{
  "openapi": "3.1.0",
  "info": {
    "title": "Hybrid ID Progressive Profiling",
    "version": "1.0.0",
    "description": "Self-declared profile requests. Requires a confidential app credential AND a current user access token with profile:request consent. Canonical integration guide: https://hybrid-id.com/integrations/progressive-profiling.md"
  },
  "servers": [
    {
      "url": "https://auth.hybrid-id.com"
    }
  ],
  "components": {
    "securitySchemes": {
      "applicationBasic": {
        "type": "http",
        "scheme": "basic"
      }
    },
    "schemas": {
      "ProfileRequirements": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "fields"
        ],
        "properties": {
          "fields": {
            "type": "array",
            "maxItems": 2,
            "uniqueItems": true,
            "items": {
              "enum": [
                "first_name",
                "last_name"
              ]
            }
          },
          "reason": {
            "type": "string",
            "maxLength": 500,
            "description": "Required and non-blank when fields are selected."
          }
        }
      },
      "ProfileRequest": {
        "type": "object",
        "required": [
          "request_id",
          "app_id",
          "app_name",
          "app_origin",
          "fields",
          "reason",
          "policy_digest",
          "status",
          "assurance",
          "created_at",
          "expires_at",
          "review_url"
        ],
        "properties": {
          "request_id": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "app_id": {
            "type": "string"
          },
          "app_name": {
            "type": "string"
          },
          "app_origin": {
            "type": "string",
            "format": "uri"
          },
          "fields": {
            "type": "array",
            "maxItems": 2,
            "uniqueItems": true,
            "items": {
              "enum": [
                "first_name",
                "last_name"
              ]
            }
          },
          "reason": {
            "type": "string"
          },
          "policy_digest": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "status": {
            "enum": [
              "pending",
              "approved",
              "declined",
              "revoked",
              "expired",
              "requirements_changed",
              "connection_revoked",
              "application_disabled"
            ]
          },
          "assurance": {
            "const": "self_declared"
          },
          "created_at": {
            "type": "integer"
          },
          "expires_at": {
            "type": "integer"
          },
          "approved_at": {
            "type": "integer"
          },
          "review_url": {
            "type": "string",
            "format": "uri"
          },
          "values": {
            "type": "object",
            "additionalProperties": false,
            "properties": {
              "first_name": {
                "type": "string",
                "maxLength": 100
              },
              "last_name": {
                "type": "string",
                "maxLength": 100
              }
            },
            "description": "Present only for approved requests; only requested fields."
          }
        },
        "allOf": [
          {
            "if": {
              "properties": {
                "status": {
                  "const": "approved"
                }
              }
            },
            "then": {
              "required": [
                "values",
                "approved_at"
              ]
            },
            "else": {
              "not": {
                "anyOf": [
                  {
                    "required": [
                      "values"
                    ]
                  },
                  {
                    "required": [
                      "approved_at"
                    ]
                  }
                ]
              }
            }
          }
        ]
      }
    }
  },
  "paths": {
    "/profile/requests": {
      "post": {
        "operationId": "profileRequest",
        "summary": "Create or read a user-approved app profile request",
        "security": [
          {
            "applicationBasic": []
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "type": "object",
                "additionalProperties": false,
                "required": [
                  "operation",
                  "access_token"
                ],
                "properties": {
                  "operation": {
                    "enum": [
                      "create",
                      "read"
                    ]
                  },
                  "access_token": {
                    "type": "string",
                    "writeOnly": true,
                    "description": "Current user OIDC access token issued to the authenticated app, including profile:request."
                  },
                  "request_id": {
                    "type": "string",
                    "pattern": "^[a-f0-9]{64}$",
                    "description": "Optional; if supplied must match this app/user/current policy/consent."
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Current request; values only on approved status",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ProfileRequest"
                }
              }
            }
          },
          "400": {
            "description": "Invalid body or fields",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "error",
                    "message"
                  ],
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "401": {
            "description": "Invalid application credential",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "error",
                    "message"
                  ],
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "403": {
            "description": "Missing or revoked user consent or authority",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "error",
                    "message"
                  ],
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "404": {
            "description": "Request not found for this app/user/policy",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "error",
                    "message"
                  ],
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "405": {
            "description": "POST required",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "error",
                    "message"
                  ],
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "409": {
            "description": "Stale request action",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "error",
                    "message"
                  ],
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "429": {
            "description": "Rate limit; Retry-After: 60",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "error",
                    "message"
                  ],
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          },
          "503": {
            "description": "Dependency unavailable; never approval",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "error",
                    "message"
                  ],
                  "properties": {
                    "error": {
                      "type": "string"
                    },
                    "message": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  }
}
