{
  "openapi": "3.1.0",
  "info": {
    "title": "sudosudo.dev External API",
    "version": "1.0.0",
    "description": "Server-to-server API for sudosudo.dev: register monitored targets (hosts or\npublic sites), edit their alert rules and SSH allowlist, read status, reports\nand schedules, and trigger an AI triage run.\n\n**Auth:** `Authorization: Bearer sot_\u2026` \u2014 an org-scoped API key. Create and\nrevoke keys in the dashboard at https://sudosudo.dev/app/members (org owner),\nor via `POST /api/orgs/{org_id}/api-tokens` with a session. Keys are stored\nhashed, are shown once, expire (default 365 days) and only see their org.\n\n**Limits:** agent-triggering calls are capped per org (burst + a daily quota\nwhen the target runs on the platform's LLM instead of its own `llm_api_key`);\nover the limit you get `429` with `Retry-After`. Targets and probes per org\nare capped (`403` with a quota message).\n"
  },
  "servers": [
    {
      "url": "https://sudosudo.dev/api/ext"
    }
  ],
  "security": [
    {
      "orgApiKey": []
    }
  ],
  "paths": {
    "/targets": {
      "get": {
        "tags": [
          "targets"
        ],
        "summary": "List Targets",
        "operationId": "get_targets",
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response List Targets Targets Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          }
        }
      },
      "post": {
        "tags": [
          "targets"
        ],
        "summary": "Create Target",
        "operationId": "post_targets",
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateTargetIn"
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/CreateTargetOut"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    },
    "/targets/{target_id}": {
      "get": {
        "tags": [
          "targets"
        ],
        "summary": "Get Target",
        "operationId": "get_targets_target_id",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Get Target Targets  Target Id  Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          }
        }
      },
      "patch": {
        "tags": [
          "targets"
        ],
        "summary": "Update Target",
        "operationId": "patch_targets_target_id",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateTargetIn"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Update Target Targets  Target Id  Patch"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    },
    "/targets/{target_id}/status": {
      "get": {
        "tags": [
          "targets"
        ],
        "summary": "Target Status",
        "description": "Org-scoped status (session-auth) \u2014 the /t/{id}/status twin for the dashboard.",
        "operationId": "get_targets_target_id_status",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Target Status Targets  Target Id  Status Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          }
        }
      }
    },
    "/targets/{target_id}/rules": {
      "get": {
        "tags": [
          "targets"
        ],
        "summary": "Get Rules",
        "operationId": "get_targets_target_id_rules",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Get Rules Targets  Target Id  Rules Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          }
        }
      },
      "put": {
        "tags": [
          "targets"
        ],
        "summary": "Put Rules",
        "operationId": "put_targets_target_id_rules",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RulesIn"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Put Rules Targets  Target Id  Rules Put"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    },
    "/targets/{target_id}/rules/suggest": {
      "post": {
        "tags": [
          "targets"
        ],
        "summary": "Suggest Rules Start",
        "description": "Kick off an agent run that proposes rules + routines for this box. Async:\npoll GET /rules/suggest for the result. Returns 202; coalesces if one is\nalready running.",
        "operationId": "post_targets_target_id_rules_suggest",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "responses": {
          "202": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Suggest Rules Start Targets  Target Id  Rules Suggest Post"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      },
      "get": {
        "tags": [
          "targets"
        ],
        "summary": "Suggest Rules Result",
        "description": "Poll the latest rule-suggestion run. While running \u2192 {status:'running'};\non success \u2192 validated proposals the UI can review and apply.",
        "operationId": "get_targets_target_id_rules_suggest",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Suggest Rules Result Targets  Target Id  Rules Suggest Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          }
        }
      }
    },
    "/targets/{target_id}/allowlist": {
      "get": {
        "tags": [
          "targets"
        ],
        "summary": "Get Allowlist",
        "operationId": "get_targets_target_id_allowlist",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Get Allowlist Targets  Target Id  Allowlist Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          }
        }
      },
      "put": {
        "tags": [
          "targets"
        ],
        "summary": "Put Allowlist",
        "operationId": "put_targets_target_id_allowlist",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/AllowlistIn"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Put Allowlist Targets  Target Id  Allowlist Put"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    },
    "/targets/{target_id}/metric-keys": {
      "get": {
        "tags": [
          "targets"
        ],
        "summary": "Get Metric Keys",
        "description": "Dotted `payload.*` paths from the most recent metric push, to power the\nrule condition autocomplete. Empty when the box hasn't pushed yet.",
        "operationId": "get_targets_target_id_metric-keys",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Get Metric Keys Targets  Target Id  Metric Keys Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          }
        }
      }
    },
