{
  "openapi": "3.1.0",
  "info": {
    "title": "Nauthilus Management API",
    "version": "v1",
    "description": "Contract for the stable protected machine-facing HTTP API subset. Dynamic custom hook aliases remain runtime configuration. Public IdP protocol and browser routes are documented by the public IdP contract.\n"
  },
  "servers": [
    {
      "url": "{baseUrl}",
      "description": "Nauthilus deployment base URL.",
      "variables": {
        "baseUrl": {
          "default": "https://nauthilus.example.com",
          "description": "Absolute base URL of the Nauthilus deployment to call."
        }
      }
    }
  ],
  "tags": [
    {
      "name": "OpenAPI",
      "x-displayName": "/api/v1/openapi",
      "description": "Embedded API contract documents."
    },
    {
      "name": "Authentication",
      "x-displayName": "/api/v1/auth",
      "description": "Structured authentication and account listing endpoints."
    },
    {
      "name": "BruteForce",
      "x-displayName": "/api/v1/bruteforce",
      "description": "Backchannel brute-force administration endpoints."
    },
    {
      "name": "Cache",
      "x-displayName": "/api/v1/cache",
      "description": "Backchannel cache administration endpoints."
    },
    {
      "name": "Config",
      "x-displayName": "/api/v1/config",
      "description": "Backchannel configuration inspection endpoint."
    },
    {
      "name": "Async",
      "x-displayName": "/api/v1/async",
      "description": "Asynchronous backchannel job status endpoint."
    },
    {
      "name": "MFA",
      "x-displayName": "/api/v1/mfa",
      "description": "Session-bound MFA management endpoints."
    },
    {
      "name": "OIDCSessions",
      "x-displayName": "/api/v1/oidc/sessions",
      "description": "Backchannel OIDC session administration endpoints."
    },
    {
      "name": "Policy",
      "x-displayName": "/api/v1/policy/decisions",
      "description": "Unary Policy decision evaluation endpoint."
    },
    {
      "name": "Reputation",
      "x-displayName": "/api/v1/custom/reputation",
      "description": "Optional authenticated native reputation administration."
    }
  ],
  "paths": {
    "/api/v1/custom/reputation/allocation": {
      "post": {
        "tags": [
          "Reputation"
        ],
        "operationId": "manageReputationAllocation",
        "summary": "Inspect or fence the current allocation generation.",
        "description": "Requires backchannel bearer nauthilus:admin. Status reads the primary and all 16 shard fences without mutation. Drain requires audit fields and fences writers before starting the retained maximum event lifetime. Retry uses the identical audit fields and actor; a different in-progress change conflicts. After a process restart, allocation_maintenance must be explicitly enabled with the original key and generation to retain administration without activating writers. Status and retry remain available while writers are unready. Do not rotate before every shard is fenced and observed_at is at least drained_at plus retention. This API never changes keys, generations, retention or learned evidence.",
        "security": [
          {
            "backchannelBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ReputationAllocationRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Verified current generation, shard fences and optional durable operator receipt.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationAllocationView"
                }
              }
            }
          },
          "400": {
            "description": "Invalid or duplicate fields, unsupported subject, or query parameters.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid backchannel access token.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "403": {
            "description": "Administrative authority or suitable authenticated actor missing.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "404": {
            "description": "Reputation plugin or custom hook surface unavailable.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "409": {
            "description": "Selected override revision changed; read current state before retrying.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "413": {
            "description": "Body exceeds 4096 bytes.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "415": {
            "description": "Expected application/json.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "500": {
            "description": "Host execution failed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "503": {
            "description": "Primary state or verified readback unavailable; a mutation outcome may be unknown.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "504": {
            "description": "Management timeout; inspect current state before retrying.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          }
        }
      }
    },
    "/api/v1/custom/reputation/lookup": {
      "post": {
        "tags": [
          "Reputation"
        ],
        "operationId": "lookupReputation",
        "summary": "Inspect one exact reputation subject.",
        "description": "Optional native reputation management endpoint. Requires a backchannel access token with nauthilus:admin, even when additional hook scopes are configured. Subjects are accepted only in the JSON body; enumeration and query parameters are prohibited. Actor identity is host-derived and cannot be supplied in the body. Reads use primary Redis and conservative active/previous key merging. Override changes target one named slot; they do not erase other slots or learned evidence. The latest per-slot operator receipt is retained for 90 days; this is not a complete audit history.",
        "security": [
          {
            "backchannelBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ReputationLookupRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Sanitized primary-backed state. Mutation success includes the independently verified change receipt.",
            "headers": {
              "Cache-Control": {
                "schema": {
                  "type": "string",
                  "const": "no-store"
                }
              }
            },
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationView"
                }
              }
            }
          },
          "400": {
            "description": "Invalid or duplicate fields, unsupported subject, or query parameters.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid backchannel access token.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "403": {
            "description": "Administrative authority or suitable authenticated actor missing.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "404": {
            "description": "Reputation plugin or custom hook surface unavailable.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "409": {
            "description": "Selected override revision changed; read current state before retrying.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "413": {
            "description": "Body exceeds 4096 bytes.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "415": {
            "description": "Expected application/json.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "500": {
            "description": "Host execution failed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "503": {
            "description": "Primary state or verified readback unavailable; a mutation outcome may be unknown.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "504": {
            "description": "Management timeout; inspect current state before retrying.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          }
        }
      }
    },
    "/api/v1/custom/reputation/override": {
      "put": {
        "tags": [
          "Reputation"
        ],
        "operationId": "putReputationOverride",
        "summary": "Create or replace one audited operator override.",
        "description": "Optional native reputation management endpoint. Requires a backchannel access token with nauthilus:admin, even when additional hook scopes are configured. Subjects are accepted only in the JSON body; enumeration and query parameters are prohibited. Actor identity is host-derived and cannot be supplied in the body. Reads use primary Redis and conservative active/previous key merging. Override changes target one named slot; they do not erase other slots or learned evidence. The latest per-slot operator receipt is retained for 90 days; this is not a complete audit history.",
        "security": [
          {
            "backchannelBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ReputationOverridePutRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Sanitized primary-backed state. Mutation success includes the independently verified change receipt.",
            "headers": {
              "Cache-Control": {
                "schema": {
                  "type": "string",
                  "const": "no-store"
                }
              }
            },
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationView"
                }
              }
            }
          },
          "400": {
            "description": "Invalid or duplicate fields, unsupported subject, or query parameters.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid backchannel access token.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "403": {
            "description": "Administrative authority or suitable authenticated actor missing.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "404": {
            "description": "Reputation plugin or custom hook surface unavailable.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "409": {
            "description": "Selected override revision changed; read current state before retrying.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "413": {
            "description": "Body exceeds 4096 bytes.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "415": {
            "description": "Expected application/json.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "500": {
            "description": "Host execution failed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "503": {
            "description": "Primary state or verified readback unavailable; a mutation outcome may be unknown.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "504": {
            "description": "Management timeout; inspect current state before retrying.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          }
        }
      },
      "delete": {
        "tags": [
          "Reputation"
        ],
        "operationId": "deleteReputationOverride",
        "summary": "Remove one selected operator override revision.",
        "description": "Optional native reputation management endpoint. Requires a backchannel access token with nauthilus:admin, even when additional hook scopes are configured. Subjects are accepted only in the JSON body; enumeration and query parameters are prohibited. Actor identity is host-derived and cannot be supplied in the body. Reads use primary Redis and conservative active/previous key merging. Override changes target one named slot; they do not erase other slots or learned evidence. The latest per-slot operator receipt is retained for 90 days; this is not a complete audit history.",
        "security": [
          {
            "backchannelBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ReputationOverrideDeleteRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Sanitized primary-backed state. Mutation success includes the independently verified change receipt.",
            "headers": {
              "Cache-Control": {
                "schema": {
                  "type": "string",
                  "const": "no-store"
                }
              }
            },
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationView"
                }
              }
            }
          },
          "400": {
            "description": "Invalid or duplicate fields, unsupported subject, or query parameters.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid backchannel access token.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "403": {
