Euler Finance Auth API

Authentication and authorization conventions used across the API, including API keys, admin secrets, and rate-limit behavior.

Operations 13

GET /v3/auth/login Start platform-operator Google SSO #
GET /v3/auth/callback Complete platform-operator Google SSO callback #
GET /v3/auth/session Get current platform-operator session #
POST /v3/auth/logout End current platform-operator session #
POST /v3/platform-admins Grant platform-admin access #
POST /v3/platform-admins/revoke Revoke platform-admin access #
GET /v3/toolbox/admin/api-keys List API keys for toolbox Admin #
POST /v3/admin/api-keys Create an API key (admin) #
GET /v3/admin/api-keys List API keys (admin) #
GET /v3/admin/api-keys/{id} Get API key by id (admin) #
PATCH /v3/admin/api-keys/{id} Update API key (admin) #
DELETE /v3/admin/api-keys/{id} Revoke API key (admin) #
GET /v3/admin/api-keys/{id}/usage Usage stats for an API key (admin) #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/euler-auth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

euler-auth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Euler Data API (V3) Auth API
  version: 3.0.0
  description: API specification for Euler Data v3.
servers:
- url: /
  description: Current environment
security: []
tags:
- name: Auth
  description: Authentication and authorization conventions used across the API, including API keys, admin secrets, and rate-limit behavior.
paths:
  /v3/auth/login:
    get:
      tags:
      - Auth
      summary: Start platform-operator Google SSO
      description: Redirects the browser to Google OAuth/OIDC and sets a signed OAuth state cookie.
      x-status: implemented
      responses:
        '302':
          description: Redirect to configured Google OAuth authorization URL.
          headers:
            Location:
              description: Google authorization URL.
              schema:
                type: string
                format: uri
            Set-Cookie:
              description: Signed OAuth state cookie with httpOnly, SameSite, path, and expiry.
              schema:
                type: string
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
      operationId: startPlatformAuthLogin
  /v3/auth/callback:
    get:
      tags:
      - Auth
      summary: Complete platform-operator Google SSO callback
      description: Validates state, nonce, Google ID-token claims, and active platform-admin access.
      x-status: implemented
      parameters:
      - name: code
        in: query
        required: true
        schema:
          type: string
        description: OAuth authorization code. Never returned in responses.
      - name: state
        in: query
        required: true
        schema:
          type: string
        description: OAuth anti-forgery state bound to the signed state cookie.
      responses:
        '302':
          description: Successful callback; session and CSRF cookies are set, then browser is redirected.
          headers:
            Location:
              description: Configured post-login redirect URL.
              schema:
                type: string
                format: uri
            Set-Cookie:
              description: Signed httpOnly session cookie, readable CSRF cookie, and cleared OAuth state cookie.
              schema:
                type: string
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
        '400':
          description: Invalid callback, state, nonce, or ID token.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: Google identity is not an active platform admin.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      operationId: completePlatformAuthCallback
  /v3/auth/session:
    get:
      tags:
      - Auth
      summary: Get current platform-operator session
      x-status: implemented
      security:
      - PlatformSession: []
      responses:
        '200':
          description: Active platform-admin session identity.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                required:
                - data
                - meta
                properties:
                  data:
                    $ref: '#/components/schemas/PlatformAuthSession'
                  meta:
                    $ref: '#/components/schemas/PaginationMeta'
        '401':
          description: Missing, invalid, or expired platform-admin session.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: Authenticated session exists, but platform-admin access is not active.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      operationId: getPlatformAuthSession
  /v3/auth/logout:
    post:
      tags:
      - Auth
      summary: End current platform-operator session
      x-status: implemented
      security:
      - PlatformSession: []
        PlatformCsrf: []
      responses:
        '200':
          description: Session cookies were cleared.
          headers:
            Set-Cookie:
              description: Expired session and CSRF cookies.
              schema:
                type: string
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                required:
                - data
                - meta
                properties:
                  data:
                    type: object
                    required:
                    - loggedOut
                    properties:
                      loggedOut:
                        type: boolean
                  meta:
                    $ref: '#/components/schemas/PaginationMeta'
        '401':
          description: Invalid signed platform-admin session.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: Missing or mismatched CSRF token, or inactive platform-admin access.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      operationId: logoutPlatformAuthSession
  /v3/platform-admins:
    post:
      tags:
      - Auth
      summary: Grant platform-admin access
      description: 'Creates an active platform-admin access row for a Google email address.

