{
  "openapi": "3.1.0",
  "info": {
    "title": "Pomerado API",
    "version": "1",
    "description": "Run and build website tools, follow their jobs, and manage logins, API keys and webhooks. Authenticate with a Pomerado API key (pom_…), an MCP OAuth token or a Dashboard session as a Bearer token."
  },
  "servers": [
    {
      "url": "https://api.pomerado.ai"
    }
  ],
  "tags": [
    {
      "name": "api_keys",
      "x-group": "API keys"
    },
    {
      "name": "webhooks",
      "x-group": "Webhooks"
    }
  ],
  "paths": {
    "/v1/api-keys": {
      "get": {
        "operationId": "api_keys.list",
        "tags": [
          "api_keys"
        ],
        "summary": "List your API keys",
        "description": "Your API keys for the REST API and MCP, newest first: name, permissions, integration, prefix, how each was created, and when it was created, expires and was last used. Never returns a secret.",
        "parameters": [
          {
            "name": "cursor",
            "in": "query",
            "required": false,
            "description": "The next_cursor of the previous page",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "limit",
            "in": "query",
            "required": false,
            "description": "Items per page, 1 to 100 (default 20)",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "One page of your keys",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "data",
                    "next_cursor"
                  ],
                  "properties": {
                    "data": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/ApiKey"
                      }
                    },
                    "next_cursor": {
                      "anyOf": [
                        {
                          "type": "string"
                        },
                        {
                          "type": "null"
                        }
                      ]
                    }
                  },
                  "additionalProperties": false
                }
              }
            }
          },
          "400": {
            "description": "invalid_request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "unauthorized, reauthentication_required",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "forbidden",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "500": {
            "description": "internal_error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "503": {
            "description": "temporarily_unavailable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearer": []
          }
        ],
        "x-pomerado-effect": "read",
        "x-pomerado-callers": [
          "session",
          "oauth",
          "api_key"
        ],
        "x-pomerado-permission": "identity",
        "x-pomerado-key-permission": "api_keys:manage",
        "x-mint": {
          "content": "**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.\n\n**Permission:** any signed-in member, on their own records; an API key also needs `api_keys:manage`.\n\n**Effect:** Read: changes nothing.\n\n**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`forbidden`](/errors#forbidden) (403), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors)."
        }
      },
      "post": {
        "operationId": "api_keys.create",
        "tags": [
          "api_keys"
        ],
        "summary": "Create an API key",
        "description": "Create an API key and return its secret once. Send the secret as a Bearer token on the REST API or any Pomerado MCP. A key carries only permissions you hold now; without permissions it carries all of them except api_keys:manage, which a key needs to manage keys. It expires after 90 days unless expires_in_days says otherwise. With deliver \"dashboard\", nothing is created yet: the answer is a Dashboard link where the person creates the key and sees the secret, so it never reaches this client.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "name"
                ],
                "properties": {
                  "name": {
                    "type": "string",
                    "description": "1 to 100 characters, without leading or trailing spaces",
                    "minLength": 1,
                    "maxLength": 100,
                    "examples": [
                      "Nightly price check"
                    ],
                    "pattern": "^\\S(?:.*\\S)?$"
                  },
                  "permissions": {
                    "type": "array",
                    "items": {
                      "type": "string",
                      "enum": [
                        "tools:read",
                        "usage:read",
                        "tools:build",
                        "runs:create",
                        "jobs:read",
                        "jobs:cancel",
                        "connections:read",
                        "credentials:manage",
                        "api_keys:manage"
                      ]
                    },
                    "description": "Permissions the key carries, each one you hold now. Default: every permission you hold except api_keys:manage",
                    "minItems": 1,
                    "examples": [
                      [
                        "tools:read",
                        "runs:create",
                        "jobs:read"
                      ]
                    ],
                    "maxItems": 16
                  },
                  "integration_id": {
                    "type": "string",
                    "description": "Bind the key to one integration: it then runs only that integration's tools, and carries only tools:read, runs:create, jobs:read and jobs:cancel",
                    "examples": [
                      "int_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
                    ]
                  },
                  "expires_in_days": {
                    "$ref": "#/components/schemas/Int",
                    "description": "Days until the key expires, 1 to 365 (default 90)",
