{
  "openapi": "3.1.0",
  "info": {
    "title": "Meduza Business — implemented management API",
    "version": "2026-10-02",
    "description": "Contract for implemented handlers in the corporate branch, not a declaration of production rollout. Payment, pool provisioning, email, device revocation, routing enforcement and node metrics use configured production adapters; availability depends on deployment configuration. Local review mode does not charge cards or send real email. All company operations enforce active membership; writes require owner/admin except billing-only subscription/invoice access. Finance membership cannot access networks or employee data. Human bearer sessions and organization-bound OAuth client credentials are supported. Inventory collections support opt-in keyset pagination and documented filters after authorization. With no limit/cursor, legacy complete collection behavior is preserved. Activity and connection history retain their separate bounded contracts. The release scope matrix explicitly separates inventory metadata from operational workflows. Generic resource metadata is extensible; lifecycle-owned fields must use their dedicated workflow. The separate openapi.json is a proposed broader standard and must not be used as proof of implemented endpoints. Administrative audit retention: 90 days, at most 10000 newest events per organization. Expired idempotency receipts are pruned; invoices, subscriptions and pending jobs are never removed by this cleanup.",
    "x-first-release-scope": "first-release-scope.json"
  },
  "servers": [
    {
      "url": "/api/business/v1",
      "description": "Same-origin deployed API; no production host assumed"
    }
  ],
  "security": [
    {
      "userBearer": []
    },
    {
      "machineBearer": []
    }
  ],
  "paths": {
    "/organizations": {
      "get": {
        "operationId": "get_organizations",
        "summary": "List companies joined by current user",
        "parameters": [
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List companies joined by current user",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations",
        "summary": "Create company and owner membership",
        "parameters": [
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create company and owner membership",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "name": {
                    "type": "string",
                    "maxLength": 160
                  }
                },
                "required": [
                  "name"
                ]
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}": {
      "get": {
        "operationId": "get_organizations_organization_id",
        "summary": "Get company",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get company",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id",
        "summary": "Rename company",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Rename company",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "name": {
                    "type": "string"
                  }
                },
                "required": [
                  "name"
                ]
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/subscription": {
      "get": {
        "operationId": "get_organizations_organization_id_subscription",
        "summary": "Read paid subscription",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Read paid subscription",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Subscription"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/subscription/quotes": {
      "post": {
        "operationId": "post_organizations_organization_id_subscription_quotes",
        "summary": "Create immutable 15-minute price quote",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create immutable 15-minute price quote",
            "content": {
              "application/json": {
                "schema": {
                  "allOf": [
                    {
                      "$ref": "#/components/schemas/Object"
                    },
                    {
                      "type": "object",
                      "properties": {
                        "data": {
                          "type": "object",
                          "properties": {
                            "capabilities": {
                              "$ref": "#/components/schemas/BillingCapabilities"
                            },
                            "payment_method": {
                              "type": "string",
                              "description": "ID from GET subscription/payment-methods. Shared with personal web checkout; native store methods are excluded."
                            },
                            "payment_mode": {
                              "type": "string",
                              "enum": [
                                "one_time",
                                "subscription"
                              ],
                              "default": "one_time"
                            },
                            "subscribe": {
                              "type": "boolean",
                              "description": "Compatibility alias. Must agree with payment_mode when both are supplied."
                            },
                            "language": {
                              "type": "string",
                              "description": "Interface language for checkout ordering/labels."
                            },
                            "country": {
                              "type": "string",
                              "description": "Checkout country hint; server resolves the authenticated request country."
                            },
                            "total_minor": {
                              "type": "integer",
                              "minimum": 0
                            },
                            "base_total_minor": {
                              "type": "integer",
                              "minimum": 0
                            },
                            "recurring_total_minor": {
                              "type": "integer",
                              "minimum": 0
                            },
                            "currency": {
                              "type": "string"
                            },
                            "base_currency": {
                              "type": "string",
                              "enum": [
                                "USD"
                              ]
                            },
                            "expires_at": {
                              "type": "string",
                              "format": "date-time"
                            }
                          }
                        }
                      }
                    }
                  ]
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "USD base: 599 cents monthly or 5499 cents annually per VPN. Volume discount: 5–9 VPN 5%; 10–99 10%; 100+ 20%. Renewal keeps count and period. Upgrade increases count, preserves period end and prorates discounted package difference; zero-charge tier crossover requires an existing verified payment. Browser values never establish paid entitlement. Payment method, mode, language and country are pinned. total_minor/currency are the actual charge; base_total_minor/base_currency retain USD commercial pricing. recurring_total_minor is the full future-period amount, distinct from any current prorated charge. No personal trial, gift or referral bonus is implicitly applied.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/QuoteRequest"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/subscription/checkout": {
      "post": {
        "operationId": "post_organizations_organization_id_subscription_checkout",
        "summary": "Queue hosted payment invoice",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "202": {
            "description": "Queue hosted payment invoice",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "Quotes are single-use financial intents. Reusing a quote returns its original invoice. When a verified checkout session expires, the invoice becomes void and a new quote is required before checkout. An unconfigured gateway returns 503 without creating an invoice.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CheckoutRequest"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/subscription/reconcile": {
      "post": {
        "operationId": "post_organizations_organization_id_subscription_reconcile",
        "summary": "Reconcile subscription from verified invoice state",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Reconcile subscription from verified invoice state",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/quotas": {
      "get": {
        "operationId": "get_organizations_organization_id_quotas",
        "summary": "Read purchased and allocated VPN quota",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Read purchased and allocated VPN quota",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "Revoked employee access does not free a physically allocated VPN slot."
      }
    },
    "/organizations/{organization_id}/members": {
      "get": {
        "operationId": "get_organizations_organization_id_members",
        "summary": "List members",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List members",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MemberCollection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      }
    },
    "/organizations/{organization_id}/members/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_members_id",
        "summary": "Get members object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get members object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MemberView"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_members_id",
        "summary": "Update members",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update members",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "role": {
                    "type": "string",
                    "enum": [
                      "admin",
                      "member",
                      "billing"
                    ]
                  },
                  "custom_role_id": {
                    "type": "string"
                  },
                  "group_ids": {
                    "type": "array",
                    "items": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          }
        },
        "description": "Only owner assigns a custom_role_id. Base role is derived from custom role. Restore a built-in role with role and empty custom_role_id. Cross-company custom roles rejected."
      }
    },
    "/organizations/{organization_id}/groups": {
      "get": {
        "operationId": "get_organizations_organization_id_groups",
        "summary": "List groups",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List groups",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_groups",
        "summary": "Create groups",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create groups",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/groups/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_groups_id",
        "summary": "Get groups object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get groups object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_groups_id",
        "summary": "Update groups",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update groups",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_groups_id",
        "summary": "Delete groups",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Delete groups"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/presets": {
      "get": {
        "operationId": "get_organizations_organization_id_presets",
        "summary": "List presets",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List presets",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_presets",
        "summary": "Create presets",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create presets",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Policy"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/presets/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_presets_id",
        "summary": "Get presets object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get presets object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_presets_id",
        "summary": "Update presets",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update presets",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Policy"
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_presets_id",
        "summary": "Delete presets",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Delete presets"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/route-packages": {
      "get": {
        "operationId": "get_organizations_organization_id_route_packages",
        "summary": "List route-packages",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List route-packages",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_route_packages",
        "summary": "Create route-packages",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create route-packages",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Policy"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/route-packages/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_route_packages_id",
        "summary": "Get route-packages object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get route-packages object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_route_packages_id",
        "summary": "Update route-packages",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update route-packages",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Policy"
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_route_packages_id",
        "summary": "Delete route-packages",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Delete route-packages"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/devices": {
      "get": {
        "operationId": "get_organizations_organization_id_devices",
        "summary": "List devices",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List devices",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      }
    },
    "/organizations/{organization_id}/devices/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_devices_id",
        "summary": "Read visible device metadata; no private key or node credential",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Read visible device metadata; no private key or node credential",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DeviceView"
                }
              }
            }
          },
          "default": {
            "description": "401 authentication; 403 permission; 404 inaccessible; 409 conflict; 412 stale version; 422 invalid input; 428 missing If-Match."
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_devices_id",
        "summary": "Rename device with company write or own-device permission",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "200": {
            "description": "Rename device with company write or own-device permission",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DeviceView"
                }
              }
            }
          },
          "default": {
            "description": "401 authentication; 403 permission; 404 inaccessible; 409 conflict; 412 stale version; 422 invalid input; 428 missing If-Match."
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/DeviceRename"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/routers": {
      "get": {
        "operationId": "get_organizations_organization_id_routers",
        "summary": "List routers",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List routers",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_routers",
        "summary": "Create routers",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create routers",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/routers/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_routers_id",
        "summary": "Get routers object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get routers object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_routers_id",
        "summary": "Update routers",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update routers",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_routers_id",
        "summary": "Delete routers",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Delete routers"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/resources": {
      "get": {
        "operationId": "get_organizations_organization_id_resources",
        "summary": "List resources",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List resources",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_resources",
        "summary": "Create resources",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create resources",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/resources/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_resources_id",
        "summary": "Get resources object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get resources object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_resources_id",
        "summary": "Update resources",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update resources",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_resources_id",
        "summary": "Delete resources",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Delete resources"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/alert-rules": {
      "get": {
        "operationId": "get_organizations_organization_id_alert_rules",
        "summary": "List alert-rules",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List alert-rules",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_alert_rules",
        "summary": "Create alert-rules",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create alert-rules",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/AlertRuleInput"
              }
            }
          }
        },
        "description": "Evaluated about every minute against real company-scoped measurements. Unknown/stale measurements do not trigger; duration/cooldown apply. New node collection events require effective collection and verified employee notice."
      }
    },
    "/organizations/{organization_id}/alert-rules/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_alert_rules_id",
        "summary": "Get alert-rules object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get alert-rules object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_alert_rules_id",
        "summary": "Update alert-rules",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update alert-rules",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/AlertRulePatch"
              }
            }
          }
        },
        "description": "Evaluated about every minute against real company-scoped measurements. Unknown/stale measurements do not trigger; duration/cooldown apply. New node collection events require effective collection and verified employee notice."
