string to have >=1 characters","path":["name"]}]}}},"invalidRegion":{"summary":"Unsupported region","value":{"success":false,"error":{"code":"INVALID_REGION","message":"Unsupported region"}}}}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"402":{"$ref":"#/components/responses/PlanRequired"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"413":{"$ref":"#/components/responses/PayloadTooLarge"},"422":{"$ref":"#/components/responses/PlanLimitReached"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/projects/{projectId}":{"get":{"tags":["Projects"],"summary":"Get project","description":"Gets a project with its consent settings. Requires projects.read.","operationId":"getProject","security":[{"bearerAuth":[]}],"parameters":[{"name":"projectId","in":"path","required":true,"description":"Project ID.","schema":{"type":"string","minLength":1},"example":"prj_123"}],"responses":{"200":{"description":"Requested project.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/Project"}}},"examples":{"default":{"value":{"success":true,"data":{"id":"prj_123","slug":"website","name":"Website","description":null,"organizationId":"org_123","organizationSlug":"acme","dashboardUrl":"https://inth.com/dashboard/acme/website","consent":{"trustedOrigins":["example.com","*.example.com"],"branding":"inth","backendUrl":"https://website-acme.inth.app/","dashboardUrl":"https://inth.com/dashboard/acme/website/consent/overview","version":"v2"}}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}},"patch":{"tags":["Projects"],"summary":"Update project","description":"Updates the name, description, or consent settings of a project. Any field left out is unchanged. Renaming a project also changes its slug and dashboard URL. Requires projects.write and an admin or owner role. Removing branding requires a plan that includes it and otherwise answers 402 before anything changes.","operationId":"updateProject","security":[{"bearerAuth":[]}],"parameters":[{"name":"projectId","in":"path","required":true,"description":"Project ID.","schema":{"type":"string","minLength":1},"example":"prj_123"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateProjectRequest"},"examples":{"default":{"value":{"name":"Marketing Website","description":"Primary marketing website.","consent":{"trustedOrigins":["example.com","*.example.com"],"branding":"none"}}}}}}},"responses":{"200":{"description":"Updated project.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/Project"}}},"examples":{"default":{"value":{"success":true,"data":{"id":"prj_123","slug":"marketing-website","name":"Marketing Website","description":"Primary marketing website.","organizationId":"org_123","organizationSlug":"acme","dashboardUrl":"https://inth.com/dashboard/acme/website","consent":{"trustedOrigins":["example.com","*.example.com"],"branding":"none","backendUrl":"https://website-acme.inth.app/","dashboardUrl":"https://inth.com/dashboard/acme/website/consent/overview","version":"v2"}}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"402":{"$ref":"#/components/responses/PlanRequired"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"413":{"$ref":"#/components/responses/PayloadTooLarge"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}},"delete":{"tags":["Projects"],"summary":"Delete project","description":"Archives the project and its consent runtime. Requires projects.write and an admin or owner role.","operationId":"deleteProject","security":[{"bearerAuth":[]}],"parameters":[{"name":"projectId","in":"path","required":true,"description":"Project ID.","schema":{"type":"string","minLength":1},"example":"prj_123"}],"responses":{"200":{"description":"Project was deleted.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/DeleteResult"}}},"examples":{"default":{"value":{"success":true,"data":{"deleted":true}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/api-keys":{"get":{"tags":["API keys"],"summary":"List API keys","description":"Lists the API keys of an organization. Secrets are never returned. Requires api-keys.read and an admin or owner role.","operationId":"listApiKeys","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"query","required":false,"description":"Organization the key belongs to. Defaults to the active organization of the credential.","schema":{"type":"string","minLength":1},"example":"org_123"},{"name":"limit","in":"query","required":true,"description":"Page size, between 1 and 100.","schema":{"type":"integer","minimum":1,"maximum":100,"default":50},"example":50},{"name":"cursor","in":"query","required":false,"description":"Opaque cursor from the previous page’s