{
  "openapi": "3.1.0",
  "info": {
    "title": "Vanda Analytics Auth API",
    "description": "Auth API with Auth0",
    "version": "1.0.0"
  },
  "servers": [
    {
      "url": "https://api.vanda-analytics.com",
      "description": "Production server"
    }
  ],
  "paths": {
    "/auth/health": {
      "get": {
        "tags": [
          "Utility",
          "Utility"
        ],
        "summary": "Health check endpoint",
        "operationId": "health_check_auth_health_get",
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          }
        },
        "security": []
      }
    },
    "/auth/change-password": {
      "post": {
        "tags": [
          "Auth",
          "Auth"
        ],
        "summary": "Endpoint to change password",
        "description": "Endpoint to change password",
        "operationId": "change_password_auth_change_password_post",
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ChangePasswordResponse"
                }
              }
            }
          }
        },
        "security": [
          {
            "HTTPBearer": []
          }
        ]
      }
    },
    "/auth/get-entitlement": {
      "get": {
        "tags": [
          "Auth",
          "Auth"
        ],
        "summary": "Endpoint to get user entitlement",
        "description": "Endpoint to get user entitlement",
        "operationId": "get_entitlement_auth_get_entitlement_get",
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/GetEntitlementResponse"
                }
              }
            }
          }
        },
        "security": [
          {
            "HTTPBearer": []
          }
        ]
      }
    },
    "/auth/basic": {
      "post": {
        "tags": [
          "Auth",
          "Auth"
        ],
        "summary": "Get Test Access Token",
        "description": "Generate access token for SDK.",
        "operationId": "get_test_token_auth_basic_post",
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/TokenRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "description": "Token generated successfully",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TokenResponse"
                }
              }
            }
          },
          "401": {
            "description": "Invalid credentials or Auth0 not configured"
          },
          "403": {
            "description": "Endpoint disabled in staging/production"
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "503": {
            "description": "Auth0 unavailable"
          }
        },
        "security": []
      }
    },
    "/auth/login": {
      "post": {
        "tags": [
          "Auth",
          "Auth"
        ],
        "summary": "Get Test Access Token",
        "description": "Generate access token for ai-agents and other required services.",
        "operationId": "get_test_token_auth_login_post",
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/TokenRequest"
              }
            }
          },
          "required": true
        },
        "responses": {
          "200": {
            "description": "Token generated successfully",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TokenResponse"
                }
              }
            }
          },
          "401": {
            "description": "Invalid credentials or Auth0 not configured"
          },
          "403": {
            "description": "Endpoint disabled in staging/production"
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "503": {
            "description": "Auth0 unavailable"
          }
        },
        "security": []
      }
    },
    "/auth/api-keys": {
      "post": {
        "tags": [
          "API Keys"
        ],
        "summary": "Generate an API key",
        "description": "`expires_in_days` is optional — omit it and the key defaults to a 90-day lifetime (`API_KEY_DEFAULT_TTL_DAYS`).\n\n`name` is optional too — a label to help you recognise the key in the list.",
        "operationId": "create_api_key_auth_api_keys_post",
        "security": [
          {
            "HTTPBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ApiKeyCreateRequest"
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ApiKeyCreateResponse"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          }
        }
      },
      "get": {
        "tags": [
          "API Keys"
        ],
        "summary": "List your API keys",
        "operationId": "list_api_keys_auth_api_keys_get",
        "security": [
          {
            "HTTPBearer": []
          }
        ],
        "parameters": [
          {
            "name": "active",
            "in": "query",
            "required": false,
            "schema": {
              "anyOf": [
                {
                  "type": "boolean"
                },
                {
                  "type": "null"
                }
              ],
              "description": "Filter by the active flag: true = not revoked, false = revoked. Omit to return all keys.",
              "title": "Active"
            },
            "description": "Filter by the active flag: true = not revoked, false = revoked. Omit to return all keys."
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "array",
                  "items": {
                    "$ref": "#/components/schemas/ApiKeyListItem"
                  },
                  "title": "Response List Api Keys Auth Api Keys Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          }
        }
      }
    },
    "/auth/api-keys/{key_id}": {
      "delete": {
        "tags": [
          "API Keys"
        ],
        "summary": "Revoke an API key",
        "operationId": "revoke_api_key_auth_api_keys__key_id__delete",
        "security": [
          {
            "HTTPBearer": []
          }
        ],
        "parameters": [
          {
            "name": "key_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "integer",
              "title": "Key Id"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Successful Response"
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          }
        }
      }
    },
    "/": {
      "get": {
        "summary": "Root",
        "description": "Root endpoint providing service metadata.",
        "operationId": "root__get",
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          }
        },
        "security": []
      }
    }
  },
  "components": {
    "schemas": {
      "ApiKeyCreateRequest": {
        "properties": {
          "expires_in_days": {
            "anyOf": [
              {
                "type": "integer",
                "maximum": 365,
                "minimum": 1
              },
              {
                "type": "null"
              }
            ],
            "title": "Expires In Days",
            "description": "Key lifetime in days. Defaults to API_KEY_DEFAULT_TTL_DAYS (90).",
            "default": 90
          },
          "name": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 100
              },
              {
                "type": "null"
              }
            ],
            "title": "Name",
            "description": "Optional label to recognise this key in the list."
