Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Headers

Idempotency-Key
string
required

Stable identity for this exact intent. Reuse it with the original body after an uncertain response.

Required string length: 16 - 128
Pattern: ^[ -~]+$

Path Parameters

orderId
string
required

Opaque organization-scoped identifier.

Body

application/json

Exact confirmation and optimistic resource/device versions.

expected_version
integer
required
Required range: x >= 1
resource_versions
object
required

Exact affected customer resource/device IDs and authoritative versions. Server validates completeness; hidden stock is guarded internally.

device_versions
object
required

Exact affected customer resource/device IDs and authoritative versions. Server validates completeness; hidden stock is guarded internally.

accepted_quote_id
string
required

Opaque organization-bound identifier.

Required string length: 1 - 128
Pattern: ^[A-Za-z0-9][A-Za-z0-9_-]*$
accepted_policy_version
string
required

Opaque organization-bound identifier.

Required string length: 1 - 128
Pattern: ^[A-Za-z0-9][A-Za-z0-9_-]*$

Response

Original command receipt. Follow status_url; acceptance is not payment, delivery or network proof.

Local durable acceptance only. Replay returns the same command/target and original accepted version, not a new side effect.

command_id
string
required

Opaque organization-bound identifier.

Required string length: 1 - 128
Pattern: ^[A-Za-z0-9][A-Za-z0-9_-]*$
target_type
enum<string>
required
Available options:
quote,
order,
proxy,
operation
target_id
string
required

Opaque organization-bound identifier.

Required string length: 1 - 128
Pattern: ^[A-Za-z0-9][A-Za-z0-9_-]*$
accepted_version
integer
required
Required range: x >= 1
status_url
string
required

Relative URL of stable readable target.

Pattern: ^/v1/
request_id
string
required

Opaque organization-bound identifier.

Required string length: 1 - 128
Pattern: ^[A-Za-z0-9][A-Za-z0-9_-]*$