pagination.nextCursor.","schema":{"type":"string","minLength":1}}],"responses":{"200":{"description":"API keys belonging to the organization.","content":{"application/json":{"schema":{"type":"object","required":["success","data","pagination"],"properties":{"success":{"type":"boolean","const":true},"data":{"type":"array","items":{"$ref":"#/components/schemas/ApiKey"}},"pagination":{"$ref":"#/components/schemas/Pagination"}}},"examples":{"default":{"value":{"success":true,"data":[{"id":"key_123","name":"CI deploy","prefix":"inth_3f9a","createdAt":"2026-01-05T09:30:00.000Z","createdBy":"usr_123","createdFrom":"dashboard"}],"pagination":{"nextCursor":null,"hasMore":false}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}},"post":{"tags":["API keys"],"summary":"Create API key","description":"Creates an organization API key with the rate limit of the current plan. The secret is returned once and never again. Requires api-keys.write, a user token, and an admin or owner role; API keys cannot create keys.","operationId":"createApiKey","security":[{"bearerAuth":[]}],"parameters":[{"name":"organizationId","in":"query","required":false,"description":"Organization to act in. Defaults to the active organization of the credential; organization API keys always act in their own.","schema":{"type":"string","minLength":1},"example":"org_123"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateApiKeyRequest"},"examples":{"default":{"value":{"name":"CI deploy"}}}}}},"responses":{"201":{"description":"The new key. The plaintext secret is returned only once.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/ApiKeySecret"}}},"examples":{"default":{"value":{"success":true,"data":{"id":"key_123","key":"inth_••••••••••••••••"}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"402":{"$ref":"#/components/responses/PlanRequired"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/KeyLimitReached"},"413":{"$ref":"#/components/responses/PayloadTooLarge"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/api-keys/{keyId}":{"delete":{"tags":["API keys"],"summary":"Delete API key","description":"Revokes an organization API key. Requires api-keys.write, a user token, and an admin or owner role; API keys cannot delete keys.","operationId":"deleteApiKey","security":[{"bearerAuth":[]}],"parameters":[{"name":"keyId","in":"path","required":true,"description":"API key ID.","schema":{"type":"string","minLength":1},"example":"key_123"},{"name":"organizationId","in":"query","required":false,"description":"Organization the key belongs to. Defaults to the active organization of the credential.","schema":{"type":"string","minLength":1},"example":"org_123"}],"responses":{"200":{"description":"API key was revoked.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/DeleteResult"}}},"examples":{"default":{"value":{"success":true,"data":{"deleted":true}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}},"/v1/api-keys/{keyId}/roll":{"post":{"tags":["API keys"],"summary":"Roll API key","description":"Replaces the secret of a key while keeping its name and ID in the key list. The previous secret stops working immediately. The new secret is minted with the current plan rate limit and is returned only once. Requires api-keys.write, a user token, and an admin or owner role; API keys cannot roll themselves.","operationId":"rollApiKey","security":[{"bearerAuth":[]}],"parameters":[{"name":"keyId","in":"path","required":true,"description":"API key ID.","schema":{"type":"string","minLength":1},"example":"key_123"},{"name":"organizationId","in":"query","required":false,"description":"Organization the key belongs to. Defaults to the active organization of the credential.","schema":{"type":"string","minLength":1},"example":"org_123"}],"responses":{"200":{"description":"The rolled key. The plaintext secret is returned only once.","content":{"application/json":{"schema":{"type":"object","required":["success","data"],"properties":{"success":{"type":"boolean","const":true},"data":{"$ref":"#/components/schemas/ApiKeySecret"}}},"examples":{"default":{"value":{"success":true,"data":{"id":"key_456","key":"inth_••••••••••••••••"}}}}}}},"400":{"$ref":"#/components/responses/InvalidPayload"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/RateLimited"},"500":{"$ref":"#/components/responses/InternalError"}}}}},"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer","description":"Use an Inth API key or OAuth access token in the Authorization header.