            "description": "Administrative authority or suitable authenticated actor missing.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "404": {
            "description": "Reputation plugin or custom hook surface unavailable.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "409": {
            "description": "Selected override revision changed; read current state before retrying.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "413": {
            "description": "Body exceeds 4096 bytes.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "415": {
            "description": "Expected application/json.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "500": {
            "description": "Host execution failed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "503": {
            "description": "Primary state or verified readback unavailable; a mutation outcome may be unknown.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          },
          "504": {
            "description": "Management timeout; inspect current state before retrying.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ReputationManagementError"
                }
              }
            }
          }
        }
      }
    },
    "/api/v1/policy/decisions": {
      "post": {
        "tags": [
          "Policy"
        ],
        "operationId": "evaluatePolicyDecision",
        "summary": "Evaluate one Policy decision.",
        "description": "Evaluates exactly one admitted Policy request. Responses are never cacheable and do not expose retry, replay, cache, or outcome-reporting controls.\n",
        "security": [
          {
            "policyBearer": []
          },
          {
            "policyBasic": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/PolicyDecisionRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/PolicyDecision"
          },
          "400": {
            "$ref": "#/components/responses/PolicyBadRequest"
          },
          "401": {
            "$ref": "#/components/responses/PolicyUnauthorized"
          },
          "403": {
            "$ref": "#/components/responses/PolicyForbidden"
          },
          "413": {
            "$ref": "#/components/responses/PolicyRequestTooLarge"
          },
          "415": {
            "$ref": "#/components/responses/PolicyUnsupportedMediaType"
          },
          "429": {
            "$ref": "#/components/responses/PolicyRateLimited"
          },
          "503": {
            "$ref": "#/components/responses/PolicyUnavailable"
          }
        }
      }
    },
    "/api/v1/openapi.yaml": {
      "get": {
        "tags": [
          "OpenAPI"
        ],
        "operationId": "getOpenAPIYAML",
        "summary": "Get the OpenAPI document as YAML.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "responses": {
          "200": {
            "description": "OpenAPI document in YAML format.",
            "content": {
              "application/yaml": {
                "schema": {
                  "type": "string"
                }
              }
            }
          }
        }
      }
    },
    "/api/v1/openapi.json": {
      "get": {
        "tags": [
          "OpenAPI"
        ],
        "operationId": "getOpenAPIJSON",
        "summary": "Get the OpenAPI document as JSON.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "responses": {
          "200": {
            "description": "OpenAPI document in JSON format.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          }
        }
      }
    },
    "/api/v1/auth/json": {
      "get": {
        "tags": [
          "Authentication"
        ],
        "operationId": "getJSONAuth",
        "summary": "Run the JSON authentication endpoint without a JSON body.",
        "description": "The GET form is primarily used for account listing or no-auth probes via the mode query parameter.\n",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/AuthMode"
          },
          {
            "$ref": "#/components/parameters/InMemoryFlag"
          },
          {
            "$ref": "#/components/parameters/CacheFlag"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/AuthJSONSuccess"
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "415": {
            "$ref": "#/components/responses/UnsupportedMediaType"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      },
      "post": {
        "tags": [
          "Authentication"
        ],
        "operationId": "postJSONAuth",
        "summary": "Authenticate with a strict JSON request body.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/AuthMode"
          },
          {
            "$ref": "#/components/parameters/InMemoryFlag"
          },
          {
            "$ref": "#/components/parameters/CacheFlag"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/AuthRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/AuthJSONSuccess"
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "415": {
            "$ref": "#/components/responses/UnsupportedMediaType"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      }
    },
    "/api/v1/auth/cbor": {
      "get": {
        "tags": [
          "Authentication"
        ],
        "operationId": "getCBORAuth",
        "summary": "Run the CBOR authentication endpoint without a CBOR body.",
        "description": "The GET form is primarily used for account listing or no-auth probes via the mode query parameter. List-account responses negotiate the response content type from the Accept header.\n",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/AuthMode"
          },
          {
            "$ref": "#/components/parameters/InMemoryFlag"
          },
          {
            "$ref": "#/components/parameters/CacheFlag"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/AuthCBORSuccess"
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "415": {
            "$ref": "#/components/responses/UnsupportedMediaType"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      },
      "post": {
        "tags": [
          "Authentication"
        ],
        "operationId": "postCBORAuth",
        "summary": "Authenticate with a strict CBOR request body.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/AuthMode"
          },
          {
            "$ref": "#/components/parameters/InMemoryFlag"
          },
          {
            "$ref": "#/components/parameters/CacheFlag"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/cbor": {
              "schema": {
                "$ref": "#/components/schemas/AuthRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "$ref": "#/components/responses/AuthCBORSuccess"
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "415": {
            "$ref": "#/components/responses/UnsupportedMediaType"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      }
    },
    "/api/v1/auth/header": {
      "get": {
        "tags": [
          "Authentication"
        ],
        "operationId": "getHeaderAuth",
        "summary": "Authenticate using configured HTTP request headers.",
        "description": "Reads credentials and connection metadata from configured request headers. The default header names are documented as parameters; they can be changed through the Nauthilus runtime configuration.\n",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/AuthMode"
          },
          {
            "$ref": "#/components/parameters/InMemoryFlag"
          },
          {
            "$ref": "#/components/parameters/CacheFlag"
          },
          {
            "$ref": "#/components/parameters/AuthUserHeader"
          },
          {
            "$ref": "#/components/parameters/AuthPassHeader"
          },
          {
            "$ref": "#/components/parameters/AuthPasswordEncodedHeader"
          },
          {
            "$ref": "#/components/parameters/AuthProtocolHeader"
          },
          {
            "$ref": "#/components/parameters/AuthMethodHeader"
          },
          {
            "$ref": "#/components/parameters/AuthLoginAttemptHeader"
          },
          {
            "$ref": "#/components/parameters/ClientIPHeader"
          },
          {
            "$ref": "#/components/parameters/ClientPortHeader"
          },
          {
            "$ref": "#/components/parameters/ClientIDHeader"
          },
          {
            "$ref": "#/components/parameters/ClientHostHeader"
          },
          {
            "$ref": "#/components/parameters/ExternalSessionIDHeader"
          },
          {
            "$ref": "#/components/parameters/LocalIPHeader"
          },
          {
            "$ref": "#/components/parameters/LocalPortHeader"
          },
          {
            "$ref": "#/components/parameters/OIDCCIDHeader"
          },
          {
            "$ref": "#/components/parameters/SSLHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSessionIDHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientVerifyHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientCNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLIssuerHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientNotBeforeHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientNotAfterHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSubjectDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLIssuerDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientSubjectDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientIssuerDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLCipherHeader"
          },
          {
            "$ref": "#/components/parameters/SSLProtocolHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSerialHeader"
          },
          {
            "$ref": "#/components/parameters/SSLFingerprintHeader"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/AuthHeaderSuccess"
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/AuthHeaderFailure"
          },
          "404": {
            "$ref": "#/components/responses/NotFound"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      },
      "post": {
        "tags": [
          "Authentication"
        ],
        "operationId": "postHeaderAuth",
        "summary": "Authenticate using configured HTTP request headers.",
        "description": "POST form mirrors the GET form for integrations that submit auth checks with POST while still carrying credentials and metadata in request headers.\n",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/AuthMode"
          },
          {
            "$ref": "#/components/parameters/InMemoryFlag"
          },
          {
            "$ref": "#/components/parameters/CacheFlag"
          },
          {
            "$ref": "#/components/parameters/AuthUserHeader"
          },
          {
            "$ref": "#/components/parameters/AuthPassHeader"
          },
          {
            "$ref": "#/components/parameters/AuthPasswordEncodedHeader"
          },
          {
            "$ref": "#/components/parameters/AuthProtocolHeader"
          },
          {
            "$ref": "#/components/parameters/AuthMethodHeader"
          },
          {
            "$ref": "#/components/parameters/AuthLoginAttemptHeader"
          },
          {
            "$ref": "#/components/parameters/ClientIPHeader"
          },
          {
            "$ref": "#/components/parameters/ClientPortHeader"
          },
          {
            "$ref": "#/components/parameters/ClientIDHeader"
          },
          {
            "$ref": "#/components/parameters/ClientHostHeader"
          },
          {
            "$ref": "#/components/parameters/ExternalSessionIDHeader"
          },
          {
            "$ref": "#/components/parameters/LocalIPHeader"
          },
          {
            "$ref": "#/components/parameters/LocalPortHeader"
          },
          {
            "$ref": "#/components/parameters/OIDCCIDHeader"
          },
          {
