openapi: 3.2.0 info: title: LDM v3 IMAP Orchestrator API description: 'Multi-tenant B2B outreach automation platform. Auth: JWT Bearer (15-min) or tenant API key (ldm_*) managed in CRM Settings → API Keys. All tenant-scoped endpoints require the X-Tenant-Id header.' version: 1.0.0 contact: {} servers: - url: https://api.live-direct-marketing.online description: Production - url: https://api.dev.live-direct-marketing.online description: Development - url: http://127.0.0.1:3000 description: Local tags: - name: IMAP Orchestrator paths: /api/imap-orchestrator/stats: get: operationId: ImapOrchestratorController_getStats parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Get IMAP orchestrator dashboard stats tags: - IMAP Orchestrator x-required-scope: - imap:read /api/imap-orchestrator/jobs: get: operationId: ImapOrchestratorController_getJobs parameters: - name: accountId required: true in: query schema: type: string - name: status required: true in: query schema: type: string - name: limit required: true in: query schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: List recent IMAP orchestrator jobs tags: - IMAP Orchestrator x-required-scope: - imap:read /api/imap-orchestrator/fetch/{accountId}: post: operationId: ImapOrchestratorController_fetchAccount parameters: - name: accountId required: true in: path schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Manually trigger an IMAP fetch for a specific account tags: - IMAP Orchestrator /api/imap-orchestrator/attention: get: operationId: ImapOrchestratorController_getAttention parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: List email accounts needing manual intervention tags: - IMAP Orchestrator x-required-scope: - imap:read /api/imap-orchestrator/sync-health: get: operationId: ImapOrchestratorController_getSyncHealth parameters: - name: accountId required: true in: query schema: type: string - name: limit required: true in: query schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Get lossless mail sync cursor, staging and quarantine health tags: - IMAP Orchestrator x-required-scope: - imap:read /api/imap-orchestrator/sync-health/{id}/retry: post: operationId: ImapOrchestratorController_retryStagedMessage parameters: - name: id required: true in: path schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Retry a failed durable inbound message, or force a re-fetch of an exhausted… tags: - IMAP Orchestrator /api/imap-orchestrator/heal: post: operationId: ImapOrchestratorController_heal parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Auto-heal stuck GAS accounts and IMAP locks for the current tenant tags: - IMAP Orchestrator x-required-scope: - imap:write /api/imap-orchestrator/heal-all: post: operationId: ImapOrchestratorController_healAll parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Auto-heal stuck IMAP/GAS state across all tenants tags: - IMAP Orchestrator x-required-scope: - imap:write /api/imap-orchestrator/fetch-all: post: operationId: ImapOrchestratorController_fetchAll parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Trigger an IMAP fetch for every active account in the tenant tags: - IMAP Orchestrator x-required-scope: - imap:write /api/imap-orchestrator/tech-log: get: operationId: ImapOrchestratorController_getTechLog parameters: - name: limit required: true in: query schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Get the latest N IMAP job log entries for monitoring tags: - IMAP Orchestrator x-required-scope: - imap:read /api/imap-orchestrator/recent-dialogs: get: operationId: ImapOrchestratorController_getRecentDialogs parameters: - name: accountId required: true in: query schema: type: string - name: limit required: true in: query schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: List recently inserted inbound dialogs tags: - IMAP Orchestrator x-required-scope: - imap:read /api/imap-orchestrator/jobs/{id}: delete: operationId: ImapOrchestratorController_cancelJob parameters: - name: id required: true in: path schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Cancel an IMAP orchestrator job tags: - IMAP Orchestrator /api/imap-orchestrator/marking-overrides: get: operationId: ImapOrchestratorController_getOverrides parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: List dialog marking override rules tags: - IMAP Orchestrator x-required-scope: - imap:read post: operationId: ImapOrchestratorController_createOverride parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Create a dialog marking override rule tags: - IMAP Orchestrator x-required-scope: - imap:write /api/imap-orchestrator/marking-overrides/{id}: post: operationId: ImapOrchestratorController_updateOverride parameters: - name: id required: true in: path schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Update a dialog marking override rule tags: - IMAP Orchestrator delete: operationId: ImapOrchestratorController_deleteOverride parameters: - name: id required: true in: path schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Delete a dialog marking override rule tags: - IMAP Orchestrator /api/imap-orchestrator/marking-patterns: get: operationId: ImapOrchestratorController_getPatterns parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: List dialog marking regex patterns tags: - IMAP Orchestrator x-required-scope: - imap:read post: operationId: ImapOrchestratorController_createPattern parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Create a dialog marking regex pattern tags: - IMAP Orchestrator x-required-scope: - imap:write /api/imap-orchestrator/marking-patterns/{id}: post: operationId: ImapOrchestratorController_updatePattern parameters: - name: id required: true in: path schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Update a dialog marking regex pattern tags: - IMAP Orchestrator delete: operationId: ImapOrchestratorController_deletePattern parameters: - name: id required: true in: path schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Delete a dialog marking regex pattern tags: - IMAP Orchestrator /api/imap-orchestrator/health-accounts: get: operationId: ImapOrchestratorController_getHealthAccounts parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: 'Admin: list all email accounts across every tenant for health checks' tags: - IMAP Orchestrator x-required-scope: - imap:read /api/imap-orchestrator/health-test: post: operationId: ImapOrchestratorController_healthTest parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: 'Admin: run SMTP/IMAP connection test (or round-trip) for a specific account' tags: - IMAP Orchestrator x-required-scope: - imap:write /api/imap-orchestrator/admin/kill: post: operationId: ImapOrchestratorController_killImapCron parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Emergency stop for IMAP cron triggers (#6 Layer 4). tags: - IMAP Orchestrator x-required-scope: - admin:write /api/imap-orchestrator/admin/resume: post: operationId: ImapOrchestratorController_resumeImapCron parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Resume IMAP cron after a kill (#6 Layer 4) tags: - IMAP Orchestrator x-required-scope: - admin:write /api/imap-orchestrator/admin/health: get: operationId: ImapOrchestratorController_getImapHealth parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: IMAP orchestrator kill-switch state + queue counts (#6 Layer 4). tags: - IMAP Orchestrator x-required-scope: - admin:read /api/imap-orchestrator/conveyor-health: get: operationId: ImapOrchestratorController_getConveyorHealth parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: 'Per-step inbound conveyor health for this tenant (#336): fetch quarantine…' tags: - IMAP Orchestrator x-required-scope: - imap:read /api/imap-orchestrator/conveyor-watchdog/run: post: operationId: ImapOrchestratorController_runConveyorWatchdog parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: 'Run the conveyor watchdog tick across all tenants NOW (#336): measure every…' tags: - IMAP Orchestrator x-required-scope: - admin:write /api/imap-orchestrator/conveyor-watchdog/last: get: operationId: ImapOrchestratorController_getConveyorWatchdogLast parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Result of the last conveyor watchdog tick across all tenants (#336), without… tags: - IMAP Orchestrator x-required-scope: - admin:read components: securitySchemes: jwt: scheme: bearer bearerFormat: JWT type: http description: JWT access token from /auth/login (Bearer ) tenant-api-key: scheme: bearer bearerFormat: JWT type: http description: Tenant API key (Bearer ldm_*) for MCP/A2A clients. Issued via CRM Settings → API Keys. rpa-service: scheme: bearer bearerFormat: JWT type: http description: Dedicated RPA service key. No tenant API-key or query-key authentication.