\n\nProduct operations need a capability. Feedback intake only requires authentication. An OAuth access token carries the capabilities it was granted as scopes; an organization API key carries a fixed set (`organizations.read`, `projects.read`, `projects.write`, `api-keys.read`, `inbox.read`, `billing.read`). A credential without the capability an operation needs is answered with `403 INSUFFICIENT_SCOPE`. `GET /v1/me` reports the capabilities of the calling credential.\n\nOAuth scopes:\n- `organizations.read`: List the organizations you belong to.\n- `organizations.write`: Create organizations you will own.\n- `projects.read`: Read projects and their consent configuration.\n- `projects.write`: Create, update, and delete projects and their consent configuration.\n- `members.read`: Read member names, email addresses, profile images, roles, and pending invitation email addresses.\n- `members.write`: Invite members, change member roles, remove members, and cancel invitations.\n- `api-keys.read`: List organization API keys.\n- `api-keys.write`: Create, roll, and delete organization API keys.\n- `code-audit.read`: Read Code Audit scans, their findings, and connected repositories.\n- `code-audit.write`: Start Code Audit scans and unlock their reports.\n- `inbox.read`: Read Inbox findings.\n- `inbox.write`: Change the status of Inbox findings and open GitHub issues for them.\n- `billing.read`: Read the plan and credit balance of an organization."},"mcpOAuthBearer":{"type":"http","scheme":"bearer","bearerFormat":"OAuth 2.1 access token","description":"Use a user-delegated OAuth access token for the MCP resource. Organization API keys are not accepted."}},"schemas":{"AgentFeedbackSubmission":{"type":"object","additionalProperties":false,"required":["category","message"],"properties":{"category":{"type":"string","enum":["bug","friction","docs_mismatch","feature_request","performance"]},"surface":{"type":"string","enum":["api","mcp","cli","docs","sdk","dashboard","other"],"description":"Affected Inth surface. Use `other` when none fit."},"message":{"type":"string","minLength":1,"maxLength":8000,"pattern":"\\S","description":"Leading and trailing whitespace is trimmed before validation and storage. Must contain non-whitespace text; length limits apply after trimming."},"expected":{"type":"string","minLength":1,"maxLength":2000,"pattern":"\\S","description":"Leading and trailing whitespace is trimmed before validation and storage. Must contain non-whitespace text; length limits apply after trimming."},"actual":{"type":"string","minLength":1,"maxLength":2000,"pattern":"\\S","description":"Leading and trailing whitespace is trimmed before validation and storage. Must contain non-whitespace text; length limits apply after trimming."},"reproduction":{"type":"string","minLength":1,"maxLength":4000,"pattern":"\\S","description":"Leading and trailing whitespace is trimmed before validation and storage. Must contain non-whitespace text; length limits apply after trimming."},"requestId":{"type":"string","minLength":1,"maxLength":128,"pattern":"\\S","description":"Leading and trailing whitespace is trimmed before validation and storage. Must contain non-whitespace text; length limits apply after trimming."},"operation":{"type":"string","minLength":1,"maxLength":255,"pattern":"\\S","description":"Leading and trailing whitespace is trimmed before validation and storage. Must contain non-whitespace text; length limits apply after trimming."},"clientName":{"type":"string","minLength":1,"maxLength":100,"pattern":"\\S","description":"Leading and trailing whitespace is trimmed before validation and storage. Must contain non-whitespace text; length limits apply after trimming."},"clientVersion":{"type":"string","minLength":1,"maxLength":100,"pattern":"\\S","description":"Leading and trailing whitespace is trimmed before validation and storage. Must contain non-whitespace text; length limits apply after trimming."}}},"AgentFeedbackResult":{"type":"object","required":["reference","alreadySubmitted"],"properties":{"reference":{"type":"string","description":"Feedback or feature-request ticket reference."},"alreadySubmitted":{"type":"boolean"}}},"ApiErrorCode":{"type":"string","enum":["UNAUTHORIZED","FORBIDDEN","INSUFFICIENT_SCOPE","PLAN_LIMIT_REACHED","PLAN_REQUIRED","INVALID_ORIGIN","INVALID_REGION","INVALID_PAYLOAD","NOT_FOUND","CONFLICT","KEY_LIMIT_REACHED","INSUFFICIENT_CREDITS","SCAN_IN_PROGRESS","UNLOCK_REQUIRED","REPOSITORY_NOT_LINKED","PAYLOAD_TOO_LARGE","RATE_LIMITED","SERVICE_UNAVAILABLE","INTERNAL_ERROR"]},"ApiError":{"type":"object","required":["code","message"],"properties":{"code":{"$ref":"#/components/schemas/ApiErrorCode"},"message":{"type":"string"},"details":{"description":"Optional structured error details."