openapi: 3.2.0 info: title: Breach402 Owner Verification API version: 0.1.5 description: Agent-native owner-verified breach exposure checks. contact: name: Breach402 security operator servers: - url: https://breach402.bmcxiv.com tags: - name: owner-verification description: Prove control of the owner's mailbox before a paid lookup. paths: /v1/enrollments: post: operationId: createOwnerEmailVerification tags: - owner-verification summary: Send a mailbox-ownership verification email description: Creates a one-time owner authorization. The approval email discloses the price, scope, requesting wallet when supplied, and that sensitive breach records may be returned to the requesting agent. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateEnrollmentRequest' responses: '202': description: Verification queued content: application/json: schema: $ref: '#/components/schemas/EnrollmentCreated' '400': $ref: '#/components/responses/Error' '429': $ref: '#/components/responses/Error' /v1/enrollments/{enrollment_id}: parameters: - in: path name: enrollment_id required: true schema: type: string get: operationId: getOwnerEmailVerification tags: - owner-verification summary: Poll owner verification security: - bearerAuth: [] responses: '200': description: Current status; a verified response includes the one-time scan token content: application/json: schema: $ref: '#/components/schemas/EnrollmentStatus' '404': $ref: '#/components/responses/Error' delete: operationId: revokeOwnerEmailVerification tags: - owner-verification summary: Revoke unused owner authorization security: - bearerAuth: [] responses: '200': description: Revoked content: application/json: schema: type: object properties: enrollment_id: type: string status: const: revoked required: - enrollment_id - status '409': $ref: '#/components/responses/Error' /v1/enrollments/{enrollment_id}/verify: post: operationId: verifyOwnerEmailCode tags: - owner-verification summary: Submit the one-time code from the owner email security: - bearerAuth: [] parameters: - in: path name: enrollment_id required: true schema: type: string requestBody: required: true content: application/json: schema: type: object properties: verification_code: type: string pattern: ^B402-[A-Z2-9]{4}-[A-Z2-9]{4}-[A-Z2-9]{4}$ required: - verification_code additionalProperties: false responses: '200': description: Verified and one-time scan token issued content: application/json: schema: $ref: '#/components/schemas/EnrollmentStatus' '400': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' components: schemas: EnrollmentStatus: type: object properties: enrollment_id: type: string status: type: string enum: - pending - verified - consumed - expired - revoked email: type: string description: Masked email requested_wallet: type: string verification_expires_at: type: string format: date-time verified_at: type: string format: date-time verification_method: type: string one_check_only: const: true scan_token: type: string description: Present once verified; sensitive, one-time bearer authorization. scan_token_expires_at: type: string format: date-time prepare_endpoint: type: string format: uri price: type: string network: type: string required: - enrollment_id - status - one_check_only EnrollmentCreated: type: object properties: enrollment_id: type: string status: const: pending email: type: string description: Masked email verification_expires_at: type: string format: date-time poll_token: type: string description: Sensitive bearer capability; never place in URLs or logs. status_url: type: string format: uri verification_methods: type: array items: type: string enum: - email_confirmation_link - one_time_code next_step: type: string required: - enrollment_id - status - poll_token - status_url CreateEnrollmentRequest: type: object properties: email: type: string format: email description: Owner-controlled address that will receive explicit approval. agent_wallet: type: string description: Optional agent-supplied Solana address displayed to the owner as an unverified claim; it is not proof of wallet control and does not replace mailbox verification. required: - email additionalProperties: false Error: type: object properties: error: type: object properties: code: type: string message: type: string details: {} required: - code - message required: - error responses: Error: description: Structured error content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: opaque-token