          }
        },
        "type": "object",
        "title": "ApiKeyCreateRequest"
      },
      "ApiKeyCreateResponse": {
        "properties": {
          "id": {
            "type": "integer",
            "title": "Id"
          },
          "api_key": {
            "type": "string",
            "title": "Api Key",
            "description": "Shown once. It cannot be recovered later."
          },
          "name": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Name"
          },
          "expires_at": {
            "type": "string",
            "format": "date-time",
            "title": "Expires At"
          },
          "created_at": {
            "type": "string",
            "format": "date-time",
            "title": "Created At"
          }
        },
        "type": "object",
        "required": [
          "id",
          "api_key",
          "expires_at",
          "created_at"
        ],
        "title": "ApiKeyCreateResponse",
        "description": "The only response that ever carries the raw key."
      },
      "ApiKeyListItem": {
        "properties": {
          "id": {
            "type": "integer",
            "title": "Id"
          },
          "name": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Name"
          },
          "key_prefix": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Key Prefix"
          },
          "created_at": {
            "type": "string",
            "format": "date-time",
            "title": "Created At"
          },
          "expires_at": {
            "type": "string",
            "format": "date-time",
            "title": "Expires At"
          },
          "last_used_at": {
            "anyOf": [
              {
                "type": "string",
                "format": "date-time"
              },
              {
                "type": "null"
              }
            ],
            "title": "Last Used At"
          },
          "active": {
            "type": "boolean",
            "title": "Active"
          }
        },
        "type": "object",
        "required": [
          "id",
          "created_at",
          "expires_at",
          "active"
        ],
        "title": "ApiKeyListItem",
        "description": "A key as shown back to its owner. Deliberately has no key material."
      },
      "ChangePasswordResponse": {
        "properties": {
          "message": {
            "type": "string",
            "title": "Message",
            "example": "Password reset email sent successfully"
          }
        },
        "type": "object",
        "required": [
          "message"
        ],
        "title": "ChangePasswordResponse"
      },
      "GetEntitlementResponse": {
        "properties": {
          "entitlement": {
            "type": "string",
            "title": "Entitlement",
            "example": "entitlement"
          }
        },
        "type": "object",
        "required": [
          "entitlement"
        ],
        "title": "GetEntitlementResponse"
      },
      "HTTPValidationError": {
        "properties": {
          "detail": {
            "items": {
              "$ref": "#/components/schemas/ValidationError"
            },
            "type": "array",
            "title": "Detail"
          }
        },
        "type": "object",
        "title": "HTTPValidationError"
      },
      "TokenRequest": {
        "properties": {
          "email": {
            "type": "string",
            "format": "email",
            "title": "Email",
            "description": "User email address"
          },
          "password": {
            "type": "string",
            "minLength": 8,
            "title": "Password",
            "description": "User password"
          }
        },
        "type": "object",
        "required": [
          "email",
          "password"
        ],
        "title": "TokenRequest",
        "example": {
          "email": "basic@test.com",
          "password": "Test1234!"
        }
      },
      "TokenResponse": {
        "properties": {
          "access_token": {
            "type": "string",
            "title": "Access Token",
            "description": "JWT access token for API authentication"
          },
          "token_type": {
            "type": "string",
            "title": "Token Type",
            "description": "Token type",
            "default": "Bearer"
          },
          "expires_in": {
            "type": "integer",
            "title": "Expires In",
            "description": "Token expiration in seconds"
          },
          "scope": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Scope",
            "description": "Granted scopes"
          }
        },
        "type": "object",
        "required": [
          "access_token",
          "expires_in"
        ],
        "title": "TokenResponse"
      },
      "ValidationError": {
        "properties": {
          "loc": {
            "items": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "integer"
                }
              ]
            },
            "type": "array",
            "title": "Location"
          },
          "msg": {
            "type": "string",
            "title": "Message"
          },
          "type": {
            "type": "string",
            "title": "Error Type"
          },
          "input": {
            "title": "Input"
          },
          "ctx": {
            "type": "object",
            "title": "Context"
          }
        },
        "type": "object",
        "required": [
          "loc",
          "msg",
          "type"
        ],
        "title": "ValidationError"
      }
    },
    "securitySchemes": {
      "HTTPBearer": {
        "type": "http",
        "scheme": "bearer"
      }
    }
  }
}