{
  "openapi": "3.1.0",
  "info": {
    "title": "Records Requests (FOIA) API",
    "version": "1.0.0",
    "description": "Supports the records-request lifecycle: intake, perfection, search, review, and release. Calculates statutory due dates by track, and exposes release packages through the Document Services API.\n\nReference design by Iron Brick LLC. Not an official government system; endpoints and data models are adapted to each agency's systems of record during implementation.",
    "contact": {
      "name": "Iron Brick LLC",
      "email": "info@ironbrick.us",
      "url": "https://dev.ironbrick.us"
    }
  },
  "servers": [
    {
      "url": "https://dev.ironbrick.us/sandbox/records-requests/v1",
      "description": "Iron Brick sandbox (synthetic data; free developer account)"
    },
    {
      "url": "https://{agency-gateway}/records-requests/v1",
      "description": "Agency deployment (behind the agency API gateway)"
    }
  ],
  "security": [
    {
      "oauth2": [
        "requests:read",
        "requests:write"
      ]
    }
  ],
  "paths": {
    "/requests": {
      "post": {
        "operationId": "createRequest",
        "summary": "Log a new request",
        "tags": [
          "Requests"
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "subject"
                ],
                "properties": {
                  "subject": {
                    "type": "string"
                  },
                  "track": {
                    "type": "string"
                  },
                  "requesterRef": {
                    "type": "string"
                  }
                }
              },
              "example": {
                "subject": "Records related to contract 70RSAT26C0000012",
                "track": "complex",
                "requesterRef": "REQ-a91e"
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Request created",
            "headers": {
              "X-Request-Id": {
                "$ref": "#/components/headers/X-Request-Id"
              }
            },
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RecordsRequest"
                }
              }
            }
          },
          "400": {
            "description": "Invalid request",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid access token",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "Caller lacks the required scope",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      },
      "get": {
        "operationId": "listRequests",
        "summary": "List requests",
        "tags": [
          "Requests"
        ],
        "parameters": [
          {
            "name": "status",
            "in": "query",
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "dueBefore",
            "in": "query",
            "schema": {
              "type": "string",
              "format": "date"
            },
            "description": "Requests due on or before this date."
          },
          {
            "name": "cursor",
            "in": "query",
            "schema": {
              "type": "string"
            },
            "description": "Pagination cursor from a previous response."
          },
          {
            "name": "limit",
            "in": "query",
            "schema": {
              "type": "integer",
              "default": 50,
              "maximum": 200
            },
            "description": "Maximum items to return."
          }
        ],
        "responses": {
          "200": {
            "description": "A page of requests",
            "headers": {
              "X-Request-Id": {
                "$ref": "#/components/headers/X-Request-Id"
              }
            },
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "data": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/RecordsRequest"
                      }
                    },
                    "page": {
                      "$ref": "#/components/schemas/Page"
                    }
                  }
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid access token",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "Caller lacks the required scope",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      }
    },
    "/requests/{requestId}": {
      "get": {
        "operationId": "getRequest",
        "summary": "Get a request",
        "tags": [
          "Requests"
        ],
        "parameters": [
          {
            "name": "requestId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Request identifier."
          }
        ],
        "responses": {
          "200": {
            "description": "The request",
            "headers": {
              "X-Request-Id": {
                "$ref": "#/components/headers/X-Request-Id"
              }
            },
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RecordsRequest"
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid access token",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "Caller lacks the required scope",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "Resource not found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      }
    },
    "/requests/{requestId}/releases": {
      "get": {
        "operationId": "listReleases",
        "summary": "List release packages",
        "tags": [
          "Requests"
        ],
        "parameters": [
          {
            "name": "requestId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Request identifier."
          }
        ],
        "responses": {
          "200": {
            "description": "Release packages",
            "headers": {
              "X-Request-Id": {
                "$ref": "#/components/headers/X-Request-Id"
              }
            },
            "content": {
              "application/json": {
                "schema": {
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "releaseId": {
                        "type": "string",
                        "example": "REL-1"
                      },
                      "documentIds": {
                        "type": "array",
                        "items": {
                          "type": "string"
                        }
                      },
                      "releasedAt": {
                        "type": "string",
                        "format": "date-time"
                      }
                    }
                  }
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid access token",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "Caller lacks the required scope",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "Resource not found",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      }
    }
  },
  "components": {
    "securitySchemes": {
      "oauth2": {
        "type": "oauth2",
        "description": "OAuth 2.0 client credentials for system-to-system calls. Agency deployments federate with the agency identity provider (PIV/CAC-backed for user-delegated access).",
        "flows": {
          "clientCredentials": {
            "tokenUrl": "https://dev.ironbrick.us/oauth/token",
            "scopes": {
              "requests:read": "Read records requests",
              "requests:write": "Create and update records requests"
            }
          }
        }
      }
    },
    "headers": {
      "X-Request-Id": {
        "description": "Unique request identifier; include it when contacting support.",
        "schema": {
          "type": "string",
          "format": "uuid"
        }
      }
    },
    "schemas": {
      "Error": {
        "type": "object",
        "required": [
          "code",
          "message",
          "requestId"
        ],
        "properties": {
          "code": {
            "type": "string",
            "example": "validation_error"
          },
          "message": {
            "type": "string",
            "example": "status must be one of: received, in_review, decided, closed"
          },
          "requestId": {
            "type": "string",
            "format": "uuid",
            "example": "3f1c9a52-7c1e-4f3e-9d2a-0b8e5f6a1c44"
          },
          "details": {
            "type": "array",
            "items": {
              "type": "object"
            }
          }
        }
      },
      "Page": {
        "type": "object",
        "properties": {
          "nextCursor": {
            "type": "string",
            "nullable": true,
            "example": "eyJvZmZzZXQiOjUwfQ"
          },
          "limit": {
            "type": "integer",
            "example": 50
          }
        }
      },
      "RecordsRequest": {
        "type": "object",
        "properties": {
          "requestId": {
            "type": "string",
            "example": "FOIA-2026-03318"
          },
          "track": {
            "type": "string",
            "enum": [
              "simple",
              "complex",
              "expedited"
            ],
            "example": "complex"
          },
          "status": {
            "type": "string",
            "enum": [
              "received",
              "perfected",
              "searching",
              "review",
              "released",
              "closed"
            ],
            "example": "searching"
          },
          "receivedDate": {
            "type": "string",
            "format": "date",
            "example": "2026-07-02"
          },
          "dueDate": {
            "type": "string",
            "format": "date",
            "example": "2026-07-31"
          },
          "subject": {
            "type": "string",
            "example": "Records related to contract 70RSAT26C0000012"
          },
          "pagesReleased": {
            "type": "integer",
            "example": 0
          }
        }
      }
    }
  }
}