{
  "openapi": "3.1.0",
  "info": {
    "title": "Tokoserver Agent Read API",
    "version": "1.0.0",
    "description": "Read-only agent API. OAuth authorization code with PKCE is configured at /api/v1/sso/config. Device authorization and deployment creation are unavailable."
  },
  "servers": [
    {
      "url": "https://api.tokoserver.com"
    }
  ],
  "components": {
    "securitySchemes": {
      "hydraAccessToken": {
        "type": "http",
        "scheme": "bearer",
        "description": "Hydra OAuth access token granted to a registered public client with PKCE S256. Scopes are enforced per operation."
      }
    },
    "schemas": {
      "Error": {
        "type": "object",
        "required": [
          "error"
        ],
        "properties": {
          "error": {
            "type": "object",
            "required": [
              "code",
              "message",
              "retryable"
            ],
            "properties": {
              "code": {
                "type": "string"
              },
              "message": {
                "type": "string"
              },
              "retryable": {
                "type": "boolean"
              }
            }
          }
        }
      },
      "Application": {
        "type": "object",
        "required": [
          "id",
          "name",
          "status",
          "repositoryFullName",
          "branch",
          "createdAt"
        ],
        "properties": {
          "id": {
            "type": "string",
            "format": "uuid"
          },
          "name": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "repositoryFullName": {
            "type": "string"
          },
          "branch": {
            "type": "string"
          },
          "deploymentUrl": {
            "type": [
              "string",
              "null"
            ]
          },
          "createdAt": {
            "type": "string",
            "format": "date-time"
          }
        }
      },
      "Deployment": {
        "type": "object",
        "required": [
          "id",
          "application_id",
          "status",
          "created_at",
          "started_at",
          "completed_at",
          "application_url"
        ],
        "properties": {
          "id": {
            "type": "string",
            "format": "uuid"
          },
          "application_id": {
            "type": "string",
            "format": "uuid"
          },
          "status": {
            "type": "string",
            "enum": [
              "Pending",
              "Cloning",
              "Building",
              "Deploying",
              "Success",
              "Failed",
              "Timeout",
              "Stopped",
              "Stopping",
              "Starting"
            ]
          },
          "created_at": {
            "type": "string",
            "format": "date-time"
          },
          "started_at": {
            "type": [
              "string",
              "null"
            ],
            "format": "date-time"
          },
          "completed_at": {
            "type": [
              "string",
              "null"
            ],
            "format": "date-time"
          },
          "application_url": {
            "type": [
              "string",
              "null"
            ]
          }
        }
      }
    },
    "responses": {
      "Unauthorized": {
        "description": "Invalid or expired token",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/Error"
            }
          }
        }
      },
      "Forbidden": {
        "description": "Missing scope, membership, IAM permission, or organization mismatch",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/Error"
            }
          }
        }
      },
      "NotFound": {
        "description": "Resource not found",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/Error"
            }
          }
        }
      },
      "RateLimited": {
        "description": "Read API rate limit exceeded; obey Retry-After",
        "headers": {
          "Retry-After": {
            "schema": {
              "type": "string"
            }
          }
        },
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/Error"
            }
          }
        }
      },
      "Unavailable": {
        "description": "Authorization provider unavailable",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/Error"
            }
          }
        }
      },
      "InternalError": {
        "description": "Agent API request failed",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/Error"
            }
          }
        }
      }
    }
  },
  "paths": {
    "/api/v1/agent/v1/applications": {
      "get": {
        "summary": "List accessible applications",
        "security": [
          {
            "hydraAccessToken": []
          }
        ],
        "description": "Requires application:read scope and deployment.projects.list IAM. Returns at most 100 most recent accessible projects.",
        "responses": {
          "200": {
            "description": "Applications",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "data"
                  ],
                  "properties": {
                    "data": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/Application"
                      }
                    }
                  }
                }
              }
            }
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "503": {
            "$ref": "#/components/responses/Unavailable"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/InternalError"
          }
        }
      }
    },
    "/api/v1/agent/v1/applications/{id}": {
      "get": {
        "summary": "Read application metadata",
        "security": [
          {
            "hydraAccessToken": []
          }
        ],
        "description": "Requires application:read scope and deployment.projects.get IAM for the application.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Application",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "data"
                  ],
                  "properties": {
                    "data": {
                      "$ref": "#/components/schemas/Application"
                    }
                  }
                }
              }
            }
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "404": {
            "$ref": "#/components/responses/NotFound"
          },
          "503": {
            "$ref": "#/components/responses/Unavailable"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/InternalError"
          }
        }
      }
    },
    "/api/v1/agent/v1/deployments/{id}": {
      "get": {
        "summary": "Read deployment status",
        "security": [
          {
            "hydraAccessToken": []
          }
        ],
        "description": "Requires deployment:read scope and deployment.projects.get IAM for the parent application.",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Deployment",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "data"
                  ],
                  "properties": {
                    "data": {
                      "$ref": "#/components/schemas/Deployment"
                    }
                  }
                }
              }
            }
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "404": {
            "$ref": "#/components/responses/NotFound"
          },
          "503": {
            "$ref": "#/components/responses/Unavailable"
          },
          "429": {
            "$ref": "#/components/responses/RateLimited"
          },
          "500": {
            "$ref": "#/components/responses/InternalError"
          }
        }
      }
    },
    "/api/v1/agent/v1/capabilities": {
      "get": {
        "summary": "Discover agent API capabilities",
        "description": "Public availability for this version of the agent API.",
        "security": [],
        "responses": {
          "200": {
            "description": "Supported and unavailable operations",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "version",
                    "authentication",
                    "operations",
                    "unavailable"
                  ],
                  "properties": {
                    "version": {
                      "type": "string"
                    },
                    "authentication": {
                      "type": "array",
                      "items": {
                        "type": "string"
                      }
                    },
                    "operations": {
                      "type": "array",
                      "items": {
                        "type": "string"
                      }
                    },
                    "unavailable": {
                      "type": "array",
                      "items": {
                        "type": "string"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  }
}
