Live Direct Marketing RPA service protocol API

The RPA service protocol API from Live Direct Marketing — 16 operation(s) for rpa service protocol.

Operations 16

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

GET /api/rpa/v1/readiness Read RPA queue and campaign readiness · Read scoped queue and campaign metadata without claiming, preparing or… #
Ask an LLM
“Can an RPA worker see what's queued without claiming any task?”
“How do I page through the full RPA queue readiness snapshot?”
Tell an agent
Show the RPA queue readiness snapshot.
Read the next page of RPA queue readiness after cursor {cursor}.
POST /api/rpa/v1/heartbeat Send an RPA worker heartbeat · Service heartbeat; include the complete task lease identity to extend a live… #
Ask an LLM
“How does an RPA worker signal it is still alive?”
“Can a heartbeat extend the lease on the task a worker holds?”
Tell an agent
Send a heartbeat for worker {workerId} on protocol {protocolVersion}.
Heartbeat worker {workerId} and extend task {taskId} on lease {leaseId}, protocol {protocolVersion}.
POST /api/rpa/v1/claim Claim the next RPA send task · Poll preparation: task:null while validating; placement-gated tasks begin… #
Ask an LLM
“How does an RPA worker pick up its next email send task?”
“Why does claiming an RPA task sometimes return a null task?”
Tell an agent
Claim the next send task for worker {workerId}.
Poll for a new RPA task as worker {workerId}.
POST /api/rpa/v1/start Start a claimed RPA send operation · Revalidate canonical send gates for the claimed operationId; send only when… #
Ask an LLM
“How does a worker confirm the send gates still pass before sending a claimed task?”
“When is an RPA worker actually allowed to send?”
Tell an agent
Start task {taskId} for worker {workerId} on lease {leaseId} with fencing token {fencingToken}.
Revalidate send gates for operation {operationId} on task {taskId}, worker {workerId}, lease {leaseId}, token {fencingToken}.
POST /api/rpa/v1/current Re-read the current RPA task and lease · Read the same task and lease after a CONTROL report or server placement poll… #
Ask an LLM
“After a control report, how does a worker re-read its current task without a second claim?”
“Can an RPA worker fetch the latest state of the task it already holds?”
Tell an agent
Read the current state of task {taskId} for worker {workerId}, lease {leaseId}, token {fencingToken}.
Re-fetch held task {taskId} and its lease {leaseId} as worker {workerId} with token {fencingToken}.
POST /api/rpa/v1/renew Renew an RPA task lease · Extend this worker’s live CLAIMED/STARTED/CONTROL_REPORTED/REAL_READY lease by… #
Ask an LLM
“How do I extend a live RPA task lease by another hour?”
“Can an expired RPA lease be renewed?”
Tell an agent
Renew lease {leaseId} on task {taskId} for worker {workerId}, token {fencingToken}.
Extend worker {workerId}'s lease {leaseId} on task {taskId} by 60 minutes using token {fencingToken}.
POST /api/rpa/v1/refresh Refresh attachment links for an RPA task · Refresh HTTPS attachment links and scoped relay context without changing… #
Ask an LLM
“My attachment links on an RPA task expired — can I refresh them?”
“Does refreshing an RPA task's context also extend its lease?”
Tell an agent
Refresh attachment links for task {taskId}, worker {workerId}, lease {leaseId}, token {fencingToken}.
Reload the relay context of task {taskId} for worker {workerId} on lease {leaseId} with token {fencingToken}.
POST /api/rpa/v1/report Report the outcome of an RPA send · Report one immutable CONTROL or REAL operation. #
Ask an LLM
“How does a worker report that a CONTROL or REAL send went through?”
“Does an accepted RPA report prove the email reached the inbox?”
Tell an agent
Report outcome {outcome} for task {taskId} on lease {leaseId}.
Report operation {operationId} on task {taskId}, lease {leaseId}, as {outcome} with provider message id {providerMessageId}.
POST /api/rpa/v1/profile-release Acknowledge the RPA browser profile is closed · Optional terminal-task browser-close acknowledgement. #
Ask an LLM
“How does a worker tell the server it closed the browser for a finished task?”
“Is acknowledging a browser profile release required?”
Tell an agent
Release the browser profile for finished task {taskId} as worker {workerId}, session closed {sessionClosed}.
