openapi: 3.2.0 info: title: LDM v3 LinkedIn / Extension API description: 'Multi-tenant B2B outreach automation platform. Auth: JWT Bearer (15-min) or tenant API key (ldm_*) managed in CRM Settings → API Keys. All tenant-scoped endpoints require the X-Tenant-Id header.' version: 1.0.0 contact: {} servers: - url: https://api.live-direct-marketing.online description: Production - url: https://api.dev.live-direct-marketing.online description: Development - url: http://127.0.0.1:3000 description: Local tags: - name: LinkedIn / Extension API paths: /api/ext/linkedin/session: post: operationId: LinkedinExtApiController_session parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' summary: Upload/update a session (cookies from an authorized browser) tags: - LinkedIn / Extension API /api/ext/linkedin/next: get: operationId: LinkedinExtApiController_next parameters: - name: key required: true in: query schema: type: string - name: accountId required: true in: query schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' summary: Claim the next due action (atomically). Empty → 204 tags: - LinkedIn / Extension API /api/ext/linkedin/report: post: operationId: LinkedinExtApiController_report parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' summary: Report on an action execution tags: - LinkedIn / Extension API /api/ext/linkedin/events: post: operationId: LinkedinExtApiController_events parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' summary: Widget events (accept/reply/warning/challenge) tags: - LinkedIn / Extension API /api/ext/linkedin/config: get: operationId: LinkedinExtApiController_config parameters: - name: key required: true in: query schema: type: string - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' summary: 'Client config: toggles + guard-rails' tags: - LinkedIn / Extension API /api/ext/linkedin/heartbeat: post: operationId: LinkedinExtApiController_heartbeat parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' summary: Widget heartbeat (+optionally fresh cookies) tags: - LinkedIn / Extension API components: securitySchemes: jwt: scheme: bearer bearerFormat: JWT type: http description: JWT access token from /auth/login (Bearer ) tenant-api-key: scheme: bearer bearerFormat: JWT type: http description: Tenant API key (Bearer ldm_*) for MCP/A2A clients. Issued via CRM Settings → API Keys. rpa-service: scheme: bearer bearerFormat: JWT type: http description: Dedicated RPA service key. No tenant API-key or query-key authentication.