openapi: 3.1.0 info: title: Greenhouse Assessment Partner ActivityFeed Auth API description: 'The Assessment Partner API defines the contract that assessment vendors implement so Greenhouse can list available tests, send a test to a candidate, and retrieve the candidate''s results. Endpoints are hosted by the partner (not Greenhouse) and are secured with HTTP Basic over HTTPS. Greenhouse may also receive PATCH callbacks from the partner with completed test status; otherwise it polls `test_status` hourly for up to 8 weeks. API keys must be fewer than 171 characters. ' version: 1.0.0 contact: name: Greenhouse Software url: https://www.greenhouse.com email: developers@greenhouse.io servers: - url: https://{partner_host}/{base_path} description: Partner-hosted endpoint variables: partner_host: default: partner.example.com base_path: default: greenhouse-assessment security: - BasicAuth: [] tags: - name: Auth description: JWT access token issuance. paths: /jwt_access_token: post: tags: - Auth summary: Issue Audit Log Access Token description: Exchanges a Harvest API key (HTTP Basic) for a JWT bearer token valid for 24 hours. operationId: issueAuditAccessToken servers: - url: https://harvest.greenhouse.io/auth security: - HarvestBasic: [] responses: '200': description: Token issued. content: application/json: schema: type: object properties: access_token: type: string token_type: type: string example: Bearer expires_in: type: integer description: Seconds until expiration. components: securitySchemes: BasicAuth: type: http scheme: basic description: HTTP Basic; the API key is Base64-encoded and used as the username (key must be <171 chars).