Acknowledge the browser was closed for task {taskId} on lease {leaseId}.
POST /api/rpa/v1/return Return an RPA task that did not send · Return an execution known not to have sent. #
Ask an LLM
“What should a worker do with a task it knows it didn't send?”
“Can a returned RPA task be retried within its attempt budget?”
Tell an agent
Return task {taskId} on lease {leaseId} as not sent, outcome {outcome}.
Hand back unsent task {taskId} from worker {workerId} so it retries through the send gates.
POST /api/rpa/v1/reconciliation List a worker's unresolved RPA tasks · Read this worker’s unresolved tasks, up to 20 per authorized target. #
Ask an LLM
“Which of my RPA worker's tasks still have an uncertain outcome?”
“How many unresolved tasks per target does the reconciliation list return?”
Tell an agent
List unresolved tasks for worker {workerId}.
Show the next unresolved tasks for worker {workerId} after {after}.
POST /api/rpa/v1/reconcile Resolve an uncertain RPA send with evidence · Resolve an uncertain execution using positive sent evidence or retained… #
Ask an LLM
“How do I settle whether an uncertain RPA send actually went out?”
“What evidence is needed to reconcile an RPA execution?”
Tell an agent
Reconcile uncertain task {taskId} using {evidenceKind} evidence {evidenceId}.
Resolve task {taskId} on lease {leaseId} as {outcome} with proof {evidenceId}.
POST /api/rpa/v1/error Report an RPA execution error · Report a deduplicated execution error; obey the returned action, never replay… #
Ask an LLM
“How does a worker report an error during an RPA send?”
“Should a worker retry sending after reporting an uncertain error?”
Tell an agent
Report error {errorCode} at stage {stage} on task {taskId}.
Log execution error {errorCode} for task {taskId}, send attempted {sendAttempted}.
POST /api/rpa/v1/placement Attach seed-copy placement evidence to a task · Attach late seed-copy placement evidence; never evidence of recipient inbox… #
Ask an LLM
“How do I record where a seed copy of an RPA send landed?”
“Does seed placement evidence prove inbox placement for the real recipient?”
Tell an agent
Attach seed placement {placement} to task {taskId} with evidence {evidenceId}.
Record that the seed copy for task {taskId} landed in {placement}, measured at {measuredAt}.
GET /api/rpa/v1/attachments/{token}/{filename} Download an RPA attachment by token and filename · Download a lease-bound signed attachment with its original filename; legacy… #
Ask an LLM
“How does a worker download a signed task attachment with its original filename?”
“Can I fetch an RPA attachment using a URL that includes the file name?”
Tell an agent
Download the signed task attachment {filename} using token {token}.
Fetch the lease-bound attachment from its filename URL.
GET /api/rpa/v1/attachments/{token} Download an RPA attachment by legacy token URL · Download a lease-bound signed attachment with its original filename; legacy… #
Ask an LLM
“Do older token-only RPA attachment URLs still work?”
“Can a worker download an attachment with just the signed token?”
Tell an agent
Download the attachment for signed token {token} via the legacy token-only URL.
Fetch a lease-bound attachment from an old token-only link.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/live-direct-marketing-online:live-direct-marketing-online-rpa-service-protocol-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

live-direct-marketing-online-rpa-service-protocol-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: LDM v3 RPA service protocol API
  description: 'Multi-tenant B2B outreach automation platform. Auth: JWT Bearer (15-min) or tenant API key (ldm_*) managed in CRM Settings → API Keys. All tenant-scoped endpoints require the X-Tenant-Id header.'
