{
    "openapi": "3.0.0",
    "info": {
        "title": "Central de Identidade Vetor Zero / Lobo",
        "version": "1.0.0"
    },
    "paths": {
        "/api/v1/users/{id}/emails": {
            "post": {
                "tags": [
                    "Users"
                ],
                "summary": "Adds the address unverified and mails the user a verification link; adding it again resends\nthe link. The link itself never comes back here: only whoever reads that mailbox may verify.",
                "operationId": "post_app_api_v1_user_email_add",
                "parameters": [
                    {
                        "$ref": "#/components/parameters/IdempotencyKey"
                    },
                    {
                        "name": "id",
                        "in": "path",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/AddEmailRequest"
                            }
                        }
                    }
                },
                "responses": {
                    "200": {
                        "description": "The user, with the new address unverified.",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/UserResource"
                                }
                            }
                        }
                    },
                    "404": {
                        "description": "No user with this id."
                    },
                    "409": {
                        "description": "The address is already verified on this user."
                    },
                    "422": {
                        "description": "The body failed validation."
                    }
                }
            }
        },
        "/api/v1/users/{id}/emails/{address}": {
            "delete": {
                "tags": [
                    "Users"
                ],
                "operationId": "delete_app_api_v1_user_email_remove",
                "parameters": [
                    {
                        "name": "id",
                        "in": "path",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    },
                    {
                        "name": "address",
                        "in": "path",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "204": {
                        "description": "The address is gone."
                    },
                    "404": {
                        "description": "No user with this id, or no such address on it."
                    },
                    "409": {
                        "description": "The address is the primary one."
                    }
                }
            }
        },
        "/api/v1/users/{id}/employment": {
            "put": {
                "tags": [
                    "Users"
                ],
                "operationId": "put_app_api_v1_user_employment_update",
                "parameters": [
                    {
                        "name": "id",
                        "in": "path",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/EmploymentRequest"
                            }
                        }
                    }
                },
                "responses": {
                    "200": {
                        "description": "The updated user.",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/UserResource"
                                }
                            }
                        }
                    },
                    "404": {
                        "description": "No user with this id."
                    },
                    "422": {
                        "description": "The body failed validation, or names an unknown organization."
                    }
                }
            }
        },
        "/api/v1/users/{id}/deactivate": {
            "post": {
                "tags": [
                    "Users"
                ],
                "summary": "Signs the user out of every client and revokes their tokens. Already inactive is a no-op.",
                "operationId": "post_app_api_v1_user_lifecycle_deactivate",
                "parameters": [
                    {
                        "$ref": "#/components/parameters/IdempotencyKey"
                    },
                    {
                        "name": "id",
                        "in": "path",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "description": "The deactivated user.",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/UserResource"
                                }
                            }
                        }
                    },
                    "404": {
                        "description": "No user with this id."
                    },
                    "422": {
                        "description": "A user token tried to deactivate its own user."
                    }
                }
            }
        },
        "/api/v1/users/{id}/reactivate": {
            "post": {
                "tags": [
                    "Users"
                ],
                "summary": "Already active is a no-op.",
                "operationId": "post_app_api_v1_user_lifecycle_reactivate",
                "parameters": [
                    {
                        "$ref": "#/components/parameters/IdempotencyKey"
                    },
                    {
                        "name": "id",
                        "in": "path",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "description": "The reactivated user.",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/UserResource"
                                }
                            }
                        }
                    },
                    "404": {
                        "description": "No user with this id."
                    }
                }
            }
        },
        "/api/v1/users/{id}/profile": {
            "put": {
                "tags": [
                    "Users"
                ],
                "operationId": "put_app_api_v1_user_profile_update",
                "parameters": [
                    {
                        "name": "id",
                        "in": "path",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/ProfileRequest"
                            }
                        }
                    }
                },
                "responses": {
                    "200": {
                        "description": "The updated user.",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/UserResource"
                                }
                            }
                        }
                    },
                    "404": {
                        "description": "No user with this id."