}}},"ErrorResponse":{"type":"object","required":["success","error"],"properties":{"success":{"type":"boolean","const":false},"error":{"$ref":"#/components/schemas/ApiError"}}},"Health":{"type":"object","required":["ok"],"properties":{"ok":{"type":"boolean"}}},"Organization":{"type":"object","required":["id","slug","name","role"],"properties":{"id":{"type":"string"},"slug":{"type":"string"},"name":{"type":"string"},"role":{"type":"string","enum":["owner","admin","member"],"description":"The role of the calling credential in this organization."}}},"Scope":{"type":"string","enum":["organizations.read","organizations.write","projects.read","projects.write","members.read","members.write","api-keys.read","api-keys.write","code-audit.read","code-audit.write","inbox.read","inbox.write","billing.read"],"description":"Something a credential is allowed to do. Scope names double as OAuth scope strings.\n- `organizations.read`: List the organizations you belong to.\n- `organizations.write`: Create organizations you will own.\n- `projects.read`: Read projects and their consent configuration.\n- `projects.write`: Create, update, and delete projects and their consent configuration.\n- `members.read`: Read member names, email addresses, profile images, roles, and pending invitation email addresses.\n- `members.write`: Invite members, change member roles, remove members, and cancel invitations.\n- `api-keys.read`: List organization API keys.\n- `api-keys.write`: Create, roll, and delete organization API keys.\n- `code-audit.read`: Read Code Audit scans, their findings, and connected repositories.\n- `code-audit.write`: Start Code Audit scans and unlock their reports.\n- `inbox.read`: Read Inbox findings.\n- `inbox.write`: Change the status of Inbox findings and open GitHub issues for them.\n- `billing.read`: Read the plan and credit balance of an organization."},"Me":{"type":"object","required":["principal","activeOrganizationId","scopes","organizations"],"properties":{"principal":{"type":"object","required":["type"],"properties":{"type":{"type":"string","enum":["session","api_key","oauth"]},"userId":{"type":"string","description":"Present for session and oauth principals. API keys are organization credentials and carry no acting user."},"keyId":{"type":"string"},"organizationId":{"type":"string","description":"The organization the API key belongs to (api_key principals only)."},"createdBy":{"type":"string","description":"User who minted the API key. Attribution only, never authorization."},"activeOrganizationId":{"oneOf":[{"type":"string"},{"type":"null"}]}}},"activeOrganizationId":{"oneOf":[{"type":"string"},{"type":"null"}]},"scopes":{"type":"array","items":{"$ref":"#/components/schemas/Scope"},"description":"What the calling credential may do, sorted. Derived from the granted OAuth scopes for oauth principals; organization API keys carry a fixed set."},"organizations":{"type":"array","items":{"$ref":"#/components/schemas/Organization"},"description":"Organizations the credential can reach. Empty when organizations.read was not granted."}}},"Member":{"type":"object","required":["id","role","joinedAt","user"],"properties":{"id":{"type":"string"},"role":{"type":"string","enum":["owner","admin","member"]},"joinedAt":{"type":"string","format":"date-time"},"user":{"type":"object","required":["id","name","email","image"],"properties":{"id":{"type":"string"},"name":{"type":"string"},"email":{"type":"string","format":"email"},"image":{"oneOf":[{"type":"string","format":"uri"},{"type":"null"}]}}}}},"UpdateMemberRequest":{"type":"object","required":["role"],"properties":{"role":{"type":"string","enum":["owner","admin","member"],"description":"New role. Only owners can grant owner."}}},"Invitation":{"type":"object","required":["id","email","role","status","createdAt","expiresAt","invitedBy"],"properties":{"id":{"type":"string"},"email":{"type":"string","format":"email"},"role":{"type":"string","enum":["owner","admin","member"]},"status":{"type":"string","enum":["pending"]},"createdAt":{"type":"string","format":"date-time"},"expiresAt":{"type":"string","format":"date-time"},"invitedBy":{"type":"object","required":["id","name","email"],"properties":{"id":{"type":"string"},"name":{"type":"string"},"email":{"type":"string","format":"email"}}}}},"CreateInvitationRequest":{"type":"object","required":["email","role"],"properties":{"email":{"type":"string","format":"email","minLength":1,"maxLength":255,"description":"Address to invite. Compared case-insensitively."},"role":{"type":"string","enum":["owner","admin","member"],"description":"Role granted on acceptance. Only owners can invite owners."