            "$ref": "#/components/parameters/SSLHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSessionIDHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientVerifyHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientCNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLIssuerHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientNotBeforeHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientNotAfterHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSubjectDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLIssuerDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientSubjectDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientIssuerDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLCipherHeader"
          },
          {
            "$ref": "#/components/parameters/SSLProtocolHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSerialHeader"
          },
          {
            "$ref": "#/components/parameters/SSLFingerprintHeader"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/AuthHeaderSuccess"
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/AuthHeaderFailure"
          },
          "404": {
            "$ref": "#/components/responses/NotFound"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      }
    },
    "/api/v1/auth/nginx": {
      "get": {
        "tags": [
          "Authentication"
        ],
        "operationId": "getNginxAuth",
        "summary": "Authenticate an NGINX auth_http request.",
        "description": "Reads NGINX mail auth_http-compatible headers and returns the decision through Auth-* response headers. NGINX mode intentionally returns HTTP 200 for authentication failures and communicates the result via Auth-Status.\n",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/AuthMode"
          },
          {
            "$ref": "#/components/parameters/InMemoryFlag"
          },
          {
            "$ref": "#/components/parameters/CacheFlag"
          },
          {
            "$ref": "#/components/parameters/AuthUserHeader"
          },
          {
            "$ref": "#/components/parameters/AuthPassHeader"
          },
          {
            "$ref": "#/components/parameters/AuthPasswordEncodedHeader"
          },
          {
            "$ref": "#/components/parameters/AuthProtocolHeader"
          },
          {
            "$ref": "#/components/parameters/AuthMethodHeader"
          },
          {
            "$ref": "#/components/parameters/AuthLoginAttemptHeader"
          },
          {
            "$ref": "#/components/parameters/ClientIPHeader"
          },
          {
            "$ref": "#/components/parameters/ClientPortHeader"
          },
          {
            "$ref": "#/components/parameters/ClientIDHeader"
          },
          {
            "$ref": "#/components/parameters/ClientHostHeader"
          },
          {
            "$ref": "#/components/parameters/ExternalSessionIDHeader"
          },
          {
            "$ref": "#/components/parameters/LocalIPHeader"
          },
          {
            "$ref": "#/components/parameters/LocalPortHeader"
          },
          {
            "$ref": "#/components/parameters/OIDCCIDHeader"
          },
          {
            "$ref": "#/components/parameters/SSLHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSessionIDHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientVerifyHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientCNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLIssuerHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientNotBeforeHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientNotAfterHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSubjectDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLIssuerDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientSubjectDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientIssuerDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLCipherHeader"
          },
          {
            "$ref": "#/components/parameters/SSLProtocolHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSerialHeader"
          },
          {
            "$ref": "#/components/parameters/SSLFingerprintHeader"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/AuthNginxResult"
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "404": {
            "$ref": "#/components/responses/NotFound"
          }
        }
      },
      "post": {
        "tags": [
          "Authentication"
        ],
        "operationId": "postNginxAuth",
        "summary": "Authenticate an NGINX auth_http request.",
        "description": "POST form mirrors the GET form for deployments that submit NGINX auth checks with POST while still carrying credentials and metadata in request headers.\n",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/AuthMode"
          },
          {
            "$ref": "#/components/parameters/InMemoryFlag"
          },
          {
            "$ref": "#/components/parameters/CacheFlag"
          },
          {
            "$ref": "#/components/parameters/AuthUserHeader"
          },
          {
            "$ref": "#/components/parameters/AuthPassHeader"
          },
          {
            "$ref": "#/components/parameters/AuthPasswordEncodedHeader"
          },
          {
            "$ref": "#/components/parameters/AuthProtocolHeader"
          },
          {
            "$ref": "#/components/parameters/AuthMethodHeader"
          },
          {
            "$ref": "#/components/parameters/AuthLoginAttemptHeader"
          },
          {
            "$ref": "#/components/parameters/ClientIPHeader"
          },
          {
            "$ref": "#/components/parameters/ClientPortHeader"
          },
          {
            "$ref": "#/components/parameters/ClientIDHeader"
          },
          {
            "$ref": "#/components/parameters/ClientHostHeader"
          },
          {
            "$ref": "#/components/parameters/ExternalSessionIDHeader"
          },
          {
            "$ref": "#/components/parameters/LocalIPHeader"
          },
          {
            "$ref": "#/components/parameters/LocalPortHeader"
          },
          {
            "$ref": "#/components/parameters/OIDCCIDHeader"
          },
          {
            "$ref": "#/components/parameters/SSLHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSessionIDHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientVerifyHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientCNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLIssuerHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientNotBeforeHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientNotAfterHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSubjectDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLIssuerDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientSubjectDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLClientIssuerDNHeader"
          },
          {
            "$ref": "#/components/parameters/SSLCipherHeader"
          },
          {
            "$ref": "#/components/parameters/SSLProtocolHeader"
          },
          {
            "$ref": "#/components/parameters/SSLSerialHeader"
          },
          {
            "$ref": "#/components/parameters/SSLFingerprintHeader"
          }
        ],
        "responses": {
          "200": {
            "$ref": "#/components/responses/AuthNginxResult"
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "404": {
            "$ref": "#/components/responses/NotFound"
          }
        }
      }
    },
    "/api/v1/bruteforce/list": {
      "get": {
        "tags": [
          "BruteForce"
        ],
        "operationId": "listBruteForceEntries",
        "summary": "List active brute-force bans and blocked accounts.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/PageLimit"
          },
          {
            "$ref": "#/components/parameters/PageOffset"
          }
        ],
        "responses": {
          "200": {
            "description": "Brute-force list result.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/BruteForceListResult"
                }
              }
            }
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      },
      "post": {
        "tags": [
          "BruteForce"
        ],
        "operationId": "listFilteredBruteForceEntries",
        "summary": "List active brute-force data with optional account and IP filters.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/PageLimit"
          },
          {
            "$ref": "#/components/parameters/PageOffset"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/BruteForceFilterRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Brute-force list result.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/BruteForceListResult"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      }
    },
    "/api/v1/bruteforce/flush": {
      "delete": {
        "tags": [
          "BruteForce"
        ],
        "operationId": "flushBruteForceRule",
        "summary": "Flush brute-force data for a configured rule.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/BruteForceFlushRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Brute-force flush result.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/BruteForceFlushResult"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      }
    },
    "/api/v1/bruteforce/flush/async": {
      "delete": {
        "tags": [
          "BruteForce"
        ],
        "operationId": "enqueueBruteForceRuleFlush",
        "summary": "Enqueue an asynchronous brute-force rule flush.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/BruteForceFlushRequest"
              }
            }
          }
        },
        "responses": {
          "202": {
            "$ref": "#/components/responses/AsyncAccepted"
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      }
    },
    "/api/v1/cache/flush": {
      "delete": {
        "tags": [
          "Cache"
        ],
        "operationId": "flushUserCache",
        "summary": "Flush authentication cache entries for a user.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CacheFlushRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Cache flush result.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/CacheFlushResult"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      }
    },
    "/api/v1/cache/flush/async": {
      "delete": {
        "tags": [
          "Cache"
        ],
        "operationId": "enqueueUserCacheFlush",
        "summary": "Enqueue an asynchronous user cache flush.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CacheFlushRequest"
              }
            }
          }
        },
        "responses": {
          "202": {
            "$ref": "#/components/responses/AsyncAccepted"
          },
          "400": {
            "$ref": "#/components/responses/JSONValidationError"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      }
    },
    "/api/v1/async/jobs/{jobId}": {
      "get": {
        "tags": [
          "Async"
        ],
        "operationId": "getAsyncJobStatus",
        "summary": "Get the status of an asynchronous backchannel job.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "name": "jobId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Async job status.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AsyncJobStatusResult"
                }
              }
            }
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "404": {
            "$ref": "#/components/responses/NotFound"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      }
    },
    "/api/v1/oidc/sessions/{user_id}": {
      "get": {
        "tags": [
          "OIDCSessions"
        ],
        "operationId": "listOIDCSessions",
        "summary": "List active OIDC sessions for a user.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "name": "user_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Active sessions without raw token material.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/OIDCSessions"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/Error"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      },
      "delete": {
        "tags": [
          "OIDCSessions"
        ],
        "operationId": "deleteOIDCSessions",
        "summary": "Delete all OIDC sessions for a user.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "name": "user_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "All sessions were deleted."