                    },
                    "409": {
                        "description": "The email already belongs to another user."
                    },
                    "422": {
                        "description": "The body failed validation."
                    }
                }
            }
        },
        "/api/v1/users": {
            "get": {
                "tags": [
                    "Users"
                ],
                "summary": "Offset pagination holds up here: oldest first, and users are deactivated rather than\ndeleted, so a new user only ever lands on the last page.",
                "operationId": "get_app_api_v1_user_index",
                "parameters": [
                    {
                        "name": "limit",
                        "in": "query",
                        "required": false,
                        "schema": {
                            "type": "integer",
                            "default": 50,
                            "maximum": 100,
                            "minimum": 1
                        }
                    },
                    {
                        "name": "offset",
                        "in": "query",
                        "required": false,
                        "schema": {
                            "type": "integer",
                            "default": 0,
                            "minimum": 0
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "description": "A page of users.",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/UserPage"
                                }
                            }
                        }
                    }
                }
            },
            "post": {
                "tags": [
                    "Users"
                ],
                "summary": "The user is born claimable: whoever first signs in with a Google account verified for the\nemail takes it over. The invite email is a courtesy; if it fails, the user still exists.",
                "operationId": "post_app_api_v1_user_create",
                "parameters": [
                    {
                        "$ref": "#/components/parameters/IdempotencyKey"
                    }
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/CreateUserRequest"
                            }
                        }
                    }
                },
                "responses": {
                    "201": {
                        "description": "The new user.",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/UserResource"
                                }
                            }
                        }
                    },
                    "409": {
                        "description": "The email already belongs to a user."
                    },
                    "422": {
                        "description": "The body failed validation."
                    }
                }
            }
        },
        "/api/v1/users/{id}": {
            "get": {
                "tags": [
                    "Users"
                ],
                "operationId": "get_app_api_v1_user_show",
                "parameters": [
                    {
                        "name": "id",
                        "in": "path",
                        "required": true,
                        "schema": {
                            "type": "string"
                        }
                    }
                ],
                "responses": {
                    "200": {
                        "description": "The user.",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/UserResource"
                                }
                            }
                        }
                    },
                    "404": {
                        "description": "No user with this id."
                    }
                }
            }
        }
    },
    "components": {
        "schemas": {
            "AddEmailRequest": {
                "required": [
                    "address"
                ],
                "properties": {
                    "address": {
                        "type": "string",
                        "maxLength": 255
                    }
                },
                "type": "object"
            },
            "EmploymentRequest": {
                "required": [
                    "servedOrganizations"
                ],
                "properties": {
                    "employer": {
                        "description": "The employer's domain, null for none.",
                        "type": "string",
                        "nullable": true
                    },
                    "servedOrganizations": {
                        "description": "Domains of the organizations served besides the employer.",
                        "type": "array",
                        "items": {
                            "type": "string"
                        }
                    },
                    "jobTitle": {
                        "type": "string",
                        "nullable": true,
                        "maxLength": 255
                    },
                    "department": {
                        "type": "string",
                        "nullable": true,
                        "maxLength": 255
                    }
                },
                "type": "object"
            },
            "ProfileRequest": {
                "required": [
                    "name",
                    "email"
                ],
                "properties": {
                    "name": {
                        "type": "string",
                        "maxLength": 255
                    },
                    "email": {
                        "description": "The primary address.",
                        "type": "string",
                        "maxLength": 255
                    }
                },
                "type": "object"
            },
            "PageQuery": {
                "properties": {
                    "limit": {
                        "type": "integer",
                        "default": 50,
                        "maximum": 100,
                        "minimum": 1
                    },
                    "offset": {
                        "type": "integer",
                        "default": 0,
