overlay: 1.0.0 info: title: API Evangelist enhancements for Channable Order Connection API version: 1.0.0 extends: openapi/channable-order-connection-openapi.json actions: - target: $.info update: x-apievangelist-enriched: '2026-07-18' x-apievangelist-provider: channable x-apievangelist-notes: >- Auth is a company-level bearer token documented at https://docs.channable.com/api/v1/ but not declared in components.securitySchemes; rate limit is per-company leaky bucket (2 req/s, burst 100). - target: $ update: servers: - url: https://api.channable.com description: >- Channable API production host. The server is the bare host because every path in the spec already carries its own version prefix (/v1/... and /v2/...); Channable's own docs state Hostname `api.channable.com` with Common Path v1 `/v1/companies/:company_id/projects/:project_id` and Common Path v2 `/v2/...`. Sandbox is provisioned as an in-app connection on the same host, not a separate base URL. - target: $.components update: securitySchemes: bearerToken: type: http scheme: bearer description: Company API token sent as Authorization Bearer (see authentication/channable-authentication.yml). accessTokenQuery: type: apiKey in: query name: access_token description: Company API token sent as the access_token query parameter (header method preferred). x-notes: >- This Overlay records API Evangelist enhancements only; it does not mutate the harvested spec. The scorer parses the original OpenAPI, so these additions (servers, securitySchemes) improve our derived artifacts and document the real, published auth/host that Channable omits from its machine-readable spec.