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_alert_rules_id",
        "summary": "Delete alert-rules",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Delete alert-rules"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/notification-channels": {
      "get": {
        "operationId": "get_organizations_organization_id_notification_channels",
        "summary": "List notification-channels",
        "x-first-release-status": "inventory_only",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List notification-channels",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": "Legacy generic inventory only; draft email/webhook/in_app contract and delivery are excluded from first release. Use the separate signed webhooks API for alert delivery. Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_notification_channels",
        "summary": "Create notification-channels",
        "x-first-release-status": "inventory_only",
        "description": "Legacy generic inventory only; draft email/webhook/in_app contract and delivery are excluded from first release. Use the separate signed webhooks API for alert delivery.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create notification-channels",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/notification-channels/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_notification_channels_id",
        "summary": "Get notification-channels object",
        "x-first-release-status": "inventory_only",
        "description": "Legacy generic inventory only; draft email/webhook/in_app contract and delivery are excluded from first release. Use the separate signed webhooks API for alert delivery.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get notification-channels object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_notification_channels_id",
        "summary": "Update notification-channels",
        "x-first-release-status": "inventory_only",
        "description": "Legacy generic inventory only; draft email/webhook/in_app contract and delivery are excluded from first release. Use the separate signed webhooks API for alert delivery.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update notification-channels",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_notification_channels_id",
        "summary": "Delete notification-channels",
        "x-first-release-status": "inventory_only",
        "description": "Legacy generic inventory only; draft email/webhook/in_app contract and delivery are excluded from first release. Use the separate signed webhooks API for alert delivery.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Delete notification-channels"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/employee-requests": {
      "get": {
        "operationId": "get_organizations_organization_id_employee_requests",
        "summary": "List employee-requests",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List employee-requests",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      }
    },
    "/organizations/{organization_id}/employee-requests/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_employee_requests_id",
        "summary": "Get employee-requests object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get employee-requests object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_employee_requests_id",
        "summary": "Update employee-requests",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update employee-requests",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_employee_requests_id",
        "summary": "Delete employee-requests",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Delete employee-requests"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/policy-deployments": {
      "get": {
        "operationId": "get_organizations_organization_id_policy_deployments",
        "summary": "List policy-deployments",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List policy-deployments",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      }
    },
    "/organizations/{organization_id}/policy-deployments/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_policy_deployments_id",
        "summary": "Get policy-deployments object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get policy-deployments object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/alerts": {
      "get": {
        "operationId": "get_organizations_organization_id_alerts",
        "summary": "List alerts",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List alerts",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      }
    },
    "/organizations/{organization_id}/alerts/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_alerts_id",
        "summary": "Get alerts object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get alerts object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_alerts_id",
        "summary": "Update alerts",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update alerts",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_alerts_id",
        "summary": "Delete alerts",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Delete alerts"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/invoices": {
      "get": {
        "operationId": "get_organizations_organization_id_invoices",
        "summary": "List invoices",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List invoices",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      }
    },
    "/organizations/{organization_id}/invoices/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_invoices_id",
        "summary": "Get invoices object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get invoices object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/billing-profile": {
      "get": {
        "operationId": "get_organizations_organization_id_billing_profile",
        "summary": "List billing-profile",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "List billing-profile",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "post": {
        "operationId": "post_organizations_organization_id_billing_profile",
        "summary": "Create billing-profile",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create billing-profile",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/billing-profile/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_billing_profile_id",
        "summary": "Get billing-profile object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get billing-profile object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_billing_profile_id",
        "summary": "Update billing-profile",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update billing-profile",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_billing_profile_id",
        "summary": "Delete billing-profile",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Delete billing-profile"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/vpns": {
      "get": {
        "operationId": "get_organizations_organization_id_vpns",
        "summary": "List vpns",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List vpns",
            "content": {
              "application/json": {
                "schema": {
                  "allOf": [
                    {
                      "$ref": "#/components/schemas/Collection"
                    },
                    {
                      "type": "object",
                      "properties": {
                        "capabilities": {
                          "$ref": "#/components/schemas/VPNCapabilities"
                        }
                      }
                    }
                  ]
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_vpns",
        "summary": "Create vpns",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyRequired"
          }
        ],
        "responses": {
          "202": {
            "description": "Create vpns",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "VPN allocation is asynchronous and requires active paid quota; poll data.status. service_id is an existing backend service identifier.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ProvisionRequest"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/vpns/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_vpns_id",
        "summary": "Get vpns object",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get vpns object",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_vpns_id",
        "summary": "Update vpns",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update vpns",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "VPN updates accept name, member_ids, group_ids and route_package_id only. Lifecycle and billing fields are server-managed.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "additionalProperties": true
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/presets/{id}/validations": {
      "post": {
        "operationId": "post_organizations_organization_id_presets_id_validations",
        "summary": "Validate saved routing configuration",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Validate saved routing configuration",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/presets/{id}/publications": {
      "post": {
        "operationId": "post_organizations_organization_id_presets_id_publications",
        "summary": "Publish routing and queue policy delivery",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "202": {
            "description": "Publish routing and queue policy delivery",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "Device application is asynchronous; inspect policy-deployments. Only VPN-server acknowledgement confirms application.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/presets/{id}/versions": {
      "get": {
        "operationId": "get_organizations_organization_id_presets_id_versions",
        "summary": "List saved versions",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "List saved versions",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/presets/{id}/copies": {
      "post": {
        "operationId": "post_organizations_organization_id_presets_id_copies",
        "summary": "Copy configuration as draft",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Copy configuration as draft",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "Target references must exist and be authorized. Machine clients may copy only within their company.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "organization_id": {
                    "type": "string"
                  }
                },
                "required": [
                  "organization_id"
                ]
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/presets/{id}/rollbacks": {
      "post": {
        "operationId": "post_organizations_organization_id_presets_id_rollbacks",
        "summary": "Restore saved version and queue delivery",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "202": {
            "description": "Restore saved version and queue delivery",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "version_id": {
                    "type": "string"
                  }
                },
                "required": [
                  "version_id"
                ]
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/route-packages/{id}/validations": {
      "post": {
        "operationId": "post_organizations_organization_id_route_packages_id_validations",
        "summary": "Validate saved routing configuration",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Validate saved routing configuration",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/route-packages/{id}/publications": {
      "post": {
        "operationId": "post_organizations_organization_id_route_packages_id_publications",
        "summary": "Publish routing and queue policy delivery",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "202": {
            "description": "Publish routing and queue policy delivery",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "Device application is asynchronous; inspect policy-deployments. Only VPN-server acknowledgement confirms application.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/route-packages/{id}/versions": {
      "get": {
        "operationId": "get_organizations_organization_id_route_packages_id_versions",
        "summary": "List saved versions",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "List saved versions",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/route-packages/{id}/copies": {
      "post": {
        "operationId": "post_organizations_organization_id_route_packages_id_copies",
        "summary": "Copy configuration as draft",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Copy configuration as draft",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "Target references must exist and be authorized. Machine clients may copy only within their company.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "organization_id": {
                    "type": "string"
                  }
                },
                "required": [
                  "organization_id"
                ]
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/route-packages/{id}/rollbacks": {
      "post": {
        "operationId": "post_organizations_organization_id_route_packages_id_rollbacks",
        "summary": "Restore saved version and queue delivery",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "202": {
            "description": "Restore saved version and queue delivery",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "version_id": {
                    "type": "string"
                  }
                },
                "required": [
                  "version_id"
                ]
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/groups/{id}/memberships": {
      "put": {
        "operationId": "put_organizations_organization_id_groups_id_memberships",
        "summary": "Update memberships",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update memberships",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Assignment"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/groups/{id}/assignments": {
      "put": {
        "operationId": "put_organizations_organization_id_groups_id_assignments",
        "summary": "Update assignments",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update assignments",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Assignment"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/vpns/{id}/assignments": {
      "put": {
        "operationId": "put_organizations_organization_id_vpns_id_assignments",
        "summary": "Update assignments",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update assignments",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/Assignment"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/members/{id}/revocations": {
      "post": {
        "operationId": "post_organizations_organization_id_members_id_revocations",
        "summary": "revocations for members",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "202": {
            "description": "revocations for members",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/members/{id}/restorations": {
      "post": {
        "operationId": "post_organizations_organization_id_members_id_restorations",
        "summary": "restorations for members",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "restorations for members",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/devices/{id}/revocations": {
      "post": {
        "operationId": "post_organizations_organization_id_devices_id_revocations",
        "summary": "revocations for devices",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "202": {
            "description": "revocations for devices",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/catalog/traffic-presets": {
      "get": {
        "operationId": "get_organizations_organization_id_catalog_traffic_presets",
        "summary": "Get traffic-presets catalog",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get traffic-presets catalog",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/catalog/protocol-capabilities": {
      "get": {
        "operationId": "get_organizations_organization_id_catalog_protocol_capabilities",
        "summary": "Get protocol-capabilities catalog",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get protocol-capabilities catalog",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/catalog/vpn-locations": {
      "get": {
        "operationId": "get_organizations_organization_id_catalog_vpn_locations",
        "summary": "Get vpn-locations catalog",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get vpn-locations catalog",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/policy-tests": {
      "post": {
        "operationId": "post_organizations_organization_id_policy_tests",
        "summary": "Preview first matching routing decision",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Preview first matching routing decision",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "App parity: first-match evaluates ordered rules including deny, maximum 128 rules. Custom traffic sets carry targets, while rules select exits. Country classification uses network registration, not physical website location.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "policy": {
                    "$ref": "#/components/schemas/Policy"
                  },
                  "target": {
                    "type": "string"
                  },
                  "ip": {
                    "type": "string"
                  }
                },
                "required": [
                  "policy"
                ]
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/metrics": {
      "get": {
        "operationId": "get_organizations_organization_id_metrics",
        "summary": "Connection history and VPN load",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Connection history and VPN load",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "Actual ULTRA node sessions, 24-hour series, seven-day retained samples; unavailable measurements remain unavailable. destination_logging=false: no browsing history, HTTPS contents, or employee productivity inference."
      }
    },
    "/organizations/{organization_id}/audit-events": {
      "get": {
        "operationId": "get_organizations_organization_id_audit_events",
        "summary": "Administrative change audit",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "Administrative change audit",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      }
    },
    "/organizations/{organization_id}/api-clients": {
      "get": {
        "operationId": "get_organizations_organization_id_api_clients",
        "summary": "List api-clients",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List api-clients",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_api_clients",
        "summary": "Create api-clients",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create api-clients",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "New secret/link is shown once; idempotent receipt replay omits private secrets. Save the initial response securely.",
        "security": [
          {
            "userBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/APIClientInput"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/api-clients/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_api_clients_id",
        "summary": "Get api-clients",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get api-clients",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ]
      }
    },
    "/organizations/{organization_id}/webhooks": {
      "get": {
        "operationId": "get_organizations_organization_id_webhooks",
        "summary": "List webhooks",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List webhooks",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_webhooks",
        "summary": "Create webhooks",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create webhooks",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/WebhookSecret"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "New secret/link is shown once; idempotent receipt replay omits private secrets. Save the initial response securely.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/WebhookInput"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/webhooks/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_webhooks_id",
        "summary": "Get webhooks",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get webhooks",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_webhooks_id",
        "summary": "Update webhooks",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update webhooks",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/WebhookInput"
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_webhooks_id",
        "summary": "Revoke webhooks",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Revoke webhooks"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/enrollment-campaigns": {
      "get": {
        "operationId": "get_organizations_organization_id_enrollment_campaigns",
        "summary": "List enrollment-campaigns",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List enrollment-campaigns",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_enrollment_campaigns",
        "summary": "Create enrollment-campaigns",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create enrollment-campaigns",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "New secret/link is shown once; idempotent receipt replay omits private secrets. Save the initial response securely.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CampaignInput"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/enrollment-campaigns/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_enrollment_campaigns_id",
        "summary": "Get enrollment-campaigns",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get enrollment-campaigns",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_enrollment_campaigns_id",
        "summary": "Update enrollment-campaigns",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Update enrollment-campaigns",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CampaignInput"
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_enrollment_campaigns_id",
        "summary": "Revoke enrollment-campaigns",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Revoke enrollment-campaigns"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/invitations": {
      "get": {
        "operationId": "get_organizations_organization_id_invitations",
        "summary": "List invitations",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List invitations",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_invitations",
        "summary": "Create invitations",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Create invitations",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "New secret/link is shown once; idempotent receipt replay omits private secrets. Save the initial response securely.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/InvitationInput"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/invitations/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_invitations_id",