}}},"Pagination":{"type":"object","required":["nextCursor","hasMore"],"properties":{"nextCursor":{"oneOf":[{"type":"string","description":"Cursor for the next page; null on the last page."},{"type":"null"}]},"hasMore":{"type":"boolean"}}},"Region":{"type":"object","required":["id","label"],"properties":{"id":{"type":"string"},"label":{"type":"string"}}},"ConsentSettings":{"type":"object","required":["trustedOrigins","branding","backendUrl","dashboardUrl","version"],"properties":{"trustedOrigins":{"type":"array","items":{"type":"string"},"description":"Origins allowed to call the consent runtime. Supports * and wildcard subdomains like *.example.com."},"branding":{"type":"string","enum":["inth","c15t","none"],"description":"Branding shown in the consent banner. Removing branding with 'none' requires an eligible paid plan."},"backendUrl":{"oneOf":[{"type":"string","format":"uri","description":"The consent runtime URL your site points the c15t client at."},{"type":"null"}]},"dashboardUrl":{"type":"string","format":"uri"},"version":{"type":"string","description":"Consent runtime version."}}},"Project":{"type":"object","required":["id","slug","name","description","organizationId","organizationSlug","dashboardUrl","consent"],"properties":{"id":{"type":"string"},"slug":{"type":"string"},"name":{"type":"string"},"description":{"oneOf":[{"type":"string"},{"type":"null"}]},"organizationId":{"type":"string"},"organizationSlug":{"type":"string"},"dashboardUrl":{"type":"string","format":"uri"},"consent":{"oneOf":[{"$ref":"#/components/schemas/ConsentSettings"},{"type":"null"}]}}},"CreateOrganizationRequest":{"type":"object","required":["name","slug"],"properties":{"name":{"type":"string","minLength":3,"maxLength":255,"description":"Organization display name, 3 to 255 characters after trimming."},"slug":{"type":"string","minLength":3,"maxLength":20,"pattern":"^[a-z0-9]+(?:-[a-z0-9]+)*$","description":"Organization URL segment, 3 to 20 characters of lowercase letters, numbers, and single hyphens. A slug any organization has ever used stays reserved and is refused with 409."}}},"ConsentSettingsInput":{"type":"object","properties":{"trustedOrigins":{"type":"array","items":{"type":"string"},"description":"Origins allowed to call the consent runtime. Supports * and wildcard subdomains like *.example.com."},"branding":{"type":"string","enum":["inth","c15t","none"],"description":"Consent banner branding. `none` requires a plan that includes remove-branding and otherwise fails with 402."}}},"CreateProjectRequest":{"type":"object","required":["name","region"],"properties":{"name":{"type":"string","minLength":1,"description":"Project display name. The slug is derived from it."},"region":{"type":"string","minLength":1,"description":"Region ID from GET /v1/regions."},"consent":{"$ref":"#/components/schemas/ConsentSettingsInput","description":"Consent settings applied at creation, so no follow-up request is needed."}}},"UpdateProjectRequest":{"type":"object","minProperties":1,"properties":{"name":{"type":"string","minLength":1,"description":"Project display name. Updating it also regenerates the project slug."},"description":{"oneOf":[{"type":"string","maxLength":512},{"type":"null"}]},"consent":{"$ref":"#/components/schemas/ConsentSettingsInput","description":"Consent settings to change. Fields left out are unchanged."}}},"ApiKey":{"type":"object","required":["id","name","prefix","createdAt","createdBy","createdFrom"],"properties":{"id":{"type":"string"},"name":{"type":"string"},"prefix":{"oneOf":[{"type":"string","description":"The first characters of the secret, for recognising a key."},{"type":"null"}]},"createdAt":{"type":"string","format":"date-time"},"createdBy":{"oneOf":[{"type":"string","description":"User who minted the key. Attribution only."},{"type":"null"}]},"createdFrom":{"oneOf":[{"type":"string","description":"Where the key was minted, such as dashboard or cli."},{"type":"null"}]}}},"CreateApiKeyRequest":{"type":"object","required":["name"],"properties":{"name":{"type":"string","minLength":1,"maxLength":255,"description":"Key name, shown in the key list."}}},"ApiKeySecret":{"type":"object","required":["id","key"],"properties":{"id":{"type":"string"},"key":{"type":"string","description":"The plaintext secret. Returned once; store it now."