                        "minimum": 0
                    }
                },
                "type": "object"
            },
            "CreateUserRequest": {
                "required": [
                    "name",
                    "email"
                ],
                "properties": {
                    "name": {
                        "type": "string",
                        "maxLength": 255
                    },
                    "email": {
                        "type": "string",
                        "maxLength": 255
                    }
                },
                "type": "object"
            },
            "EmailResource": {
                "required": [
                    "address",
                    "verified"
                ],
                "properties": {
                    "address": {
                        "type": "string"
                    },
                    "verified": {
                        "type": "boolean"
                    }
                },
                "type": "object"
            },
            "OrganizationResource": {
                "required": [
                    "domain",
                    "name"
                ],
                "properties": {
                    "domain": {
                        "type": "string"
                    },
                    "name": {
                        "type": "string"
                    }
                },
                "type": "object"
            },
            "UserResource": {
                "required": [
                    "id",
                    "name",
                    "email",
                    "emails",
                    "servedOrganizations",
                    "active",
                    "claimable",
                    "createdAt"
                ],
                "properties": {
                    "id": {
                        "type": "string"
                    },
                    "name": {
                        "type": "string"
                    },
                    "email": {
                        "description": "The primary address, one of `emails`.",
                        "type": "string"
                    },
                    "emails": {
                        "type": "array",
                        "items": {
                            "$ref": "#/components/schemas/EmailResource"
                        }
                    },
                    "employer": {
                        "nullable": true,
                        "oneOf": [
                            {
                                "$ref": "#/components/schemas/OrganizationResource"
                            }
                        ]
                    },
                    "servedOrganizations": {
                        "type": "array",
                        "items": {
                            "$ref": "#/components/schemas/OrganizationResource"
                        }
                    },
                    "jobTitle": {
                        "type": "string",
                        "nullable": true
                    },
                    "department": {
                        "type": "string",
                        "nullable": true
                    },
                    "active": {
                        "type": "boolean"
                    },
                    "claimable": {
                        "description": "Taken over by whoever next signs in with a Google account verified for `email`.",
                        "type": "boolean"
                    },
                    "createdAt": {
                        "type": "string",
                        "format": "date-time"
                    }
                },
                "type": "object"
            },
            "UserPage": {
                "required": [
                    "items",
                    "total"
                ],
                "properties": {
                    "items": {
                        "type": "array",
                        "items": {
                            "$ref": "#/components/schemas/UserResource"
                        }
                    },
                    "total": {
                        "description": "Users across every page.",
                        "type": "integer"
                    },
                    "next": {
                        "type": "string",
                        "nullable": true
                    },
                    "prev": {
                        "type": "string",
                        "nullable": true
                    }
                },
                "type": "object"
            }
        },
        "parameters": {
            "IdempotencyKey": {
                "name": "Idempotency-Key",
                "in": "header",
                "description": "Sending the same request again under the same key replays the first successful response (marked Idempotent-Replayed) instead of running it twice. Reusing a key for a different request is a 422; while the first is still running, a 409. Keys are kept for at least 7 days.",
                "required": false,
                "schema": {
                    "type": "string",
                    "maxLength": 255
                }
            }
        },
        "securitySchemes": {
            "client": {
                "type": "oauth2",
                "description": "Act as the client, with its own roles. Needs the client_credentials grant and API access.",
                "flows": {
                    "clientCredentials": {
                        "tokenUrl": "/token",
                        "scopes": {}
                    }
                }
            },
            "bearer": {
                "type": "http",
                "description": "An access token already in hand, from POST /token (never the client secret itself): client_credentials to act as the client, authorization_code to act as the user.",
                "scheme": "bearer"
            }
        }
    },
    "security": [
        {
            "client": []
        },
        {
            "bearer": []
        }
    ],
    "tags": [
        {
            "name": "Users"
        }
    ],
    "externalDocs": {
        "description": "Central de Identidade: login, integration checklist and the rest of the docs",
        "url": "/docs/"
    }
}