                    "examples": [
                      30
                    ],
                    "minimum": 1,
                    "maximum": 365
                  },
                  "deliver": {
                    "type": "string",
                    "enum": [
                      "dashboard"
                    ],
                    "description": "Answer a Dashboard link instead of the secret, so the secret never reaches this client"
                  }
                },
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "With deliver dashboard: where to finish",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DashboardDelivery"
                }
              }
            }
          },
          "201": {
            "description": "The new key and its one-time secret",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ApiKeyWithSecret"
                }
              }
            }
          },
          "400": {
            "description": "invalid_request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "unauthorized, reauthentication_required",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "permission_not_held, forbidden",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "not_found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "409": {
            "description": "api_key_limit_reached",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "413": {
            "description": "request_too_large",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "500": {
            "description": "internal_error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "503": {
            "description": "temporarily_unavailable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearer": []
          }
        ],
        "x-pomerado-effect": "write",
        "x-pomerado-callers": [
          "session",
          "oauth",
          "api_key"
        ],
        "x-pomerado-permission": "identity",
        "x-pomerado-key-permission": "api_keys:manage",
        "x-mint": {
          "content": "**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.\n\n**Permission:** any signed-in member, on their own records; an API key also needs `api_keys:manage`.\n\n**Effect:** Write: creates or changes something in your account.\n\n**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`permission_not_held`](/errors#permission_not_held) (403), [`forbidden`](/errors#forbidden) (403), [`not_found`](/errors#not_found) (404), [`api_key_limit_reached`](/errors#api_key_limit_reached) (409), [`request_too_large`](/errors#request_too_large) (413), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors)."
        }
      }
    },
    "/v1/api-keys/{id}/rotate": {
      "post": {
        "operationId": "api_keys.rotate",
        "tags": [
          "api_keys"
        ],
        "summary": "Rotate an API key",
        "description": "Replace a key's secret and return the new one once. The old secret stops working at once; the key keeps its ID, permissions, expiry and running jobs. With deliver \"dashboard\", nothing changes yet: the answer is a Dashboard link where the person rotates the key and sees the new secret. Only a key whose permissions the caller holds itself can be rotated.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "an API key ID: key_ and 32 lowercase hex digits",
            "schema": {
              "type": "string",
              "examples": [
                "key_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
              ]
            }
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [],
                "properties": {
                  "deliver": {
                    "type": "string",
                    "enum": [
                      "dashboard"
                    ],
                    "description": "Answer a Dashboard link instead of the secret, so the secret never reaches this client"
                  }
                },
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The key and its new one-time secret; With deliver dashboard: where to finish",
            "content": {
              "application/json": {
                "schema": {
                  "oneOf": [
                    {
                      "$ref": "#/components/schemas/ApiKeyWithSecret"
                    },
                    {
                      "$ref": "#/components/schemas/DashboardDelivery"
                    }
                  ]
                }
              }
            }
          },
          "400": {
            "description": "invalid_request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "unauthorized, reauthentication_required",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "permission_not_held, forbidden",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "not_found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "413": {
            "description": "request_too_large",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "500": {
            "description": "internal_error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "503": {
            "description": "temporarily_unavailable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearer": []
          }
        ],
        "x-pomerado-effect": "destructive",
        "x-pomerado-callers": [
          "session",
          "oauth",
          "api_key"
        ],
        "x-pomerado-permission": "identity",
        "x-pomerado-key-permission": "api_keys:manage",
        "x-mint": {
          "content": "**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.\n\n**Permission:** any signed-in member, on their own records; an API key also needs `api_keys:manage`.\n\n**Effect:** Destructive: replaces or removes something, and cannot be undone.\n\n**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`permission_not_held`](/errors#permission_not_held) (403), [`forbidden`](/errors#forbidden) (403), [`not_found`](/errors#not_found) (404), [`request_too_large`](/errors#request_too_large) (413), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors)."
