OpenAPI
The generated OpenAPI JSON is the source of truth for public browser submission routes and the account-scoped Agency API.
It documents:
- Public
POST /f/{formKey}andPOST /submitroutes usinghc_pub_keys. - Agency routes rooted at
/api/v1/accounts/{accountId}using account-owned Agency API keys. - Exact request, response, pagination, filter, revision, idempotency, and error schemas.
- Required service capabilities in
x-required-capabilities.
It intentionally excludes /api/app dashboard routes, credential-management endpoints, billing management, recipient management, test email, form duplication/deletion, submission mutations, provider integrations, and MCP internals.
Security schemes
Section titled “Security schemes”Public form posts do not use bearer auth. Agency operations use:
Authorization: Bearer hc_live_REPLACEThe scheme represents an Agency API key only. A browser session, OAuth/MCP token, or legacy personal key cannot substitute for it.
Tooling
Section titled “Tooling”
Open raw OpenAPI JSON
View in Swagger UI
Generated clients must preserve opaque cursors, ETag/If-Match, and Idempotency-Key semantics. They should also surface X-Request-Id and honor Retry-After.