    "/targets/{target_id}/push-credentials": {
      "get": {
        "tags": [
          "targets"
        ],
        "summary": "Get Push Credentials",
        "description": "Return push_url + push_token in clear, for rendering push.py.\n\nSame auth as the rest of the target API (org-scoped session or admin\ntoken). Kept on a separate endpoint so the normal GET stays scrubbed\nand logs never accidentally capture the token.",
        "operationId": "get_targets_target_id_push-credentials",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Get Push Credentials Targets  Target Id  Push Credentials Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          }
        }
      }
    },
    "/targets/{target_id}/reports": {
      "get": {
        "tags": [
          "targets"
        ],
        "summary": "List Reports",
        "operationId": "get_targets_target_id_reports",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response List Reports Targets  Target Id  Reports Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          }
        }
      }
    },
    "/targets/{target_id}/reports/{rid}": {
      "get": {
        "tags": [
          "targets"
        ],
        "summary": "Get Report",
        "operationId": "get_targets_target_id_reports_rid",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          },
          {
            "name": "rid",
            "in": "path",
            "required": true,
            "schema": {
              "type": "integer",
              "title": "Rid"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Get Report Targets  Target Id  Reports  Rid  Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          }
        }
      }
    },
    "/targets/{target_id}/schedules": {
      "get": {
        "tags": [
          "targets"
        ],
        "summary": "List Schedules",
        "operationId": "get_targets_target_id_schedules",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response List Schedules Targets  Target Id  Schedules Get"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          }
        }
      },
      "post": {
        "tags": [
          "targets"
        ],
        "summary": "Create Schedule",
        "operationId": "post_targets_target_id_schedules",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateScheduleIn"
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Create Schedule Targets  Target Id  Schedules Post"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    },
    "/targets/{target_id}/schedules/{sid}": {
      "patch": {
        "tags": [
          "targets"
        ],
        "summary": "Update Schedule",
        "operationId": "patch_targets_target_id_schedules_sid",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          },
          {
            "name": "sid",
            "in": "path",
            "required": true,
            "schema": {
              "type": "integer",
              "title": "Sid"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/UpdateScheduleIn"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Update Schedule Targets  Target Id  Schedules  Sid  Patch"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      },
      "delete": {
        "tags": [
          "targets"
        ],
        "summary": "Delete Schedule",
        "operationId": "delete_targets_target_id_schedules_sid",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          },
          {
            "name": "sid",
            "in": "path",
            "required": true,
            "schema": {
              "type": "integer",
              "title": "Sid"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Delete Schedule Targets  Target Id  Schedules  Sid  Delete"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    },
    "/targets/{target_id}/schedules/{sid}/run-now": {
      "post": {
        "tags": [
          "targets"
        ],
        "summary": "Run Now",
        "operationId": "post_targets_target_id_schedules_sid_run-now",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          },
          {
            "name": "sid",
            "in": "path",
            "required": true,
            "schema": {
              "type": "integer",
              "title": "Sid"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Run Now Targets  Target Id  Schedules  Sid  Run Now Post"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    },
    "/targets/{target_id}/triage": {
      "post": {
        "tags": [
          "targets"
        ],
        "summary": "Test Alert",
        "description": "Records the alert in DB; full agent/email dispatch happens on next push.",
        "operationId": "post_targets_target_id_triage",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/TestAlertIn"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Test Alert Targets  Target Id  Test Alert Post"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    },
    "/targets/{target_id}/install-token": {
      "post": {
        "tags": [
          "targets"
        ],
        "summary": "Mint Install Token",
        "description": "Mint a short-lived, single-fetch install token for the box installer and\nreturn the one-liner. Org/admin-scoped (the operator). The raw token is shown\nonce (it ends up in the install URL); only its hash is stored.",
        "operationId": "post_targets_target_id_install-token",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/InstallTokenIn"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Mint Install Token Targets  Target Id  Install Token Post"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    },
    "/targets/{target_id}/tunnel/provision": {
      "post": {
        "tags": [
          "targets"
        ],
        "summary": "Tunnel Provision",
        "description": "Provision the direct-tunnel door (#3) for a target: allocate a unique\nloopback port, generate the per-target login keypair (private stored\nencrypted), and return what the box needs to set up its outbound tunnel \u2014\nthe login PUBLIC key + this control plane's tunnel SSH endpoint + the port.\nSee docs/tunnel-security.md.",