        }
      }
    },
    "/v1/api-keys/{id}": {
      "delete": {
        "operationId": "api_keys.revoke",
        "tags": [
          "api_keys"
        ],
        "summary": "Revoke an API key",
        "description": "Revoke a key at once: requests with it are refused from then on, and the jobs it started stop. An API key may revoke only keys within its own permissions.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "an API key ID: key_ and 32 lowercase hex digits",
            "schema": {
              "type": "string",
              "examples": [
                "key_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
              ]
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Revoked"
          },
          "400": {
            "description": "invalid_request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "unauthorized, reauthentication_required",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "permission_not_held, forbidden",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "not_found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "500": {
            "description": "internal_error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "503": {
            "description": "temporarily_unavailable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearer": []
          }
        ],
        "x-pomerado-effect": "destructive",
        "x-pomerado-callers": [
          "session",
          "oauth",
          "api_key"
        ],
        "x-pomerado-permission": "identity",
        "x-pomerado-key-permission": "api_keys:manage",
        "x-mint": {
          "content": "**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.\n\n**Permission:** any signed-in member, on their own records; an API key also needs `api_keys:manage`.\n\n**Effect:** Destructive: replaces or removes something, and cannot be undone.\n\n**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`permission_not_held`](/errors#permission_not_held) (403), [`forbidden`](/errors#forbidden) (403), [`not_found`](/errors#not_found) (404), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors)."
        }
      }
    },
    "/v1/webhooks": {
      "get": {
        "operationId": "webhooks.list",
        "tags": [
          "webhooks"
        ],
        "summary": "List webhooks",
        "description": "The webhooks you made in this account, newest first: who made each, its URL and events, whether it is active and why not, and when it was created and last delivered. A Business Owner or Admin gets every member's webhooks, a departed member's included, and may delete any of them; only its creator changes, tests or rotates one. Never returns a signing secret.",
        "parameters": [
          {
            "name": "cursor",
            "in": "query",
            "required": false,
            "description": "The next_cursor of the previous page",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "limit",
            "in": "query",
            "required": false,
            "description": "Items per page, 1 to 100 (default 20)",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "One page of webhooks",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "data",
                    "next_cursor"
                  ],
                  "properties": {
                    "data": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/Webhook"
                      }
                    },
                    "next_cursor": {
                      "anyOf": [
                        {
                          "type": "string"
                        },
                        {
                          "type": "null"
                        }
                      ]
                    }
                  },
                  "additionalProperties": false
                }
              }
            }
          },
          "400": {
            "description": "invalid_request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "unauthorized, reauthentication_required",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "webhooks_unavailable, forbidden",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "500": {
            "description": "internal_error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "503": {
            "description": "temporarily_unavailable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearer": []
          }
        ],
        "x-pomerado-effect": "read",
        "x-pomerado-callers": [
          "session",
          "oauth",
          "api_key"
        ],
        "x-pomerado-permission": "jobs:read",
        "x-mint": {
          "content": "**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.\n\n**Permission:** `jobs:read`.\n\n**Effect:** Read: changes nothing.\n\n**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`webhooks_unavailable`](/errors#webhooks_unavailable) (403), [`forbidden`](/errors#forbidden) (403), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors)."