        "summary": "Get invitations",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get invitations",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_invitations_id",
        "summary": "Revoke invitations",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Revoke invitations"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/api-clients/{id}/rotate": {
      "post": {
        "operationId": "post_organizations_organization_id_api_clients_id_rotate",
        "summary": "rotate API client",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "rotate API client",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/api-clients/{id}/revoke": {
      "post": {
        "operationId": "post_organizations_organization_id_api_clients_id_revoke",
        "summary": "revoke API client",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "revoke API client",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/webhooks/{id}/rotate": {
      "post": {
        "operationId": "post_organizations_organization_id_webhooks_id_rotate",
        "summary": "Rotate signing secret",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Rotate signing secret",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/WebhookSecret"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "Already queued deliveries retain the secret used at enqueue time; allow a transition window at receiver.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/webhooks/{id}/test": {
      "post": {
        "operationId": "post_organizations_organization_id_webhooks_id_test",
        "summary": "Queue webhook test event",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "202": {
            "description": "Queue webhook test event",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/webhooks/{id}/deliveries": {
      "get": {
        "operationId": "get_organizations_organization_id_webhooks_id_deliveries",
        "summary": "Read delivery attempt history",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Read delivery attempt history",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/webhooks/{id}/deliveries/{delivery_id}/retry": {
      "post": {
        "operationId": "post_organizations_organization_id_webhooks_id_deliveries_delivery_id_retry",
        "summary": "Retry failed delivery",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "delivery_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "202": {
            "description": "Retry failed delivery",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/enrollment-campaigns/{id}/rotations": {
      "post": {
        "operationId": "post_organizations_organization_id_enrollment_campaigns_id_rotations",
        "summary": "Rotate team invitation URL",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Rotate team invitation URL",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/enrollment-campaigns/{id}/claims": {
      "get": {
        "operationId": "get_organizations_organization_id_enrollment_campaigns_id_claims",
        "summary": "List team join requests",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "List team join requests",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/enrollment-campaigns/{id}/claims/{claim_id}/approve": {
      "post": {
        "operationId": "post_organizations_organization_id_enrollment_campaigns_id_claims_claim_id_approve",
        "summary": "approve join request",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "claim_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "approve join request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/enrollment-campaigns/{id}/claims/{claim_id}/reject": {
      "post": {
        "operationId": "post_organizations_organization_id_enrollment_campaigns_id_claims_claim_id_reject",
        "summary": "reject join request",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "claim_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "reject join request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/invitations/{id}/resends": {
      "post": {
        "operationId": "post_organizations_organization_id_invitations_id_resends",
        "summary": "Rotate invitation link and queue email again",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Rotate invitation link and queue email again",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/invitation-template": {
      "get": {
        "operationId": "get_organizations_organization_id_invitation_template",
        "summary": "Get invitation message template",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get invitation message template",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_invitation_template",
        "summary": "Edit invitation message template",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Edit invitation message template",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "subject": {
                    "type": "string"
                  },
                  "message": {
                    "type": "string"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/invitation-template/preview": {
      "get": {
        "operationId": "get_organizations_organization_id_invitation_template_preview",
        "summary": "Preview invitation message",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Preview invitation message",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/employee-requests/{id}/comments": {
      "get": {
        "operationId": "get_organizations_organization_id_employee_requests_id_comments",
        "summary": "List request replies",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "List request replies",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      },
      "post": {
        "operationId": "post_organizations_organization_id_employee_requests_id_comments",
        "summary": "Reply to employee",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Reply to employee",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "body": {
                    "type": "string",
                    "maxLength": 5000
                  }
                },
                "required": [
                  "body"
                ]
              }
            }
          }
        }
      }
    },
    "/me/workspaces": {
      "get": {
        "operationId": "get_me_workspaces",
        "summary": "List joined companies",
        "parameters": [
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List joined companies",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      }
    },
    "/me/invitations": {
      "get": {
        "operationId": "get_me_invitations",
        "summary": "List pending invitations",
        "parameters": [
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List pending invitations",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      }
    },
    "/me/vpn-grants": {
      "get": {
        "operationId": "get_me_vpn_grants",
        "summary": "List effective VPN access",
        "parameters": [
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List effective VPN access",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      }
    },
    "/me/notifications": {
      "get": {
        "operationId": "get_me_notifications",
        "summary": "List notifications",
        "parameters": [
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List notifications",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      }
    },
    "/me/requests": {
      "get": {
        "operationId": "get_me_requests",
        "summary": "List own requests",
        "parameters": [
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List own requests",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_me_requests",
        "summary": "Report working VPN problem",
        "parameters": [
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Report working VPN problem",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RequestInput"
              }
            }
          }
        }
      }
    },
    "/me": {
      "get": {
        "operationId": "get_me",
        "summary": "Read signed-in identity",
        "parameters": [],
        "responses": {
          "200": {
            "description": "Read signed-in identity",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ]
      }
    },
    "/me/invitations/preview": {
      "post": {
        "operationId": "post_me_invitations_preview",
        "summary": "preview invitation or team link",
        "parameters": [
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "preview invitation or team link",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "Supply token, invitation_id, or campaign_token. Claim requires consent=true; email invitations require matching signed-in address. Moderated team links may return pending approval instead of membership.",
        "security": [
          {
            "userBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/InviteClaim"
              }
            }
          }
        }
      }
    },
    "/me/invitations/claim": {
      "post": {
        "operationId": "post_me_invitations_claim",
        "summary": "claim invitation or team link",
        "parameters": [
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "claim invitation or team link",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "Supply token, invitation_id, or campaign_token. Claim requires consent=true; email invitations require matching signed-in address. Moderated team links may return pending approval instead of membership.",
        "security": [
          {
            "userBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/InviteClaim"
              }
            }
          }
        }
      }
    },
    "/me/invitations/{id}/decline": {
      "post": {
        "operationId": "post_me_invitations_id_decline",
        "summary": "Decline own invitation",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Decline own invitation",
            "content": {
              "application/json": {
                "schema": {}
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/me/memberships/{id}": {
      "delete": {
        "operationId": "delete_me_memberships_id",
        "summary": "Leave company and revoke own grants",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Leave company and revoke own grants"
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "description": "Owner must transfer ownership first.",
        "security": [
          {
            "userBearer": []
          }
        ]
      }
    },
    "/me/devices/{id}/revocations": {
      "post": {
        "operationId": "post_me_devices_id_revocations",
        "summary": "Revoke own device credential",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "202": {
            "description": "Revoke own device credential",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/me/notifications/{id}": {
      "patch": {
        "operationId": "patch_me_notifications_id",
        "summary": "Mark notification read",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "200": {
            "description": "Mark notification read",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {}
              }
            }
          }
        }
      }
    },
    "/me/services/{service_id}/policy": {
      "get": {
        "operationId": "get_me_services_service_id_policy",
        "summary": "Get effective published corporate policy",
        "parameters": [
          {
            "name": "service_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Get effective published corporate policy",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "activity_audit": {
                      "type": "object",
                      "properties": {
                        "enabled": {
                          "type": "boolean"
                        },
                        "retention_days": {
                          "type": "integer"
                        },
                        "policy_version": {
                          "type": "integer"
                        },
                        "source": {
                          "type": "string",
                          "enum": [
                            "node_destination_metadata"
                          ]
                        }
                      }
                    }
                  }
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ]
      }
    },
    "/me/requests/{id}": {
      "get": {
        "operationId": "get_me_requests_id",
        "summary": "Read own request",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Read own request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ]
      }
    },
    "/me/requests/{id}/comments": {
      "get": {
        "operationId": "get_me_requests_id_comments",
        "summary": "Read own request replies",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Read own request replies",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Collection"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ]
      },
      "post": {
        "operationId": "post_me_requests_id_comments",
        "summary": "Reply to own request",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "responses": {
          "201": {
            "description": "Reply to own request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "body": {
                    "type": "string",
                    "maxLength": 5000
                  }
                },
                "required": [
                  "body"
                ]
              }
            }
          }
        }
      }
    },
    "/oauth/token": {
      "post": {
        "operationId": "post_oauth_token",
        "summary": "Exchange company client credentials",
        "parameters": [],
        "responses": {
          "200": {
            "description": "Exchange company client credentials",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Token"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "$ref": "#/components/schemas/TokenRequest"
              }
            }
          }
        },
        "security": [],
        "description": "One-hour bearer token. Client is bound to one company and issuer must remain an active owner/admin. Client rotation/revocation invalidates its tokens. Machine clients cannot access /me, create companies, or manage API clients. Scope is read or read write. OAuth failures use {error: invalid_client|unsupported_grant_type}."
      }
    },
    "/organizations/{organization_id}/vpns/{id}/retire": {
      "post": {
        "operationId": "post_organizations_organization_id_vpns_id_retire",
        "summary": "Permanently retire a company VPN and release allocation after backend confirmation",
        "description": "Requires owner/admin, explicit confirm=true and current If-Match. Returns retire_pending, immediately denies access and queues credential revocation. Cannot remove an exit referenced by a draft or latest published routing package. Retirement worker checks organization/service binding, actual backend status canceled and absence of live pool allocation. Slot remains occupied during failures/retries. This destroys the server; subscription price is unchanged. Repeated already-pending/completed operation may return 200.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "confirm": {
                    "type": "boolean",
                    "const": true
                  }
                },
                "required": [
                  "confirm"
                ]
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Retirement queued; poll the VPN object until status=retired and backend_cancel_confirmed=true.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Object"
                }
              }
            }
          },
          "200": {
            "description": "Already pending or retired"
          },
          "409": {
            "description": "Provisioning still running or routing still references VPN"
          },
          "503": {
            "description": "Retirement adapter unavailable"
          }
        }
      }
    },
    "/organizations/{organization_id}/roles": {
      "get": {
        "operationId": "get_organizations_organization_id_roles",
        "summary": "Read role matrix and current effective permissions",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "Read role matrix and current effective permissions",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RoleCollection"
                }
              }
            }
          },
          "default": {
            "description": "401 authentication; 403 permission; 404 inaccessible; 409 conflict; 412 stale version; 422 invalid input; 428 missing If-Match."
          }
        },
        "x-inventory-pagination": "opt-in",
        "description": " Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422."
      },
      "post": {
        "operationId": "post_organizations_organization_id_roles",
        "summary": "Owner creates a restricted copy of a built-in role",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "201": {
            "description": "Owner creates a restricted copy of a built-in role",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Role"
                }
              }
            }
          },
          "default": {
            "description": "401 authentication; 403 permission; 404 inaccessible; 409 conflict; 412 stale version; 422 invalid input; 428 missing If-Match."
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RoleInput"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/roles/{id}": {
      "get": {
        "operationId": "get_organizations_organization_id_roles_id",
        "summary": "Read a custom role",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Read a custom role",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Role"
                }
              }
            }
          },
          "default": {
            "description": "401 authentication; 403 permission; 404 inaccessible; 409 conflict; 412 stale version; 422 invalid input; 428 missing If-Match."
          }
        }
      },
      "patch": {
        "operationId": "patch_organizations_organization_id_roles_id",
        "summary": "Owner updates name or permission subset; base immutable",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "200": {
            "description": "Owner updates name or permission subset; base immutable",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Role"
                }
              }
            }
          },
          "default": {
            "description": "401 authentication; 403 permission; 404 inaccessible; 409 conflict; 412 stale version; 422 invalid input; 428 missing If-Match."
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "name": {
                    "type": "string"
                  },
                  "permissions": {
                    "type": "array",
                    "items": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          }
        }
      },
      "delete": {
        "operationId": "delete_organizations_organization_id_roles_id",
        "summary": "Owner deletes unassigned custom role; built-ins immutable",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "204": {
            "description": "Owner deletes unassigned custom role; built-ins immutable"
          },
          "default": {
            "description": "401 authentication; 403 permission; 404 inaccessible; 409 conflict; 412 stale version; 422 invalid input; 428 missing If-Match."
          }
        }
      }
    },
    "/me/devices/{id}": {
      "get": {
        "operationId": "get_me_devices_id",
        "summary": "Read visible device metadata; no private key or node credential",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Read visible device metadata; no private key or node credential",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DeviceView"
                }
              }
            }
          },
          "default": {
            "description": "401 authentication; 403 permission; 404 inaccessible; 409 conflict; 412 stale version; 422 invalid input; 428 missing If-Match."
          }
        }
      },
      "patch": {
        "operationId": "patch_me_devices_id",
        "summary": "Rename device with company write or own-device permission",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "200": {
            "description": "Rename device with company write or own-device permission",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DeviceView"
                }
              }
            }
          },
          "default": {
            "description": "401 authentication; 403 permission; 404 inaccessible; 409 conflict; 412 stale version; 422 invalid input; 428 missing If-Match."
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/DeviceRename"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/employee-analytics": {
      "get": {
        "operationId": "get_employee_connection_analytics",
        "summary": "Employee connection observations and device access events",
        "x-role-permissions": [
          "employee-analytics.read"
        ],
        "description": "Active owner/admin or equivalent restricted custom role with employee-analytics.read. Company-scoped authorization also applies to machine credentials. Seven-day history; defaults to trailing 24 hours. Hourly aggregates include full hours enclosing the requested range (aggregate_from/aggregate_to); event filtering uses exact from/to. One positive observation is not work duration. A VPN tunnel may use several relays. Missing/stale (>3 minutes) node measurements stay unknown/null. Personal VPNs excluded. No destination URLs, request content, per-employee byte totals or productivity inference. Latest 200 events returned; narrow dates/member when events_truncated. Internal observation storage is never client writable. Administrative audit is a separate endpoint. The connections field provides sampled daily VPN duration, bounded sessions and lifecycle events. Employee duration merges overlapping device intervals separately per employee; device duration sums intervals. Duration stops at the last positive node observation, never at the current clock. Gaps longer than 180 seconds close observation. Counts use actual event timestamps in [from,to), not clipped interval boundaries. App reports are labeled client_reported and do not increase duration or node event counts. Manual action is identified only by client_source=user. Time is observed VPN connectivity, not work time or website dwell time.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "from",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            },
            "description": "RFC3339; interval must be positive and at most seven days."
          },
          {
            "name": "to",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            },
            "description": "RFC3339; past end time with one-minute clock tolerance."
          },
          {
            "name": "member_id",
            "in": "query",
            "schema": {
              "type": "string"
            },
            "description": "Company membership ID; foreign member IDs return 404."
          },
          {
            "name": "timezone",
            "in": "query",
            "schema": {
              "type": "string",
              "default": "UTC",
              "example": "Europe/Moscow"
            },
            "description": "IANA time zone used for daily calendar buckets; invalid zones return 422."