        Requires a valid platform session and CSRF token because this is an unsafe

        cookie-authenticated write.'
      x-status: implemented
      security:
      - PlatformSession: []
        PlatformCsrf: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PlatformAdminAccessRequest'
      responses:
        '200':
          description: Existing revoked platform-admin access was reactivated.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                required:
                - data
                - meta
                properties:
                  data:
                    $ref: '#/components/schemas/PlatformAdminCreateAccessResult'
                  meta:
                    $ref: '#/components/schemas/PaginationMeta'
        '201':
          description: Platform-admin access was created.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                required:
                - data
                - meta
                properties:
                  data:
                    $ref: '#/components/schemas/PlatformAdminCreateAccessResult'
                  meta:
                    $ref: '#/components/schemas/PaginationMeta'
        '400':
          description: Malformed JSON request body.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Missing, invalid, or expired platform-admin session.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: Inactive platform-admin access, missing CSRF token, or mismatched CSRF token.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '409':
          description: Platform-admin access already exists.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '422':
          description: Missing or invalid Google email.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      operationId: createPlatformAdminAccess
  /v3/platform-admins/revoke:
    post:
      tags:
      - Auth
      summary: Revoke platform-admin access
      description: 'Soft-revokes platform-admin access for a Google email address. Requires a

        valid platform session and CSRF token because this is an unsafe

        cookie-authenticated write.'
      x-status: implemented
      security:
      - PlatformSession: []
        PlatformCsrf: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PlatformAdminAccessRequest'
      responses:
        '200':
          description: Platform-admin access was revoked.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                required:
                - data
                - meta
                properties:
                  data:
                    $ref: '#/components/schemas/PlatformAdminRevokeAccessResult'
                  meta:
                    $ref: '#/components/schemas/PaginationMeta'
        '400':
          description: Malformed JSON request body.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Missing, invalid, or expired platform-admin session.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: Inactive platform-admin access, missing CSRF token, or mismatched CSRF token.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: Platform-admin access was not found.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '409':
          description: Platform-admin access was already revoked.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '422':
          description: Missing or invalid Google email.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      operationId: revokePlatformAdminAccess
  /v3/toolbox/admin/api-keys:
    get:
      tags:
      - Auth
      summary: List API keys for toolbox Admin
      description: Lists API key metadata for the toolbox Admin screen. Requires an active platform-admin session and a Google email present in `TOOLBOX_ADMIN_EMAILS`.
      x-status: implemented
      security:
      - PlatformSession: []
      responses:
        '200':
          description: API key metadata visible to toolbox admins.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                required:
                - data
                - meta
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/ApiKeyResponse'
                  meta:
                    $ref: '#/components/schemas/PaginationMeta'
        '401':
          $ref: '#/components/responses/Error401'
        '403':
          $ref: '#/components/responses/Error403'
        '500':
          $ref: '#/components/responses/Error500'
      operationId: getToolboxAdminApiKeys
  /v3/admin/api-keys:
    post:
      tags:
      - Auth
      summary: Create an API key (admin)
      x-status: implemented
      security:
      - AdminSecret: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ApiKeyCreateRequest'
      responses:
        '201':
          description: API key created
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/ApiKeyCreateResponse'
        '400':
          $ref: '#/components/responses/Error400'
        '401':
          $ref: '#/components/responses/Error401'
        '403':
          $ref: '#/components/responses/Error403'
        '413':
          $ref: '#/components/responses/Error413'
        '415':
          $ref: '#/components/responses/Error415'
        '500':
          $ref: '#/components/responses/Error500'
      operationId: postAdminApiKeys
    get:
      tags:
      - Auth
      summary: List API keys (admin)
      x-status: implemented
      security:
      - AdminSecret: []
      responses:
        '200':
          description: API keys
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/ApiKeyResponse'
        '401':
          $ref: '#/components/responses/Error401'
        '403':
          $ref: '#/components/responses/Error403'
        '500':
          $ref: '#/components/responses/Error500'
      operationId: getAdminApiKeys
  /v3/admin/api-keys/{id}:
    get:
      tags:
      - Auth
      summary: Get API key by id (admin)
      x-status: implemented
      security:
      - AdminSecret: []
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: API key
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/ApiKeyResponse'
        '401':
          $ref: '#/components/responses/Error401'
        '403':
          $ref: '#/components/responses/Error403'
        '404':
          $ref: '#/components/responses/Error404'
        '500':
          $ref: '#/components/responses/Error500'
      operationId: getAdminApiKeysById
    patch:
      tags:
      - Auth
      summary: Update API key (admin)
      x-status: implemented
      security:
      - AdminSecret: []
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                rateLimit:
                  type: integer
                isActive:
                  type: boolean
                keyType:
                  type: string
                  enum:
                  - standard
                  - curator
                scopeMode:
                  type: string
                  enum:
                  - all_vaults
                  - allowlist
                vaultAllowlist:
                  type: array
                  items:
                    type: object
                    required:
                    - chainId
                    - vaultAddress
                    properties:
                      chainId:
                        type: integer
                      vaultAddress:
                        type: string
      responses:
        '200':
          description: Updated
