{"openapi":"3.1.0","info":{"title":"Alethica Partner API","version":"1.1.0","description":"Embedded finance API for partner integrations (INNOV-13)."},"servers":[{"url":"https://api-staging.alethica.co/api/v1"}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"OAuthTokenResponse":{"type":"object","properties":{"access_token":{"type":"string"},"token_type":{"type":"string","example":"Bearer"},"expires_in":{"type":"integer"},"scope":{"type":"string"}},"required":["access_token","token_type","expires_in","scope"]},"PartnerApplicationCreateRequest":{"type":"object","properties":{"externalApplicationId":{"type":"string"},"application":{"type":"object","description":"Dealer submission payload compatible with internal dealerSubmitLoan schema."}},"required":["externalApplicationId","application"]},"PartnerWebhookEndpoint":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"url":{"type":"string","format":"uri"},"subscribedEvents":{"type":"array","items":{"type":"string"}},"isActive":{"type":"boolean"},"maxRetries":{"type":"integer"},"timeoutMs":{"type":"integer"},"createdAt":{"type":"string","format":"date-time"},"updatedAt":{"type":"string","format":"date-time"}}},"PartnerSignatureSummary":{"type":"object","properties":{"externalSignatureId":{"type":"string"},"signatureRequestId":{"type":"string","format":"uuid"},"code":{"type":"string"},"type":{"type":"string"},"title":{"type":"string"},"description":{"type":"string","nullable":true},"status":{"type":"string"},"documentHash":{"type":"string"},"documentSize":{"type":"integer"},"expiresAt":{"type":"string","format":"date-time","nullable":true},"completedAt":{"type":"string","format":"date-time","nullable":true},"cancelledAt":{"type":"string","format":"date-time","nullable":true},"createdAt":{"type":"string","format":"date-time"},"updatedAt":{"type":"string","format":"date-time"},"signatures":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"status":{"type":"string"},"method":{"type":"string"},"signedAt":{"type":"string","format":"date-time","nullable":true},"signerName":{"type":"string"},"signerEmail":{"type":"string","nullable":true}}}}}},"PartnerCrmWhatsAppLine":{"type":"object","nullable":true,"description":"Physical store number anchoring the deal thread. Null until a message exists on the wire. Failed or merely queued sends do not establish affinity.","properties":{"connectionId":{"type":"string","format":"uuid"},"label":{"type":["string","null"],"description":"Store-configured line label, for example Vendas."},"phoneNumber":{"type":["string","null"],"description":"Store WhatsApp number as reported by the provider."}},"required":["connectionId","label","phoneNumber"]}}},"paths":{"/partner/oauth/token":{"post":{"summary":"Issue OAuth2 client credentials token","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"grant_type":{"type":"string","enum":["client_credentials"]},"client_id":{"type":"string"},"client_secret":{"type":"string"},"scope":{"type":"string"}},"required":["grant_type","client_id","client_secret"]}},"application/x-www-form-urlencoded":{"schema":{"type":"object","properties":{"grant_type":{"type":"string","enum":["client_credentials"]},"client_id":{"type":"string"},"client_secret":{"type":"string"},"scope":{"type":"string"}},"required":["grant_type","client_id","client_secret"]}}}},"responses":{"200":{"description":"Token issued","content":{"application/json":{"schema":{"$ref":"#/components/schemas/OAuthTokenResponse"}}}}}}},"/partner/applications":{"post":{"summary":"Create partner application","security":[{"bearerAuth":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/PartnerApplicationCreateRequest"}}}},"responses":{"200":{"description":"Idempotent replay"},"201":{"description":"Created"}}}},"/partner/applications/{externalApplicationId}":{"get":{"summary":"Get application by partner external ID","security":[{"bearerAuth":[]}],"parameters":[{"name":"externalApplicationId","in":"path","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"Found"}}}},"/partner/applications/{externalApplicationId}/timeline":{"get":{"summary":"Get application timeline","security":[{"bearerAuth":[]}],"parameters":[{"name":"externalApplicationId","in":"path","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"Timeline returned"}}}},"/partner/crm/deals":{"get":{"summary":"List CRM deals (scope: crm:read). Structured customer contact