          }
        ],
        "responses": {
          "200": {
            "description": "Measured employee analytics",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/EmployeeAnalytics"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/activity": {
      "get": {
        "operationId": "get_organization_activity",
        "summary": "Read company destination connection requests",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "from",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          },
          {
            "name": "to",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date-time"
            }
          },
          {
            "name": "member_id",
            "in": "query",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "search",
            "in": "query",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "cursor",
            "in": "query",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "action",
            "in": "query",
            "schema": {
              "type": "string",
              "enum": [
                "allow",
                "deny",
                "error"
              ]
            }
          },
          {
            "name": "limit",
            "in": "query",
            "schema": {
              "type": "integer",
              "minimum": 1,
              "maximum": 250,
              "default": 100
            }
          },
          {
            "name": "category",
            "in": "query",
            "schema": {
              "type": "string",
              "enum": [
                "worktools",
                "development",
                "communication",
                "video",
                "social",
                "games",
                "storage",
                "system",
                "unknown"
              ]
            },
            "description": "Applies to events, hourly series, summaries and analysis."
          }
        ],
        "responses": {
          "200": {
            "description": "Read company destination connection requests",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActivityPage"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          },
          {
            "machineBearer": []
          }
        ],
        "description": "Requires activity.read. Window maximum seven days. Search is a lowercase host/IP fragment <=253 characters. Identity labels are company-scoped. Pagination does not change filtered summary. No URLs, bodies, local blocks or direct traffic."
      }
    },
    "/organizations/{organization_id}/activity-settings": {
      "get": {
        "operationId": "get_activity_settings",
        "summary": "Read destination collection settings",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Read destination collection settings",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActivitySettings"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          },
          {
            "machineBearer": []
          }
        ]
      },
      "patch": {
        "operationId": "patch_activity_settings",
        "summary": "Owner opt-in/out of destination collection",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "responses": {
          "200": {
            "description": "Owner opt-in/out of destination collection",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActivitySettings"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        },
        "security": [
          {
            "userBearer": []
          }
        ],
        "description": "Owner only, machine clients forbidden. If-Match uses raw settings.version. PATCH supports enabled, default_enabled, classification_rules independently and preserves unspecified fields. New companies default false/false; legacy companies preserve prior behavior. Company disclosure consent_version is stable across normal settings changes, currently 2000001. Verified employee acknowledgement is stored once per company. Category changes reclassify the selected historical log, not a historical category snapshot. Manual longest domain suffix precedes IP/CIDR longest prefix, then built-ins and unknown.",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "minProperties": 1,
                "additionalProperties": false,
                "properties": {
                  "enabled": {
                    "type": "boolean"
                  },
                  "classification_rules": {
                    "type": "array",
                    "maxItems": 64,
                    "items": {
                      "oneOf": [
                        {
                          "$ref": "#/components/schemas/ActivityCategoryRule"
                        },
                        {
                          "type": "object",
                          "additionalProperties": false,
                          "required": [
                            "domain",
                            "category"
                          ],
                          "properties": {
                            "domain": {
                              "type": "string",
                              "maxLength": 253,
                              "description": "Canonical domain suffix including subdomains; no URLs or wildcard notation."
                            },
                            "category": {
                              "type": "string",
                              "enum": [
                                "worktools",
                                "development",
                                "communication",
                                "video",
                                "social",
                                "games",
                                "storage",
                                "system",
                                "unknown"
                              ]
                            }
                          }
                        }
                      ]
                    }
                  },
                  "default_enabled": {
                    "type": "boolean"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/members/{member_id}/activity-collection": {
      "get": {
        "tags": [
          "Business"
        ],
        "summary": "Read member logging override and effective source",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "member_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Current effective collection setting",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActivityCollection"
                }
              }
            }
          }
        }
      },
      "patch": {
        "tags": [
          "Business"
        ],
        "summary": "Owner changes member logging override",
        "description": "Company-wide off wins. Member override wins over groups; group off wins over group on; otherwise company default. If-Match is the member/group object version.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "member_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "If-Match",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "mode"
                ],
                "additionalProperties": false,
                "properties": {
                  "mode": {
                    "type": "string",
                    "enum": [
                      "inherit",
                      "on",
                      "off"
                    ]
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Current effective collection setting",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActivityCollection"
                }
              }
            }
          },
          "403": {
            "description": "Owner permission required"
          },
          "412": {
            "description": "Object version conflict"
          }
        }
      }
    },
    "/organizations/{organization_id}/groups/{group_id}/activity-collection": {
      "get": {
        "tags": [
          "Business"
        ],
        "summary": "Read group logging override and effective source",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "group_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Current effective collection setting",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActivityCollection"
                }
              }
            }
          }
        }
      },
      "patch": {
        "tags": [
          "Business"
        ],
        "summary": "Owner changes group logging override",
        "description": "Company-wide off wins. Member override wins over groups; group off wins over group on; otherwise company default. If-Match is the member/group object version.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "group_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "If-Match",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "mode"
                ],
                "additionalProperties": false,
                "properties": {
                  "mode": {
                    "type": "string",
                    "enum": [
                      "inherit",
                      "on",
                      "off"
                    ]
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Current effective collection setting",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActivityCollection"
                }
              }
            }
          },
          "403": {
            "description": "Owner permission required"
          },
          "412": {
            "description": "Object version conflict"
          }
        }
      }
    },
    "/organizations/{organization_id}/activity-category-presets": {
      "get": {
        "tags": [
          "Business"
        ],
        "summary": "Preview built-in editable category presets",
        "description": "Requires activity read permission. Built-ins already apply. Merge selected rules with current company rules and PATCH activity-settings to save; never silently replace existing overrides.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Category catalog and typed rule presets",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "max_rules": {
                      "type": "integer",
                      "enum": [
                        64
                      ]
                    },
                    "builtins_enabled": {
                      "type": "boolean"
                    },
                    "taxonomy_version": {
                      "type": "string"
                    },
                    "categories": {
                      "type": "array",
                      "items": {
                        "type": "object",
                        "properties": {
                          "id": {
                            "type": "string"
                          },
                          "label": {
                            "type": "string"
                          },
                          "label_en": {
                            "type": "string"
                          },
                          "rules": {
                            "type": "array",
                            "items": {
                              "$ref": "#/components/schemas/ActivityCategoryRule"
                            }
                          }
                        }
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/activity-category-templates": {
      "get": {
        "tags": [
          "Business"
        ],
        "summary": "List reusable company category templates",
        "description": "Reads require activity.read. Writes require the human organization owner. Template changes never change active classification: merge rules into the draft and explicitly PATCH activity-settings to apply. Built-in presets remain immutable. Inventory pagination/filtering is applied after current tenant/RBAC projection. Ordering is created_at ascending then id ascending; entries without created_at sort first by id. Newer creations after the initial page cutoff are excluded from continuation. Concurrent edits/revocations can change visible totals; this is not a frozen database snapshot. Unsupported or repeated query parameters return422.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/InventoryLimit"
          },
          {
            "$ref": "#/components/parameters/InventoryCursor"
          },
          {
            "$ref": "#/components/parameters/InventoryStatus"
          },
          {
            "$ref": "#/components/parameters/InventoryMemberId"
          },
          {
            "$ref": "#/components/parameters/InventoryUserId"
          },
          {
            "$ref": "#/components/parameters/InventoryVpnId"
          },
          {
            "$ref": "#/components/parameters/InventorySearch"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedFrom"
          },
          {
            "$ref": "#/components/parameters/InventoryCreatedTo"
          }
        ],
        "responses": {
          "200": {
            "description": "List reusable company category templates",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "items": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/ActivityCategoryTemplate"
                      }
                    }
                  }
                }
              }
            }
          },
          "403": {
            "description": "Permission denied"
          }
        },
        "x-inventory-pagination": "opt-in"
      },
      "post": {
        "tags": [
          "Business"
        ],
        "summary": "Create company template or save a built-in copy",
        "description": "Reads require activity.read. Writes require the human organization owner. Template changes never change active classification: merge rules into the draft and explicitly PATCH activity-settings to apply. Built-in presets remain immutable.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "201": {
            "description": "Create company template or save a built-in copy",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActivityCategoryTemplate"
                }
              }
            }
          },
          "403": {
            "description": "Permission denied"
          },
          "422": {
            "description": "Invalid name or category rules."
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ActivityCategoryTemplateInput"
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/activity-category-templates/{id}": {
      "get": {
        "tags": [
          "Business"
        ],
        "summary": "Read company category template",
        "description": "Reads require activity.read. Writes require the human organization owner. Template changes never change active classification: merge rules into the draft and explicitly PATCH activity-settings to apply. Built-in presets remain immutable.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Read company category template",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActivityCategoryTemplate"
                }
              }
            }
          },
          "403": {
            "description": "Permission denied"
          }
        }
      },
      "patch": {
        "tags": [
          "Business"
        ],
        "summary": "Edit reusable company category template",
        "description": "Reads require activity.read. Writes require the human organization owner. Template changes never change active classification: merge rules into the draft and explicitly PATCH activity-settings to apply. Built-in presets remain immutable.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "If-Match",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Quoted current object version."
          }
        ],
        "responses": {
          "200": {
            "description": "Edit reusable company category template",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ActivityCategoryTemplate"
                }
              }
            }
          },
          "403": {
            "description": "Permission denied"
          },
          "412": {
            "description": "Object version changed; reload before retrying."
          },
          "428": {
            "description": "If-Match header required."
          },
          "422": {
            "description": "Invalid name or category rules."
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "name": {
                    "type": "string",
                    "minLength": 1,
                    "maxLength": 120
                  },
                  "rules": {
                    "type": "array",
                    "minItems": 1,
                    "maxItems": 64,
                    "items": {
                      "oneOf": [
                        {
                          "$ref": "#/components/schemas/ActivityCategoryRule"
                        },
                        {
                          "type": "object",
                          "required": [
                            "domain",
                            "category"
                          ],
                          "properties": {
                            "domain": {
                              "type": "string"
                            },
                            "category": {
                              "type": "string"
                            }
                          }
                        }
                      ]
                    }
                  }
                }
              }
            }
          }
        }
      },
      "delete": {
        "tags": [
          "Business"
        ],
        "summary": "Delete template without changing applied rules",
        "description": "Reads require activity.read. Writes require the human organization owner. Template changes never change active classification: merge rules into the draft and explicitly PATCH activity-settings to apply. Built-in presets remain immutable.",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "If-Match",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Quoted current object version."
          }
        ],
        "responses": {
          "204": {
            "description": "Delete template without changing applied rules"
          },
          "403": {
            "description": "Permission denied"
          },
          "412": {
            "description": "Object version changed; reload before retrying."
          },
          "428": {
            "description": "If-Match header required."
          }
        }
      }
    },
    "/organizations/{organization_id}/subscription/payment-methods": {
      "get": {
        "operationId": "getCorporatePaymentMethods",
        "summary": "Supported corporate payment methods and checkout-country defaults",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "language",
            "in": "query",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "country",
            "in": "query",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Catalog with per-mode integration availability",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/CorporatePaymentOptions"
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/subscription/cancel-renewal": {
      "post": {
        "operationId": "cancelCorporateRenewal",
        "summary": "Cancel future automatic charges; preserve paid access",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "language": {
                    "type": "string"
                  },
                  "country": {
                    "type": "string"
                  }
                },
                "additionalProperties": false
              }
            }
          }
        },
        "description": "Durable provider operation. Poll subscription for confirmation. Resumption can require a provider approval_url; submitting or opening the URL does not confirm completion. Only capability-supported actions are accepted.",
        "responses": {
          "202": {
            "description": "Durable request recorded. Poll GET subscription for provider_status, operation_state and any approval_url.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "status",
                    "version",
                    "operation_id"
                  ],
                  "properties": {
                    "status": {
                      "type": "string",
                      "enum": [
                        "pending"
                      ]
                    },
                    "version": {
                      "type": "integer"
                    },
                    "operation_id": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    },
    "/organizations/{organization_id}/subscription/resume-renewal": {
      "post": {
        "operationId": "resumeCorporateRenewal",
        "summary": "Request automatic renewal resumption",
        "parameters": [
          {
            "name": "organization_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          },
          {
            "$ref": "#/components/parameters/IfMatch"
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "language": {
                    "type": "string"
                  },
                  "country": {
                    "type": "string"
                  }
                },
                "additionalProperties": false
              }
            }
          }
        },
        "description": "Durable provider operation. Poll subscription for confirmation. Resumption can require a provider approval_url; submitting or opening the URL does not confirm completion. Only capability-supported actions are accepted.",
        "responses": {
          "202": {
            "description": "Durable request recorded. Poll GET subscription for provider_status, operation_state and any approval_url.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "status",
                    "version",
                    "operation_id"
                  ],
                  "properties": {
                    "status": {
                      "type": "string",
                      "enum": [
                        "pending"
                      ]
                    },
                    "version": {
                      "type": "integer"
                    },
                    "operation_id": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "default": {
            "description": "Failure. 401 unauthenticated; 403 role/scope denied; 404 inaccessible object; 409 conflict; 412 stale version; 422 validation; 428 missing If-Match; 503 adapter/store unavailable.",
            "content": {
              "application/problem+json": {
                "schema": {
                  "$ref": "#/components/schemas/Problem"
                }
              }
            }
          }
        }
      }
    }
  },
  "components": {
    "securitySchemes": {
      "userBearer": {
        "type": "http",
        "scheme": "bearer",
        "description": "Existing signed-in Meduza user session"
      },
      "machineBearer": {
        "type": "http",
        "scheme": "bearer",
        "description": "One-hour OAuth client credentials token, one company only"
      }
    },
    "parameters": {
      "IfMatch": {
        "name": "If-Match",
        "in": "header",
        "required": true,
        "schema": {
          "type": "string"
        },
        "example": "\"3\"",
        "description": "Quoted integer Object.version. Object responses include ETag; missing=428, stale=412."