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
        '400':
          $ref: '#/components/responses/Error400'
        '401':
          $ref: '#/components/responses/Error401'
        '403':
          $ref: '#/components/responses/Error403'
        '404':
          $ref: '#/components/responses/Error404'
        '413':
          $ref: '#/components/responses/Error413'
        '415':
          $ref: '#/components/responses/Error415'
        '500':
          $ref: '#/components/responses/Error500'
      operationId: patchAdminApiKeysById
    delete:
      tags:
      - Auth
      summary: Revoke API key (admin)
      x-status: implemented
      security:
      - AdminSecret: []
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Revoked
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
        '401':
          $ref: '#/components/responses/Error401'
        '403':
          $ref: '#/components/responses/Error403'
        '404':
          $ref: '#/components/responses/Error404'
        '500':
          $ref: '#/components/responses/Error500'
      operationId: deleteAdminApiKeysById
  /v3/admin/api-keys/{id}/usage:
    get:
      tags:
      - Auth
      summary: Usage stats for an API key (admin)
      x-status: implemented
      security:
      - AdminSecret: []
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      - name: days
        in: query
        required: false
        schema:
          type: integer
      responses:
        '200':
          description: Usage stats
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/ApiKeyUsageResponse'
        '401':
          $ref: '#/components/responses/Error401'
        '403':
          $ref: '#/components/responses/Error403'
        '404':
          $ref: '#/components/responses/Error404'
        '500':
          $ref: '#/components/responses/Error500'
      operationId: getAdminApiKeysByIdUsage
components:
  schemas:
    ApiKeyCreateResponse:
      type: object
      required:
      - message
      - key
      - keyPrefix
      - id
      - name
      - keyType
      - rateLimit
      properties:
        message:
          type: string
        key:
          type: string
        keyPrefix:
          type: string
        id:
          type: string
        name:
          type: string
        keyType:
          type: string
          enum:
          - standard
          - curator
        scopeMode:
          type: string
          enum:
          - all_vaults
          - allowlist
          nullable: true
        vaultAllowlist:
          type: array
          items:
            type: object
            required:
            - chainId
            - vaultAddress
            properties:
              chainId:
                type: integer
              vaultAddress:
                type: string
        rateLimit:
          type: integer
        expiresAt:
          type: string
          format: date-time
          nullable: true
    ApiKeyCreateRequest:
      type: object
      required:
      - name
      properties:
        name:
          type: string
        ownerEmail:
          type: string
          format: email
        keyType:
          type: string
          enum:
          - standard
          - curator
          default: standard
        scopeMode:
          type: string
          enum:
          - all_vaults
          - allowlist
        vaultAllowlist:
          type: array
          items:
            type: object
            required:
            - chainId
            - vaultAddress
            properties:
              chainId:
                type: integer
              vaultAddress:
                type: string
        rateLimit:
          type: integer
        expiresInDays:
          type: integer
    PlatformAdminRevokeAccessResult:
      type: object
      required:
      - admin
      - state
      properties:
        admin:
          $ref: '#/components/schemas/PlatformAdminAccess'
        state:
          type: string
          enum:
          - revoked
    PlatformAdminAccess:
      type: object
      required:
      - id
      - googleEmail
      - createdAt
      - revokedAt
      properties:
        id:
          type: string
          format: uuid
        googleEmail:
          type: string
          format: email
        createdAt:
          type: string
          format: date-time
        revokedAt:
          type: string
          format: date-time
          nullable: true
    ApiKeyUsageResponse:
      type: object
      required:
      - period
      - summary
      - endpoints
      properties:
        period:
          type: object
          required:
          - days
          - since
          properties:
            days:
              type: integer
            since:
              type: string
              format: date-time
        summary:
          type: object
          required:
          - totalRequests
          - avgResponseTimeMs
          - errorCount
          properties:
            totalRequests:
              type: integer
            avgResponseTimeMs:
              type: integer
            errorCount:
              type: integer
        endpoints:
          type: array
          items:
            type: object
            required:
            - endpoint
            - method
            - count
            - avgResponseTime
            properties:
              endpoint:
                type: string
              method:
                type: string
              count:
                type: integer
              avgResponseTime:
                type: integer
    ApiKeyResponse:
      type: object
      required:
      - id
      - name
      - keyType
      - rateLimit
      - isActive
      - createdAt
      properties:
        id:
          type: string
        keyPrefix:
          type: string
        name:
          type: string
        ownerEmail:
          type: string
          nullable: true
        keyType:
          type: string
          enum:
          - standard
          - curator
        scopeMode:
          type: string
          enum:
          - all_vaults
          - allowlist
          nullable: true
        vaultAllowlist:
          type: array
          items:
            type: object
            required:
            - chainId
            - vaultAddress
            properties:
              chainId:
                type: integer
              vaultAddress:
                type: string
        rateLimit:
          type: integer
        isActive:
          type: boolean
        createdAt:
          type: string
          format: date-time
        lastUsedAt:
          type: string
          format: date-time
          nullable: true
        expiresAt:
          type: string
          format: date-time
          nullable: true
    PlatformAdminCreateAccessResult:
      type: object
      required:
      - admin
      - state
      properties:
        admin:
          $ref: '#/components/schemas/PlatformAdminAccess'
        state:
          type: string
          enum:
          - created
          - reactivated
    ErrorResponse:
      type: object
      required:
      - error
      properties:
        error:
          type: object
          required:
          - code
          - message
          - requestId
          properties:
            code:
              type: string
              description: 'Domain error code. Examples:

