{
  "openapi": "3.1.0",
  "info": {
    "title": "Events & Webhooks API",
    "version": "1.0.0",
    "description": "Publishes domain events (case status changes, new documents, application decisions) to subscriber endpoints. Each delivery is signed with HMAC-SHA256 (`X-IronBrick-Signature`), retried with exponential backoff, and available for replay for 7 days.\n\nReference design by Iron Brick LLC. Not an official government system; endpoints and data models are adapted to each agency's systems of record during implementation.",
    "contact": {
      "name": "Iron Brick LLC",
      "email": "info@ironbrick.us",
      "url": "https://dev.ironbrick.us"
    }
  },
  "servers": [
    {
      "url": "https://dev.ironbrick.us/sandbox/events/v1",
      "description": "Iron Brick sandbox (synthetic data; free developer account)"
    },
    {
      "url": "https://{agency-gateway}/events/v1",
      "description": "Agency deployment (behind the agency API gateway)"
    }
  ],
  "security": [
    {
      "oauth2": [
        "events:manage"
      ]
    }
  ],
  "paths": {
    "/subscriptions": {
      "post": {
        "operationId": "createSubscription",
        "summary": "Create a subscription",
        "tags": [
          "Subscriptions"
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "eventTypes",
                  "callbackUrl"
                ],
                "properties": {
                  "eventTypes": {
                    "type": "array",
                    "items": {
                      "type": "string"
                    }
                  },
                  "callbackUrl": {
                    "type": "string"
                  }
                }
              },
              "example": {
                "eventTypes": [
                  "case.status_changed"
                ],
                "callbackUrl": "https://partner.example.gov/hooks/ironbrick"
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Subscription created (includes the signing secret, shown once)",
            "headers": {
              "X-Request-Id": {
                "$ref": "#/components/headers/X-Request-Id"
              }
            },
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Subscription"
                }
              }
            }
          },
          "400": {
            "description": "Invalid request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid access token",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "Caller lacks the required scope",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      },
      "get": {
        "operationId": "listSubscriptions",
        "summary": "List subscriptions",
        "tags": [
          "Subscriptions"
        ],
        "responses": {
          "200": {
            "description": "Subscriptions",
            "headers": {
              "X-Request-Id": {
                "$ref": "#/components/headers/X-Request-Id"
              }
            },
            "content": {
              "application/json": {
                "schema": {
                  "type": "array",
                  "items": {
                    "$ref": "#/components/schemas/Subscription"
                  }
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid access token",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "Caller lacks the required scope",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      }
    },
    "/subscriptions/{subscriptionId}": {
      "delete": {
        "operationId": "deleteSubscription",
        "summary": "Delete a subscription",
        "tags": [
          "Subscriptions"
        ],
        "parameters": [
          {
            "name": "subscriptionId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Subscription identifier."
          }
        ],
        "responses": {
          "204": {
            "description": "Deleted"
          },
          "401": {
            "description": "Missing or invalid access token",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "Caller lacks the required scope",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "Resource not found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      }
    },
    "/event-types": {
      "get": {
        "operationId": "listEventTypes",
        "summary": "List event types",
        "tags": [
          "Events"
        ],
        "responses": {
          "200": {
            "description": "Available event types",
            "headers": {
              "X-Request-Id": {
                "$ref": "#/components/headers/X-Request-Id"
              }
            },
            "content": {
              "application/json": {
                "schema": {
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "type": {
                        "type": "string",
                        "example": "case.status_changed"
                      },
                      "description": {
                        "type": "string"
                      }
                    }
                  }
                },
                "example": [
                  {
                    "type": "case.status_changed",
                    "description": "A case moved to a new status."
                  },
                  {
                    "type": "application.decided",
                    "description": "An application was found eligible, ineligible, or awarded."
                  },
                  {
                    "type": "document.available",
                    "description": "A document passed scanning and is ready."
                  },
                  {
                    "type": "request.released",
                    "description": "A records request release package was published."
                  }
                ]
              }
            }
          },
          "401": {
            "description": "Missing or invalid access token",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      }
    },
    "/subscriptions/{subscriptionId}/replay": {
      "post": {
        "operationId": "replayEvents",
        "summary": "Replay recent events",
        "tags": [
          "Subscriptions"
        ],
        "description": "Re-delivers events from the last 7 days, for recovery after an outage.",
        "parameters": [
          {
            "name": "subscriptionId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Subscription identifier."
          }
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "example": {
                "since": "2026-10-01T00:00:00Z"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Replay started"
          },
          "401": {
            "description": "Missing or invalid access token",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "Caller lacks the required scope",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "Resource not found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      }
    }
  },
  "components": {
    "securitySchemes": {
      "oauth2": {
        "type": "oauth2",
        "description": "OAuth 2.0 client credentials for system-to-system calls. Agency deployments federate with the agency identity provider (PIV/CAC-backed for user-delegated access).",
        "flows": {
          "clientCredentials": {
            "tokenUrl": "https://dev.ironbrick.us/oauth/token",
            "scopes": {
              "events:manage": "Manage event subscriptions"
            }
          }
        }
      }
    },
    "headers": {
      "X-Request-Id": {
        "description": "Unique request identifier; include it when contacting support.",
        "schema": {
          "type": "string",
          "format": "uuid"
        }
      }
    },
    "schemas": {
      "Error": {
        "type": "object",
        "required": [
          "code",
          "message",
          "requestId"
        ],
        "properties": {
          "code": {
            "type": "string",
            "example": "validation_error"
          },
          "message": {
            "type": "string",
            "example": "status must be one of: received, in_review, decided, closed"
          },
          "requestId": {
            "type": "string",
            "format": "uuid",
            "example": "3f1c9a52-7c1e-4f3e-9d2a-0b8e5f6a1c44"
          },
          "details": {
            "type": "array",
            "items": {
              "type": "object"
            }
          }
        }
      },
      "Page": {
        "type": "object",
        "properties": {
          "nextCursor": {
            "type": "string",
            "nullable": true,
            "example": "eyJvZmZzZXQiOjUwfQ"
          },
          "limit": {
            "type": "integer",
            "example": 50
          }
        }
      },
      "Subscription": {
        "type": "object",
        "properties": {
          "subscriptionId": {
            "type": "string",
            "example": "SUB-0091"
          },
          "eventTypes": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "example": [
              "case.status_changed",
              "document.available"
            ]
          },
          "callbackUrl": {
            "type": "string",
            "format": "uri",
            "example": "https://partner.example.gov/hooks/ironbrick"
          },
          "status": {
            "type": "string",
            "enum": [
              "active",
              "paused",
              "failing"
            ],
            "example": "active"
          },
          "createdAt": {
            "type": "string",
            "format": "date-time"
          }
        }
      }
    }
  }
}