  version: 1.0.0
  contact: {}
servers:
- url: https://api.live-direct-marketing.online
  description: Production
- url: https://api.dev.live-direct-marketing.online
  description: Development
- url: http://127.0.0.1:3000
  description: Local
tags:
- name: RPA service protocol
paths:
  /api/rpa/v1/readiness:
    get:
      operationId: RpaOutboxController_queueReadiness
      parameters:
      - name: cursor
        required: false
        in: query
        description: Use pagination.nextCursor from the preceding target page
        schema:
          maxLength: 512
          type: string
      - name: limit
        required: false
        in: query
        schema:
          minimum: 1
          maximum: 5
          default: 1
          type: number
      - name: campaignAfter
        required: false
        in: query
        description: Use campaigns.nextCampaignAfter, keeping the same target cursor
        schema:
          maxLength: 128
          type: string
      - name: campaignLimit
        required: false
        in: query
        schema:
          minimum: 1
          maximum: 20
          default: 5
          type: number
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      responses:
        '200':
          description: ''
      security:
      - rpa-service: []
      summary: Read scoped queue and campaign metadata without claiming, preparing or…
      tags:
      - RPA service protocol
  /api/rpa/v1/heartbeat:
    post:
      operationId: RpaOutboxController_heartbeat
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaHeartbeatDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Service heartbeat; include the complete task lease identity to extend a live…
      tags:
      - RPA service protocol
  /api/rpa/v1/claim:
    post:
      description: 'Full tasks include context: durable businessTask UUID and dialog/history links, frozen-render creative/brief references and explicitly mutable source bindings. Links target current CRM resources and require an owner session. Unavailable metadata is explicit. context is not an envelope, send permission, or report input; signed taskId remains the protocol identity.'
      operationId: RpaOutboxController_claim
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaWorkerDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: 'Poll preparation: task:null while validating; placement-gated tasks begin…'
      tags:
      - RPA service protocol
  /api/rpa/v1/start:
    post:
      description: Includes compact businessTask owner-navigation references, not a second envelope. Read full context from current/refresh; never replace signed taskId with businessTask.id.
      operationId: RpaOutboxController_start
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaLeaseDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Revalidate canonical send gates for the claimed operationId; send only when…
      tags:
      - RPA service protocol
  /api/rpa/v1/current:
    post:
      description: Includes the same context contract as claim. Frozen identities are tied to render.fingerprint/renderLeaseId; current names/URLs are not the frozen content. Metadata does not grant CRM access or permission to send.
      operationId: RpaOutboxController_current
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaLeaseDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Read the same task and lease after a CONTROL report or server placement poll…
      tags:
      - RPA service protocol
  /api/rpa/v1/renew:
    post:
      operationId: RpaOutboxController_renew
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaLeaseDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Extend this worker’s live CLAIMED/STARTED/CONTROL_REPORTED/REAL_READY lease by…
      tags:
      - RPA service protocol
  /api/rpa/v1/refresh:
    post:
      description: Refreshes context/current-resource availability without substituting live campaign creatives or briefs for the matching frozen render. Does not extend the lease.
      operationId: RpaOutboxController_refresh
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaLeaseDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Refresh HTTPS attachment links and scoped relay context without changing…
      tags:
      - RPA service protocol
  /api/rpa/v1/report:
    post:
      description: Acknowledgements include compact businessTask references only, never context in the receipt hash. A historical duplicate links its own archived execution/dialog or reports that link unavailable; it does not describe a new child. accepted is receipt acceptance, not proof of final accounting or recipient inbox delivery.
      operationId: RpaOutboxController_report
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaReportRequestDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Report one immutable CONTROL or REAL operation.
      tags:
      - RPA service protocol
  /api/rpa/v1/profile-release:
    post:
      operationId: RpaOutboxController_releaseProfile
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaProfileReleaseDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Optional terminal-task browser-close acknowledgement.
      tags:
      - RPA service protocol
  /api/rpa/v1/return:
    post:
      operationId: RpaOutboxController_returnTask
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaReturnDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Return an execution known not to have sent.
      tags:
      - RPA service protocol
  /api/rpa/v1/reconciliation:
    post:
      operationId: RpaOutboxController_reconciliation
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaReconciliationListDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Read this worker’s unresolved tasks, up to 20 per authorized target.