        }
      },
      "post": {
        "operationId": "webhooks.create",
        "tags": [
          "webhooks"
        ],
        "summary": "Create a webhook",
        "description": "Create a webhook that receives the job events of every job you could see, the jobs you start from any client (the Dashboard, an MCP client or an API key), and return its signing secret once. Every member can make webhooks, and only you change, test and rotate yours; a Business Owner or Admin also sees and may delete them. Deliveries are signed with Standard Webhooks (webhook-id, webhook-timestamp, webhook-signature), retried for about 15 minutes, and sent only to public HTTPS addresses. The webhook keeps working if you leave the team. Without events it receives all four. Events: job.needs_input (a job asks a question; the payload has its screened questions and the page where you answer), job.input_expiring (three minutes left to answer), job.succeeded and job.failed (a job settled). No event carries a result: read it from the job through the client that started it. You can hold at most 20 webhooks.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "url"
                ],
                "properties": {
                  "url": {
                    "type": "string"
                  },
                  "events": {
                    "type": "array",
                    "items": {
                      "type": "string",
                      "enum": [
                        "job.needs_input",
                        "job.input_expiring",
                        "job.succeeded",
                        "job.failed"
                      ]
                    },
                    "description": "an array of at least 1 item(s)",
                    "minItems": 1
                  }
                },
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "The new webhook and its one-time secret",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/WebhookWithSecret"
                }
              }
            }
          },
          "400": {
            "description": "invalid_request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "unauthorized, reauthentication_required",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "webhooks_unavailable, forbidden",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "409": {
            "description": "webhook_limit_reached",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "413": {
            "description": "request_too_large",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "500": {
            "description": "internal_error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "503": {
            "description": "temporarily_unavailable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearer": []
          }
        ],
        "x-pomerado-effect": "write",
        "x-pomerado-callers": [
          "session",
          "oauth",
          "api_key"
        ],
        "x-pomerado-permission": "jobs:read",
        "x-mint": {
          "content": "**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.\n\n**Permission:** `jobs:read`.\n\n**Effect:** Write: creates or changes something in your account.\n\n**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`webhooks_unavailable`](/errors#webhooks_unavailable) (403), [`forbidden`](/errors#forbidden) (403), [`webhook_limit_reached`](/errors#webhook_limit_reached) (409), [`request_too_large`](/errors#request_too_large) (413), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors)."
        }
      }
    },
    "/v1/webhooks/{id}": {
      "get": {
        "operationId": "webhooks.get",
        "tags": [
          "webhooks"
        ],
        "summary": "Get a webhook",
        "description": "One of your webhooks, or for a Business Owner or Admin any member's. Never returns its signing secret.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "a webhook ID: wh_ and 32 lowercase hex digits",
            "schema": {
              "type": "string",
              "examples": [
                "wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
              ]
            }
          }
        ],
        "responses": {
          "200": {
            "description": "The webhook",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Webhook"
                }
              }
            }
          },
          "400": {
            "description": "invalid_request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "unauthorized, reauthentication_required",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "webhooks_unavailable, forbidden",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "not_found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "500": {
            "description": "internal_error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "503": {
            "description": "temporarily_unavailable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearer": []
          }
        ],
        "x-pomerado-effect": "read",
        "x-pomerado-callers": [
          "session",
          "oauth",
          "api_key"
        ],
        "x-pomerado-permission": "jobs:read",
        "x-mint": {
          "content": "**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.\n\n**Permission:** `jobs:read`.\n\n**Effect:** Read: changes nothing.\n\n**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`webhooks_unavailable`](/errors#webhooks_unavailable) (403), [`forbidden`](/errors#forbidden) (403), [`not_found`](/errors#not_found) (404), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors)."
