generated: '2026-07-21' method: derived source: openapi/ + https://developer.workspan.com authentication: style: OAuth 2.0 client-credentials bearer token (Authentication API) plus Azure API Management subscription key subscription_key: header: Ocp-Apim-Subscription-Key query: subscription-key bearer: Access token from POST /oauth/token (expires_in 3600, refresh_token issued) artifact: authentication/workspan-authentication.yml idempotency: supported: false note: No idempotency key or replay-safety contract is documented anywhere in the published APIs. pagination: style: mixed scim: params: - startIndex - count - filter note: SCIM 2.0 pagination/filtering on /Users note: Non-SCIM list endpoints (co-sell partners, report list) do not document pagination parameters. field_expansion: supported: false request_tracing: documented: false versioning: scheme: uri-path artifact: lifecycle/workspan-lifecycle.yml error_envelope: shape: 'plain JSON; APIM gateway errors use {"statusCode": n, "message": "..."}; OAuth errors use RFC 6749 {"error": "..."}' artifact: errors/workspan-problem-types.yml rate_limiting: signal: HTTP 429 documented on Co-Sell operations headers_documented: false bulk_semantics: note: Bulk API accepts JSON/CSV inline or JSON/CSV/XLSX file upload (upload_url flow), keyed by integration_id; status polled via GET /bulkload/status.