{"openapi":"3.1.0","info":{"title":"GET /api/v1/tokens/access","version":"1.0.0","description":"Get API access status"},"servers":[{"url":"https://api.ondayzero.com","description":"Production"}],"paths":{"/api/v1/tokens/access":{"get":{"tags":["api-tokens"],"summary":"Get API access status","description":"Whether the caller may create and use API tokens. API access is off until a DayZero operator approves a request for it.","operationId":"get_api_access","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Authorization"}}],"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessEnvelope_ApiAccessStateResponse_"}}}},"401":{"description":"Unauthorized - Missing/invalid token or no access to this business","content":{"application/json":{"example":{"error":"unauthorized","message":"Authentication required","code":"AUTH_001","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"},"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"example":{"error":"validation_error","message":"Validation failed: amount: Input should be a valid integer","errors":{"amount":"Input should be a valid integer"},"code":"GEN_002","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"}}}}},"x-fastapi-operation-id":"get_api_access_api_v1_tokens_access_get"}}},"components":{"schemas":{"ApiAccessRequestSummary":{"properties":{"id":{"type":"string","title":"Id"},"status":{"type":"string","title":"Status","description":"pending | approved | denied | revoked"},"use_case":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Use Case"},"company_name":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Company Name"},"requested_at":{"type":"string","format":"date-time","title":"Requested At"},"decided_at":{"anyOf":[{"type":"string","format":"date-time"},{"type":"null"}],"title":"Decided At"},"decision_note":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Decision Note","description":"Note from the DayZero operator who decided the request"}},"type":"object","required":["id","status","requested_at"],"title":"ApiAccessRequestSummary","description":"The user's own view of their latest request."},"ApiAccessStateResponse":{"properties":{"status":{"type":"string","enum":["not_requested","pending","approved","denied","revoked","firm_disabled"],"title":"Status","description":"`approved` — may create and use API tokens. `pending` — a request is waiting for DayZero. `denied` / `revoked` — turned down or taken away; a new request may be sent. `not_requested` — never asked. `firm_disabled` — approved by DayZero but switched off by the user's firm."},"can_request":{"type":"boolean","title":"Can Request","description":"Whether a new access request may be submitted now"},"request":{"anyOf":[{"$ref":"#/components/schemas/ApiAccessRequestSummary"},{"type":"null"}],"description":"The most recent request, if any"}},"type":"object","required":["status","can_request"],"title":"ApiAccessStateResponse","description":"Where the caller stands on API access."},"SuccessEnvelope_ApiAccessStateResponse_":{"properties":{"success":{"type":"boolean","title":"Success","default":true},"message":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Message"},"code":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Code"},"data":{"anyOf":[{"$ref":"#/components/schemas/ApiAccessStateResponse"},{"type":"null"}]}},"additionalProperties":true,"type":"object","title":"SuccessEnvelope[ApiAccessStateResponse]"},"ErrorResponse":{"title":"ErrorResponse","type":"object","description":"Envelope returned by every non-2xx response. Branch on `code` (stable) rather than `message` (human-readable, may change).","required":["error","message","code"],"properties":{"error":{"type":"string","description":"Error category: `validation_error`, `unauthorized`, `forbidden`, `not_found`, `conflict`, `rate_limited`, `server_error`, or `service_unavailable`."},"message":{"type":"string","description":"Human-readable explanation, safe to show to end users."},"code":{"type":"string","description":"Stable machine-readable code in `CATEGORY_NNN` form (e.g. `NOT_FOUND_006`, `AUTH_010`, `GEN_002`)."},"request_id":{"type":"string","description":"Correlation id for support requests. Echoes the `x-request-id` request header when one was supplied."},"errors":{"type":"object","additionalProperties":{"type":"string"},"description":"Field-level validation messages keyed by field name. Present on 400/422 validation failures only."}}}},"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"API Token","description":"API token authentication. Format: `Bearer dz_...`"}}},"security":[{"BearerAuth":[]}]}