        }
      },
      "patch": {
        "operationId": "webhooks.update",
        "tags": [
          "webhooks"
        ],
        "summary": "Change a webhook",
        "description": "Change one of your webhooks' URL or events, or turn it off or on again; another member's is forbidden. A webhook turns itself off when its receiver answers 410 or fails 20 deliveries in a row; status active turns it back on and clears its failures. Events: job.needs_input (a job asks a question; the payload has its screened questions and the page where you answer), job.input_expiring (three minutes left to answer), job.succeeded and job.failed (a job settled). No event carries a result: read it from the job through the client that started it.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "a webhook ID: wh_ and 32 lowercase hex digits",
            "schema": {
              "type": "string",
              "examples": [
                "wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
              ]
            }
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [],
                "properties": {
                  "url": {
                    "type": "string"
                  },
                  "events": {
                    "type": "array",
                    "items": {
                      "type": "string",
                      "enum": [
                        "job.needs_input",
                        "job.input_expiring",
                        "job.succeeded",
                        "job.failed"
                      ]
                    },
                    "description": "an array of at least 1 item(s)",
                    "minItems": 1
                  },
                  "status": {
                    "type": "string",
                    "enum": [
                      "active",
                      "disabled"
                    ],
                    "description": "active turns a disabled webhook on again and clears its failures; disabled turns it off"
                  }
                },
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The changed webhook",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Webhook"
                }
              }
            }
          },
          "400": {
            "description": "invalid_request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "unauthorized, reauthentication_required",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "webhooks_unavailable, forbidden",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "not_found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "413": {
            "description": "request_too_large",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "500": {
            "description": "internal_error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "503": {
            "description": "temporarily_unavailable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearer": []
          }
        ],
        "x-pomerado-effect": "write",
        "x-pomerado-callers": [
          "session",
          "oauth",
          "api_key"
        ],
        "x-pomerado-permission": "jobs:read",
        "x-mint": {
          "content": "**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.\n\n**Permission:** `jobs:read`.\n\n**Effect:** Write: creates or changes something in your account.\n\n**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`webhooks_unavailable`](/errors#webhooks_unavailable) (403), [`forbidden`](/errors#forbidden) (403), [`not_found`](/errors#not_found) (404), [`request_too_large`](/errors#request_too_large) (413), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors)."
        }
      },
      "delete": {
        "operationId": "webhooks.delete",
        "tags": [
          "webhooks"
        ],
        "summary": "Delete a webhook",
        "description": "Delete one of your webhooks at once, or as a Business Owner or Admin any member's. Events not yet delivered to it are dropped; nothing else changes.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "a webhook ID: wh_ and 32 lowercase hex digits",
            "schema": {
              "type": "string",
              "examples": [
                "wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
              ]
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Deleted"
          },
          "400": {
            "description": "invalid_request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "unauthorized, reauthentication_required",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "webhooks_unavailable, forbidden",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "not_found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "500": {
            "description": "internal_error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "503": {
            "description": "temporarily_unavailable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearer": []
          }
        ],
        "x-pomerado-effect": "destructive",
        "x-pomerado-callers": [
          "session",
          "oauth",
          "api_key"
        ],
        "x-pomerado-permission": "jobs:read",
        "x-mint": {
          "content": "**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.\n\n**Permission:** `jobs:read`.\n\n**Effect:** Destructive: replaces or removes something, and cannot be undone.\n\n**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`webhooks_unavailable`](/errors#webhooks_unavailable) (403), [`forbidden`](/errors#forbidden) (403), [`not_found`](/errors#not_found) (404), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors)."
        }
      }
    },
    "/v1/webhooks/{id}/test": {
      "post": {
        "operationId": "webhooks.test",
        "tags": [
          "webhooks"
        ],
        "summary": "Send a test event",
        "description": "Send one signed webhook.test event to one of your webhooks now, active or not, and answer how its receiver responded. The event is {\"id\", \"type\": \"webhook.test\", \"created_at\", \"data\": {\"webhook_id\"}}; it is not retried and does not count toward turning the webhook off.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "a webhook ID: wh_ and 32 lowercase hex digits",
            "schema": {
              "type": "string",
              "examples": [
                "wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
              ]
            }
          }
        ],
        "responses": {
          "200": {
            "description": "How the receiver answered",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/WebhookTestResult"
                }
              }
            }
          },
          "400": {
            "description": "invalid_request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "unauthorized, reauthentication_required",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "webhooks_unavailable, forbidden",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "not_found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "409": {
            "description": "webhook_secret_unreadable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "500": {
            "description": "internal_error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "503": {
            "description": "temporarily_unavailable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearer": []
          }
        ],
        "x-pomerado-effect": "write",
        "x-pomerado-callers": [
          "session",
          "oauth",
          "api_key"
        ],
        "x-pomerado-permission": "jobs:read",
        "x-mint": {
          "content": "**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.\n\n**Permission:** `jobs:read`.\n\n**Effect:** Write: creates or changes something in your account.\n\n**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`webhooks_unavailable`](/errors#webhooks_unavailable) (403), [`forbidden`](/errors#forbidden) (403), [`not_found`](/errors#not_found) (404), [`webhook_secret_unreadable`](/errors#webhook_secret_unreadable) (409), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors)."