      },
      "IdempotencyKey": {
        "name": "Idempotency-Key",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string",
          "maxLength": 200
        },
        "description": "24-hour actor/client+method+path receipt. Reuse with different body=409. Secret values are not replayed."
      },
      "IdempotencyRequired": {
        "name": "Idempotency-Key",
        "in": "header",
        "required": true,
        "schema": {
          "type": "string",
          "maxLength": 200
        },
        "description": "Stable allocation identity; retry the same body with the same key."
      },
      "InventoryLimit": {
        "name": "limit",
        "in": "query",
        "schema": {
          "type": "integer",
          "minimum": 1,
          "maximum": 200,
          "default": 100
        },
        "description": "Opt-in pagination. Omit limit and cursor for the legacy complete collection; existing clients are not silently truncated."
      },
      "InventoryCursor": {
        "name": "cursor",
        "in": "query",
        "schema": {
          "type": "string",
          "maxLength": 4096
        },
        "description": "Opaque continuation returned by this same actor, path and filter/limit query. Repeat all filters unchanged. Authorization is checked again; cursor is not a permission grant."
      },
      "InventoryStatus": {
        "name": "status",
        "in": "query",
        "schema": {
          "type": "string",
          "maxLength": 200
        },
        "description": "Exact match against the visible field; member_id also matches group member_ids. A missing field does not match."
      },
      "InventoryMemberId": {
        "name": "member_id",
        "in": "query",
        "schema": {
          "type": "string",
          "maxLength": 200
        },
        "description": "Exact match against the visible field; member_id also matches group member_ids. A missing field does not match."
      },
      "InventoryUserId": {
        "name": "user_id",
        "in": "query",
        "schema": {
          "type": "string",
          "maxLength": 200
        },
        "description": "Exact match against the visible field; member_id also matches group member_ids. A missing field does not match."
      },
      "InventoryVpnId": {
        "name": "vpn_id",
        "in": "query",
        "schema": {
          "type": "string",
          "maxLength": 200
        },
        "description": "Exact match against the visible field; member_id also matches group member_ids. A missing field does not match."
      },
      "InventorySearch": {
        "name": "search",
        "in": "query",
        "schema": {
          "type": "string",
          "maxLength": 200
        },
        "description": "Case-insensitive substring of visible id/name/email/description/company_name only."
      },
      "InventoryCreatedFrom": {
        "name": "created_from",
        "in": "query",
        "schema": {
          "type": "string",
          "format": "date-time"
        },
        "description": "RFC3339 creation time: lower bound inclusive, upper bound exclusive. Entries without created_at do not match date filters."
      },
      "InventoryCreatedTo": {
        "name": "created_to",
        "in": "query",
        "schema": {
          "type": "string",
          "format": "date-time"
        },
        "description": "RFC3339 creation time: lower bound inclusive, upper bound exclusive. Entries without created_at do not match date filters."
      }
    },
    "schemas": {
      "Object": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "organization_id": {
            "type": "string"
          },
          "kind": {
            "type": "string"
          },
          "version": {
            "type": "integer",
            "minimum": 1
          },
          "created_at": {
            "type": "string",
            "format": "date-time"
          },
          "updated_at": {
            "type": "string",
            "format": "date-time"
          },
          "data": {
            "type": "object",
            "additionalProperties": true
          }
        },
        "required": [
          "id",
          "kind",
          "version",
          "data"
        ]
      },
      "Collection": {
        "type": "object",
        "properties": {
          "items": {
            "type": "array",
            "items": {}
          },
          "next_cursor": {
            "type": "null"
          },
          "total": {
            "type": "integer",
            "minimum": 0,
            "description": "Current filtered visible count for inventory collections; not a tenant-global count."
          },
          "limit": {
            "type": "integer",
            "minimum": 1,
            "maximum": 200
          }
        },
        "required": [
          "items",
          "next_cursor"
        ]
      },
      "Problem": {
        "type": "object",
        "properties": {
          "type": {
            "type": "string"
          },
          "title": {
            "type": "string"
          },
          "status": {
            "type": "integer"
          },
          "detail": {
            "type": "string"
          },
          "request_id": {
            "type": "string"
          }
        },
        "required": [
          "status",
          "detail"
        ]
      },
      "QuoteRequest": {
        "type": "object",
        "properties": {
          "vpn_count": {
            "type": "integer",
            "minimum": 5,
            "maximum": 10000
          },
          "period": {
            "type": "string",
            "enum": [
              "monthly",
              "annual"
            ]
          },
          "operation": {
            "type": "string",
            "enum": [
              "purchase",
              "renewal",
              "upgrade"
            ],
            "default": "purchase"
          },
          "payment_method": {
            "type": "string",
            "description": "ID from GET subscription/payment-methods. Shared with personal web checkout; native store methods are excluded."
          },
          "payment_mode": {
            "type": "string",
            "enum": [
              "one_time",
              "subscription"
            ],
            "default": "one_time"
          },
          "subscribe": {
            "type": "boolean",
            "description": "Compatibility alias. Must agree with payment_mode when both are supplied."
          },
          "language": {
            "type": "string",
            "description": "Interface language for checkout ordering/labels."
          },
          "country": {
            "type": "string",
            "description": "Checkout country hint; server resolves the authenticated request country."
          }
        },
        "required": [
          "vpn_count",
          "period"
        ]
      },
      "CheckoutRequest": {
        "type": "object",
        "properties": {
          "quote_id": {
            "type": "string"
          },
          "payment_method": {
            "type": "string",
            "description": "ID from GET subscription/payment-methods. Shared with personal web checkout; native store methods are excluded."
          },
          "payment_mode": {
            "type": "string",
            "enum": [
              "one_time",
              "subscription"
            ],
            "default": "one_time"
          },
          "subscribe": {
            "type": "boolean",
            "description": "Compatibility alias. Must agree with payment_mode when both are supplied."
          },
          "language": {
            "type": "string",
            "description": "Interface language for checkout ordering/labels."
          },
          "country": {
            "type": "string",
            "description": "Checkout country hint; server resolves the authenticated request country."
          }
        },
        "required": [
          "quote_id",
          "payment_method"
        ],
        "description": "Echo the selected quote payment method and mode. Mismatch is rejected; changing terms requires a new quote. Repeat requests recover the original invoice."
      },
      "ProvisionRequest": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 160
          },
          "pricing_id": {
            "type": "integer",
            "minimum": 1
          },
          "member_id": {
            "type": "string",
            "description": "Optional membership ID for dedicated assignment. Omit for company-wide VPN."
          }
        },
        "required": [
          "name",
          "pricing_id"
        ]
      },
      "Subscription": {
        "type": "object",
        "properties": {
          "status": {
            "type": "string",
            "enum": [
              "not_purchased",
              "active",
              "expired",
              "payment_review"
            ]
          },
          "vpn_count": {
            "type": "integer"
          },
          "period": {
            "type": "string",
            "enum": [
              "monthly",
              "annual"
            ]
          },
          "currency": {
            "type": "string"
          },
          "period_start": {
            "type": "string",
            "format": "date-time"
          },
          "period_end": {
            "type": "string",
            "format": "date-time"
          },
          "discount_percent": {
            "type": "integer"
          },
          "last_invoice_id": {
            "type": "string"
          },
          "capabilities": {
            "$ref": "#/components/schemas/BillingCapabilities"
          },
          "version": {
            "type": "integer"
          },
          "payment_mode": {
            "type": "string",
            "enum": [
              "one_time",
              "subscription"
            ],
            "default": "one_time"
          },
          "payment_method": {
            "type": "string",
            "description": "ID from GET subscription/payment-methods. Shared with personal web checkout; native store methods are excluded."
          },
          "auto_renew": {
            "type": "boolean"
          },
          "provider_status": {
            "type": "string",
            "description": "Provider-confirmed or explicitly pending state. Pending cancellation/resume/approval must not be represented as completed."
          },
          "cancel_at_period_end": {
            "type": "boolean"
          },
          "recurring_subscription_id": {
            "type": "integer"
          },
          "recurring_total_minor": {
            "type": "integer"
          },
          "approval_url": {
            "type": "string",
            "format": "uri",
            "description": "Hosted provider approval required to finish a pending resumption, when supplied."
          },
          "pending_action": {
            "type": "string",
            "description": "Pending recurring management action, such as start or schedule_change."
          },
          "operation_state": {
            "type": "string",
            "description": "Durable provider-operation status. pending_approval requires approval_url confirmation, possibly after the initial invoice is already paid. Continue polling subscription; paid invoice alone does not confirm future recurring billing."
          }
        },
        "required": [
          "status",
          "vpn_count"
        ]
      },
      "Rule": {
        "type": "object",
        "properties": {
          "target": {
            "type": "string"
          },
          "type": {
            "type": "string",
            "enum": [
              "preset",
              "domain",
              "wildcard",
              "cidr",
              "ip"
            ]
          },
          "action": {
            "type": "string",
            "enum": [
              "vpn",
              "direct",
              "deny"
            ]
          },
          "vpn_id": {
            "type": "string",
            "description": "Corporate VPN object ID, only for action=vpn."
          }
        },
        "required": [
          "target",
          "type",
          "action"
        ]
      },
      "TrafficPreset": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "domains": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "networks": {
            "type": "array",
            "items": {
              "type": "string"
            }
          }
        }
      },
      "Policy": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 160
          },
          "description": {
            "type": "string"
          },
          "mode": {
            "type": "string",
            "enum": [
              "full",
              "include",
              "exclude"
            ]
          },
          "entry_vpn_id": {
            "type": "string",
            "description": "Corporate VPN ID. Empty disables app-style routing while retaining rules."
          },
          "evaluation": {
            "type": "string",
            "enum": [
              "ordered",
              "first-match"
            ]
          },
          "others": {
            "type": "string",
            "description": "Fallback exit: direct or corporate VPN ID; deny/block is not permitted in first-match mode."
          },
          "rules": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/Rule"
            }
          },
          "custom_presets": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/TrafficPreset"
            }
          },
          "allow_personal": {
            "type": "boolean"
          },
          "dns": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "ipv6": {
            "type": "string"
          }
        },
        "required": [
          "mode",
          "rules"
        ]
      },
      "WebhookInput": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 160
          },
          "url": {
            "type": "string",
            "format": "uri",
            "description": "Public HTTPS endpoint on port 443. Private/reserved DNS answers and redirects are rejected."
          },
          "events": {
            "type": "array",
            "items": {
              "type": "string",
              "description": "*, audit.event, or resource.created / updated / deleted."
            }
          },
          "status": {
            "type": "string",
            "enum": [
              "active",
              "paused"
            ]
          }
        },
        "required": [
          "name",
          "url",
          "events"
        ]
      },
      "WebhookSecret": {
        "type": "object",
        "properties": {
          "webhook": {
            "$ref": "#/components/schemas/Object"
          },
          "secret": {
            "type": "string",
            "description": "One-time signing secret; never returned by GET."