}}},"Billing":{"type":"object","required":["organizationId","tier","plan","credits","autoTopUp"],"properties":{"organizationId":{"type":"string"},"tier":{"type":"string","enum":["trial","hobby","starter","pro","enterprise"]},"plan":{"oneOf":[{"type":"object","required":["name","family","billingInterval","pastDue"],"properties":{"name":{"type":"string"},"family":{"type":"string","enum":["free","startup","enterprise"]},"billingInterval":{"oneOf":[{"type":"string","enum":["month","year"]},{"type":"null"}]},"pastDue":{"type":"boolean"}}},{"type":"null"}]},"credits":{"oneOf":[{"type":"object","required":["remaining","unlimited"],"properties":{"remaining":{"type":"number"},"unlimited":{"type":"boolean"}}},{"type":"null"}]},"autoTopUp":{"oneOf":[{"type":"object","required":["enabled","thresholdCredits","quantityCredits"],"properties":{"enabled":{"type":"boolean"},"thresholdCredits":{"oneOf":[{"type":"integer"},{"type":"null"}]},"quantityCredits":{"oneOf":[{"type":"integer"},{"type":"null"}]}},"description":"Null when the organization has no billing account. Threshold and quantity are null when automatic top-ups are not available on the plan."},{"type":"null"}]}}},"CodeAuditRepository":{"type":"object","required":["id","organizationId","owner","name","htmlUrl","defaultBranch","visibility","connectedAt","projects"],"properties":{"id":{"type":"string"},"organizationId":{"type":"string"},"owner":{"type":"string"},"name":{"type":"string"},"htmlUrl":{"type":"string","format":"uri"},"defaultBranch":{"oneOf":[{"type":"string"},{"type":"null"}]},"visibility":{"type":"string"},"connectedAt":{"oneOf":[{"type":"string","format":"date-time"},{"type":"null"}]},"projects":{"type":"array","items":{"type":"object","required":["projectId","projectSlug","projectName","productionBranch","rootDirectory","pullRequestScansEnabled"],"properties":{"projectId":{"type":"string"},"projectSlug":{"type":"string"},"projectName":{"type":"string"},"productionBranch":{"oneOf":[{"type":"string"},{"type":"null"}]},"rootDirectory":{"oneOf":[{"type":"string"},{"type":"null"}]},"pullRequestScansEnabled":{"type":"boolean"}}}}}},"CodeAuditScan":{"type":"object","required":["id","organizationId","repositoryId","repositoryName","branch","headCommitSha","pullRequestNumber","scope","trigger","status","access","unlockCredits","findingCount","issueCount","progress","createdAt","startedAt","completedAt"],"properties":{"id":{"type":"string"},"organizationId":{"type":"string"},"repositoryId":{"type":"string"},"repositoryName":{"type":"string"},"branch":{"oneOf":[{"type":"string"},{"type":"null"}]},"headCommitSha":{"oneOf":[{"type":"string"},{"type":"null"}]},"pullRequestNumber":{"oneOf":[{"type":"integer"},{"type":"null"}]},"scope":{"type":"string","description":"What was scanned: repository, pull_request, and so on."},"trigger":{"type":"string","description":"What started the scan: manual, pull_request, scheduled."},"status":{"type":"string"},"access":{"type":"string","enum":["full","free-preview","locked"],"description":"Whether every finding is readable. A free preview shows a subset until unlocked."},"unlockCredits":{"oneOf":[{"type":"integer","description":"Credits needed to unlock a free preview."},{"type":"null"}]},"findingCount":{"oneOf":[{"type":"integer"},{"type":"null"}]},"issueCount":{"oneOf":[{"type":"integer"},{"type":"null"}]},"progress":{"oneOf":[{"type":"object","required":["stage","stageStatus","completedStages","totalStages"],"properties":{"stage":{"type":"string"},"stageStatus":{"oneOf":[{"type":"string"},{"type":"null"}]},"completedStages":{"oneOf":[{"type":"integer"},{"type":"null"}]},"totalStages":{"oneOf":[{"type":"integer"},{"type":"null"}]}}},{"type":"null"}]},"createdAt":{"type":"string","format":"date-time"},"startedAt":{"oneOf":[{"type":"string","format":"date-time"},{"type":"null"}]},"completedAt":{"oneOf":[{"type":"string","format":"date-time"},{"type":"null"}]}}},"StartCodeAuditScanRequest":{"type":"object","required":["repositoryId"],"properties":{"repositoryId":{"type":"string","minLength":1,"description":"Repository ID from the connected repositories list."},"requestId":{"type":"string","minLength":1,"description":"Idempotency key. Repeating a request with the same key does not start a second scan."}}},"CodeAuditScanStart":{"oneOf":[{"type":"object","required":["status","scan"],"properties":{"status":{"type":"string","const":"started"},"scan":{"$ref":"#/components/schemas/CodeAuditScan"}}},{"type":"object","required":["status","preparationId","repositoryId"],"properties":{"status":{"type":"string","const":"starting"},"preparationId":{"type":"string","description":"Poll the scan request with this ID."