openapi: 3.2.0 info: title: LDM v3 API Keys (tenant-scoped) API description: 'Multi-tenant B2B outreach automation platform. Auth: JWT Bearer (15-min) or tenant API key (ldm_*) managed in CRM Settings → API Keys. All tenant-scoped endpoints require the X-Tenant-Id header.' version: 1.0.0 contact: {} servers: - url: https://api.live-direct-marketing.online description: Production - url: https://api.dev.live-direct-marketing.online description: Development - url: http://127.0.0.1:3000 description: Local tags: - name: API Keys (tenant-scoped) paths: /api/api-keys: get: operationId: ApiKeysController_list parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: List tenant API keys (raw key value hidden) tags: - API Keys (tenant-scoped) post: operationId: ApiKeysController_create parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Create a new tenant API key. tags: - API Keys (tenant-scoped) /api/api-keys/whoami: get: operationId: ApiKeysController_whoami parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Check that the current Bearer credentials (API key or JWT) are valid, and learn… tags: - API Keys (tenant-scoped) /api/api-keys/{id}/reveal: get: operationId: ApiKeysController_reveal parameters: - name: id required: true in: path schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Reveal the raw value of an existing API key. tags: - API Keys (tenant-scoped) /api/api-keys/scopes/structured: get: operationId: ApiKeysController_structuredScopes parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Structured scope catalog for the API Keys UI wizard. tags: - API Keys (tenant-scoped) x-required-scope: - keys:read /api/api-keys/{id}: patch: operationId: ApiKeysController_update parameters: - name: id required: true in: path schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: 'Upgrade an existing API key in-place: set/unset Act-as-me.' tags: - API Keys (tenant-scoped) delete: operationId: ApiKeysController_remove parameters: - name: id required: true in: path schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Permanently delete a tenant API key tags: - API Keys (tenant-scoped) /api/api-keys/{id}/revoke: delete: operationId: ApiKeysController_revoke parameters: - name: id required: true in: path schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Revoke (deactivate) a tenant API key without deleting it tags: - API Keys (tenant-scoped) components: securitySchemes: jwt: scheme: bearer bearerFormat: JWT type: http description: JWT access token from /auth/login (Bearer ) tenant-api-key: scheme: bearer bearerFormat: JWT type: http description: Tenant API key (Bearer ldm_*) for MCP/A2A clients. Issued via CRM Settings → API Keys. rpa-service: scheme: bearer bearerFormat: JWT type: http description: Dedicated RPA service key. No tenant API-key or query-key authentication.