          }
        },
        "required": [
          "webhook",
          "secret"
        ]
      },
      "APIClientInput": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 160
          },
          "scope": {
            "type": "string",
            "enum": [
              "read",
              "read write"
            ]
          },
          "expires_in_days": {
            "type": "integer",
            "minimum": 1,
            "maximum": 365
          }
        },
        "required": [
          "name",
          "scope"
        ]
      },
      "TokenRequest": {
        "type": "object",
        "properties": {
          "grant_type": {
            "type": "string",
            "enum": [
              "client_credentials"
            ]
          },
          "client_id": {
            "type": "string"
          },
          "client_secret": {
            "type": "string"
          }
        },
        "required": [
          "grant_type",
          "client_id",
          "client_secret"
        ]
      },
      "Token": {
        "type": "object",
        "properties": {
          "access_token": {
            "type": "string"
          },
          "token_type": {
            "type": "string",
            "enum": [
              "Bearer"
            ]
          },
          "expires_in": {
            "type": "integer",
            "const": 3600
          }
        },
        "required": [
          "access_token",
          "token_type",
          "expires_in"
        ]
      },
      "InvitationInput": {
        "type": "object",
        "properties": {
          "email": {
            "type": "string",
            "format": "email"
          },
          "role": {
            "type": "string",
            "enum": [
              "member",
              "admin",
              "billing"
            ],
            "default": "member"
          },
          "group_id": {
            "type": "string"
          },
          "locale": {
            "type": "string",
            "enum": [
              "ru",
              "en"
            ]
          }
        },
        "required": [
          "email"
        ]
      },
      "InviteClaim": {
        "type": "object",
        "properties": {
          "token": {
            "type": "string"
          },
          "invitation_id": {
            "type": "string"
          },
          "campaign_token": {
            "type": "string"
          },
          "consent": {
            "type": "boolean"
          }
        }
      },
      "CampaignInput": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 160
          },
          "max_claims": {
            "type": "integer",
            "minimum": 1,
            "maximum": 1000
          },
          "group_id": {
            "type": "string"
          },
          "approval_required": {
            "type": "boolean"
          },
          "expires_at": {
            "type": "string",
            "format": "date-time"
          },
          "locale": {
            "type": "string",
            "enum": [
              "ru",
              "en"
            ]
          }
        },
        "required": [
          "name",
          "max_claims"
        ]
      },
      "Assignment": {
        "type": "object",
        "properties": {
          "member_ids": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "route_package_id": {
            "type": "string"
          }
        }
      },
      "RequestInput": {
        "type": "object",
        "properties": {
          "organization_id": {
            "type": "string"
          },
          "vpn_id": {
            "type": "string"
          },
          "subject": {
            "type": "string"
          },
          "body": {
            "type": "string",
            "maxLength": 5000
          },
          "diagnostics_consent": {
            "type": "boolean"
          }
        },
        "required": [
          "organization_id",
          "body"
        ]
      },
      "RoleInput": {
        "type": "object",
        "required": [
          "name",
          "base_role",
          "permissions"
        ],
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 160
          },
          "base_role": {
            "type": "string",
            "enum": [
              "admin",
              "member",
              "billing"
            ]
          },
          "permissions": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "Subset of base role permissions returned by GET roles. organizations.read and roles.read remain enabled."
          }
        }
      },
      "Role": {
        "allOf": [
          {
            "$ref": "#/components/schemas/Object"
          },
          {
            "type": "object",
            "properties": {
              "editable": {
                "type": "boolean"
              },
              "assignable": {
                "type": "boolean"
              },
              "assigned_members": {
                "type": "integer"
              },
              "data": {
                "type": "object",
                "required": [
                  "name",
                  "base_role",
                  "permissions"
                ],
                "properties": {
                  "name": {
                    "type": "string"
                  },
                  "base_role": {
                    "type": "string",
                    "enum": [
                      "owner",
                      "admin",
                      "member",
                      "billing"
                    ]
                  },
                  "permissions": {
                    "type": "array",
                    "items": {
                      "type": "string"
                    }
                  },
                  "builtin": {
                    "type": "boolean"
                  }
                }
              }
            }
          }
        ]
      },
      "RoleCollection": {
        "type": "object",
        "properties": {
          "items": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/Role"
            }
          },
          "effective_permissions": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "can_manage": {
            "type": "boolean"
          },
          "permission_definitions": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "id": {
                  "type": "string"
                },
                "name": {
                  "type": "string"
                },
                "name_en": {
                  "type": "string"
                }
              }
            }
          }
        }
      },
      "DeviceView": {
        "allOf": [
          {
            "$ref": "#/components/schemas/Object"
          },
          {
            "type": "object",
            "properties": {
              "data": {
                "type": "object",
                "properties": {
                  "display_name": {
                    "type": "string"
                  },
                  "registered_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "enrolled_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "last_api_contact_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "last_api_ip": {
                    "type": "string",
                    "description": "Authenticated API transport peer, not browsing history or VPN destination."
                  },
                  "api_ip_source": {
                    "type": "string",
                    "enum": [
                      "transport_peer"
                    ]
                  },
                  "platform": {
                    "type": "string"
                  },
                  "client_version": {
                    "type": "string"
                  },
                  "owner": {
                    "type": "object"
                  },
                  "vpn": {
                    "type": "object"
                  },
                  "can_rename": {
                    "type": "boolean"
                  },
                  "can_revoke": {
                    "type": "boolean"
                  },
                  "last_vpn_connection_at": {
                    "type": "string",
                    "format": "date-time",
                    "nullable": true
                  },
                  "last_vpn_peer_observed_at": {
                    "type": "string",
                    "format": "date-time",
                    "nullable": true
                  },
                  "vpn_peer_checked_at": {
                    "type": "string",
                    "format": "date-time",
                    "nullable": true
                  },
                  "vpn_peer_observed_at": {
                    "type": "string",
                    "format": "date-time",
                    "nullable": true
                  },
                  "last_vpn_peer_ip": {
                    "type": "string",
                    "description": "Kernel TCP remote endpoint observed on the VPN node, never HTTP/client metadata."
                  },
                  "vpn_peer_status": {
                    "type": "string",
                    "enum": [
                      "measured",
                      "unavailable"
                    ]
                  },
                  "vpn_peer_source": {
                    "type": "string",
                    "enum": [
                      "node_transport_peer"
                    ]
                  },
                  "vpn_peer_time_source": {
                    "type": "string",
                    "enum": [
                      "authenticated_process_start"
                    ]
                  },
                  "vpn_peers": {
                    "type": "array",
                    "maxItems": 64,
                    "items": {
                      "type": "object",
                      "properties": {
                        "ip": {
                          "type": "string"
                        },
                        "port": {
                          "type": "integer"
                        },
                        "connected_at": {
                          "type": "string",
                          "format": "date-time"
                        },
                        "source": {
                          "type": "string",
                          "enum": [
                            "node_transport_peer"
                          ]
                        },
                        "time_source": {
                          "type": "string",
                          "enum": [
                            "authenticated_process_start"
                          ]
                        }
                      }
                    }
                  }
                }
              }
            }
          }
        ]
      },
      "DeviceRename": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "name"
        ],
        "properties": {
          "name": {
            "type": "string",
            "minLength": 1,
            "maxLength": 80
          }
        }
      },
      "EmployeeConnectionRow": {
        "type": "object",
        "properties": {
          "member_id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "email": {
            "type": "string"
          },
          "membership_status": {
            "type": "string"
          },
          "registered_devices": {
            "type": "integer",
            "minimum": 0
          },
          "active_credentials": {
            "type": "integer",
            "minimum": 0
          },
          "online_devices": {
            "type": "integer",
            "minimum": 0
          },
          "samples": {
            "type": "integer",
            "minimum": 0
          },
          "measured_samples": {
            "type": "integer",
            "minimum": 0
          },
          "online_samples": {
            "type": "integer",
            "minimum": 0
          },
          "peak_transport_sessions": {
            "type": "integer",
            "minimum": 0
          },
          "transport_sessions_now": {
            "type": [
              "integer",
              "null"
            ],
            "minimum": 0,
            "description": "Authenticated relay sessions, not a count of human logins or VPN tunnels. Null when no current measurement exists."
          },
          "connection_status": {
            "type": "string",
            "enum": [
              "online",
              "offline",
              "partial",
              "unknown"
            ]
          },
          "last_observed_at": {
            "type": [
              "string",
              "null"
            ],
            "format": "date-time"
          },
          "last_api_contact_at": {
            "type": "string",
            "description": "API credential enrollment/renewal time or empty string; never a website visit."
          }
        },
        "required": [
          "member_id",
          "name",
          "email",
          "membership_status",
          "registered_devices",
          "active_credentials",
          "online_devices",
          "samples",
          "measured_samples",
          "online_samples",
          "peak_transport_sessions",
          "transport_sessions_now",
          "connection_status",
          "last_observed_at",
          "last_api_contact_at"
        ]
      },
      "EmployeeConnectionPoint": {
        "type": "object",
        "properties": {
          "at": {
            "type": "string",
            "format": "date-time"
          },
          "online_samples": {
            "type": "integer",
            "minimum": 0
          },
          "measured_samples": {
            "type": "integer",
            "minimum": 0
          },
          "samples": {
            "type": "integer",
            "minimum": 0
          },
          "employees_observed_online": {
            "type": "integer",
            "minimum": 0
          },
          "peak_employee_transport_sessions": {
            "type": "integer",
            "minimum": 0
          }
        },
        "required": [
          "at",
          "online_samples",
          "measured_samples",
          "samples",
          "employees_observed_online",
          "peak_employee_transport_sessions"
        ]
      },
      "EmployeeConnectionEvent": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "member_id": {
            "type": "string"
          },
          "member_name": {
            "type": "string"
          },
          "device_id": {
            "type": "string"
          },
          "vpn_id": {
            "type": "string"
          },
          "state": {
            "type": "string"
          },
          "at": {
            "type": "string",
            "format": "date-time"
          },
          "source": {
            "type": "string",
            "enum": [
              "access_control",
              "node_observation"
            ]
          }
        },
        "required": [
          "id",
          "member_id",
          "member_name",
          "device_id",
          "vpn_id",
          "state",
          "at",
          "source"
        ]
      },
      "EmployeeAnalytics": {
        "type": "object",
        "properties": {
          "from": {
            "type": "string",
            "format": "date-time"
          },
          "to": {
            "type": "string",
            "format": "date-time"
          },
          "aggregate_from": {
            "type": "string",
            "format": "date-time"
          },
          "aggregate_to": {
            "type": "string",
            "format": "date-time"
          },
          "updated_at": {
            "type": "string",
            "format": "date-time"
          },
          "retention_days": {
            "type": "integer",
            "const": 7
          },
          "sample_interval_seconds": {
            "type": "integer",
            "const": 60
          },
          "capabilities": {
            "type": "object",
            "properties": {
              "employee_connections": {
                "type": "boolean",
                "const": true
              },
              "per_employee_bytes": {
                "type": "boolean",
                "const": false
              },
              "destination_history": {
                "type": "boolean",
                "const": false
              },
              "request_content": {
                "type": "boolean",
                "const": false
              }
            },
            "required": [
              "employee_connections",
              "per_employee_bytes",
              "destination_history",
              "request_content"
            ]
          },
          "summary": {
            "type": "object",
            "properties": {
              "employees": {
                "type": "integer",
                "minimum": 0
              },
              "employees_online_now": {
                "type": "integer",
                "minimum": 0
              },
              "measured_devices": {
                "type": "integer",
                "minimum": 0
              },
              "unknown_devices": {
                "type": "integer",
                "minimum": 0
              }
            },
            "required": [
              "employees",
              "employees_online_now",
              "measured_devices",
              "unknown_devices"
            ]
          },
          "employees": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/EmployeeConnectionRow"
            }
          },
          "series": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/EmployeeConnectionPoint"
            }
          },
          "events": {
            "type": "array",
            "maxItems": 200,
            "items": {
              "$ref": "#/components/schemas/EmployeeConnectionEvent"
            }
          },
          "events_truncated": {
            "type": "boolean"
          },
          "history_status": {
            "type": "string",
            "enum": [
              "measured",
              "awaiting_samples"
            ]
          },
          "source": {
            "type": "string",
            "const": "authenticated_node_relay_session_observations"
          },
          "connections": {
            "$ref": "#/components/schemas/VpnConnectionHistory"
          }
        },
        "required": [
          "from",
          "to",
          "aggregate_from",
          "aggregate_to",
          "updated_at",
          "retention_days",
          "sample_interval_seconds",
          "capabilities",
          "summary",
          "employees",
          "series",
          "events",
          "events_truncated",
          "history_status",
          "source"
        ]
      },
      "ActivityCoverage": {
        "type": "object",
        "properties": {
          "enabled": {
            "type": "boolean"
          },
          "status": {
            "type": "string",
            "enum": [
              "disabled",
              "unavailable",
              "partial",
              "collecting",
              "no_eligible_devices"
            ]
          },
          "source": {
            "type": "string",
            "enum": [
              "node"
            ]
          },
          "host_source": {
            "type": "string",
            "enum": [
              "client_requested_destination"
            ]
          },
          "retention_days": {
            "type": "integer",
            "enum": [
              7
            ]
          },
          "max_stored_events": {
            "type": "integer"
          },
          "measured_devices": {
            "type": "integer"
          },
          "unavailable_devices": {
            "type": "integer"
          },
          "last_collected_at": {
            "type": "string",
            "format": "date-time",
            "nullable": true
          },
          "dropped_events": {
            "type": "integer"
          },
          "client_side_blocks": {
            "type": "boolean"
          },
          "direct_traffic": {
            "type": "boolean"
          },
          "url_paths": {
            "type": "boolean"
          },
          "request_bodies": {
            "type": "boolean"
          },
          "reasons": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "effective_devices": {
            "type": "integer",
            "minimum": 0,
            "description": "Active devices included by the effective company/member/group collection setting; measured plus unavailable."