},"repositoryId":{"type":"string"}}}]},"CodeAuditScanRequestState":{"oneOf":[{"type":"object","required":["status","scan"],"properties":{"status":{"type":"string","const":"started"},"scan":{"$ref":"#/components/schemas/CodeAuditScan"}}},{"type":"object","required":["status","preparationId","repositoryId"],"properties":{"status":{"type":"string","const":"starting"},"preparationId":{"type":"string"},"repositoryId":{"type":"string"}}},{"type":"object","required":["status","message"],"properties":{"status":{"type":"string","const":"failed"},"message":{"type":"string"}}}]},"CodeAuditIssue":{"type":"object","required":["id","title","description","priority","reviewPriority","potentialImpact","recommendation","files","category","resolution","evidence"],"properties":{"id":{"type":"string"},"title":{"type":"string"},"description":{"oneOf":[{"type":"string"},{"type":"null"}]},"priority":{"type":"string","description":"P0 to P3."},"reviewPriority":{"oneOf":[{"type":"string","enum":["urgent","high","normal","low"]},{"type":"null"}]},"potentialImpact":{"oneOf":[{"type":"string","enum":["critical","high","medium","low"]},{"type":"null"}]},"recommendation":{"oneOf":[{"type":"string"},{"type":"null"}]},"files":{"type":"array","items":{"type":"string"}},"category":{"oneOf":[{"type":"string","description":"Stable finding category, such as pii-in-logs."},{"type":"null"}]},"resolution":{"oneOf":[{"type":"string","enum":["active","fixed","superseded"]},{"type":"null"}]},"evidence":{"oneOf":[{"type":"object","required":["filePath","lineNumbers"],"properties":{"filePath":{"type":"string"},"lineNumbers":{"type":"array","items":{"type":"integer"}},"snippet":{"type":"string"},"snippetStartLine":{"type":"integer"},"snippetEndLine":{"type":"integer"}}},{"type":"null"}]}}},"CodeAuditReport":{"type":"object","required":["scanId","access","totalCount","lockedCount","unlockCredits","priorityCounts","issues"],"properties":{"scanId":{"type":"string"},"access":{"type":"string","enum":["full","free-preview","locked"]},"totalCount":{"type":"integer"},"lockedCount":{"type":"integer","description":"Findings withheld until the report is unlocked."},"unlockCredits":{"oneOf":[{"type":"integer"},{"type":"null"}]},"priorityCounts":{"oneOf":[{"type":"object","required":["P0","P1","P2","P3"],"properties":{"P0":{"type":"integer"},"P1":{"type":"integer"},"P2":{"type":"integer"},"P3":{"type":"integer"}}},{"type":"null"}]},"issues":{"type":"array","items":{"$ref":"#/components/schemas/CodeAuditIssue"}}}},"CodeAuditUnlockResult":{"type":"object","required":["status"],"properties":{"status":{"type":"string","enum":["unlocked","already-unlocked"]}}},"InboxItem":{"type":"object","required":["id","organizationId","title","summary","priority","status","source","projectId","repositoryName","githubIssue","updatedAt","version"],"properties":{"id":{"type":"string"},"organizationId":{"type":"string"},"title":{"type":"string"},"summary":{"oneOf":[{"type":"string"},{"type":"null"}]},"priority":{"oneOf":[{"type":"string","enum":["P0","P1","P2","P3"]},{"type":"null"}]},"status":{"type":"string","enum":["open","accepted","dismissed","resolved"]},"source":{"type":"string","enum":["advisory","code-audit","runtime"]},"projectId":{"oneOf":[{"type":"string"},{"type":"null"}]},"repositoryName":{"oneOf":[{"type":"string"},{"type":"null"}]},"githubIssue":{"oneOf":[{"type":"object","required":["number","url","createdAt"],"properties":{"number":{"type":"integer"},"url":{"type":"string","format":"uri"},"createdAt":{"type":"string","format":"date-time"}}},{"type":"null"}]},"updatedAt":{"type":"string","format":"date-time"},"version":{"type":"string","description":"Send back as `version` when changing the status."}}},"InboxItemDetail":{"allOf":[{"$ref":"#/components/schemas/InboxItem"},{"type":"object","required":["codeEvidence"],"properties":{"codeEvidence":{"oneOf":[{"type":"object","required":["filePath","lineNumbers","rule","recommendation","reportId","repositoryHtmlUrl","snippet"],"properties":{"filePath":{"type":"string"},"lineNumbers":{"type":"array","items":{"type":"integer"}},"rule":{"type":"string"},"recommendation":{"oneOf":[{"type":"string"},{"type":"null"}]},"reportId":{"oneOf":[{"type":"string","description":"The scan that produced the finding."},{"type":"null"}]},"repositoryHtmlUrl":{"oneOf":[{"type":"string","format":"uri"},{"type":"null"}]},"snippet":{"oneOf":[{"type":"string"},{"type":"null"}]},"snippetStartLine":{"type":"integer"},"snippetEndLine":{"type":"integer"}}},{"type":"null"}]}}}]},"UpdateInboxItemRequest":{"type":"object","required":["status","version"],"properties":{"status":{"type":"string","enum":["open","accepted","dismissed","resolved"]},"version":{"type":"string","pattern":"^\\d+$","description":"The `version` of the item as last read."