          },
          "400": {
            "$ref": "#/components/responses/Error"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      }
    },
    "/api/v1/oidc/sessions/{user_id}/{token}": {
      "delete": {
        "tags": [
          "OIDCSessions"
        ],
        "operationId": "deleteOIDCSession",
        "summary": "Delete one OIDC session for a user.",
        "security": [
          {
            "backchannelBasic": []
          },
          {
            "backchannelBearer": []
          }
        ],
        "parameters": [
          {
            "name": "user_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "token",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "204": {
            "description": "Session was deleted."
          },
          "400": {
            "$ref": "#/components/responses/Error"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          },
          "403": {
            "$ref": "#/components/responses/Forbidden"
          },
          "500": {
            "$ref": "#/components/responses/Error"
          }
        }
      }
    }
  },
  "components": {
    "securitySchemes": {
      "policyBasic": {
        "type": "http",
        "scheme": "basic",
        "description": "Dedicated Policy client credentials; never management Basic credentials."
      },
      "policyBearer": {
        "type": "http",
        "scheme": "bearer",
        "bearerFormat": "JWT",
        "description": "Policy-resource Bearer token with nauthilus:policy_evaluate scope."
      },
      "backchannelBasic": {
        "type": "http",
        "scheme": "basic",
        "description": "Backchannel Basic authentication."
      },
      "backchannelBearer": {
        "type": "http",
        "scheme": "bearer",
        "bearerFormat": "JWT",
        "description": "Backchannel OIDC bearer token. Some admin endpoints require security or admin scope."
      }
    },
    "parameters": {
      "AuthMode": {
        "name": "mode",
        "in": "query",
        "required": false,
        "schema": {
          "type": "string",
          "enum": [
            "no-auth",
            "list-accounts"
          ]
        },
        "description": "Optional authentication operation mode."
      },
      "InMemoryFlag": {
        "name": "in-memory",
        "in": "query",
        "required": false,
        "schema": {
          "type": "string",
          "enum": [
            "0"
          ]
        },
        "description": "Disable in-memory monitoring for this request when set to 0."
      },
      "CacheFlag": {
        "name": "cache",
        "in": "query",
        "required": false,
        "schema": {
          "type": "string",
          "enum": [
            "0"
          ]
        },
        "description": "Disable cache monitoring for this request when set to 0."
      },
      "AuthUserHeader": {
        "name": "Auth-User",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Username header. Required for authentication unless mode is no-auth or list-accounts."
      },
      "AuthPassHeader": {
        "name": "Auth-Pass",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string",
          "format": "password"
        },
        "description": "Password header. The configured header is removed from the request after it is read."
      },
      "AuthPasswordEncodedHeader": {
        "name": "X-Auth-Password-Encoded",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string",
          "enum": [
            "1"
          ]
        },
        "description": "Set to 1 when Auth-Pass carries URL-safe base64 encoded password bytes."
      },
      "AuthProtocolHeader": {
        "name": "Auth-Protocol",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string",
          "enum": [
            "smtp",
            "imap",
            "pop3"
          ]
        },
        "description": "Mail protocol of the upstream authentication attempt."
      },
      "AuthMethodHeader": {
        "name": "Auth-Method",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Authentication mechanism such as LOGIN or PLAIN."
      },
      "AuthLoginAttemptHeader": {
        "name": "Auth-Login-Attempt",
        "in": "header",
        "required": false,
        "schema": {
          "type": "integer",
          "minimum": 0
        },
        "description": "One-based login attempt hint from the caller."
      },
      "ClientIPHeader": {
        "name": "Client-IP",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client source IP address."
      },
      "ClientPortHeader": {
        "name": "X-Client-Port",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client source TCP port."
      },
      "ClientIDHeader": {
        "name": "X-Client-ID",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Optional upstream client identifier."
      },
      "ClientHostHeader": {
        "name": "X-Client-Host",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Optional upstream client hostname."
      },
      "ExternalSessionIDHeader": {
        "name": "X-External-Session-ID",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Optional upstream session correlation identifier."
      },
      "LocalIPHeader": {
        "name": "X-Local-IP",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Local listener IP address."
      },
      "LocalPortHeader": {
        "name": "X-Auth-Port",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Local listener TCP port."
      },
      "OIDCCIDHeader": {
        "name": "X-OIDC-CID",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Optional OIDC client identifier associated with the request."
      },
      "PageLimit": {
        "name": "limit",
        "in": "query",
        "required": false,
        "schema": {
          "type": "integer",
          "minimum": 1,
          "maximum": 1000
        },
        "description": "Maximum number of records to return per brute-force list section."
      },
      "PageOffset": {
        "name": "offset",
        "in": "query",
        "required": false,
        "schema": {
          "type": "integer",
          "minimum": 0
        },
        "description": "Zero-based offset for brute-force list paging."
      },
      "SSLHeader": {
        "name": "X-SSL",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "SSL/TLS state hint from the caller."
      },
      "SSLSessionIDHeader": {
        "name": "X-SSL-Session-ID",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "SSL session identifier."
      },
      "SSLClientVerifyHeader": {
        "name": "X-SSL-Client-Verify",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client certificate verification status."
      },
      "SSLClientDNHeader": {
        "name": "X-SSL-Client-DN",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client certificate subject DN."
      },
      "SSLClientCNHeader": {
        "name": "X-SSL-Client-CN",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client certificate common name."
      },
      "SSLIssuerHeader": {
        "name": "X-SSL-Issuer",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client certificate issuer."
      },
      "SSLClientNotBeforeHeader": {
        "name": "X-SSL-Client-NotBefore",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client certificate validity start."
      },
      "SSLClientNotAfterHeader": {
        "name": "X-SSL-Client-NotAfter",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client certificate validity end."
      },
      "SSLSubjectDNHeader": {
        "name": "X-SSL-Subject-DN",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "SSL subject distinguished name."
      },
      "SSLIssuerDNHeader": {
        "name": "X-SSL-Issuer-DN",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "SSL issuer distinguished name."
      },
      "SSLClientSubjectDNHeader": {
        "name": "X-SSL-Client-Subject-DN",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client certificate subject distinguished name."
      },
      "SSLClientIssuerDNHeader": {
        "name": "X-SSL-Client-Issuer-DN",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client certificate issuer distinguished name."
      },
      "SSLCipherHeader": {
        "name": "X-SSL-Cipher",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "TLS cipher suite."
      },
      "SSLProtocolHeader": {
        "name": "X-SSL-Protocol",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "TLS protocol version."
      },
      "SSLSerialHeader": {
        "name": "Auth-SSL-Serial",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client certificate serial number."
      },
      "SSLFingerprintHeader": {
        "name": "Auth-SSL-Fingerprint",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Client certificate fingerprint."