        "operationId": "post_targets_target_id_tunnel_provision",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Tunnel Provision Targets  Target Id  Tunnel Provision Post"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    },
    "/targets/{target_id}/tunnel/report": {
      "post": {
        "tags": [
          "targets"
        ],
        "summary": "Tunnel Report",
        "description": "Receive the box's reported tunnel public key + sshd host key (relayed via\nOrquesta after the bootstrap task). Authorizes the box's tunnel key on the\nlocked-down `tunnel` user (restricted to its one port) and pins the host key.",
        "operationId": "post_targets_target_id_tunnel_report",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/TunnelReportIn"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Tunnel Report Targets  Target Id  Tunnel Report Post"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    },
    "/targets/{target_id}/set-orquesta-agent": {
      "post": {
        "tags": [
          "targets"
        ],
        "summary": "Set Orquesta Agent",
        "description": "Wire a target's resident-agent (ARE) door from an already-provisioned\nOrquesta project + oxa_ dispatch token. Counterpart to enroll-orquesta for the\ncase where Orquesta drives the integration (it owns the project/agent already).\n\nexecution_mode='orquesta-agent' makes triage try the resident agent first with\nSSH as the fallback door (\"both\"); 'ssh' keeps SSH primary and stores the ARE\ntoken as a dormant fallback.",
        "operationId": "post_targets_target_id_set-orquesta-agent",
        "parameters": [
          {
            "name": "target_id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "title": "Target Id"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/SetOrquestaAgentIn"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful Response",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true,
                  "title": "Response Set Orquesta Agent Targets  Target Id  Set Orquesta Agent Post"
                }
              }
            }
          },
          "422": {
            "description": "Validation Error",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HTTPValidationError"
                }
              }
            }
          },
          "401": {
            "description": "missing bearer token"
          },
          "403": {
            "description": "invalid/expired API key, or quota reached"
          },
          "429": {
            "description": "rate limited \u2014 see Retry-After"
          }
        }
      }
    }
  },
  "components": {
    "securitySchemes": {
      "orgApiKey": {
        "type": "http",
        "scheme": "bearer",
        "bearerFormat": "sot_\u2026",
        "description": "Org-scoped API key (create at /app/members)."
      }
    },
    "schemas": {
      "AllowlistIn": {
        "properties": {
          "tiers": {
            "items": {
              "type": "string"
            },
            "type": "array",
            "title": "Tiers",
            "default": []
          },
          "read": {
            "items": {
              "type": "string"
            },
            "type": "array",
            "title": "Read",
            "default": []
          },
          "remediate": {
            "items": {
              "type": "string"
            },
            "type": "array",
            "title": "Remediate",
            "default": []
          },
          "dangerous_blocklist": {
            "items": {
              "type": "string"
            },
            "type": "array",
            "title": "Dangerous Blocklist",
            "default": []
          }
        },
        "type": "object",
        "title": "AllowlistIn"
      },
      "CreateScheduleIn": {
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 120,
            "minLength": 1,
            "title": "Name"
          },
          "kind": {
            "type": "string",
            "title": "Kind"
          },
          "interval_s": {
            "anyOf": [
              {
                "type": "integer"
              },
              {
                "type": "null"
              }
            ],
            "title": "Interval S"
          },
          "daily_at": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Daily At"
          },
          "prompt": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Prompt"
          },
          "recipients": {
            "anyOf": [
              {
                "items": {
                  "type": "string"
                },
                "type": "array"
              },
              {
                "type": "null"
              }
            ],
            "title": "Recipients"
          },
          "window_s": {
            "anyOf": [
              {
                "type": "integer"
              },
              {
                "type": "null"
              }
            ],
            "title": "Window S"
          },
          "enabled": {
            "type": "boolean",
            "title": "Enabled",
            "default": true
          },
          "process_name": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Process Name"
          },
          "process_selector": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Process Selector"
          },
          "operator_prompt": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Operator Prompt"
          },
          "on_failure": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "On Failure"
          }
        },
        "type": "object",
        "required": [
          "name",
          "kind"
        ],
        "title": "CreateScheduleIn"
      },
      "CreateTargetIn": {
        "properties": {
          "id": {
            "type": "string",
            "title": "Id"
          },
          "name": {
            "type": "string",
            "title": "Name"
          },
          "kind": {
            "type": "string",
            "enum": [
              "host",
              "site"
            ],
            "title": "Kind",
            "default": "host"
          },
          "recipients": {
            "items": {