          },
          "excluded_devices": {
            "type": "integer",
            "minimum": 0,
            "description": "Active devices excluded by effective collection settings. Exclusion is not a node availability error."
          }
        }
      },
      "ActivitySettings": {
        "type": "object",
        "required": [
          "enabled",
          "version",
          "retention_days",
          "source",
          "coverage"
        ],
        "properties": {
          "enabled": {
            "type": "boolean"
          },
          "version": {
            "type": "integer"
          },
          "retention_days": {
            "type": "integer",
            "enum": [
              7
            ]
          },
          "source": {
            "type": "string",
            "enum": [
              "node"
            ]
          },
          "coverage": {
            "$ref": "#/components/schemas/ActivityCoverage"
          },
          "classification_rules": {
            "type": "array",
            "maxItems": 64,
            "items": {
              "oneOf": [
                {
                  "$ref": "#/components/schemas/ActivityCategoryRule"
                },
                {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "domain",
                    "category"
                  ],
                  "properties": {
                    "domain": {
                      "type": "string",
                      "maxLength": 253,
                      "description": "Canonical domain suffix including subdomains; no URLs or wildcard notation."
                    },
                    "category": {
                      "type": "string",
                      "enum": [
                        "worktools",
                        "development",
                        "communication",
                        "video",
                        "social",
                        "games",
                        "storage",
                        "system",
                        "unknown"
                      ]
                    }
                  }
                }
              ]
            }
          },
          "consent_version": {
            "type": "integer",
            "minimum": 0,
            "description": "Stable company disclosure schema version 2000001. Routine settings and category changes do not require another acknowledgement."
          },
          "taxonomy_version": {
            "type": "string"
          },
          "consent_schema_version": {
            "type": "integer",
            "minimum": 0
          },
          "default_enabled": {
            "type": "boolean",
            "description": "New organizations default false. Legacy settings preserve existing enabled behavior."
          }
        }
      },
      "ActivityEvent": {
        "type": "object",
        "description": "Node-observed connection request, not a page visit. Host is the authenticated client-requested destination; no TLS content inspection. IP is supplied endpoint IP, not necessarily resolved DNS IP.",
        "properties": {
          "id": {
            "type": "string"
          },
          "member_id": {
            "type": "string"
          },
          "member_name": {
            "type": "string"
          },
          "member_email": {
            "type": "string"
          },
          "device_id": {
            "type": "string"
          },
          "device_name": {
            "type": "string"
          },
          "vpn_id": {
            "type": "string"
          },
          "vpn_name": {
            "type": "string"
          },
          "host": {
            "type": "string"
          },
          "ip": {
            "type": "string"
          },
          "at": {
            "type": "string",
            "format": "date-time"
          },
          "port": {
            "type": "integer"
          },
          "network": {
            "type": "string",
            "enum": [
              "tcp",
              "udp"
            ]
          },
          "decision": {
            "type": "string",
            "enum": [
              "allow",
              "deny",
              "error"
            ]
          },
          "source": {
            "type": "string",
            "enum": [
              "node"
            ]
          },
          "category": {
            "type": "string",
            "enum": [
              "worktools",
              "development",
              "communication",
              "video",
              "social",
              "games",
              "storage",
              "system",
              "unknown"
            ]
          },
          "category_source": {
            "type": "string",
            "enum": [
              "manual",
              "builtin",
              "unknown"
            ]
          },
          "taxonomy_version": {
            "type": "string"
          }
        }
      },
      "ActivityPage": {
        "type": "object",
        "properties": {
          "items": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/ActivityEvent"
            }
          },
          "summary": {
            "type": "object",
            "properties": {
              "total_events": {
                "type": "integer"
              },
              "allowed": {
                "type": "integer"
              },
              "denied": {
                "type": "integer"
              },
              "errors": {
                "type": "integer"
              },
              "unique_destinations": {
                "type": "integer"
              }
            }
          },
          "series": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "at": {
                  "type": "string",
                  "format": "date-time"
                },
                "events": {
                  "type": "integer"
                },
                "allowed": {
                  "type": "integer"
                },
                "denied": {
                  "type": "integer"
                },
                "errors": {
                  "type": "integer"
                }
              }
            }
          },
          "members": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "id": {
                  "type": "string"
                },
                "name": {
                  "type": "string"
                },
                "email": {
                  "type": "string"
                }
              }
            }
          },
          "coverage": {
            "$ref": "#/components/schemas/ActivityCoverage"
          },
          "next_cursor": {
            "type": "string"
          },
          "analysis": {
            "$ref": "#/components/schemas/ActivityAnalysis"
          }
        }
      },
      "ActivityAnalysis": {
        "type": "object",
        "properties": {
          "taxonomy_version": {
            "type": "string"
          },
          "classification_version": {
            "type": "integer",
            "description": "Current company classification settings version applied to the selected historical window."
          },
          "interval_seconds": {
            "type": "integer",
            "enum": [
              60
            ]
          },
          "basis": {
            "type": "string",
            "enum": [
              "observed_connection_minutes"
            ]
          },
          "active_minutes": {
            "type": "integer",
            "minimum": 0,
            "description": "Distinct employee UTC-minute buckets containing observed requests. Not website dwell time or work duration."
          },
          "truncated": {
            "type": "boolean"
          },
          "category_totals": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "id": {
                  "type": "string",
                  "enum": [
                    "worktools",
                    "development",
                    "communication",
                    "video",
                    "social",
                    "games",
                    "storage",
                    "system",
                    "unknown"
                  ]
                },
                "label": {
                  "type": "string"
                },
                "label_en": {
                  "type": "string"
                },
                "events": {
                  "type": "integer",
                  "minimum": 0
                },
                "active_minutes": {
                  "type": "integer",
                  "minimum": 0,
                  "description": "Distinct employee UTC-minute buckets containing observed requests. Not website dwell time or work duration."
                }
              }
            }
          },
          "employee_categories": {
            "type": "array",
            "maxItems": 500,
            "items": {
              "type": "object",
              "properties": {
                "member_id": {
                  "type": "string"
                },
                "category": {
                  "type": "string",
                  "enum": [
                    "worktools",
                    "development",
                    "communication",
                    "video",
                    "social",
                    "games",
                    "storage",
                    "system",
                    "unknown"
                  ]
                },
                "events": {
                  "type": "integer",
                  "minimum": 0
                },
                "active_minutes": {
                  "type": "integer",
                  "minimum": 0,
                  "description": "Distinct employee UTC-minute buckets containing observed requests. Not website dwell time or work duration."
                }
              }
            }
          },
          "hourly_categories": {
            "type": "array",
            "maxItems": 2000,
            "items": {
              "type": "object",
              "properties": {
                "at": {
                  "type": "string",
                  "format": "date-time"
                },
                "category": {
                  "type": "string",
                  "enum": [
                    "worktools",
                    "development",
                    "communication",
                    "video",
                    "social",
                    "games",
                    "storage",
                    "system",
                    "unknown"
                  ]
                },
                "events": {
                  "type": "integer",
                  "minimum": 0
                },
                "active_minutes": {
                  "type": "integer",
                  "minimum": 0,
                  "description": "Distinct employee UTC-minute buckets containing observed requests. Not website dwell time or work duration."
                }
              }
            }
          },
          "top_destinations": {
            "type": "array",
            "maxItems": 100,
            "items": {
              "type": "object",
              "properties": {
                "host": {
                  "type": "string"
                },
                "ip": {
                  "type": "string"
                },
                "category": {
                  "type": "string",
                  "enum": [
                    "worktools",
                    "development",
                    "communication",
                    "video",
                    "social",
                    "games",
                    "storage",
                    "system",
                    "unknown"
                  ]
                },
                "events": {
                  "type": "integer",
                  "minimum": 0
                },
                "active_minutes": {
                  "type": "integer",
                  "minimum": 0,
                  "description": "Distinct employee UTC-minute buckets containing observed requests. Not website dwell time or work duration."
                }
              }
            }
          }
        },
        "description": "Aggregates cover the whole filtered interval, independent of raw-event pagination. Overall active_minutes deduplicates employee+minute across all categories; category totals must not be summed. Truncation is explicit."
      },
      "ActivityCategoryRule": {
        "type": "object",
        "required": [
          "type",
          "value",
          "category"
        ],
        "additionalProperties": false,
        "properties": {
          "type": {
            "type": "string",
            "enum": [
              "domain",
              "ip",
              "cidr"
            ]
          },
          "value": {
            "type": "string",
            "maxLength": 253
          },
          "category": {
            "type": "string",
            "enum": [
              "worktools",
              "development",
              "communication",
              "video",
              "social",
              "games",
              "storage",
              "system",
              "unknown"
            ]
          }
        }
      },
      "ActivityCollection": {
        "type": "object",
        "required": [
          "mode",
          "effective_enabled",
          "source",
          "version"
        ],
        "properties": {
          "mode": {
            "type": "string",
            "enum": [
              "inherit",
              "on",
              "off"
            ]
          },
          "effective_enabled": {
            "type": "boolean"
          },
          "source": {
            "type": "string",
            "enum": [
              "global_off",
              "member",
              "group_off",
              "group_on",
              "company_default",
              "group"
            ]
          },
          "version": {
            "type": "integer"
          }
        }
      },
      "MemberView": {
        "allOf": [
          {
            "$ref": "#/components/schemas/Object"
          },
          {
            "type": "object",
            "properties": {
              "data": {
                "type": "object",
                "properties": {
                  "activity_notice_acknowledged": {
                    "type": "boolean",
                    "readOnly": true,
                    "description": "Verified employee acknowledgement for this organization. Independent of effective collection setting; never writable by administrators."
                  },
                  "activity_notice_accepted_at": {
                    "type": "string",
                    "format": "date-time",
                    "nullable": true,
                    "readOnly": true,
                    "description": "Actual authenticated acceptance timestamp; null when no receipt is available."
                  },
                  "activity_notice_version": {
                    "type": "integer",
                    "readOnly": true,
                    "description": "Current company disclosure schema identifier, presently 2000001."
                  }
                }
              }
            }
          }
        ]
      },
      "MemberCollection": {
        "type": "object",
        "properties": {
          "items": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/MemberView"
            }
          },
          "next_cursor": {
            "type": "string",
            "nullable": true
          },
          "total": {
            "type": "integer",
            "minimum": 0,
            "description": "Current filtered visible count for inventory collections; not a tenant-global count."
