1Fort agent_runtime (v2) API

**Access:** requires a JWT access token.

OpenAPI Specification

1fort-agent-runtime-v2-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: 1Fort API Documentation agent_runtime (v2) agent_runtime (v2) API
  description: '# 1Fort API


    REST API for the 1Fort insurance platform. This document is the authoritative

    map of the API surface; endpoints are grouped in the sidebar by **app** and

    **version**, and large apps are split into per-resource sub-groups.


    ## Authentication


    Almost every endpoint requires a **JWT access token**. Send it in the

    `Authorization` header as either `Bearer <token>` or `JWT <token>`. Tokens may

    also be presented as an HTTP-only cookie. Endpoints documented with no security

    requirement are intentionally public (for example sign-in, OTP and storefront

    endpoints).


    ## Multi-tenancy


    Resources are scoped to a tenant. Nested routes carry the owning resource id in

    the path (for example `/v2/broker/{business_pk}/applications`); a token is only

    authorised for the businesses its user may access. Object-level permissions are

    enforced per endpoint.


    ## Versioning


    `v2` endpoints live under `/apis/v2/...` and are the current surface. `v1`

    endpoints remain documented for compatibility. Endpoints marked **deprecated**

    are scheduled for removal; prefer the documented replacement.

    '
  termsOfService: https://www.1fort.com/
  license:
    name: Privately owned
  version: v1
servers:
- url: https://api.1fort.com/apis/
security:
- Bearer: []
tags:
- name: agent_runtime (v2)
  x-displayName: Agent runtime (v2)
  description: '**Access:** requires a JWT access token.'
paths:
  /v2/broker/agent/businesses:
    parameters: []
    post:
      operationId: v2_broker_agent_businesses_create
      summary: POST /v2/broker/agent/businesses
      description: 'Create a business for the session''s broker directly from extracted document

        data, with no EmailInsured profile. Address/contacts are written as

        ParameterValue via the shared writer (same as the email business creator).'
      responses:
        '201':
          description: ''
        '403':
          description: Permission denied.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIException'
        '404':
          description: Object does not exist or caller has insufficient permissions to access it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIException'
        '500':
          description: Internal server error.
      tags:
      - agent_runtime (v2)
  /v2/broker/agent/businesses/find:
    parameters: []
    get:
      operationId: v2_broker_agent_businesses_find_list
      summary: GET /v2/broker/agent/businesses/find
      description: 'Broker-scoped business search (NOT profile search), backed by the broker''s

        OpenSearch index. The quote runtime uses this to find an existing business

        before creating one. Query params (all optional, pass what you have):

        `q`/`name`/`domain_name`/`address` fuzzy-match the name and full address;

        `state` and `postal_code` boost exact matches (postal is the strongest

        same-business signal); `limit` caps results (default 20, max 100). Returns

        `{count, results: [{id, name, domain_name, addresses}]}` ranked by relevance.'
      responses:
        '200':
          description: ''
        '500':
          description: Internal server error.
      tags:
      - agent_runtime (v2)
  /v2/broker/agent/businesses/{business_id}/update:
    parameters:
    - name: business_id
      in: path
      required: true
      schema:
        type: string
    post:
      operationId: v2_broker_agent_businesses_update_create
      summary: POST /v2/broker/agent/businesses/{business_id}/update
      description: 'Updates an existing business with details from source documents. Real model

        columns are written directly; address and contacts go to ParameterValue via

        the shared writer. Never creates a business.'
      responses:
        '201':
          description: ''
        '403':
          description: Permission denied.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIException'
        '404':
          description: Object does not exist or caller has insufficient permissions to access it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIException'
        '500':
          description: Internal server error.
      tags:
      - agent_runtime (v2)
  /v2/broker/agent/quotes/{quote_id}:
    parameters:
    - name: quote_id
      in: path
      required: true
      schema:
        type: string
    get:
      operationId: v2_broker_agent_quotes_read
      summary: GET /v2/broker/agent/quotes/{quote_id}
      description: 'Broker-scoped read of a draft quote (NOT profile-scoped). The runtime uses

        this to inspect what the draft already has before filling, so re-runs stay

        idempotent. Reads through the CoverageTermQuote proxy for the same flat

        fields the profile retrieve returns.'
      responses:
        '200':
          description: ''
        '403':
          description: Permission denied.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIException'
        '404':
          description: Object does not exist or caller has insufficient permissions to access it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIException'
        '500':
          description: Internal server error.
      tags:
      - agent_runtime (v2)
  /v2/broker/agent/quotes/{quote_id}/fill:
    parameters:
    - name: quote_id
      in: path
      required: true
      schema:
        type: string
    post:
      operationId: v2_broker_agent_quotes_fill_create
      summary: POST /v2/broker/agent/quotes/{quote_id}/fill
      description: 'Fills an existing draft quote in place from agent-extracted data, scoped to a