              "type": "string"
            },
            "type": "array",
            "title": "Recipients",
            "default": []
          },
          "rules_yaml": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Rules Yaml"
          },
          "allowlist_yaml": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Allowlist Yaml"
          },
          "ssh_host": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Ssh Host"
          },
          "ssh_user": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Ssh User"
          },
          "ssh_password": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Ssh Password"
          },
          "ssh_ports": {
            "anyOf": [
              {
                "items": {
                  "type": "integer"
                },
                "type": "array"
              },
              {
                "type": "null"
              }
            ],
            "title": "Ssh Ports"
          },
          "llm_provider": {
            "type": "string",
            "title": "Llm Provider",
            "default": "kimi-cli"
          },
          "llm_base_url": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Llm Base Url"
          },
          "llm_api_key": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Llm Api Key"
          },
          "llm_model": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Llm Model"
          },
          "agent_context_md": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Agent Context Md"
          },
          "seed_schedules": {
            "type": "boolean",
            "title": "Seed Schedules",
            "default": true
          }
        },
        "type": "object",
        "required": [
          "id",
          "name"
        ],
        "title": "CreateTargetIn"
      },
      "CreateTargetOut": {
        "properties": {
          "id": {
            "type": "string",
            "title": "Id"
          },
          "push_token": {
            "type": "string",
            "title": "Push Token"
          },
          "admin_token": {
            "type": "string",
            "title": "Admin Token"
          },
          "push_url": {
            "type": "string",
            "title": "Push Url"
          },
          "status_url": {
            "type": "string",
            "title": "Status Url"
          },
          "caddy": {
            "anyOf": [
              {
                "additionalProperties": true,
                "type": "object"
              },
              {
                "type": "null"
              }
            ],
            "title": "Caddy"
          }
        },
        "type": "object",
        "required": [
          "id",
          "push_token",
          "admin_token",
          "push_url",
          "status_url"
        ],
        "title": "CreateTargetOut"
      },
      "HTTPValidationError": {
        "properties": {
          "detail": {
            "items": {
              "$ref": "#/components/schemas/ValidationError"
            },
            "type": "array",
            "title": "Detail"
          }
        },
        "type": "object",
        "title": "HTTPValidationError"
      },
      "InstallTokenIn": {
        "properties": {
          "with_triage": {
            "type": "boolean",
            "title": "With Triage",
            "default": false
          },
          "ttl_s": {
            "type": "integer",
            "maximum": 3600.0,
            "minimum": 60.0,
            "title": "Ttl S",
            "default": 900
          },
          "push_url": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Push Url"
          },
          "push_token": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Push Token"
          }
        },
        "type": "object",
        "title": "InstallTokenIn"
      },
      "RuleIn": {
        "properties": {
          "key": {
            "type": "string",
            "title": "Key"
          },
          "when": {
            "type": "string",
            "title": "When"
          },
          "severity": {
            "type": "string",
            "title": "Severity"
          },
          "cooldown_s": {
            "anyOf": [
              {
                "type": "integer"
              },
              {
                "type": "null"
              }
            ],
            "title": "Cooldown S"
          },
          "subject": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Subject"
          },
          "body": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Body"
          },
          "action": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Action"
          }
        },
        "type": "object",
        "required": [
          "key",
          "when",
          "severity"
        ],
        "title": "RuleIn"
      },
      "RulesIn": {
        "properties": {
          "rules": {
            "items": {
              "$ref": "#/components/schemas/RuleIn"
            },
            "type": "array",
            "title": "Rules"
          }
        },
        "type": "object",
        "required": [
          "rules"
        ],
        "title": "RulesIn"
      },
      "SetOrquestaAgentIn": {
        "properties": {
          "orquesta_project": {
            "type": "string",
            "title": "Orquesta Project"
          },
          "orquesta_agent": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Orquesta Agent"
          },
          "orquesta_token": {
            "type": "string",
            "title": "Orquesta Token"
          },
          "execution_mode": {
            "type": "string",
            "pattern": "^(ssh|orquesta-agent)$",
            "title": "Execution Mode",
            "default": "orquesta-agent"
          }
        },
        "type": "object",
        "required": [
          "orquesta_project",
          "orquesta_token"
        ],
        "title": "SetOrquestaAgentIn",
        "description": "Direct ARE wiring when the caller (Orquesta) ALREADY owns the project and a\nlive resident agent \u2014 no Notlogin VC handshake needed. Orquesta mints the oxa_\ndispatch token on its side and hands it over here."