fields are returned to the bound partner; only staff names and free-text notes (incl. the lost reason) are redacted. whatsappLine identifies the physical store number anchoring the thread. Deal identity is id, never customer phone. No customer-PII search.","security":[{"bearerAuth":[]}],"parameters":[{"name":"page","in":"query","schema":{"type":"integer"}},{"name":"limit","in":"query","schema":{"type":"integer","maximum":200}},{"name":"status","in":"query","schema":{"type":"string","enum":["OPEN","WON","LOST"]}},{"name":"stage","in":"query","schema":{"type":"string"},"description":"Stage id or slug. Stages are STORE-DEFINED — discover them via GET /partner/crm/pipelines. Unscoped, a slug matches every pipeline carrying it; add pipelineId to scope. Unknown → 400 INVALID_STAGE with the valid slugs."},{"name":"pipelineId","in":"query","schema":{"type":"string","format":"uuid"},"description":"Scope the list (and the stage filter) to one funnel."},{"name":"source","in":"query","schema":{"type":"string"}},{"name":"assignedToUserId","in":"query","schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"Deals page (redacted)"}}},"post":{"summary":"Create a CRM deal (crm:write). Structured contact fields persist and are returned. Pass externalRef for idempotency — re-POSTing a known LIVE ref UPDATES that deal instead of duplicating (a soft-deleted ref is freed → re-POST mints a NEW deal, never resurrects).","security":[{"bearerAuth":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"customerName":{"type":"string"},"customerEmail":{"type":"string","format":"email"},"customerPhone":{"type":"string"},"customerCpf":{"type":"string","description":"CPF or CNPJ (customer document)"},"customerCompany":{"type":"string"},"customerCity":{"type":"string"},"customerState":{"type":"string"},"vehicleMake":{"type":"string"},"vehicleModel":{"type":"string"},"vehicleYear":{"type":"integer"},"estimatedValue":{"type":"number"},"source":{"type":"string","description":"WALK_IN | MARKETPLACE_INQUIRY | AD | REFERRAL | WHATSAPP | CHATWOOT | OTHER"},"sourceOptionId":{"type":"string","format":"uuid","description":"Custom source pick (GET /partner/crm/options → sources) — projects source=OTHER on the wire, returned as deal.sourceOption. Sending an enum `source` without it clears a previous pick."},"pipelineId":{"type":"string","format":"uuid","description":"Target funnel (must be a live pipeline of the bound store); omitted = the default funnel. The deal lands on its entry stage."},"externalRef":{"type":"string","description":"Your own reference (idempotency key, scoped per dealership)"},"metadata":{"type":"object","description":"Free-form attribute bag (≤50 keys, ≤8 KB serialized)"}},"required":["customerName"]}}}},"responses":{"201":{"description":"Created (contact fields included; staff notes/lostReason redacted)"}}}},"/partner/crm/deals/pipeline-summary":{"get":{"summary":"Funnel rollup — open value/count per stage (zero-filled over the funnel's live open stages, position order) + won-this-month (store-wide). byStage rows carry stage (slug) + additive stageId/name/kind/position. (crm:read)","security":[{"bearerAuth":[]}],"parameters":[{"name":"pipelineId","in":"query","schema":{"type":"string","format":"uuid"},"description":"Which funnel to summarize; omitted = the default funnel."}],"responses":{"200":{"description":"Summary"}}}},"/partner/crm/pipelines":{"get":{"summary":"Funnel discovery (crm:read) — the bound store's pipelines + stage definitions {id, slug, name, kind, position, archivedAt}. Stages are store-defined: consume this instead of hard-coding the legacy 7-value taxonomy. kind ∈ OPEN|WON|LOST is the stable semantic anchor.","security":[{"bearerAuth":[]}],"responses":{"200":{"description":"Pipelines + stages (configuration only, no PII)"}}}},"/partner/crm/options":{"get":{"summary":"Pick-list discovery (crm:read) — the bound store's sources / lostReasons / paymentMethods, each {id, name, systemKey, position, archivedAt}. systemKey names the enum a seeded built-in projects to on the wire; custom options have systemKey null and project OUTRO/OTHER. Send the ids on win (paymentOptionIds), lose (lostReasonOptionId) and create/update (sourceOptionId); deal reads resolve them as sourceOption/lostReasonOption/paymentMethodOptions. Archived options stay listed (closed deals reference them) — offer only archivedAt=null as picks.","security":[{"bearerAuth":[]}],"responses":{"200":{"description":"Options (store configuration only, no PII)"}}}},"/partner/crm/deals/analytics":{"get":{"summary":"CRM analytics — funnel, win/loss, cycle, per-rep (crm:read). Rep names stripped.","security":[{"bearerAuth":[]}],"parameters":[{"name":"days","in":"query","schema":{"type":"integer"}},{"name":"pipelineId","in":"query","schema":{"type":"string","format":"uuid"},"description":"Scope the funnel snapshot to one funnel; every other cohort stays store-wide."