      }
    },
    "responses": {
      "PolicyDecision": {
        "description": "Completed Policy evaluation, including an indeterminate effect when safe to construct.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/PolicyDecisionResponse"
            }
          }
        }
      },
      "PolicyBadRequest": {
        "description": "Strict JSON or public-field validation failed.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/PolicyError"
            }
          }
        }
      },
      "PolicyForbidden": {
        "description": "The authenticated Policy caller is not admitted for this request.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/PolicyError"
            }
          }
        }
      },
      "PolicyRequestTooLarge": {
        "description": "The request or a submitted value exceeded an admitted limit.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/PolicyError"
            }
          }
        }
      },
      "PolicyRateLimited": {
        "description": "The admitted client exceeded concurrency or rate limits.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/PolicyError"
            }
          }
        }
      },
      "PolicyUnauthorized": {
        "description": "Policy credentials are missing or invalid.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/PolicyError"
            }
          }
        }
      },
      "PolicyUnsupportedMediaType": {
        "description": "The Policy endpoint accepts application/json only.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/PolicyError"
            }
          }
        }
      },
      "PolicyUnavailable": {
        "description": "The Policy service was unavailable before evaluation began.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/PolicyError"
            }
          }
        }
      },
      "AuthHeaderFailure": {
        "description": "Header-mode authentication failure. The response body is JSON null; Auth-Status carries the status message.",
        "headers": {
          "Auth-Status": {
            "schema": {
              "type": "string"
            }
          },
          "Auth-Wait": {
            "schema": {
              "type": "string"
            }
          },
          "X-Nauthilus-Session": {
            "schema": {
              "type": "string"
            }
          }
        },
        "content": {
          "application/json": {
            "schema": {
              "type": "null"
            }
          }
        }
      },
      "AuthHeaderSuccess": {
        "description": "Header-mode authentication result. Successful requests return headers such as Auth-Status, Auth-User, X-Nauthilus-Session, and dynamic X-Nauthilus-* attribute headers.\n",
        "headers": {
          "Auth-Status": {
            "schema": {
              "type": "string"
            }
          },
          "Auth-User": {
            "schema": {
              "type": "string"
            }
          },
          "X-Nauthilus-Memory-Cache": {
            "schema": {
              "type": "string",
              "enum": [
                "Hit",
                "Miss"
              ]
            }
          },
          "X-Nauthilus-Session": {
            "schema": {
              "type": "string"
            }
          }
        }
      },
      "AuthNginxResult": {
        "description": "NGINX auth_http result. HTTP status is 200 for both success and authentication failure; Auth-Status carries OK or the failure message.\n",
        "headers": {
          "Auth-Status": {
            "schema": {
              "type": "string"
            }
          },
          "Auth-User": {
            "schema": {
              "type": "string"
            }
          },
          "Auth-Server": {
            "schema": {
              "type": "string"
            }
          },
          "Auth-Port": {
            "schema": {
              "type": "string"
            }
          },
          "Auth-Wait": {
            "schema": {
              "type": "string"
            }
          },
          "Auth-Error-Code": {
            "schema": {
              "type": "string"
            }
          },
          "X-Nauthilus-Memory-Cache": {
            "schema": {
              "type": "string",
              "enum": [
                "Hit",
                "Miss"
              ]
            }
          },
          "X-Nauthilus-Session": {
            "schema": {
              "type": "string"
            }
          }
        },
        "content": {
          "application/json": {
            "schema": {
              "type": "null"
            }
          }
        }
      },
      "AuthJSONSuccess": {
        "description": "Authentication result, account list, or no-auth result.",
        "headers": {
          "Auth-Status": {
            "schema": {
              "type": "string"
            }
          },
          "X-Nauthilus-Session": {
            "schema": {
              "type": "string"
            }
          }
        },
        "content": {
          "application/json": {
            "schema": {
              "oneOf": [
                {
                  "$ref": "#/components/schemas/AuthSuccess"
                },
                {
                  "$ref": "#/components/schemas/AuthError"
                },
                {
                  "$ref": "#/components/schemas/AccountList"
                }
              ]
            }
          },
          "text/plain": {
            "schema": {
              "type": "string"
            }
          },
          "application/x-www-form-urlencoded": {
            "schema": {
              "type": "string"
            }
          }
        }
      },
      "AuthCBORSuccess": {
        "description": "Authentication result, account list, or no-auth result.",
        "headers": {
          "Auth-Status": {
            "schema": {
              "type": "string"
            }
          },
          "X-Nauthilus-Session": {
            "schema": {
              "type": "string"
            }
          }
        },
        "content": {
          "application/cbor": {
            "schema": {
              "oneOf": [
                {
                  "$ref": "#/components/schemas/AuthSuccess"
                },
                {
                  "$ref": "#/components/schemas/AuthError"
                },
                {
                  "$ref": "#/components/schemas/AccountList"
                }
              ]
            }
          },
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/AccountList"
            }
          },
          "text/plain": {
            "schema": {
              "type": "string"
            }
          },
          "application/x-www-form-urlencoded": {
            "schema": {
              "type": "string"
            }
          }
        }
      },
      "AsyncAccepted": {
        "description": "Async job was queued.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/AsyncAcceptedResult"
            }
          }
        }
      },
      "Error": {
        "description": "Error response.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/ErrorResponse"
            }
          }
        }
      },
      "Forbidden": {
        "description": "Request is authenticated but lacks the required scope.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/ErrorResponse"
            }
          }
        }
      },
      "JSONValidationError": {
        "description": "Invalid JSON or request validation failure.",
        "content": {
          "application/json": {
            "schema": {
              "oneOf": [
                {
                  "$ref": "#/components/schemas/ErrorResponse"
                },
                {
                  "$ref": "#/components/schemas/FieldErrorResponse"
                }
              ]
            }
          }
        }
      },
      "NotFound": {
        "description": "Resource was not found.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/ErrorResponse"
            }
          }
        }
      },
      "Unauthorized": {
        "description": "Authentication is missing or invalid.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/ErrorResponse"
            }
          }
        }
      },
      "UnsupportedMediaType": {
        "description": "Requested or submitted media type is not supported.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/ErrorResponse"
            }
          }
        }
      }
    },
    "schemas": {
      "ReputationAllocationRequest": {
        "oneOf": [
          {
            "type": "object",
            "additionalProperties": false,
            "required": [
              "action"
            ],
            "properties": {
              "action": {
                "type": "string",
                "enum": [
                  "status"
                ]
              }
            }
          },
          {
            "type": "object",
            "additionalProperties": false,
            "required": [
              "action",
              "reason",
              "origin",
              "audit_id"
            ],
            "properties": {
              "action": {
                "type": "string",
                "enum": [
                  "drain"
                ]
              },
              "reason": {
                "type": "string",
                "minLength": 1,
                "maxLength": 64,
                "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
              },
              "origin": {
                "type": "string",
                "minLength": 1,
                "maxLength": 64,
                "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
              },
              "audit_id": {
                "type": "string",
                "minLength": 1,
                "maxLength": 128
              }
            }
          }
        ]
      },
      "ReputationAllocationView": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "mode",
          "generation",
          "next_generation",
          "fenced_shards",
          "drained_at",
          "retention",
          "observed_at"
        ],
        "properties": {
          "mode": {
            "type": "string",
            "enum": [
              "active",
              "draining"
            ]
          },
          "generation": {
            "type": "integer",
            "minimum": 0,
            "maximum": 1000000
          },
          "next_generation": {
            "type": "integer",
            "minimum": 1,
            "maximum": 1000001
          },
          "fenced_shards": {
            "type": "integer",
            "minimum": 0,
            "maximum": 16
          },
          "drained_at": {
            "type": "number",
            "minimum": 0,
            "maximum": 100000000000
          },
          "retention": {
            "type": "number",
            "minimum": 1,
            "maximum": 31536000
          },
          "observed_at": {
            "type": "number",
            "minimum": 0,
            "maximum": 100000000000
          },
          "audit": {
            "$ref": "#/components/schemas/ReputationAllocationAudit"
          }
        }
      },
      "ReputationAllocationAudit": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "reason",
          "origin",
          "audit_id",
          "creator"
        ],
        "properties": {
          "reason": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64,
            "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
          },
          "origin": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64,
            "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
          },
          "audit_id": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128
          },
          "creator": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128
          }
        }
      },
      "ReputationLookupRequest": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "kind",
          "subject"
        ],
        "properties": {
          "kind": {
            "type": "string",
            "enum": [
              "ip",