        }
      }
    },
    "/v1/webhooks/{id}/rotate-secret": {
      "post": {
        "operationId": "webhooks.rotate_secret",
        "tags": [
          "webhooks"
        ],
        "summary": "Rotate a webhook's signing secret",
        "description": "Replace one of your webhooks' signing secret and return the new one once. For 24 hours each delivery is signed with both secrets (two webhook-signature entries), so the receiver can switch without missing an event; then only the new one signs.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "a webhook ID: wh_ and 32 lowercase hex digits",
            "schema": {
              "type": "string",
              "examples": [
                "wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
              ]
            }
          }
        ],
        "responses": {
          "200": {
            "description": "The webhook and its new one-time secret",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/WebhookWithSecret"
                }
              }
            }
          },
          "400": {
            "description": "invalid_request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "unauthorized, reauthentication_required",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "webhooks_unavailable, forbidden",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "not_found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "500": {
            "description": "internal_error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "503": {
            "description": "temporarily_unavailable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearer": []
          }
        ],
        "x-pomerado-effect": "write",
        "x-pomerado-callers": [
          "session",
          "oauth",
          "api_key"
        ],
        "x-pomerado-permission": "jobs:read",
        "x-mint": {
          "content": "**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.\n\n**Permission:** `jobs:read`.\n\n**Effect:** Write: creates or changes something in your account.\n\n**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`webhooks_unavailable`](/errors#webhooks_unavailable) (403), [`forbidden`](/errors#forbidden) (403), [`not_found`](/errors#not_found) (404), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors)."
        }
      }
    }
  },
  "components": {
    "schemas": {
      "Error": {
        "type": "object",
        "required": [
          "error"
        ],
        "properties": {
          "error": {
            "type": "object",
            "required": [
              "code",
              "message",
              "retryable",
              "docs_url"
            ],
            "properties": {
              "code": {
                "type": "string"
              },
              "message": {
                "type": "string"
              },
              "retryable": {
                "type": "boolean"
              },
              "docs_url": {
                "type": "string"
              },
              "details": {
                "type": "object",
                "required": [],
                "properties": {},
                "additionalProperties": {
                  "$id": "/schemas/unknown"
                }
              }
            },
            "additionalProperties": false
          }
        },
        "additionalProperties": false
      },
      "ApiKey": {
        "type": "object",
        "required": [
          "id",
          "name",
          "permissions",
          "integration_id",
          "prefix",
          "created_via",
          "created_at",
          "expires_at",
          "last_used_at"
        ],
        "properties": {
          "id": {
            "$ref": "#/components/schemas/api_key_id"
          },
          "name": {
            "type": "string",
            "examples": [
              "Nightly price check"
            ]
          },
          "permissions": {
            "type": "array",
            "items": {
              "type": "string",
              "enum": [
                "tools:read",
                "usage:read",
                "tools:build",
                "runs:create",
                "jobs:read",
                "jobs:cancel",
                "connections:read",
                "credentials:manage",
                "api_keys:manage"
              ]
            },
            "examples": [
              [
                "tools:read",
                "runs:create",
                "jobs:read"
              ]
            ]
          },
          "integration_id": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/integration_id"
              },
              {
                "type": "null"
              }
            ],
            "description": "The one integration the key is bound to, or null for an account key"
          },
          "prefix": {
            "type": "string",
            "description": "The token's visible start, pom_ and 8 hex digits, to tell keys apart",
            "examples": [
              "pom_0f8e2d1c"
            ]
          },
          "created_via": {
            "type": "string",
            "enum": [
              "dashboard",
              "api",
              "mcp"
            ],
            "description": "Where the key was created"
          },
          "created_at": {
            "$ref": "#/components/schemas/Timestamp"
