{"openapi":"3.1.0","info":{"title":"POST /api/v1/webhooks/esign","version":"1.0.0","description":"E-signature provider webhook"},"servers":[{"url":"https://api.ondayzero.com","description":"Production"}],"paths":{"/api/v1/webhooks/esign":{"post":{"tags":["orders-esign"],"summary":"E-signature provider webhook","description":"Inbound envelope-event receiver for the e-signature provider (DocuSign Connect). Deliveries are authenticated by HMAC-SHA256 signature over the raw body; unsigned or mis-signed deliveries get 403. Envelope `completed` marks the order signed; `declined` and `voided` are recorded. Redeliveries are idempotent.","operationId":"esign_webhook","responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ESignWebhookAck"}}}},"400":{"description":"Bad Request - Invalid input","content":{"application/json":{"example":{"error":"validation_error","message":"Validation failed: due_date: Input should be a valid date","errors":{"due_date":"Input should be a valid date"},"code":"GEN_002","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"},"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"403":{"description":"Forbidden - Insufficient permissions","content":{"application/json":{"example":{"error":"forbidden","message":"You don't have permission to access this resource","code":"AUTH_002","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"},"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}}},"x-fastapi-operation-id":"esign_webhook_api_v1_webhooks_esign_post"}}},"components":{"schemas":{"ESignWebhookAck":{"properties":{"status":{"type":"string","title":"Status","description":"processed, duplicate, or ignored."},"envelope_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Envelope Id"}},"type":"object","required":["status"],"title":"ESignWebhookAck","description":"Acknowledgement returned to the e-signature provider's webhook."},"ErrorResponse":{"title":"ErrorResponse","type":"object","description":"Envelope returned by every non-2xx response. Branch on `code` (stable) rather than `message` (human-readable, may change).","required":["error","message","code"],"properties":{"error":{"type":"string","description":"Error category: `validation_error`, `unauthorized`, `forbidden`, `not_found`, `conflict`, `rate_limited`, `server_error`, or `service_unavailable`."},"message":{"type":"string","description":"Human-readable explanation, safe to show to end users."},"code":{"type":"string","description":"Stable machine-readable code in `CATEGORY_NNN` form (e.g. `NOT_FOUND_006`, `AUTH_010`, `GEN_002`)."},"request_id":{"type":"string","description":"Correlation id for support requests. Echoes the `x-request-id` request header when one was supplied."},"errors":{"type":"object","additionalProperties":{"type":"string"},"description":"Field-level validation messages keyed by field name. Present on 400/422 validation failures only."}}}},"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"API Token","description":"API token authentication. Format: `Bearer dz_...`"}}},"security":[{"BearerAuth":[]}]}