      tags:
      - RPA service protocol
  /api/rpa/v1/reconcile:
    post:
      operationId: RpaOutboxController_reconcile
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaReconcileDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Resolve an uncertain execution using positive sent evidence or retained…
      tags:
      - RPA service protocol
  /api/rpa/v1/error:
    post:
      operationId: RpaOutboxController_error
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaExecutionErrorDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Report a deduplicated execution error; obey the returned action, never replay…
      tags:
      - RPA service protocol
  /api/rpa/v1/placement:
    post:
      operationId: RpaOutboxController_placement
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RpaPlacementDto'
      responses:
        '201':
          description: ''
      security:
      - rpa-service: []
      summary: Attach late seed-copy placement evidence; never evidence of recipient inbox…
      tags:
      - RPA service protocol
  /api/rpa/v1/attachments/{token}/{filename}:
    get:
      operationId: RpaOutboxAttachmentController_download[0]
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      responses:
        '200':
          description: ''
      summary: Download a lease-bound signed attachment with its original filename; legacy…
      tags:
      - RPA service protocol
  /api/rpa/v1/attachments/{token}:
    get:
      operationId: RpaOutboxAttachmentController_download[1]
      parameters:
      - name: X-Tenant-Id
        in: header
        required: false
        schema:
          type: string
          format: uuid
        description: Tenant UUID — required for all tenant-scoped endpoints
      responses:
        '200':
          description: ''
      summary: Download a lease-bound signed attachment with its original filename; legacy…
      tags:
      - RPA service protocol
components:
  schemas:
    RpaReconcileDto:
      type: object
      properties:
        workerId:
          type: string
          minLength: 1
          maxLength: 128
        capabilityVersion:
          type: string
          maxLength: 64
          description: Required on placement-gated tasks and echoed in the durable receipt
        taskId:
          type: string
          minLength: 1
          maxLength: 4096
        leaseId:
          type: string
          minLength: 1
          maxLength: 128
        fencingToken:
          type: number
          minimum: 1
        operation:
          type: string
          enum:
          - CONTROL
          - REAL
          description: Required for placement-gated tasks; binds this receipt to one immutable phase.
        operationId:
          type: string
          maxLength: 128
          description: Immutable operation identity returned in the full claim.
        taskVersion:
          type: string
          maxLength: 128
        contentFingerprint:
          type: string
          maxLength: 128
        outcome:
          type: string
          enum:
          - SENT
          - DEFINITE_FAILURE
          - UNKNOWN
        relayAccountId:
          type: string
          minLength: 1
          maxLength: 128
        method:
          type: string
          enum:
          - RPA
        envelopeHash:
          type: string
          minLength: 64
          maxLength: 64
        occurredAt:
          type: string
        providerMessageId:
          type: string
          maxLength: 998
        headersApplied:
          type: boolean
        provider:
          type: string
          maxLength: 256
        sender:
          type: string
          maxLength: 320
          description: Sender mailbox from claim.envelope.from; display name is not part of sender identity.
        senderName:
          type: string
          maxLength: 320
          description: Optional display name. Does not authorize delivery or change receipt identity.
        eventId:
          type: string
          format: uuid
        evidenceKind:
          type: string
          enum:
          - PROVIDER_SENT
          - EXECUTOR_NOT_SENT
        evidenceId:
          type: string
          minLength: 1
          maxLength: 256
          description: Reference to retained executor/provider evidence. An empty Sent-folder search is not NOT_SENT evidence.
      required:
      - workerId
      - taskId
      - leaseId
      - fencingToken
      - outcome
      - relayAccountId
      - method
      - envelopeHash
      - occurredAt
      - headersApplied
      - eventId
      - evidenceKind
      - evidenceId
    RpaPlacementDto:
      type: object
      properties:
        workerId:
          type: string
          minLength: 1
          maxLength: 128
        capabilityVersion:
          type: string
          maxLength: 64
          description: Required on placement-gated tasks
        taskId:
          type: string
          minLength: 1
          maxLength: 4096
        leaseId:
          type: string
          minLength: 1
          maxLength: 128
        fencingToken:
          type: number
          minimum: 1
        operation:
          type: string
          enum:
          - CONTROL
          - REAL
        operationId:
          type: string
          maxLength: 128
        taskVersion:
          type: string
          maxLength: 128
        contentFingerprint:
          type: string
          maxLength: 128
        placement:
          type: string
          enum:
          - INBOX
          - SPAM
          - PROMOTIONS
          - NOT_RECEIVED
          - ERROR
        scope:
          type: string
          enum:
          - seed_copy
        provenance:
          type: string
          enum:
          - external_rpa
        correlation:
          type: string
          minLength: 1
          maxLength: 256
        evidenceId:
          type: string
          minLength: 1
          maxLength: 256
        measuredAt:
          type: string
        sentAt:
          type: string
      required:
      - workerId
      - taskId
      - leaseId
      - fencingToken
      - placement
      - scope
      - provenance
      - correlation
      - evidenceId
      - measuredAt
      - sentAt
    RpaProfileReleaseDto:
      type: object
      properties:
        workerId:
          type: string
          minLength: 1
          maxLength: 128
        capabilityVersion:
          type: string
          maxLength: 64
          description: Required for placement-gated tasks; legacy workers fail closed when omitted
        taskId:
          type: string
          minLength: 1
          maxLength: 4096
        leaseId:
          type: string
          minLength: 1
          maxLength: 128
        fencingToken:
          type: number
          minimum: 1
        operation:
          type: string
          enum:
          - CONTROL
          - REAL
        operationId:
          type: string
          maxLength: 128
        taskVersion:
          type: string
          maxLength: 128
        contentFingerprint:
          type: string
          maxLength: 128
        sessionClosed:
          type: number
          enum:
          - true
          description: Positive executor acknowledgement that this task browser session is closed. Mail reports alone do not release the profile before expiresAt.