              "network",
              "asn",
              "dns_domain",
              "account",
              "service"
            ]
          },
          "subject": {
            "type": "string",
            "minLength": 1,
            "maxLength": 512
          }
        }
      },
      "ReputationOverridePutRequest": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "kind",
          "subject",
          "reason",
          "audit_id",
          "origin",
          "band",
          "ttl_seconds"
        ],
        "properties": {
          "kind": {
            "type": "string",
            "enum": [
              "ip",
              "network",
              "asn",
              "dns_domain",
              "account",
              "service"
            ]
          },
          "subject": {
            "type": "string",
            "minLength": 1,
            "maxLength": 512
          },
          "reason": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64,
            "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
          },
          "audit_id": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128
          },
          "origin": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64,
            "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
          },
          "previous_audit": {
            "type": "string",
            "maxLength": 128
          },
          "slot": {
            "type": "string",
            "enum": [
              "active",
              "previous"
            ],
            "default": "active"
          },
          "band": {
            "type": "string",
            "enum": [
              "blocked",
              "trusted",
              "neutral"
            ]
          },
          "ttl_seconds": {
            "type": "integer",
            "format": "int64",
            "minimum": 0,
            "maximum": 31536000
          }
        }
      },
      "ReputationOverrideDeleteRequest": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "kind",
          "subject",
          "reason",
          "audit_id",
          "origin",
          "previous_audit"
        ],
        "properties": {
          "kind": {
            "type": "string",
            "enum": [
              "ip",
              "network",
              "asn",
              "dns_domain",
              "account",
              "service"
            ]
          },
          "subject": {
            "type": "string",
            "minLength": 1,
            "maxLength": 512
          },
          "reason": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64,
            "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
          },
          "audit_id": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128
          },
          "origin": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64,
            "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
          },
          "previous_audit": {
            "type": "string",
            "maxLength": 128
          },
          "slot": {
            "type": "string",
            "enum": [
              "active",
              "previous"
            ],
            "default": "active"
          }
        }
      },
      "ReputationAudit": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "schema",
          "kind",
          "operation",
          "reason",
          "creator",
          "audit_id",
          "previous_audit",
          "origin",
          "created_at"
        ],
        "properties": {
          "schema": {
            "type": "string",
            "enum": [
              "reputation-operator-audit.v1"
            ]
          },
          "kind": {
            "type": "string",
            "enum": [
              "ip",
              "network",
              "asn",
              "dns_domain",
              "account",
              "service"
            ]
          },
          "operation": {
            "type": "string",
            "enum": [
              "override_put",
              "override_delete"
            ]
          },
          "reason": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64,
            "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
          },
          "creator": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128
          },
          "audit_id": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128
          },
          "previous_audit": {
            "type": "string",
            "maxLength": 128
          },
          "origin": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64,
            "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
          },
          "created_at": {
            "type": "number",
            "minimum": 0,
            "maximum": 100000000000
          }
        }
      },
      "ReputationOverride": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "band",
          "reason",
          "creator",
          "audit_id",
          "origin",
          "created_at",
          "expires_at"
        ],
        "properties": {
          "band": {
            "type": "string",
            "enum": [
              "blocked",
              "trusted",
              "neutral"
            ]
          },
          "reason": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64,
            "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
          },
          "creator": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128
          },
          "audit_id": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128
          },
          "origin": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64,
            "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
          },
          "created_at": {
            "type": "number",
            "minimum": 0,
            "maximum": 100000000000
          },
          "expires_at": {
            "type": "number",
            "minimum": 0,
            "maximum": 100000000000
          }
        }
      },
      "ReputationScores": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "risk_score",
          "trust_score",
          "confidence",
          "samples",
          "source_diversity",
          "age_seconds"
        ],
        "properties": {
          "risk_score": {
            "type": "number",
            "minimum": 0,
            "maximum": 1
          },
          "trust_score": {
            "type": "number",
            "minimum": 0,
            "maximum": 1
          },
          "confidence": {
            "type": "number",
            "minimum": 0,
            "maximum": 1
          },
          "samples": {
            "type": "number",
            "minimum": 0,
            "maximum": 8000000
          },
          "source_diversity": {
            "type": "integer",
            "minimum": 0,
            "maximum": 8
          },
          "age_seconds": {
            "type": "integer",
            "format": "int64",
            "minimum": 0,
            "maximum": 100000000000
          }
        }
      },
      "ReputationProfile": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "state",
          "band",
          "override"
        ],
        "properties": {
          "state": {
            "type": "string",
            "enum": [
              "fresh",
              "not_found"
            ]
          },
          "band": {
            "type": "string",
            "enum": [
              "unknown",
              "trusted",
              "positive",
              "neutral",
              "suspicious",
              "blocked"
            ]
          },
          "override": {
            "type": "string",
            "enum": [
              "none",
              "trusted",
              "neutral",
              "blocked"
            ]
          },
          "details": {
            "$ref": "#/components/schemas/ReputationScores"
          }
        }
      },
      "ReputationSourceClasses": {
        "type": "object",
        "additionalProperties": false,
        "required": [],
        "properties": {
          "fast": {
            "type": "array",
            "maxItems": 8,
            "uniqueItems": true,
            "items": {
              "type": "string",
              "minLength": 1,
              "maxLength": 64,
              "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
            }
          },
          "operational": {
            "type": "array",
            "maxItems": 8,
            "uniqueItems": true,
            "items": {
              "type": "string",
              "minLength": 1,
              "maxLength": 64,
              "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
            }
          },
          "baseline": {
            "type": "array",
            "maxItems": 8,
            "uniqueItems": true,
            "items": {
              "type": "string",
              "minLength": 1,
              "maxLength": 64,
              "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
            }
          }
        }
      },
      "ReputationEvidence": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "kind",
          "slot",
          "state",
          "source_classes",
          "observed_at",
          "updated_at",
          "risk_at",
          "trust_at",
          "authoritative_at"
        ],
        "properties": {
          "kind": {
            "type": "string",
            "enum": [
              "ip",
              "network",
              "asn",
              "dns_domain",
              "account",
              "service"
            ]
          },
          "slot": {
            "type": "string",
            "enum": [
              "active",
              "previous"
            ]
          },
          "state": {
            "type": "string",
            "enum": [
              "fresh",
              "not_found"
            ]
          },
          "source_classes": {
            "$ref": "#/components/schemas/ReputationSourceClasses"
          },
          "override": {
            "$ref": "#/components/schemas/ReputationOverride"
          },
          "last_change": {
            "$ref": "#/components/schemas/ReputationAudit"
          },
          "observed_at": {
            "type": "number",
            "minimum": 0,
            "maximum": 100000000000
          },
          "updated_at": {
            "type": "number",
            "minimum": 0,
            "maximum": 100000000000
          },
          "risk_at": {
            "type": "number",
            "minimum": 0,
            "maximum": 100000000000
          },
          "trust_at": {
            "type": "number",
            "minimum": 0,
            "maximum": 100000000000
          },
          "authoritative_at": {
            "type": "number",
            "minimum": 0,
            "maximum": 100000000000
          }
        }
      },
      "ReputationView": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "schema",
          "kind",
          "model_id",
          "model_revision",
          "config_revision",
          "profiles",
          "evidence"
        ],
        "properties": {
          "schema": {
            "type": "string",
            "enum": [
              "reputation-management.v1"
            ]
          },
          "kind": {
            "type": "string",
            "enum": [
              "ip",
              "network",
              "asn",
              "dns_domain",
              "account",
              "service"
            ]
          },
          "model_id": {
            "type": "string",
            "minLength": 1,
            "maxLength": 64,
            "pattern": "^[a-z][a-z0-9_.-]{0,63}$"
          },
          "model_revision": {
            "type": "string",
            "pattern": "^[0-9a-f]{64}$"
          },
          "config_revision": {
            "type": "string",
            "pattern": "^[0-9a-f]{64}$"
          },
          "profiles": {
            "type": "object",
            "additionalProperties": false,
            "required": [
              "fast",
              "operational",
              "baseline"
            ],
            "properties": {
