openapi: 3.2.0 info: title: LDM v3 Tracking / Bot List API description: 'Multi-tenant B2B outreach automation platform. Auth: JWT Bearer (15-min) or tenant API key (ldm_*) managed in CRM Settings → API Keys. All tenant-scoped endpoints require the X-Tenant-Id header.' version: 1.0.0 contact: {} servers: - url: https://api.live-direct-marketing.online description: Production - url: https://api.dev.live-direct-marketing.online description: Development - url: http://127.0.0.1:3000 description: Local tags: - name: Tracking / Bot List paths: /api/bot-list: get: operationId: BotListController_stats parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Bot-list stats (feed count, custom CIDR/UA, last refresh). tags: - Tracking / Bot List /api/bot-list/refresh: post: operationId: BotListController_refresh parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Reload external bot-feeds now (BOT_FEED_URLS) into the in-memory matcher. tags: - Tracking / Bot List x-required-scope: - admin:write /api/bot-list/cidr: post: operationId: BotListController_addCidr parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Add a custom bot CIDR to the GLOBAL bot-list (e.g. tags: - Tracking / Bot List x-required-scope: - admin:write delete: operationId: BotListController_removeCidr parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Remove a custom bot CIDR from the GLOBAL bot-list. SUPER-only tags: - Tracking / Bot List x-required-scope: - admin:write /api/bot-list/ua: post: operationId: BotListController_addUa parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '201': description: '' security: - jwt: [] summary: Add a custom bot User-Agent regex to the GLOBAL bot-list (e.g. tags: - Tracking / Bot List x-required-scope: - admin:write delete: operationId: BotListController_removeUa parameters: - name: X-Tenant-Id in: header required: false schema: type: string format: uuid description: Tenant UUID — required for all tenant-scoped endpoints responses: '200': description: '' security: - jwt: [] summary: Remove a custom bot User-Agent regex from the GLOBAL bot-list. SUPER-only tags: - Tracking / Bot List x-required-scope: - admin:write components: securitySchemes: jwt: scheme: bearer bearerFormat: JWT type: http description: JWT access token from /auth/login (Bearer ) tenant-api-key: scheme: bearer bearerFormat: JWT type: http description: Tenant API key (Bearer ldm_*) for MCP/A2A clients. Issued via CRM Settings → API Keys. rpa-service: scheme: bearer bearerFormat: JWT type: http description: Dedicated RPA service key. No tenant API-key or query-key authentication.