Skip to content

OpenAPI

The generated OpenAPI JSON is the source of truth for public browser submission routes and the account-scoped Agency API.

It documents:

  • Public POST /f/{formKey} and POST /submit routes using hc_pub_ keys.
  • Agency routes rooted at /api/v1/accounts/{accountId} using account-owned Agency API keys.
  • Exact request, response, pagination, filter, revision, idempotency, and error schemas.
  • Required service capabilities in x-required-capabilities.

It intentionally excludes /api/app dashboard routes, credential-management endpoints, billing management, recipient management, test email, form duplication/deletion, submission mutations, provider integrations, and MCP internals.

Public form posts do not use bearer auth. Agency operations use:

Authorization: Bearer hc_live_REPLACE

The scheme represents an Agency API key only. A browser session, OAuth/MCP token, or legacy personal key cannot substitute for it.

Open raw OpenAPI JSON
View in Swagger UI

Generated clients must preserve opaque cursors, ETag/If-Match, and Idempotency-Key semantics. They should also surface X-Request-Id and honor Retry-After.