      required:
      - workerId
      - taskId
      - leaseId
      - fencingToken
      - sessionClosed
    RpaLeaseDto:
      type: object
      properties:
        workerId:
          type: string
          minLength: 1
          maxLength: 128
        capabilityVersion:
          type: string
          maxLength: 64
          description: Required for placement-gated tasks; legacy workers fail closed when omitted
        taskId:
          type: string
          minLength: 1
          maxLength: 4096
        leaseId:
          type: string
          minLength: 1
          maxLength: 128
        fencingToken:
          type: number
          minimum: 1
        operation:
          type: string
          enum:
          - CONTROL
          - REAL
        operationId:
          type: string
          maxLength: 128
        taskVersion:
          type: string
          maxLength: 128
        contentFingerprint:
          type: string
          maxLength: 128
      required:
      - workerId
      - taskId
      - leaseId
      - fencingToken
    RpaReturnDto:
      type: object
      properties:
        workerId:
          type: string
          minLength: 1
          maxLength: 128
        capabilityVersion:
          type: string
          maxLength: 64
          description: Required on placement-gated tasks and echoed in the durable receipt
        taskId:
          type: string
          minLength: 1
          maxLength: 4096
        leaseId:
          type: string
          minLength: 1
          maxLength: 128
        fencingToken:
          type: number
          minimum: 1
        operation:
          type: string
          enum:
          - CONTROL
          - REAL
          description: Required for placement-gated tasks; binds this receipt to one immutable phase.
        operationId:
          type: string
          maxLength: 128
          description: Immutable operation identity returned in the full claim.
        taskVersion:
          type: string
          maxLength: 128
        contentFingerprint:
          type: string
          maxLength: 128
        outcome:
          type: string
          enum:
          - DEFINITE_FAILURE
        relayAccountId:
          type: string
          minLength: 1
          maxLength: 128
        method:
          type: string
          enum:
          - RPA
        envelopeHash:
          type: string
          minLength: 64
          maxLength: 64
        occurredAt:
          type: string
        providerMessageId:
          type: string
          maxLength: 998
        headersApplied:
          type: boolean
        provider:
          type: string
          maxLength: 256
        sender:
          type: string
          maxLength: 320
          description: Sender mailbox from claim.envelope.from; display name is not part of sender identity.
        senderName:
          type: string
          maxLength: 320
          description: Optional display name. Does not authorize delivery or change receipt identity.