}}},"DeleteResult":{"type":"object","required":["deleted"],"properties":{"deleted":{"type":"boolean"}}},"UpdateResult":{"type":"object","required":["updated"],"properties":{"updated":{"type":"boolean"}}}},"responses":{"InvalidPayload":{"description":"The request payload or parameters are invalid.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"default":{"value":{"success":false,"error":{"code":"INVALID_PAYLOAD","message":"Invalid request payload","details":[{"code":"too_small","message":"Too small: expected string to have >=1 characters","path":["name"]}]}}}}}}},"Unauthorized":{"description":"Authentication is missing, invalid, or expired.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"default":{"value":{"success":false,"error":{"code":"UNAUTHORIZED","message":"Authentication required"}}}}}}},"Forbidden":{"description":"The credential is valid but may not perform the operation.\n\n`INSUFFICIENT_SCOPE`: the credential was never granted the capability the operation needs. `details.requiredScope` names it, and the `WWW-Authenticate` header carries `Bearer error=\"insufficient_scope\"`. An OAuth client fixes this by requesting the scope; an organization API key cannot gain it.\n\n`FORBIDDEN`: the capability is present but the membership behind the credential lacks the role, or the resource belongs to another organization.","headers":{"WWW-Authenticate":{"description":"Present on `INSUFFICIENT_SCOPE`: `Bearer error=\"insufficient_scope\", scope=\"<required scope>\"`.","schema":{"type":"string"}}},"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"insufficientScope":{"summary":"Capability scope not granted","value":{"success":false,"error":{"code":"INSUFFICIENT_SCOPE","message":"This token was not granted the projects.write scope","details":{"requiredScope":"projects.write"}}}},"forbidden":{"summary":"Membership role does not allow the operation","value":{"success":false,"error":{"code":"FORBIDDEN","message":"Organization membership is required"}}}}}}},"PlanRequired":{"description":"The organization's plan does not include the requested option, for example removing consent banner branding. API access itself is available on every plan.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"default":{"value":{"success":false,"error":{"code":"PLAN_REQUIRED","message":"Removing branding requires an eligible paid plan"}}}}}}},"PlanLimitReached":{"description":"The caller has reached a plan limit for this resource.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"default":{"value":{"success":false,"error":{"code":"PLAN_LIMIT_REACHED","message":"You can only own up to 50 organizations"}}}}}}},"InsufficientCredits":{"description":"The organization does not hold enough credits. `details` carries the remaining and required amounts. Enable automatic top-ups or buy credits in the dashboard.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"default":{"value":{"success":false,"error":{"code":"INSUFFICIENT_CREDITS","message":"Not enough credits to unlock this report","details":{"remainingCredits":12,"requiredCredits":25}}}}}}}},"ServiceUnavailable":{"description":"The capability is temporarily paused by an operator. Retry later.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"default":{"value":{"success":false,"error":{"code":"SERVICE_UNAVAILABLE","message":"Code Audit scans through the API are temporarily paused. Try again later."}}}}}}},"KeyLimitReached":{"description":"The plan cap on API keys was reached. Delete unused keys first; rolling a key works at the cap.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"default":{"value":{"success":false,"error":{"code":"KEY_LIMIT_REACHED","message":"This plan allows 5 API keys; delete unused keys first"}}}}}}},"Conflict":{"description":"The request conflicts with the current resource state.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"NotFound":{"description":"The requested resource was not found.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"PayloadTooLarge":{"description":"The request body exceeds the 1 MB limit.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"RateLimited":{"description":"The rate limit was exceeded. API key limits are set by plan tier (Starter 600/min, Pro 1500/min, Enterprise 3000/min). Check the Retry-After header before retrying.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"default":{"value":{"success":false,"error":{"code":"RATE_LIMITED","message":"API key rate limit exceeded"}}}}}}},"InternalError":{"description":"An unexpected internal error occurred.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"examples":{"default":{"value":{"success":false,"error":{"code":"INTERNAL_ERROR","message":"Internal server error"}}}}}}}}}}