              "fast": {
                "$ref": "#/components/schemas/ReputationProfile"
              },
              "operational": {
                "$ref": "#/components/schemas/ReputationProfile"
              },
              "baseline": {
                "$ref": "#/components/schemas/ReputationProfile"
              }
            }
          },
          "evidence": {
            "type": "array",
            "minItems": 1,
            "maxItems": 4,
            "items": {
              "$ref": "#/components/schemas/ReputationEvidence"
            }
          },
          "verified_change": {
            "$ref": "#/components/schemas/ReputationAudit"
          }
        }
      },
      "ReputationManagementError": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "error"
        ],
        "properties": {
          "error": {
            "type": "string",
            "minLength": 1,
            "maxLength": 128
          }
        }
      },
      "PolicyAdvice": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "id",
          "parameters"
        ],
        "properties": {
          "id": {
            "type": "string",
            "maxLength": 512
          },
          "parameters": {
            "$ref": "#/components/schemas/PolicyResponseValueMap"
          }
        }
      },
      "PolicyDecisionRequest": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "version",
          "target"
        ],
        "properties": {
          "version": {
            "type": "string",
            "enum": [
              "1"
            ]
          },
          "request_id": {
            "type": "string",
            "maxLength": 128
          },
          "target": {
            "$ref": "#/components/schemas/PolicyTarget"
          },
          "subject": {
            "$ref": "#/components/schemas/PolicyEntity"
          },
          "resource": {
            "$ref": "#/components/schemas/PolicyEntity"
          },
          "environment": {
            "$ref": "#/components/schemas/PolicyEnvironment"
          },
          "attributes": {
            "$ref": "#/components/schemas/PolicyValueMap"
          },
          "options": {
            "$ref": "#/components/schemas/PolicyEvaluationOptions"
          }
        }
      },
      "PolicyDecisionResponse": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "request_id",
          "decision_id",
          "effect",
          "status"
        ],
        "properties": {
          "request_id": {
            "type": "string",
            "maxLength": 128
          },
          "decision_id": {
            "type": "string",
            "maxLength": 128
          },
          "effect": {
            "type": "string",
            "enum": [
              "permit",
              "deny",
              "not_applicable",
              "indeterminate"
            ]
          },
          "status": {
            "$ref": "#/components/schemas/PolicyStatus"
          },
          "obligations": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/PolicyObligation"
            }
          },
          "advice": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/PolicyAdvice"
            }
          },
          "diagnostics": {
            "$ref": "#/components/schemas/PolicyDiagnostics"
          }
        }
      },
      "PolicyDiagnostics": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "entries"
        ],
        "properties": {
          "entries": {
            "$ref": "#/components/schemas/PolicyResponseValueMap"
          }
        }
      },
      "PolicyEntity": {
        "type": "object",
        "additionalProperties": false,
        "properties": {
          "type": {
            "type": "string",
            "maxLength": 512
          },
          "id": {
            "type": "string",
            "maxLength": 512
          },
          "attributes": {
            "$ref": "#/components/schemas/PolicyValueMap"
          }
        }
      },
      "PolicyEnvironment": {
        "type": "object",
        "additionalProperties": false,
        "properties": {
          "service": {
            "type": "string",
            "maxLength": 512
          },
          "instance": {
            "type": "string",
            "maxLength": 512
          },
          "protocol": {
            "type": "string",
            "maxLength": 512
          },
          "attributes": {
            "$ref": "#/components/schemas/PolicyValueMap"
          }
        }
      },
      "PolicyError": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "code",
          "message"
        ],
        "properties": {
          "code": {
            "type": "string"
          },
          "message": {
            "type": "string"
          },
          "details": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/PolicyValidationDetail"
            }
          }
        }
      },
      "PolicyEvaluationOptions": {
        "type": "object",
        "additionalProperties": false,
        "properties": {
          "include_diagnostics": {
            "type": "boolean"
          }
        }
      },
      "PolicyObligation": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "id",
          "parameters"
        ],
        "properties": {
          "id": {
            "type": "string",
            "maxLength": 512
          },
          "parameters": {
            "$ref": "#/components/schemas/PolicyResponseValueMap"
          }
        }
      },
      "PolicyStatus": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "code",
          "message",
          "retryable"
        ],
        "properties": {
          "code": {
            "type": "string",
            "description": "Stable result code. effect_outcome_unknown is non-retryable. effect_replay_unsafe is non-retryable because an earlier non-idempotent effect already completed or was accepted before a later failure. effect_outcome_unknown_replay_safe permits retrying the complete Policy request with unchanged admitted idempotency keys and payload. The host never retries an effect within one request."
          },
          "message": {
            "type": "string"
          },
          "retryable": {
            "type": "boolean",
            "description": "Whether the caller may retry; replay-safe unknown outcomes require the same complete request and idempotency keys."
          },
          "details": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/PolicyValidationDetail"
            }
          }
        }
      },
      "PolicyTarget": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "namespace",
          "action"
        ],
        "properties": {
          "namespace": {
            "type": "string",
            "maxLength": 64
          },
          "action": {
            "type": "string",
            "maxLength": 64
          }
        }
      },
      "PolicyValidationDetail": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "field",
          "reason"
        ],
        "properties": {
          "field": {
            "type": "string"
          },
          "reason": {
            "type": "string"
          }
        }
      },
      "PolicyValue": {
        "type": "object",
        "additionalProperties": false,
        "oneOf": [
          {
            "required": [
              "string"
            ]
          },
          {
            "required": [
              "boolean"
            ]
          },
          {
            "required": [
              "integer"
            ]
          },
          {
            "required": [
              "double"
            ]
          },
          {
            "required": [
              "strings"
            ]
          },
          {
            "required": [
              "bytes"
            ]
          },
          {
            "required": [
              "timestamp"
            ]
          },
          {
            "required": [
              "records"
            ]
          }
        ],
        "properties": {
          "string": {
            "type": "string"
          },
          "boolean": {
            "type": "boolean"
          },
          "integer": {
            "type": "string",
            "pattern": "^-?(0|[1-9][0-9]*)$"
          },
          "double": {
            "type": "number",
            "format": "double"
          },
          "strings": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "bytes": {
            "type": "string",
            "contentEncoding": "base64"
          },
          "timestamp": {
            "type": "string",
            "format": "date-time"
          },
          "records": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/PolicyRecord"
            }
          }
        }
      },
      "PolicyRecord": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "fields"
        ],
        "properties": {
          "fields": {
            "type": "array",
            "minItems": 1,
            "items": {
              "$ref": "#/components/schemas/PolicyRecordField"
            }
          }
        }
      },
      "PolicyRecordField": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "name",
          "value"
        ],
        "properties": {
          "name": {
            "type": "string"
          },
          "value": {
            "$ref": "#/components/schemas/PolicyRecordFieldValue"
          }
        }
      },
      "PolicyRecordFieldValue": {
        "type": "object",
        "additionalProperties": false,
        "oneOf": [
          {
            "required": [
              "string"
            ]
          },
          {
            "required": [
              "boolean"
            ]
          },
          {
            "required": [
              "integer"
            ]
          },
          {
            "required": [
              "double"
            ]
          },
          {
            "required": [
              "strings"
            ]
          },
          {
            "required": [
              "bytes"
            ]
          },
          {
            "required": [
              "timestamp"
            ]
          }
        ],
        "properties": {
          "string": {
            "type": "string"
          },
          "boolean": {
            "type": "boolean"
          },
          "integer": {
            "type": "string",
            "pattern": "^-?(0|[1-9][0-9]*)$"
          },
          "double": {
            "type": "number",
            "format": "double"
          },
          "strings": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "bytes": {
            "type": "string",
            "contentEncoding": "base64"
          },
          "timestamp": {
            "type": "string",
            "format": "date-time"
          }
        }
      },
      "PolicyResponseValue": {
        "$ref": "#/components/schemas/PolicyRecordFieldValue"
      },
      "PolicyResponseValueMap": {
        "type": "object",
        "additionalProperties": {
          "$ref": "#/components/schemas/PolicyResponseValue"
        }
      },
      "PolicyValueMap": {
        "type": "object",
        "additionalProperties": {
          "$ref": "#/components/schemas/PolicyValue"
        }
      },
      "AccountList": {
        "type": "array",
        "items": {
          "type": "string"
        }
      },
      "AsyncAcceptedPayload": {
        "type": "object",
        "required": [
          "jobId",
          "status"
        ],
        "properties": {
          "jobId": {
            "type": "string"
          },
          "status": {
            "type": "string",
            "description": "The initial state returned immediately after the job is accepted.",
            "enum": [
              "QUEUED"
            ],
            "x-enum-varnames": [
              "AsyncAcceptedStatusQueued"
            ]
          }
        }
      },
      "AsyncAcceptedResult": {
        "allOf": [
          {
            "$ref": "#/components/schemas/ResultEnvelope"
          },
          {
            "type": "object",
            "properties": {
              "result": {
                "$ref": "#/components/schemas/AsyncAcceptedPayload"
              }
            }