          },
          "expires_at": {
            "$ref": "#/components/schemas/Timestamp"
          },
          "last_used_at": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/Timestamp"
              },
              {
                "type": "null"
              }
            ],
            "description": "When a request last used the key, or null if none has"
          }
        },
        "additionalProperties": false
      },
      "api_key_id": {
        "type": "string",
        "description": "an API key ID: key_ and 32 lowercase hex digits",
        "examples": [
          "key_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
        ]
      },
      "integration_id": {
        "type": "string",
        "description": "an integration ID: int_ and 32 lowercase hex digits",
        "examples": [
          "int_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
        ]
      },
      "Timestamp": {
        "type": "string",
        "format": "date-time",
        "description": "An ISO 8601 timestamp in UTC",
        "examples": [
          "2026-10-05T18:30:00.000Z"
        ]
      },
      "ApiKeyWithSecret": {
        "type": "object",
        "required": [
          "id",
          "name",
          "permissions",
          "integration_id",
          "prefix",
          "created_via",
          "created_at",
          "expires_at",
          "last_used_at",
          "secret"
        ],
        "properties": {
          "id": {
            "$ref": "#/components/schemas/api_key_id"
          },
          "name": {
            "type": "string",
            "examples": [
              "Nightly price check"
            ]
          },
          "permissions": {
            "type": "array",
            "items": {
              "type": "string",
              "enum": [
                "tools:read",
                "usage:read",
                "tools:build",
                "runs:create",
                "jobs:read",
                "jobs:cancel",
                "connections:read",
                "credentials:manage",
                "api_keys:manage"
              ]
            },
            "examples": [
              [
                "tools:read",
                "runs:create",
                "jobs:read"
              ]
            ]
          },
          "integration_id": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/integration_id"
              },
              {
                "type": "null"
              }
            ],
            "description": "The one integration the key is bound to, or null for an account key"
          },
          "prefix": {
            "type": "string",
            "description": "The token's visible start, pom_ and 8 hex digits, to tell keys apart",
            "examples": [
              "pom_0f8e2d1c"
            ]
          },
          "created_via": {
            "type": "string",
            "enum": [
              "dashboard",
              "api",
              "mcp"
            ],
            "description": "Where the key was created"
          },
          "created_at": {
            "$ref": "#/components/schemas/Timestamp"
          },
          "expires_at": {
            "$ref": "#/components/schemas/Timestamp"
          },
          "last_used_at": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/Timestamp"
              },
              {
                "type": "null"
              }
            ],
            "description": "When a request last used the key, or null if none has"
          },
          "secret": {
            "type": "string",
            "description": "The key's secret, shown in this answer only. Send it as a Bearer token.",
            "examples": [
              "pom_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190_example-secret-not-a-real-key-0000000000000"
            ]
          }
        },
        "additionalProperties": false
      },
      "DashboardDelivery": {
        "type": "object",
        "required": [
          "dashboard_url"
        ],
        "properties": {
          "dashboard_url": {
            "type": "string",
            "description": "A signed-in Dashboard page where the person finishes this and sees the secret once"
          }
        },
        "additionalProperties": false
      },
      "Int": {
        "type": "integer",
        "description": "an integer"
      },
      "Webhook": {
        "type": "object",
        "required": [
          "id",
          "created_by",
          "url",
          "events",
          "status",
          "disabled_reason",
          "created_at",
          "last_delivery_at"
        ],
        "properties": {
          "id": {
            "$ref": "#/components/schemas/webhook_id"
          },
          "created_by": {
            "$ref": "#/components/schemas/WebhookCreator"
          },
          "url": {
            "type": "string"
          },
          "events": {
            "type": "array",
            "items": {
              "type": "string",
              "enum": [
                "job.needs_input",
                "job.input_expiring",
                "job.succeeded",
                "job.failed"
              ]
            }
          },
          "status": {
            "type": "string",
            "enum": [
              "active",
              "disabled"
            ]
          },