      },
      "TestAlertIn": {
        "properties": {
          "severity": {
            "type": "string",
            "pattern": "^(info|warn|crit)$",
            "title": "Severity",
            "default": "warn"
          },
          "subject": {
            "type": "string",
            "title": "Subject",
            "default": "[TEST] synthetic alert"
          },
          "body": {
            "type": "string",
            "title": "Body",
            "default": "This is a synthetic alert triggered via /test-alert."
          }
        },
        "type": "object",
        "title": "TestAlertIn"
      },
      "TunnelReportIn": {
        "properties": {
          "tunnel_pubkey": {
            "type": "string",
            "title": "Tunnel Pubkey",
            "description": "box-generated tunnel PUBLIC key"
          },
          "host_key": {
            "type": "string",
            "title": "Host Key",
            "description": "box sshd host PUBLIC key (known_hosts pin)"
          }
        },
        "type": "object",
        "required": [
          "tunnel_pubkey",
          "host_key"
        ],
        "title": "TunnelReportIn"
      },
      "UpdateScheduleIn": {
        "properties": {
          "name": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Name"
          },
          "interval_s": {
            "anyOf": [
              {
                "type": "integer"
              },
              {
                "type": "null"
              }
            ],
            "title": "Interval S"
          },
          "daily_at": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Daily At"
          },
          "prompt": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Prompt"
          },
          "recipients": {
            "anyOf": [
              {
                "items": {
                  "type": "string"
                },
                "type": "array"
              },
              {
                "type": "null"
              }
            ],
            "title": "Recipients"
          },
          "window_s": {
            "anyOf": [
              {
                "type": "integer"
              },
              {
                "type": "null"
              }
            ],
            "title": "Window S"
          },
          "enabled": {
            "anyOf": [
              {
                "type": "boolean"
              },
              {
                "type": "null"
              }
            ],
            "title": "Enabled"
          },
          "process_name": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Process Name"
          },
          "process_selector": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Process Selector"
          },
          "operator_prompt": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Operator Prompt"
          },
          "on_failure": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "On Failure"
          }
        },
        "type": "object",
        "title": "UpdateScheduleIn"
      },
      "UpdateTargetIn": {
        "properties": {
          "name": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Name"
          },
          "recipients": {
            "anyOf": [
              {
                "items": {
                  "type": "string"
                },
                "type": "array"
              },
              {
                "type": "null"
              }
            ],
            "title": "Recipients"
          },
          "rules_yaml": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Rules Yaml"
          },
          "allowlist_yaml": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Allowlist Yaml"
          },
          "ssh_host": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Ssh Host"
          },
          "ssh_user": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Ssh User"
          },
          "ssh_password": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Ssh Password"
          },
          "ssh_ports": {
            "anyOf": [
              {
                "items": {
                  "type": "integer"
                },
                "type": "array"
              },
              {
                "type": "null"
              }
            ],
            "title": "Ssh Ports"
          },
          "llm_provider": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Llm Provider"
          },
          "llm_base_url": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Llm Base Url"
          },
          "llm_api_key": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Llm Api Key"
          },
          "llm_model": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Llm Model"
          },
          "agent_context_md": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Agent Context Md"
          },
          "agent_timeout_s": {
            "anyOf": [
              {
                "type": "integer"
              },
              {
                "type": "null"
              }
            ],
            "title": "Agent Timeout S"
          },
          "agent_sudo": {
            "anyOf": [
              {
                "type": "boolean"
              },
              {
                "type": "null"
              }
            ],
            "title": "Agent Sudo"
          },
          "sudo_password": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "title": "Sudo Password"
          },
          "heartbeat_timeout_s": {
            "anyOf": [
              {
                "type": "integer"
              },
              {
                "type": "null"
              }
            ],
            "title": "Heartbeat Timeout S"
          },
          "enabled": {
            "anyOf": [
              {
                "type": "boolean"
              },
              {
                "type": "null"
              }
            ],
            "title": "Enabled"
          }
        },
        "type": "object",
        "title": "UpdateTargetIn"
      },
      "ValidationError": {
        "properties": {
          "loc": {
            "items": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "integer"
                }
              ]
            },
            "type": "array",
            "title": "Location"
          },
          "msg": {
            "type": "string",
            "title": "Message"
          },
          "type": {
            "type": "string",
            "title": "Error Type"
          },
          "input": {
            "title": "Input"
          },
          "ctx": {
            "type": "object",
            "title": "Context"
          }
        },
        "type": "object",
        "required": [
          "loc",
          "msg",
          "type"
        ],
        "title": "ValidationError"
      }
    }
  }
}