        business (no profile). Body: business_id + nested coverage_term + header

        fields. Creates the CoverageTerm and CoverageApplication only if the draft

        doesn''t already have them (idempotent re-runs).'
      responses:
        '201':
          description: ''
        '403':
          description: Permission denied.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIException'
        '404':
          description: Object does not exist or caller has insufficient permissions to access it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIException'
        '500':
          description: Internal server error.
      tags:
      - agent_runtime (v2)
  /v2/broker/agent/sessions/{session_pk}/files:
    parameters:
    - name: session_pk
      in: path
      required: true
      schema:
        type: string
    get:
      operationId: v2_broker_agent_sessions_files_list
      description: GET /v2/broker/agent/sessions/{session_pk}/files
      responses:
        '200':
          description: ''
        '500':
          description: Internal server error.
      tags:
      - agent_runtime (v2)
      summary: List Files
  /v2/broker/agent/sessions/{session_pk}/files/{file_pk}/content:
    parameters:
    - name: session_pk
      in: path
      required: true
      schema:
        type: string
    - name: file_pk
      in: path
      required: true
      schema:
        type: string
    get:
      operationId: v2_broker_agent_sessions_files_content_list
      description: GET /v2/broker/agent/sessions/{session_pk}/files/{file_pk}/content
      responses:
        '200':
          description: ''
        '500':
          description: Internal server error.
      tags:
      - agent_runtime (v2)
      summary: List Content
components:
  schemas:
    APIException:
      title: Generic API Error
      required:
      - detail
      type: object
      properties:
        detail:
          description: Error details
          type: string
  securitySchemes:
    Bearer:
      type: apiKey
      name: Authorization
      in: header
      description: JWT access token. Send as `Bearer <token>` or `JWT <token>`.
    ApiKey:
      type: apiKey
      name: Authorization
      in: header
      description: API key. Send as `Api-Key <key>`.
x-tagGroups:
- name: Agent runtime (v2)
  tags:
  - agent_runtime (v2)
- name: Analytics
  tags:
  - analytics
- name: Application
  tags:
  - 'application: applications'
  - 'application: clients'
- name: Application (v2)
  tags:
  - 'application (v2): applications'
  - 'application (v2): coverages'
- name: Ascend
  tags:
  - ascend
- name: Ascend (v2)
  tags:
  - ascend (v2)
- name: Authentication
  tags:
  - Authentication
  - auth
- name: Billing (v2)
  tags:
  - billing (v2)
- name: Broker
  tags:
  - broker
  - broker-ams-integration
  - broker-google
  - broker-office365
  - broker-office365-individual
  - 'broker: ai-customization-types'
  - 'broker: ai-customizations'
  - 'broker: clients'
  - 'broker: email_preferences'
  - 'broker: proposal-preferences'
  - 'broker: take-rates'
  - 'broker: user-ai-customizations'
  - 'broker: users'
  - broker_groups
  - broker_settings
- name: Broker (v2)
  tags:
  - 'broker (v2): applications'
  - 'broker (v2): clients'
  - 'broker (v2): coverages'
  - 'broker (v2): email-templates'
  - 'broker (v2): quote-policies'
  - 'broker (v2): quotes'
  - 'broker (v2): storefront'
  - 'broker (v2): team-users'
- name: Business
  tags:
  - business
  - business-broker-users
  - business-user
  - business_admin
- name: Carrier
  tags:
  - carrier
- name: Checkout
  tags:
  - checkout
- name: Email AI
  tags:
  - email_ai
- name: Email AI (v2)
  tags:
  - 'email_ai (v2): attachments'
  - 'email_ai (v2): carriers'
  - 'email_ai (v2): coverage-types'
  - 'email_ai (v2): emails'
  - 'email_ai (v2): gmail'
  - 'email_ai (v2): office365'
  - 'email_ai (v2): profiles'
  - 'email_ai (v2): wholesalers'
- name: Email AI Agent
  tags:
  - Email AI Agent
  - Email AI Agent - Attachments
  - Email AI Agent - Businesses
  - Email AI Agent - Entities
  - Email AI Agent - Markets
  - Email AI Agent - Profiles
  - Email AI Agent - Reference Data
- name: Google workspace (v2)
  tags:
  - google_workspace (v2)
- name: Herald (v2)
  tags:
  - herald (v2)
- name: Indications (v2)
  tags:
  - indications (v2)
- name: Insurance (v2)
  tags:
  - insurance (v2)
- name: Invite
  tags:
  - invite
- name: Legal
  tags:
  - legal
- name: Market
  tags:
  - Markets
  - Markets - Business
- name: Market (v2)
  tags:
  - market (v2)
- name: Office365 (v2)
  tags:
  - office365 (v2)
- name: Premium finance (v2)
  tags:
  - premium_finance (v2)
- name: Quote
  tags:
  - 'quote: applications'
  - 'quote: clients'
  - 'quote: quotes'
- name: Quote (v2)
  tags:
  - 'quote (v2): application'
  - 'quote (v2): binders'
  - 'quote (v2): checkout'
  - 'quote (v2): cios'
  - 'quote (v2): coverages'
  - 'quote (v2): quote-policies'
  - 'quote (v2): quotes'
  - 'quote (v2): tasks'
  - quote_ai (v2)
- name: Reports
  tags:
  - reports
- name: Reward
  tags:
  - reward
- name: Risk manager
  tags:
  - risk_manager
- name: Sanity check AI
  tags:
  - sanity_check_ai
- name: Storefront (v2)
  tags:
  - storefront (v2)
- name: Stripe
  tags:
  - stripe
- name: Suggestion AI
  tags:
  - suggestion_ai
- name: Treasury (v2)
  tags:
  - treasury (v2)
- name: User
  tags:
  - user
  - 'user: default-access-role'