          "disabled_reason": {
            "anyOf": [
              {
                "type": "string",
                "enum": [
                  "manual",
                  "gone",
                  "unreachable",
                  "secret_unreadable"
                ]
              },
              {
                "type": "null"
              }
            ],
            "description": "Why a disabled webhook sends nothing: manual (turned off), gone (its receiver answered 410), unreachable (20 failed deliveries in a row) or secret_unreadable (rotate its secret)"
          },
          "created_at": {
            "$ref": "#/components/schemas/Date"
          },
          "last_delivery_at": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/Date"
              },
              {
                "type": "null"
              }
            ]
          }
        },
        "additionalProperties": false
      },
      "webhook_id": {
        "type": "string",
        "description": "a webhook ID: wh_ and 32 lowercase hex digits",
        "examples": [
          "wh_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
        ]
      },
      "WebhookCreator": {
        "type": "object",
        "required": [
          "user_id",
          "email"
        ],
        "properties": {
          "user_id": {
            "type": "string",
            "description": "The member's user ID"
          },
          "email": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "description": "The email they sign in with, or null when the account no longer has it"
          }
        },
        "additionalProperties": false,
        "description": "The member who made the webhook: only they change, test and rotate it, and it carries the events of the jobs they could see"
      },
      "Date": {
        "type": "string",
        "description": "a string to be decoded into a Date"
      },
      "WebhookWithSecret": {
        "type": "object",
        "required": [
          "id",
          "created_by",
          "url",
          "events",
          "status",
          "disabled_reason",
          "created_at",
          "last_delivery_at",
          "secret"
        ],
        "properties": {
          "id": {
            "$ref": "#/components/schemas/webhook_id"
          },
          "created_by": {
            "$ref": "#/components/schemas/WebhookCreator"
          },
          "url": {
            "type": "string"
          },
          "events": {
            "type": "array",
            "items": {
              "type": "string",
              "enum": [
                "job.needs_input",
                "job.input_expiring",
                "job.succeeded",
                "job.failed"
              ]
            }
          },
          "status": {
            "type": "string",
            "enum": [
              "active",
              "disabled"
            ]
          },
          "disabled_reason": {
            "anyOf": [
              {
                "type": "string",
                "enum": [
                  "manual",
                  "gone",
                  "unreachable",
                  "secret_unreadable"
                ]
              },
              {
                "type": "null"
              }
            ],
            "description": "Why a disabled webhook sends nothing: manual (turned off), gone (its receiver answered 410), unreachable (20 failed deliveries in a row) or secret_unreadable (rotate its secret)"
          },
          "created_at": {
            "$ref": "#/components/schemas/Date"
          },
          "last_delivery_at": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/Date"
              },
              {
                "type": "null"
              }
            ]
          },
          "secret": {
            "type": "string",
            "description": "The Standard Webhooks signing secret (whsec_…), shown in this answer only. Verify each delivery's webhook-signature with it."
          }
        },
        "additionalProperties": false
      },
      "WebhookTestResult": {
        "type": "object",
        "required": [
          "delivered",
          "status",
          "failure"
        ],
        "properties": {
          "delivered": {
            "type": "boolean",
            "description": "The receiver answered with a 2xx"
          },
          "status": {
            "anyOf": [
              {
                "$ref": "#/components/schemas/Int"
              },
              {
                "type": "null"
              }
            ],
            "description": "The receiver's HTTP status, or null when none answered"
          },
          "failure": {
            "anyOf": [
              {
                "type": "string",
                "enum": [
                  "invalid_url",
                  "forbidden_address",
                  "timeout",
                  "unreachable"
                ]
              },
              {
                "type": "null"
              }
            ],
            "description": "Why no receiver answered: forbidden_address when the URL resolves to a private address, timeout after 10 seconds, or unreachable"
          }
        },
        "additionalProperties": false
      }
    },
    "securitySchemes": {
      "bearer": {
        "type": "http",
        "scheme": "bearer"
      }
    }
  }
}