}],"responses":{"200":{"description":"Analytics"}}}},"/partner/crm/assignable-members":{"get":{"summary":"Assignable team members — userId + role only, no names (crm:read)","security":[{"bearerAuth":[]}],"responses":{"200":{"description":"Members"}}}},"/partner/crm/deals/{id}":{"get":{"summary":"Get a CRM deal incl. activity timeline (crm:read). Contact fields and nullable whatsappLine {connectionId,label,phoneNumber} returned; staff notes/lostReason redacted; tasks not exposed. Pick-list picks resolve as sourceOption / lostReasonOption / paymentMethodOptions ({id, name}); the flat enums stay the stable wire.","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"Deal (redacted)"}}},"patch":{"summary":"Update a CRM deal (crm:write). Same field set as create (contact, vehicle, values, source). Sending an enum `source` WITHOUT `sourceOptionId` clears a previous custom pick; sending `sourceOptionId` projects source=OTHER.","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"source":{"type":"string","description":"Enum source — clears a previous sourceOptionId when sent alone"},"sourceOptionId":{"type":"string","format":"uuid","description":"Custom source pick (GET /partner/crm/options → sources); projects source=OTHER"}},"description":"Plus the create field set (customer*, vehicle*, estimatedValue, assignedToUserId, metadata…)"}}}},"responses":{"200":{"description":"Updated"}}},"delete":{"summary":"Soft-delete a CRM deal (crm:write). Recoverable on our side; fires deal.deleted so a mirror can drop it. Re-deleting a deleted deal → DEAL_NOT_FOUND.","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"Deleted. Repeating the request returns 404 DEAL_NOT_FOUND."}}}},"/partner/crm/deals/{id}/stage":{"patch":{"summary":"Move a deal to an OPEN stage of its own funnel (crm:write). `stage` = stage id or slug (store-defined — see GET /partner/crm/pipelines). Terminal stages are rejected: win/lose have their own endpoints. Unknown/terminal → 400 INVALID_STAGE with the valid slugs.","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"stage":{"type":"string","description":"Stage id or slug"}},"required":["stage"]}}}},"responses":{"200":{"description":"Updated"}}}},"/partner/crm/deals/{id}/activities":{"post":{"summary":"Add a note to a deal (crm:write)","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"message":{"type":"string"}},"required":["message"]}}}},"responses":{"201":{"description":"Activity added"}}}},"/partner/crm/deals/{id}/win":{"post":{"summary":"Mark a deal won (crm:write). Send paymentOptionIds (store pick-list ids — GET /partner/crm/options) and/or legacy paymentMethods enums; option picks are returned as deal.paymentMethodOptions and project stable enums into deal.paymentMethods.","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"requestBody":{"content":{"application/json":{"schema":{"type":"object","properties":{"paymentMethods":{"type":"array","items":{"type":"string"},"description":"Legacy enum values"},"paymentOptionIds":{"type":"array","items":{"type":"string","format":"uuid"},"description":"Store pick-list ids (GET /partner/crm/options → paymentMethods)"}}}}}},"responses":{"200":{"description":"Won"}}}},"/partner/crm/deals/{id}/lose":{"post":{"summary":"Mark a deal lost (crm:write). Send a lostReasonOptionId (store pick-list id) OR a structured lostReasonCode, and/or free-text lostReason (at least one). The option/code are returned on deal reads (lostReasonOption / lostReasonCode); the free text is stored but never returned.","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"lostReason":{"type":"string","maxLength":500,"description":"Free text — stored, never returned over the API"},"lostReasonCode":{"type":"string","enum":["PRECO","COMPROU_OUTRO_LUGAR","FINANCIAMENTO_NEGADO","SEM_RETORNO","DESISTIU","OUTRO"],"description":"Structured taxonomy — returned as deal.lostReasonCode"},"lostReasonOptionId":{"type":"string","format":"uuid","description":"Store pick-list id (GET /partner/crm/options → lostReasons) — projects the matching lostReasonCode"}}}}}},"responses":{"200":{"description":"Lost"}}}},"/partner/crm/deals/from-inquiry/{inquiryId}":{"post":{"summary":"Create a deal from a marketplace inquiry, idempotent (crm:write)","security":[{"bearerAuth":[]}],"parameters":[{"name":"inquiryId","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"responses":{"201":{"description":"Created"}}}},"/partner/crm/deals/{id}/start-financing":{"post":{"summary":"Start financing for a deal — mints a Loan via the standard origination path (scope: crm:financing:start, isolated/most-privileged). Anchors the loan in the partner-application ledger; idempotent on retry.","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","description":"Full dealer loan submission (customer, vehicle, amount, term) + optional externalDealId"}}}},"responses":{"201":{"description":"Financing started"}}}},"/partner/crm/deals/{id}/tasks":{"post":{"summary":"Add a follow-up task to a deal (scope: crm:tasks:write)","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"title":{"type":"string"},"dueAt":{"type":"string","format":"date-time"},"assignedToUserId":{"type":"string","format":"uuid"}},"required":["title","dueAt"]}}}},"responses":{"201":{"description":"Task created"}}}},"/partner/crm/tasks/{id}":{"patch":{"summary":"Update a task (crm:tasks:write)","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"Updated"}}},"delete":{"summary":"Delete a task (crm:tasks:write)","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"Deleted"}}}},"/partner/marketplace":{"get":{"summary":"List the dealer's vehicle listings (scope: marketplace:listings:read)","security":[{"bearerAuth":[]}],"parameters":[{"name":"page","in":"query","schema":{"type":"integer","minimum":1}},{"name":"limit","in":"query","schema":{"type":"integer","minimum":1,"maximum":100}},{"name":"status","in":"query","schema":{"type":"string"}}],"responses":{"200":{"description":"Listings page"}}}},"/partner/marketplace/{externalListingId}":{"get":{"summary":"Get a listing by the partner's own external ID (scope: marketplace:listings:read)","security":[{"bearerAuth":[]}],"parameters":[{"name":"externalListingId","in":"path","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"Found"}}},"put":{"summary":"Upsert (create or update) a listing, keyed by externalListingId (scope: marketplace:listings:write)","security":[{"bearerAuth":[]}],"parameters":[{"name":"externalListingId","in":"path","required":true,"schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"make":{"type":"string"},"model":{"type":"string"},"year":{"type":"integer"},"version":{"type":"string"},"color":{"type":"string"},"mileage":{"type":"integer"},"askingPrice":{"type":"number"},"negotiable":{"type":"boolean"},"fuelType":{"type":"string"},"transmission":{"type":"string"},"bodyType":{"type":"string"},"city":{"type":"string"},"state":{"type":"string"},"description":{"type":"string"},"features":{"type":"array","items":{"type":"string"}}},"required":["make","model","year","askingPrice","city","state"]}}}},"responses":{"200":{"description":"Upserted"}}},"delete":{"summary":"Remove (unpublish) a listing (scope: marketplace:listings:write)","security":[{"bearerAuth":[]}],"parameters":[{"name":"externalListingId","in":"path","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"Removed"}}}},"/partner/marketplace/{externalListingId}/submit":{"post":{"summary":"Submit a listing for approval/publication (scope: marketplace:listings:write)","security":[{"bearerAuth":[]}],"parameters":[{"name":"externalListingId","in":"path","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"Submitted"}}}},"/partner/signatures":{"post":{"summary":"Create signature request for a PDF document","security":[{"bearerAuth":[]}],"requestBody":{"required":true,"content":{"multipart/form-data":{"schema":{"type":"object","properties":{"document":{"type":"string","format":"binary"},"externalSignatureId":{"type":"string"},"title":{"type":"string"},"description":{"type":"string"},"signers":{"type":"string","description":"JSON string array of signers"},"expiresInDays":{"type":"integer"}},"required":["document","externalSignatureId","title","signers"]}}}},"responses":{"200":{"description":"Idempotent