generated: '2026-08-17' method: generated source: >- Generated by API Evangelist from the fourteen OpenAPI/Swagger documents in openapi/ (harvested 2026-08-17 from https://api.coorpacademy.com/), plus the derived conventions, error, data-model and authentication artifacts in this repo and live unauthenticated probes of the four API hosts. Searched first for provider-published Agent Skills, an AGENTS.md or an llms.txt across coorpacademy.com, api.coorpacademy.com, support.coorpacademy.com and github.com/CoorpAcademy — none exists. summary: >- Five packaged Agent Skills covering the marquee integration flows across the Coorpacademy estate. Every operationId referenced in every skill was verified present in the harvested specifications; none is invented. All five carry the same cross-cutting rules, because the estate's biggest hazards are cross-cutting: five different auth header names, zero idempotency, zero rate-limit signal, three incompatible error envelopes, and an authoring model where writing to the wrong path prefix silently publishes nothing. skills: - name: coorpacademy-provision-users-scim file: coorpacademy-provision-users-scim.md api: Coorpacademy SCIM API base_url: https://api.coorpacademy.com/scim spec: openapi/coorpacademy-scim-openapi.json operations: [listUsers, onboardingPOST, recommendedCoursePOST, putUser, patchUser] consequence: writes-identity-records escalation: human-approval-required-for-writes note: >- Corrects the base URL (the spec omits the /scim prefix) and flags two operationIds copy-pasted from the unrelated email API, one of which names a GET operation `recommendedCoursePOST`. - name: coorpacademy-read-learner-progress file: coorpacademy-read-learner-progress.md api: Coorpacademy Progression API (+ Review API) base_url: https://progression.coorpacademy.com/api spec: openapi/coorpacademy-progression-openapi.json operations: [progressionsGET, progressionGET, actionsGET, completionFromDynamodbForUserGET, reviewCompletionFromDynamodbForUserGET, starsBySkillIForUserGET, slideCountFromDynamodbForUserGET, heroRecommendationFromDynamodbGET, getUserSkillsToReview] consequence: reads-personal-data escalation: read-only note: >- Teaches the v1/v2 trap — on this API they are not successive versions but the write and read surfaces of the same service — and documents the raw DynamoDB pagination cursor. - name: coorpacademy-publish-certification file: coorpacademy-publish-certification.md api: Coorpacademy Content API base_url: https://content.coorpacademy.com/api/v2 spec: openapi/coorpacademy-content-openapi.json operations: [findCertifications, findOneCertification, upsertCertification, undoCertificationChange, findCertificationsConsommation, upsertCertificationConsommation, countCertificationConsommation] consequence: writes-learner-facing-content escalation: human-approval-required-for-publish note: >- Exists mainly to prevent the estate's most expensive mistake: writing to the edition surface, getting a 201, and reporting success while learners see nothing. - name: coorpacademy-configure-brand-sso file: coorpacademy-configure-brand-sso.md api: Coorpacademy Platform API base_url: https://platform.coorpacademy.com/api/v1 spec: openapi/coorpacademy-platform-openapi.json operations: [brandsListGET, brandsGET, brandsIdExistGET, brandsIdGET, brandsIdSSOPOST, brandsIdPUT] consequence: writes-tenant-authentication-configuration escalation: human-approval-required note: >- Deliberately EXCLUDES brandsPOST, brandsDELETE and brandsIdMigratePOST — creating, deleting and migrating a tenant are not configuration changes and have no undo. - name: coorpacademy-ingest-external-content file: coorpacademy-ingest-external-content.md api: Coorpacademy Content API (+ External, SCORM services) base_url: https://content.coorpacademy.com/api/v2 spec: openapi/coorpacademy-content-openapi.json operations: [findExternalCourses, createExternalCourse, findExternalContents, createExternalContent, bulkExternalContentUPSERT, bulkExternalContentsGETAll, bulkExternalContentGET, generateMetadataReport, externalPOST, presignedUrlPOST, presignedBulkUrlPOST] consequence: writes-learner-facing-content escalation: human-approval-required-for-bulk note: >- Spans three services with three different auth arrangements, and flags the External spec's staging server, which points at the H5P service's path. operations_deliberately_excluded: - surface: 'mail (27 operations, all POST)' reason: >- Every operation sends a real email to a real learner. No idempotency key, and only 200/500 are declared — a 500 does not tell you whether the message was already handed to Mandrill. No skill wraps this service; a retry duplicates a learner-facing message. - surface: 'platform: brandsPOST, brandsDELETE, brandsIdMigratePOST' reason: Tenant creation, deletion and cluster migration. Destructive at the customer level, no undo. - surface: 'progression writes: movePOST, answersPOST, askCluePOST, viewResourcePOST, extraLifeAcceptedPOST, extraLifeRefusedPOST, currentFromDynamodbForUserPOST' reason: >- Mutate a learner's recorded performance. Return 409 on state drift, requiring a read-modify-retry loop with no replay-safe primitive. Belong to the player runtime, not to an integration agent. cross_cutting_rules: authentication: >- Five different API-key header names across the estate — `authorization` (content, review), `Authorization` (content-scorm, mail, scorm), `token` (h5p, scim), `authentication` (platform, progression, progression-aggregations), `Api-Secret` (mobile). Three services declare none at all. No OAuth, no OIDC, no bearer tokens, no scopes. See authentication/coorpacademy-authentication.yml. idempotency: >- Does not exist. Zero matches for "idempoten" across 96 paths and 155 operations. Never blind-retry a POST. See conventions/coorpacademy-conventions.yml. rate_limits: >- Not published and not signalled. No 429 declared on any operation, no RateLimit-*/Retry-After header observed live. Self-throttle. See rate-limits/coorpacademy-rate-limits.yml. errors: >- Three incompatible envelopes, no application/problem+json, and `code` was the literal string "server_error" on every live body observed including a 401. Branch on HTTP status, never on `code`. See errors/coorpacademy-problem-types.yml. tenancy: >- Everything is brand/repository-scoped. Know which tenant you are acting for before any call. change_detection: >- No webhooks, no AsyncAPI, no xAPI/LRS. Polling is the only mechanism. See asyncapi/coorpacademy-event-surface.yml. identifiers: >- Content is addressed by the composite natural key (repository, ref, version) — no ids, no URNs, no UUIDs, no id prefixes. See data-model/coorpacademy-data-model.yml. pointers_emitted: - type: AgentSkill url: skills/_index.yml