                - INVALID_ADDRESS

                - CHAIN_NOT_SUPPORTED

                - VAULT_NOT_FOUND

                - TOKEN_NOT_FOUND

                - ACCOUNT_NOT_FOUND

                - VALIDATION_ERROR

                - RATE_LIMIT_EXCEEDED

                - UNSUPPORTED_MEDIA_TYPE

                - UNAUTHORIZED

                - FORBIDDEN

                - INTERNAL_ERROR

                '
            message:
              type: string
            requestId:
              type: string
            details:
              type: object
              additionalProperties: true
    PaginationMeta:
      type: object
      required:
      - timestamp
      properties:
        total:
          type: integer
          description: Exact total count when the endpoint provides one.
        hasMore:
          type: boolean
          description: Indicates whether another page exists beyond the current page.
        offset:
          type: integer
        limit:
          type: integer
          description: Echoed page size after endpoint-side clamping.
        timestamp:
          type: string
          format: date-time
        chainId:
          type: string
          description: Comma-separated chain IDs for multi-chain responses.
    PlatformAuthSession:
      type: object
      required:
      - platformAdminId
      - googleEmail
      - googleSubject
      - active
      - expiresAt
      properties:
        platformAdminId:
          type: string
          format: uuid
        googleEmail:
          type: string
          format: email
        googleSubject:
          type: string
        active:
          type: boolean
          const: true
        expiresAt:
          type: string
          format: date-time
    PlatformAdminAccessRequest:
      type: object
      additionalProperties: false
      required:
      - googleEmail
      properties:
        googleEmail:
          type: string
          format: email
          description: Google Workspace email address to grant or revoke.
  headers:
    X-Request-Id:
      description: Request identifier for tracing.
      schema:
        type: string
  responses:
    Error500:
      description: Internal server error
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Error403:
      description: Forbidden
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Error400:
      description: Bad request
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Error413:
      description: Request body too large
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Error415:
      description: Unsupported media type
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Error401:
      description: Unauthorized
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Error404:
      description: Not found
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key
      description: API key authentication (optional; higher rate limits).
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API key
      description: 'Alternative to X-API-Key using Authorization: Bearer <key>'
    AdminSecret:
      type: apiKey
      in: header
      name: X-Admin-Secret
      description: Admin secret (server-to-server) for API key management.
    PlatformSession:
      type: apiKey
      in: cookie
      name: euler_platform_session
      description: Signed, httpOnly platform-operator browser session cookie.
    PlatformCsrf:
      type: apiKey
      in: header
      name: X-CSRF-Token
      description: Double-submit CSRF token required for unsafe cookie-authenticated methods.