          }
        ]
      },
      "AsyncJobStatusPayload": {
        "type": "object",
        "properties": {
          "jobId": {
            "type": "string"
          },
          "status": {
            "type": "string",
            "description": "Current async job lifecycle state.",
            "enum": [
              "QUEUED",
              "INPROGRESS",
              "DONE",
              "ERROR"
            ],
            "x-enum-varnames": [
              "AsyncJobStatusQueued",
              "AsyncJobStatusInProgress",
              "AsyncJobStatusDone",
              "AsyncJobStatusError"
            ]
          },
          "type": {
            "type": "string"
          },
          "createdAt": {
            "type": "string"
          },
          "startedAt": {
            "type": "string"
          },
          "finishedAt": {
            "type": "string"
          },
          "resultCount": {
            "type": "string"
          },
          "error": {
            "type": "string"
          }
        }
      },
      "AsyncJobStatusResult": {
        "allOf": [
          {
            "$ref": "#/components/schemas/ResultEnvelope"
          },
          {
            "type": "object",
            "properties": {
              "result": {
                "$ref": "#/components/schemas/AsyncJobStatusPayload"
              }
            }
          }
        ]
      },
      "AttributeMapping": {
        "type": "object",
        "additionalProperties": {
          "type": "array",
          "items": {}
        }
      },
      "AuthError": {
        "type": "object",
        "required": [
          "error"
        ],
        "properties": {
          "error": {
            "type": "string"
          }
        }
      },
      "AuthRequest": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "username"
        ],
        "properties": {
          "username": {
            "type": "string"
          },
          "password": {
            "type": "string",
            "format": "password"
          },
          "client_ip": {
            "type": "string"
          },
          "client_port": {
            "type": "string"
          },
          "client_hostname": {
            "type": "string"
          },
          "client_id": {
            "type": "string"
          },
          "external_session_id": {
            "type": "string"
          },
          "user_agent": {
            "type": "string"
          },
          "local_ip": {
            "type": "string"
          },
          "local_port": {
            "type": "string"
          },
          "protocol": {
            "type": "string"
          },
          "method": {
            "type": "string"
          },
          "ssl": {
            "type": "string"
          },
          "ssl_session_id": {
            "type": "string"
          },
          "ssl_client_verify": {
            "type": "string"
          },
          "ssl_client_dn": {
            "type": "string"
          },
          "ssl_client_cn": {
            "type": "string"
          },
          "ssl_issuer": {
            "type": "string"
          },
          "ssl_client_notbefore": {
            "type": "string"
          },
          "ssl_client_notafter": {
            "type": "string"
          },
          "ssl_subject_dn": {
            "type": "string"
          },
          "ssl_issuer_dn": {
            "type": "string"
          },
          "ssl_client_subject_dn": {
            "type": "string"
          },
          "ssl_client_issuer_dn": {
            "type": "string"
          },
          "ssl_protocol": {
            "type": "string"
          },
          "ssl_cipher": {
            "type": "string"
          },
          "ssl_serial": {
            "type": "string"
          },
          "ssl_fingerprint": {
            "type": "string"
          },
          "oidc_cid": {
            "type": "string"
          },
          "auth_login_attempt": {
            "type": "integer",
            "minimum": 0
          }
        }
      },
      "AuthSuccess": {
        "type": "object",
        "required": [
          "ok",
          "account_field",
          "backend",
          "attributes"
        ],
        "properties": {
          "ok": {
            "type": "boolean"
          },
          "account_field": {
            "type": "string"
          },
          "totp_secret_field": {
            "type": "string"
          },
          "backend": {
            "type": "integer"
          },
          "attributes": {
            "$ref": "#/components/schemas/AttributeMapping"
          }
        }
      },
      "BruteForceBanEntry": {
        "type": "object",
        "properties": {
          "network": {
            "type": "string"
          },
          "bucket": {
            "type": "string"
          },
          "ban_time": {
            "type": "integer",
            "format": "int64"
          },
          "ttl": {
            "type": "integer",
            "format": "int64"
          },
          "banned_at": {
            "type": "string",
            "format": "date-time"
          }
        }
      },
      "BruteForceBlockedAccounts": {
        "type": "object",
        "required": [
          "accounts"
        ],
        "properties": {
          "accounts": {
            "type": "object",
            "additionalProperties": {
              "type": "array",
              "items": {
                "type": "string"
              }
            }
          },
          "error": {
            "type": [
              "string",
              "null"
            ]
          },
          "page": {
            "$ref": "#/components/schemas/PageInfo"
          }
        }
      },
      "BruteForceBlockedIPAddresses": {
        "type": "object",
        "required": [
          "entries"
        ],
        "properties": {
          "entries": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/BruteForceBanEntry"
            }
          },
          "error": {
            "type": [
              "string",
              "null"
            ]
          },
          "page": {
            "$ref": "#/components/schemas/PageInfo"
          }
        }
      },
      "BruteForceFilterRequest": {
        "type": "object",
        "additionalProperties": false,
        "properties": {
          "accounts": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "ip_addresses": {
            "type": "array",
            "items": {
              "type": "string"
            }
          }
        }
      },
      "BruteForceFlushPayload": {
        "type": "object",
        "properties": {
          "ip_address": {
            "type": "string"
          },
          "rule_name": {
            "type": "string"
          },
          "protocol": {
            "type": "string"
          },
          "oidc_cid": {
            "type": "string"
          },
          "removed_keys": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "status": {
            "type": "string"
          }
        }
      },
      "BruteForceFlushRequest": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "ip_address",
          "rule_name"
        ],
        "properties": {
          "ip_address": {
            "type": "string"
          },
          "rule_name": {
            "type": "string"
          },
          "protocol": {
            "type": "string"
          },
          "oidc_cid": {
            "type": "string"
          }
        }
      },
      "BruteForceFlushResult": {
        "allOf": [
          {
            "$ref": "#/components/schemas/ResultEnvelope"
          },
          {
            "type": "object",
            "properties": {
              "result": {
                "$ref": "#/components/schemas/BruteForceFlushPayload"
              }
            }
          }
        ]
      },
      "BruteForceListResult": {
        "allOf": [
          {
            "$ref": "#/components/schemas/ResultEnvelope"
          },
          {
            "type": "object",
            "properties": {
              "result": {
                "type": "array",
                "prefixItems": [
                  {
                    "$ref": "#/components/schemas/BruteForceBlockedIPAddresses"
                  },
                  {
                    "$ref": "#/components/schemas/BruteForceBlockedAccounts"
                  }
                ]
              }
            }
          }
        ]
      },
      "CacheFlushPayload": {
        "type": "object",
        "properties": {
          "user": {
            "type": "string"
          },
          "removed_keys": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "status": {
            "type": "string"
          }
        }
      },
      "CacheFlushRequest": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "user"
        ],
        "properties": {
          "user": {
            "type": "string"
          }
        }
      },
      "CacheFlushResult": {
        "allOf": [
          {
            "$ref": "#/components/schemas/ResultEnvelope"
          },
          {
            "type": "object",
            "properties": {
              "result": {
                "$ref": "#/components/schemas/CacheFlushPayload"
              }
            }
          }
        ]
      },
      "ErrorResponse": {
        "type": "object",
        "required": [
          "error"
        ],
        "properties": {
          "error": {
            "type": "string"
          }
        }
      },
      "FieldError": {
        "type": "object",
        "properties": {
          "field": {
            "type": "string"
          },
          "message": {
            "type": "string"
          }
        }
      },
      "FieldErrorResponse": {
        "type": "object",
        "required": [
          "errors"
        ],
        "properties": {
          "errors": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/FieldError"
            }
          }
        }
      },
      "OIDCSessions": {
        "type": "object",
        "required": [
          "sessions"
        ],
        "properties": {
          "sessions": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/OIDCSessionSummary"
            }
          }
        }
      },
      "OIDCSessionSummary": {
        "type": "object",
        "required": [
          "id",
          "client_id",
          "user_id",
          "auth_time"
        ],
        "properties": {
          "id": {
            "type": "string",
            "description": "Stable non-secret session identifier derived from the stored token."
          },
          "client_id": {
            "type": "string"
          },
          "user_id": {
            "type": "string"
          },
          "username": {
            "type": "string"
          },
          "display_name": {
            "type": "string"
          },
          "redirect_uri": {
            "type": "string"
          },
          "mfa_method": {
            "type": "string"
          },
          "scopes": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "auth_time": {
            "type": "string",
            "format": "date-time"
          },
          "mfa_completed": {
            "type": "boolean"
          }
        }
      },
      "PageInfo": {
        "type": "object",
        "required": [
          "limit",
          "offset",
          "next_offset",
          "has_more"
        ],
        "properties": {
          "limit": {
            "type": "integer"
          },
          "offset": {
            "type": "integer"
          },
          "next_offset": {
            "type": "integer"
          },
          "has_more": {
            "type": "boolean"
          }
        }
      },
      "ResultEnvelope": {
        "type": "object",
        "required": [
          "session",
          "object",
          "operation",
          "result"
        ],
        "properties": {
          "session": {
            "type": "string"
          },
          "object": {
            "type": "string"
          },
          "operation": {
            "type": "string"
          },
          "result": {}
        }
      }
    }
  }
}
