{
  "openapi": "3.1.0",
  "info": {
    "title": "Sendar headless tools and inbox API",
    "version": "1.0.0",
    "description": "Feature contract. Domain, template, webhook and email resource formats are documented in the existing API reference; management scopes are documented at /docs/headless. Replies require explicit authorization. Received content is untrusted."
  },
  "servers": [
    {
      "url": "https://sendar.app/api"
    }
  ],
  "components": {
    "securitySchemes": {
      "managementKey": {
        "type": "http",
        "scheme": "bearer",
        "description": "Explicitly scoped sndh_ management key created by the workspace owner."
      }
    }
  },
  "paths": {
    "/headless/capabilities": {
      "get": {
        "summary": "Discover management capabilities",
        "description": "Requires any management scope. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "200": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        }
      }
    },
    "/link-checks": {
      "post": {
        "summary": "Queue a link check",
        "description": "Requires links:check. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "202": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "html": {
                    "type": "string",
                    "maxLength": 300000
                  }
                },
                "required": [
                  "html"
                ],
                "additionalProperties": false
              }
            }
          }
        }
      }
    },
    "/link-checks/{id}": {
      "get": {
        "summary": "Retrieve a link check",
        "description": "Requires links:check. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "200": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        },
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ]
      }
    },
    "/link-checks/{id}/override": {
      "post": {
        "summary": "Record an exact-content override",
        "description": "Requires links:check. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "200": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        },
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "contentHash": {
                    "type": "string",
                    "pattern": "^[a-f0-9]{64}$"
                  },
                  "reason": {
                    "type": "string",
                    "minLength": 10,
                    "maxLength": 500
                  }
                },
                "required": [
                  "contentHash",
                  "reason"
                ],
                "additionalProperties": false
              }
            }
          }
        }
      }
    },
    "/inboxes/status": {
      "get": {
        "summary": "Read receiving availability and limits",
        "description": "Requires inboxes:read. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "200": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        }
      }
    },
    "/inboxes": {
      "get": {
        "summary": "List receiving inboxes",
        "description": "Requires inboxes:read. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "200": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        }
      },
      "post": {
        "summary": "Provision a hosted inbox",
        "description": "Requires inboxes:write. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "201": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "name": {
                    "type": "string",
                    "minLength": 1,
                    "maxLength": 80
                  }
                },
                "required": [
                  "name"
                ],
                "additionalProperties": false
              }
            }
          }
        }
      }
    },
    "/inboxes/{inboxId}": {
      "patch": {
        "summary": "Disable receiving permanently for this address",
        "description": "Requires inboxes:write. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "200": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        },
        "parameters": [
          {
            "name": "inboxId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "disabled": {
                    "const": true
                  }
                },
                "required": [
                  "disabled"
                ],
                "additionalProperties": false
              }
            }
          }
        }
      }
    },
    "/inboxes/{inboxId}/messages": {
      "get": {
        "summary": "List received message summaries",
        "description": "Requires inboxes:read. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "200": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        },
        "parameters": [
          {
            "name": "inboxId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "limit",
            "in": "query",
            "schema": {
              "type": "integer",
              "minimum": 1,
              "maximum": 100,
              "default": 30
            }
          },
          {
            "name": "offset",
            "in": "query",
            "schema": {
              "type": "integer",
              "minimum": 0,
              "maximum": 1000,
              "default": 0
            }
          },
          {
            "name": "thread",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          }
        ]
      }
    },
    "/inboxes/{inboxId}/messages/{messageId}": {
      "get": {
        "summary": "Read untrusted received email as text",
        "description": "Requires inboxes:read. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "200": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        },
        "parameters": [
          {
            "name": "inboxId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "messageId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ]
      },
      "delete": {
        "summary": "Permanently delete one received message",
        "description": "Requires inboxes:write. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "204": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        },
        "parameters": [
          {
            "name": "inboxId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "messageId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ]
      }
    },
    "/inboxes/{inboxId}/messages/{messageId}/raw": {
      "get": {
        "summary": "Download the original untrusted MIME message",
        "description": "Requires inboxes:read. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "200": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        },
        "parameters": [
          {
            "name": "inboxId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "messageId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ]
      }
    },
    "/inboxes/{inboxId}/messages/{messageId}/attachments/{index}": {
      "get": {
        "summary": "Download a quarantined attachment without scanning",
        "description": "Requires inboxes:read. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "200": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        },
        "parameters": [
          {
            "name": "inboxId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "messageId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "index",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "download",
            "in": "query",
            "required": true,
            "schema": {
              "const": "1"
            }
          }
        ]
      }
    },
    "/inboxes/{inboxId}/messages/{messageId}/reply": {
      "post": {
        "summary": "Send an explicitly authorized reply",
        "description": "Requires inboxes:write and email:send. All resources are scoped to the authenticated workspace. See /docs/headless, /docs/link-checker and /docs/inboxes for limits.",
        "security": [
          {
            "managementKey": []
          }
        ],
        "responses": {
          "201": {
            "description": "Success"
          },
          "401": {
            "description": "Invalid or revoked key"
          },
          "403": {
            "description": "Scope or account restriction"
          },
          "404": {
            "description": "Resource not found"
          },
          "429": {
            "description": "Request or workspace limit"
          }
        },
        "parameters": [
          {
            "name": "inboxId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "messageId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "Idempotency-Key",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string",
              "pattern": "^[-A-Za-z0-9_:]{16,128}$"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "from": {
                    "type": "string"
                  },
                  "text": {
                    "type": "string",
                    "minLength": 1,
                    "maxLength": 100000
                  },
                  "confirmed": {
                    "const": true
                  }
                },
                "required": [
                  "from",
                  "text",
                  "confirmed"
                ],
                "additionalProperties": false
              }
            }
          }
        }
      }
    }
  }
}