replay"},"201":{"description":"Created"}}},"get":{"summary":"List partner signature requests","security":[{"bearerAuth":[]}],"parameters":[{"name":"page","in":"query","schema":{"type":"integer","minimum":1}},{"name":"limit","in":"query","schema":{"type":"integer","minimum":1,"maximum":100}},{"name":"status","in":"query","schema":{"type":"string"}},{"name":"type","in":"query","schema":{"type":"string"}}],"responses":{"200":{"description":"List returned"}}}},"/partner/signatures/{externalSignatureId}":{"get":{"summary":"Get signature request by external signature ID","security":[{"bearerAuth":[]}],"parameters":[{"name":"externalSignatureId","in":"path","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"Found","content":{"application/json":{"schema":{"$ref":"#/components/schemas/PartnerSignatureSummary"}}}}}}},"/partner/signatures/by-id/{signatureRequestId}":{"get":{"summary":"Get signature request by internal signature request ID","security":[{"bearerAuth":[]}],"parameters":[{"name":"signatureRequestId","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"Found"}}}},"/partner/signatures/by-id/{signatureRequestId}/evidence":{"get":{"summary":"Get evidence/audit payload for a signature request","security":[{"bearerAuth":[]}],"parameters":[{"name":"signatureRequestId","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"Evidence returned"}}}},"/partner/signatures/by-id/{signatureRequestId}/document":{"get":{"summary":"Stream original PDF document by signature request ID","security":[{"bearerAuth":[]}],"parameters":[{"name":"signatureRequestId","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"PDF stream","content":{"application/pdf":{}}}}}},"/partner/signatures/by-id/{signatureRequestId}/cancel":{"post":{"summary":"Cancel a partner-owned signature request","description":"Marks every still-PENDING signature on the request as DECLINED with the given reason (or a default if omitted) and transitions the request to CANCELLED. Already-COMPLETED, CANCELLED or EXPIRED requests are rejected with 400.","security":[{"bearerAuth":[]}],"parameters":[{"name":"signatureRequestId","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"requestBody":{"required":false,"content":{"application/json":{"schema":{"type":"object","properties":{"reason":{"type":"string","maxLength":500}}}}}},"responses":{"200":{"description":"Cancelled (idempotent — re-cancelling sets `repeated: true`)","content":{"application/json":{"schema":{"type":"object","properties":{"success":{"type":"boolean","example":true},"data":{"type":"object","properties":{"status":{"type":"string","enum":["CANCELLED"]},"reason":{"type":"string"},"repeated":{"type":"boolean","description":"true when this call was a no-op against an already-cancelled request"}},"required":["status","reason","repeated"]}}}}}},"400":{"description":"Terminal-state errors: `ALREADY_COMPLETED` (request already signed by all signers), `ALREADY_EXPIRED` (signing window passed), `DECLINED_BY_SIGNER` (a signer rejected the document — the request is CANCELLED but not by you, so the cancel is not idempotent)."},"404":{"description":"Signature request not found for this partner"}}}},"/partner/signatures/by-id/{signatureRequestId}/signers/{signatureId}/resend":{"post":{"summary":"Resend the signing-invite email to one signer","description":"Re-sends the existing invite email (template and URL are resolved from stored signature data — no new tokens are issued). Only PENDING signatures on a non-terminal request can have their invite resent.","security":[{"bearerAuth":[]}],"parameters":[{"name":"signatureRequestId","in":"path","required":true,"schema":{"type":"string","format":"uuid"}},{"name":"signatureId","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"Email resent. The magic-link URL is intentionally not returned — partners already supplied the recipient at create time.","content":{"application/json":{"schema":{"type":"object","properties":{"success":{"type":"boolean","example":true},"data":{"type":"object","properties":{"resent":{"type":"boolean","example":true},"signatureId":{"type":"string","format":"uuid"},"recipientEmail":{"type":"string","format":"email"}},"required":["resent","signatureId","recipientEmail"]}}}}}},"400":{"description":"Signature is no longer pending or request expired/cancelled"},"404":{"description":"Signature request not found for