      required:
      - workerId
      - taskId
      - leaseId
      - fencingToken
      - outcome
      - relayAccountId
      - method
      - envelopeHash
      - occurredAt
      - headersApplied
    RpaExecutionErrorDto:
      type: object
      properties:
        workerId:
          type: string
          minLength: 1
          maxLength: 128
        capabilityVersion:
          type: string
          maxLength: 64
          description: Required for placement-gated tasks; legacy workers fail closed when omitted
        taskId:
          type: string
          minLength: 1
          maxLength: 4096
        leaseId:
          type: string
          minLength: 1
          maxLength: 128
        fencingToken:
          type: number
          minimum: 1
        operation:
          type: string
          enum:
          - CONTROL
          - REAL
        operationId:
          type: string
          maxLength: 128
        taskVersion:
          type: string
          maxLength: 128
        contentFingerprint:
          type: string
          maxLength: 128
        eventId:
          type: string
          format: uuid
        stage:
          type: string
          enum:
          - PROFILE
          - OPEN_SITE
          - LOGIN
          - PREPARE
          - SEND
          - CONFIRM
        errorCode:
          type: string
          enum:
          - PROFILE_START_FAILED
          - WEBSITE_UNAVAILABLE
          - DNS_ERROR
          - TIMEOUT
          - AUTH_FAILED
          - TWO_FACTOR_REQUIRED
          - CAPTCHA_REQUIRED
          - ACCOUNT_BANNED
          - DELIVERY_UNCERTAIN
        sendAttempted:
          type: boolean
      required:
      - workerId
      - taskId
      - leaseId
      - fencingToken
      - eventId
      - stage
      - errorCode
      - sendAttempted
    RpaReconciliationListDto:
      type: object
      properties:
        workerId:
          type: string
          minLength: 1
          maxLength: 128
        capabilityVersion:
          type: string
          maxLength: 64
          description: Required for placement-gated tasks; legacy workers fail closed when omitted
        after:
          type: string
          description: Read the next page after this delivery ID, independently in each authorized target
      required:
      - workerId
    RpaHeartbeatDto:
      type: object
      properties:
        workerId:
          type: string
          minLength: 1
          maxLength: 128
        capabilityVersion:
          type: string
          maxLength: 64
          description: Required for placement-gated tasks; legacy workers fail closed when omitted
        protocolVersion:
          type: string
          enum:
          - '1'
        taskId:
          type: string
          minLength: 1
          maxLength: 4096
          description: Supply all three lease fields to extend a live task; omit all for service telemetry only
        leaseId:
          type: string
          minLength: 1
          maxLength: 128
        fencingToken:
          type: number
          minimum: 1
        operation:
          type: string
          enum:
          - CONTROL
          - REAL
        operationId:
          type: string
          maxLength: 128
        taskVersion:
          type: string
          maxLength: 128
        contentFingerprint:
          type: string
          maxLength: 128
      required:
      - workerId
      - protocolVersion
    RpaWorkerDto:
      type: object
      properties:
        workerId:
          type: string
          minLength: 1
          maxLength: 128
        capabilityVersion:
          type: string
          maxLength: 64
          description: Required for placement-gated tasks; legacy workers fail closed when omitted
      required:
      - workerId
    RpaReportRequestDto:
      type: object
      properties:
        taskId:
          type: string
          minLength: 1
          maxLength: 4096
        leaseId:
          type: string
          minLength: 1
          maxLength: 128
        outcome:
          type: string
          enum:
          - SENT
          - DEFINITE_FAILURE
          - UNKNOWN
        workerId:
          type: string
          minLength: 1
          maxLength: 128
        capabilityVersion:
          type: string
          maxLength: 64
          description: Required on placement-gated tasks and echoed in the durable receipt
        fencingToken:
          type: number
          minimum: 1
        operation:
          type: string
          enum:
          - CONTROL
          - REAL
          description: Required for placement-gated tasks; binds this receipt to one immutable phase.
        operationId:
          type: string
          maxLength: 128
          description: Immutable operation identity returned in the full claim.
        taskVersion:
          type: string
          maxLength: 128
        contentFingerprint:
          type: string
          maxLength: 128
        relayAccountId:
          type: string
          minLength: 1
          maxLength: 128
        method:
          type: string
          enum:
          - RPA
        envelopeHash:
          type: string
          minLength: 64
          maxLength: 64
        occurredAt:
          type: string
        providerMessageId:
          type: string
          maxLength: 998
        headersApplied:
          type: boolean
        provider:
          type: string
          maxLength: 256
        sender:
          type: string
          maxLength: 320
          description: Sender mailbox from claim.envelope.from; display name is not part of sender identity.
        senderName:
          type: string
          maxLength: 320
          description: Optional display name. Does not authorize delivery or change receipt identity.
      required:
      - taskId
      - leaseId
      - outcome
  securitySchemes:
    jwt:
      scheme: bearer
      bearerFormat: JWT
      type: http
      description: JWT access token from /auth/login (Bearer <token>)
    tenant-api-key:
      scheme: bearer
      bearerFormat: JWT
      type: http
      description: Tenant API key (Bearer ldm_*) for MCP/A2A clients. Issued via CRM Settings → API Keys.
    rpa-service:
      scheme: bearer
      bearerFormat: JWT
      type: http
      description: Dedicated RPA service key. No tenant API-key or query-key authentication.