          },
          "limit": {
            "type": "integer",
            "minimum": 1,
            "maximum": 200
          }
        }
      },
      "ActivityCategoryTemplateInput": {
        "type": "object",
        "required": [
          "name",
          "rules"
        ],
        "properties": {
          "name": {
            "type": "string",
            "minLength": 1,
            "maxLength": 120
          },
          "rules": {
            "type": "array",
            "minItems": 1,
            "maxItems": 64,
            "items": {
              "oneOf": [
                {
                  "$ref": "#/components/schemas/ActivityCategoryRule"
                },
                {
                  "type": "object",
                  "required": [
                    "domain",
                    "category"
                  ],
                  "properties": {
                    "domain": {
                      "type": "string"
                    },
                    "category": {
                      "type": "string"
                    }
                  }
                }
              ]
            }
          }
        }
      },
      "ActivityCategoryTemplate": {
        "allOf": [
          {
            "$ref": "#/components/schemas/Object"
          },
          {
            "type": "object",
            "properties": {
              "data": {
                "type": "object",
                "properties": {
                  "name": {
                    "type": "string"
                  },
                  "rules": {
                    "type": "array",
                    "minItems": 1,
                    "maxItems": 64,
                    "items": {
                      "oneOf": [
                        {
                          "$ref": "#/components/schemas/ActivityCategoryRule"
                        },
                        {
                          "type": "object",
                          "required": [
                            "domain",
                            "category"
                          ],
                          "properties": {
                            "domain": {
                              "type": "string"
                            },
                            "category": {
                              "type": "string"
                            }
                          }
                        }
                      ]
                    }
                  },
                  "origin": {
                    "type": "string",
                    "enum": [
                      "company"
                    ]
                  }
                }
              }
            }
          }
        ]
      },
      "AlertRuleInput": {
        "type": "object",
        "required": [
          "metric",
          "threshold"
        ],
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 160
          },
          "description": {
            "type": "string"
          },
          "metric": {
            "type": "string",
            "enum": [
              "share_load_now_pct",
              "active_sessions",
              "vpn_probe_unavailable",
              "policy_unconfirmed_devices",
              "denied_destinations_5m",
              "activity_collection_unavailable",
              "new_devices_5m"
            ]
          },
          "threshold": {
            "type": "integer",
            "minimum": 1,
            "maximum": 1000000,
            "description": "For share_load_now_pct maximum100."
          },
          "duration_seconds": {
            "type": "integer",
            "minimum": 0,
            "maximum": 86400
          },
          "cooldown_seconds": {
            "type": "integer",
            "minimum": 60,
            "maximum": 604800,
            "description": "Legacy omitted/0 uses60seconds."
          },
          "status": {
            "type": "string",
            "enum": [
              "active",
              "disabled"
            ]
          }
        }
      },
      "AlertRulePatch": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 160
          },
          "description": {
            "type": "string"
          },
          "metric": {
            "type": "string",
            "enum": [
              "share_load_now_pct",
              "active_sessions",
              "vpn_probe_unavailable",
              "policy_unconfirmed_devices",
              "denied_destinations_5m",
              "activity_collection_unavailable",
              "new_devices_5m"
            ]
          },
          "threshold": {
            "type": "integer",
            "minimum": 1,
            "maximum": 1000000,
            "description": "For share_load_now_pct maximum100."
          },
          "duration_seconds": {
            "type": "integer",
            "minimum": 0,
            "maximum": 86400
          },
          "cooldown_seconds": {
            "type": "integer",
            "minimum": 60,
            "maximum": 604800,
            "description": "Legacy omitted/0 uses60seconds."
          },
          "status": {
            "type": "string",
            "enum": [
              "active",
              "disabled"
            ]
          }
        }
      },
      "BillingCapabilities": {
        "type": "object",
        "description": "Configured integration callbacks, not a guarantee of upstream health. False disables the corresponding operation before creating an invoice or changing access.",
        "required": [
          "checkout",
          "provision",
          "retire"
        ],
        "properties": {
          "checkout": {
            "type": "boolean"
          },
          "provision": {
            "type": "boolean"
          },
          "retire": {
            "type": "boolean"
          },
          "cancel_renewal": {
            "type": "boolean"
          },
          "resume_renewal": {
            "type": "boolean"
          }
        }
      },
      "VPNCapabilities": {
        "type": "object",
        "required": [
          "provision",
          "retire"
        ],
        "properties": {
          "provision": {
            "type": "boolean"
          },
          "retire": {
            "type": "boolean"
          }
        }
      },
      "VpnConnectionDay": {
        "type": "object",
        "properties": {
          "date": {
            "type": "string",
            "format": "date"
          },
          "timezone": {
            "type": "string"
          },
          "employee_seconds": {
            "type": "integer",
            "minimum": 0
          },
          "device_seconds": {
            "type": "integer",
            "minimum": 0
          },
          "connections": {
            "type": "integer",
            "minimum": 0
          },
          "disconnections": {
            "type": "integer",
            "minimum": 0
          }
        },
        "required": [
          "date",
          "timezone",
          "employee_seconds",
          "device_seconds",
          "connections",
          "disconnections"
        ]
      },
      "VpnConnectionSession": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "member_id": {
            "type": "string"
          },
          "member_name": {
            "type": "string"
          },
          "device_id": {
            "type": "string"
          },
          "device_name": {
            "type": "string"
          },
          "vpn_id": {
            "type": "string"
          },
          "vpn_name": {
            "type": "string"
          },
          "started_at": {
            "type": "string",
            "format": "date-time"
          },
          "start_source": {
            "type": "string",
            "enum": [
              "authenticated_process_start",
              "first_observation"
            ]
          },
          "last_seen_at": {
            "type": "string",
            "format": "date-time"
          },
          "ended_at": {
            "type": [
              "string",
              "null"
            ],
            "format": "date-time"
          },
          "end_reason": {
            "type": [
              "string",
              "null"
            ],
            "enum": [
              null,
              "node_observed_disconnect",
              "observation_lost",
              "access_revoked"
            ]
          },
          "end_source": {
            "type": "string",
            "enum": [
              "node_observation",
              "access_control"
            ]
          },
          "counted_until": {
            "type": "string",
            "format": "date-time"
          },
          "duration_seconds": {
            "type": "integer",
            "minimum": 0
          },
          "status": {
            "type": "string",
            "enum": [
              "open",
              "closed"
            ]
          },
          "source": {
            "type": "string",
            "const": "node_observation"
          },
          "counted_from": {
            "type": "string",
            "format": "date-time"
          },
          "first_observed_at": {
            "type": "string",
            "format": "date-time"
          }
        },
        "required": [
          "id",
          "member_id",
          "device_id",
          "vpn_id",
          "started_at",
          "start_source",
          "last_seen_at",
          "ended_at",
          "end_reason",
          "counted_until",
          "duration_seconds",
          "status",
          "source"
        ]
      },
      "VpnConnectionLifecycleEvent": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "session_id": {
            "type": "string"
          },
          "member_id": {
            "type": "string"
          },
          "member_name": {
            "type": "string"
          },
          "device_id": {
            "type": "string"
          },
          "device_name": {
            "type": "string"
          },
          "vpn_id": {
            "type": "string"
          },
          "vpn_name": {
            "type": "string"
          },
          "at": {
            "type": "string",
            "format": "date-time"
          },
          "occurred_at": {
            "type": "string",
            "format": "date-time",
            "description": "Optional bounded device-reported time. For client_reported events, at is authoritative server receipt time."
          },
          "type": {
            "type": "string",
            "enum": [
              "connected",
              "disconnected",
              "observation_lost",
              "reconnecting",
              "restored"
            ]
          },
          "reason": {
            "type": [
              "string",
              "null"
            ],
            "description": "Source-provided reason. manual_disconnect only for explicit disconnected user action. Missing reasons are not inferred."
          },
          "source": {
            "type": "string",
            "enum": [
              "node_observation",
              "access_control",
              "client_reported"
            ]
          },
          "client_source": {
            "type": "string",
            "enum": [
              "user",
              "system",
              "mia",
              "cli",
              "switch",
              "autofix",
              "app"
            ]
          }
        },
        "required": [
          "id",
          "member_id",
          "device_id",
          "at",
          "type",
          "source"
        ]
      },
      "VpnConnectionHistory": {
        "type": "object",
        "properties": {
          "source": {
            "type": "string",
            "const": "node_observation"
          },
          "precision": {
            "type": "string",
            "const": "sampled"
          },
          "poll_interval_seconds": {
            "type": "integer",
            "const": 60
          },
          "max_observation_gap_seconds": {
            "type": "integer",
            "const": 180
          },
          "retention_days": {
            "type": "integer",
            "const": 7
          },
          "truncated": {
            "type": "boolean"
          },
          "summary": {
            "type": "object",
            "properties": {
              "employee_seconds": {
                "type": "integer",
                "minimum": 0
              },
              "device_seconds": {
                "type": "integer",
                "minimum": 0
              },
              "connections": {
                "type": "integer",
                "minimum": 0
              },
              "disconnections": {
                "type": "integer",
                "minimum": 0
              },
              "open_sessions": {
                "type": "integer",
                "minimum": 0
              },
              "observation_lost": {
                "type": "integer",
                "minimum": 0
              },
              "client_reported_events": {
                "type": "integer",
                "minimum": 0
              }
            },
            "required": [
              "employee_seconds",
              "device_seconds",
              "connections",
              "disconnections",
              "open_sessions",
              "observation_lost",
              "client_reported_events"
            ]
          },
          "daily": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/VpnConnectionDay"
            }
          },
          "sessions": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/VpnConnectionSession"
            },
            "maxItems": 200
          },
          "events": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/VpnConnectionLifecycleEvent"
            },
            "maxItems": 400
          },
          "timezone": {
            "type": "string"
          },
          "sessions_truncated": {
            "type": "boolean"
          },
          "events_truncated": {
            "type": "boolean"
          },
          "history_truncated": {
            "type": "boolean"
          },
          "retention_start": {
            "type": "string",
            "format": "date-time"
          },
          "history_started_at": {
            "type": [
              "string",
              "null"
            ],
            "format": "date-time",
            "description": "First activation of node observation history for this company. Earlier intervals are not backfilled."
          }
        },
        "required": [
          "source",
          "precision",
          "poll_interval_seconds",
          "max_observation_gap_seconds",
          "retention_days",
          "truncated",
          "summary",
          "daily",
          "sessions",
          "events"
        ],
        "description": "Seven-day observed company VPN history. employee_seconds unions overlapping intervals per employee; device_seconds sums per-device intervals. No time is extrapolated beyond last_seen_at. Client reports never extend sessions or increase node counts. Truncated responses require a narrower date/member filter."
      },
      "CorporatePaymentMethod": {
        "type": "object",
        "required": [
          "id",
          "currency",
          "recurring",
          "available"
        ],
        "properties": {
          "id": {
            "type": "string",
            "description": "ID from GET subscription/payment-methods. Shared with personal web checkout; native store methods are excluded."
          },
          "provider": {
            "type": "string"
          },
          "currency": {
            "type": "string"
          },
          "one_time": {
            "type": "boolean"
          },
          "subscription": {
            "type": "boolean"
          },
          "recurring": {
            "type": "boolean"
          },
          "available": {
            "type": "boolean"
          },
          "available_one_time": {
            "type": "boolean"
          },
          "available_subscription": {
            "type": "boolean"
          }
        }
      },
      "CorporatePaymentOptions": {
        "type": "object",
        "required": [
          "methods",
          "checkout_country"
        ],
        "properties": {
          "methods": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/CorporatePaymentMethod"
            }
          },
          "default_payment_method": {
            "type": "string",
            "description": "ID from GET subscription/payment-methods. Shared with personal web checkout; native store methods are excluded."
          },
          "default_payment_mode": {
            "type": "string",
            "enum": [
              "one_time",
              "subscription"
            ],
            "default": "one_time"
          },
          "checkout_country": {
            "type": "string"
          }
        },
        "description": "Supported method catalog remains visible when gateway credentials are unavailable. Availability is reported separately for one-time and recurring checkout."
      }
    }
  },
  "x-webhook-delivery": {
    "events": "Audit changes are delivered at least once to matching active subscriptions. Dedupe by Meduza-Event-Id. Billing worker transitions emit invoices.updated, subscriptions.updated and vpns.updated; alerts emit alerts.created. Fingerprints dedupe unchanged polling states.",
    "signature": "Meduza-Signature: t=<unix seconds>,v1=<hex HMAC-SHA256(secret, timestamp + \".\" + exact raw JSON body)>",
    "headers": [
      "Meduza-Event-Id",
      "Meduza-Delivery-Id"
    ],
    "security": "Verify signature in constant time, constrain timestamp replay window, retain prior secret for queued deliveries during rotation. HTTPS/public-IP only, DNS pinned per attempt, no redirects.",
    "retry": "Non-2xx responses retry with exponential backoff, maximum eight attempts; failed deliveries support manual retry. Terminal history expires after 30 days (max 2000 per webhook). Pending/failed retain up to 1000 per webhook, with active leases protected. Overflow discards oldest unleased events and increments visible dropped_deliveries counter; resynchronize via API."
  },
  "x-role-permissions": {
    "enforcement": "Custom roles only subtract from base. Machine clients use creator live membership. vpn.connect changes queue node-confirmed revocation.",
    "own_scopes": [
      "devices.self",
      "requests.self",
      "vpn.connect"
    ],
    "assignment": "Owner only; invitations currently use built-in roles."
  }
}
