{"openapi":"3.1.0","info":{"title":"POST /api/v1/credit/scorecards/validate","version":"1.0.0","description":"Validate a scorecard before putting it on a program"},"servers":[{"url":"https://api.ondayzero.com","description":"Production"}],"paths":{"/api/v1/credit/scorecards/validate":{"post":{"tags":["credit"],"summary":"Validate a scorecard before putting it on a program","description":"The framework for the partner's underwriting scorecard (O-01). Checks the criteria shape and reports which keys DayZero can measure today. Unmeasured keys are allowed and report as unmeasured on every assessment; a *required* unmeasured key means an assessment can never pass, so it is called out. Nothing is saved: put the scorecard on the program with `PATCH /credit/programs/{id}` (`underwriting_criteria`).","operationId":"validate_scorecard","parameters":[{"name":"authorization","in":"header","required":false,"schema":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Authorization"}},{"name":"x-business-id","in":"header","required":false,"schema":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"X-Business-Id"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScorecardValidateRequest"}}}},"responses":{"201":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessEnvelope_ScorecardValidateResponse_"}}}},"400":{"description":"Bad Request - Invalid input","content":{"application/json":{"example":{"error":"validation_error","message":"Validation failed: due_date: Input should be a valid date","errors":{"due_date":"Input should be a valid date"},"code":"GEN_002","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"},"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"401":{"description":"Unauthorized - Missing/invalid token or no access to this business","content":{"application/json":{"example":{"error":"unauthorized","message":"Authentication required","code":"AUTH_001","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"},"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"403":{"description":"Forbidden - Insufficient permissions","content":{"application/json":{"example":{"error":"forbidden","message":"You don't have permission to access this resource","code":"AUTH_002","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"},"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"example":{"error":"validation_error","message":"Validation failed: amount: Input should be a valid integer","errors":{"amount":"Input should be a valid integer"},"code":"GEN_002","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"}}}}},"x-fastapi-operation-id":"validate_scorecard_api_v1_credit_scorecards_validate_post"}}},"components":{"schemas":{"ScorecardValidateRequest":{"properties":{"underwriting_criteria":{"items":{"additionalProperties":true,"type":"object"},"type":"array","title":"Underwriting Criteria","description":"Criteria items: key, comparator (gte, lte, gt, lt, eq, between), threshold (number, or [low, high] for between), optional label, unit, weight, required, segments."}},"additionalProperties":false,"type":"object","required":["underwriting_criteria"],"title":"ScorecardValidateRequest","description":"A scorecard to check before it is put on a program (O-01 framework)."},"ScorecardValidateResponse":{"properties":{"valid":{"type":"boolean","title":"Valid"},"errors":{"items":{"type":"string"},"type":"array","title":"Errors"},"criteria_count":{"type":"integer","title":"Criteria Count","default":0},"measured":{"items":{"type":"string"},"type":"array","title":"Measured"},"unmeasured":{"items":{"type":"string"},"type":"array","title":"Unmeasured"},"required_unmeasured":{"items":{"type":"string"},"type":"array","title":"Required Unmeasured","description":"Required criteria DayZero cannot measure: an assessment can never pass them."}},"type":"object","required":["valid"],"title":"ScorecardValidateResponse"},"SuccessEnvelope_ScorecardValidateResponse_":{"properties":{"success":{"type":"boolean","title":"Success","default":true},"message":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Message"},"code":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Code"},"data":{"anyOf":[{"$ref":"#/components/schemas/ScorecardValidateResponse"},{"type":"null"}]}},"additionalProperties":true,"type":"object","title":"SuccessEnvelope[ScorecardValidateResponse]"},"ErrorResponse":{"title":"ErrorResponse","type":"object","description":"Envelope returned by every non-2xx response. Branch on `code` (stable) rather than `message` (human-readable, may change).","required":["error","message","code"],"properties":{"error":{"type":"string","description":"Error category: `validation_error`, `unauthorized`, `forbidden`, `not_found`, `conflict`, `rate_limited`, `server_error`, or `service_unavailable`."},"message":{"type":"string","description":"Human-readable explanation, safe to show to end users."},"code":{"type":"string","description":"Stable machine-readable code in `CATEGORY_NNN` form (e.g. `NOT_FOUND_006`, `AUTH_010`, `GEN_002`)."},"request_id":{"type":"string","description":"Correlation id for support requests. Echoes the `x-request-id` request header when one was supplied."},"errors":{"type":"object","additionalProperties":{"type":"string"},"description":"Field-level validation messages keyed by field name. Present on 400/422 validation failures only."}}}},"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"API Token","description":"API token authentication. Format: `Bearer dz_...`"}}},"security":[{"BearerAuth":[]}]}