this partner"}}}},"/partner/signatures/by-id/{signatureRequestId}/document/signed":{"get":{"summary":"Stream sealed PDF (original + Certificate of Completion) by signature request ID","description":"Available after the signature request reaches COMPLETED. Lazy-seals on first call when the post-completion seal has not yet persisted; returns 503 if a concurrent background seal is still in progress and 400 if the request is not yet completed.","security":[{"bearerAuth":[]}],"parameters":[{"name":"signatureRequestId","in":"path","required":true,"schema":{"type":"string","format":"uuid"}},{"name":"download","in":"query","required":false,"schema":{"type":"string","enum":["1"]},"description":"Set to \"1\" for Content-Disposition: attachment."}],"responses":{"200":{"description":"Sealed PDF stream","content":{"application/pdf":{}}},"400":{"description":"Request not yet completed"},"404":{"description":"Signature request not found"},"503":{"description":"Sealing in progress, retry shortly"}}}},"/partner/usage/summary":{"get":{"summary":"Get partner usage summary","security":[{"bearerAuth":[]}],"parameters":[{"name":"from","in":"query","schema":{"type":"string","format":"date-time"}},{"name":"to","in":"query","schema":{"type":"string","format":"date-time"}}],"responses":{"200":{"description":"Usage summary returned"}}}},"/partner/webhooks":{"get":{"summary":"List webhook endpoints","security":[{"bearerAuth":[]}],"responses":{"200":{"description":"Webhook endpoints","content":{"application/json":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/PartnerWebhookEndpoint"}}}}}}},"post":{"summary":"Create webhook endpoint","security":[{"bearerAuth":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"url":{"type":"string","format":"uri"},"subscribedEvents":{"type":"array","items":{"type":"string"},"description":"Events: loan.*, signature.*, vehicle_listing.*, and the CRM deal.* events (deal.created, deal.stage_changed, deal.won, deal.lost, deal.updated, deal.deleted). Subscribing to any deal.* event additionally requires the crm:read scope."},"signingSecret":{"type":"string"},"maxRetries":{"type":"integer"},"timeoutMs":{"type":"integer"},"isActive":{"type":"boolean"}},"required":["url","subscribedEvents"]}}}},"responses":{"201":{"description":"Webhook endpoint created"}}}},"/partner/webhooks/{id}":{"patch":{"summary":"Update webhook endpoint","security":[{"bearerAuth":[]}],"parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object"}}}},"responses":{"200":{"description":"Webhook endpoint updated"}}}},"/partner/webhooks/deliveries":{"get":{"summary":"List webhook delivery attempts","security":[{"bearerAuth":[]}],"parameters":[{"name":"page","in":"query","schema":{"type":"integer","minimum":1}},{"name":"limit","in":"query","schema":{"type":"integer","minimum":1,"maximum":100}},{"name":"status","in":"query","schema":{"type":"string"}},{"name":"eventType","in":"query","schema":{"type":"string"}},{"name":"endpointId","in":"query","schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"Delivery attempts returned"}}}},"/partner/webhooks/deliveries/{deliveryId}/retry":{"post":{"summary":"Retry a failed/dead-letter delivery","security":[{"bearerAuth":[]}],"parameters":[{"name":"deliveryId","in":"path","required":true,"schema":{"type":"string","format":"uuid"}}],"responses":{"200":{"description":"Delivery queued for retry"}}}},"/partner/widget/sessions":{"post":{"summary":"Create short-lived widget session token","security":[{"bearerAuth":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"origin":{"type":"string","format":"uri"},"prefill":{"type":"object"}},"required":["origin"]}}}},"responses":{"201":{"description":"Widget session created"}}}},"/widget/embed.js":{"get":{"summary":"Widget bootstrap script for partner websites","description":"Load this script with data-session-token and data-container-id attributes.","responses":{"200":{"description":"JavaScript bootstrap returned"}}}},"/widget/applications":{"post":{"summary":"Submit application through widget session token","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"sessionToken":{"type":"string"},"externalApplicationId":{"type":"string"},"application":{"type":"object"}},"required":["sessionToken","externalApplicationId","application"]}}}},"responses":{"200":{"description":"Idempotent replay"},"201":{"description":"Application submitted"}}}}}}