Opply api API

The api API from Opply — 122 operation(s) for api.

Operations 176

GET /api/schema/ #
POST /api/v1/agents/agent-task-runs/{run_uuid}/claim/ #
POST /api/v1/agents/agent-task-runs/{run_uuid}/complete/ #
POST /api/v1/agents/agent-task-runs/{run_uuid}/heartbeat/ #
POST /api/v1/agents/buyer-onboarding/invocations/ #
POST /api/v1/agents/feedback/ #
POST /api/v1/agents/opply-assistant/invocations/ #
GET /api/v1/agents/opply-assistant/sessions/me/ #
DELETE /api/v1/agents/opply-assistant/sessions/me/ #
GET /api/v1/agents/opply-assistant/sessions/me/events/ #
POST /api/v1/agents/unleashed-invoice-assistant/invocations/ #
POST /api/v1/agents/xero-invoice-assistant/invocations/ #
GET /api/v1/agreements/lead-generation-jobs/ #
POST /api/v1/agreements/lead-generation-jobs/ #
GET /api/v1/app-orders/alerts/ #
GET /api/v1/app-orders/brand/order-adjustments/ #
GET /api/v1/app-orders/brand/order-adjustments/{uuid}/ #
GET /api/v1/app-orders/forecasts/ #
GET /api/v1/app-orders/merchant-of-record/order-adjustments/ #
POST /api/v1/app-orders/merchant-of-record/order-adjustments/ Create a new OrderAdjustment in AVAILABLE state (multipart upload) #
GET /api/v1/app-orders/merchant-of-record/order-adjustments/{uuid}/ #
POST /api/v1/app-orders/merchant-of-record/order-adjustments/{uuid}/apply/ Apply an AVAILABLE adjustment to a target order #
POST /api/v1/app-orders/merchant-of-record/order-adjustments/{uuid}/finalise/ Finalise a PENDING_APPLICATION adjustment now that the target invoice exists #
GET /api/v1/app-orders/merchant-of-record/order-adjustments/{uuid}/supplier-document/ Download the supplier-uploaded credit/debit note file #
POST /api/v1/app-orders/merchant-of-record/order-adjustments/{uuid}/void/ Void an adjustment (idempotent on already-VOID rows) #
GET /api/v1/companies/document-types/ #
GET /api/v1/companies/document-types/{uuid}/ #
GET /api/v1/companies/mor/onboarding-suppliers/{uuid}/notes/ #
POST /api/v1/companies/mor/onboarding-suppliers/{uuid}/notes/ #
GET /api/v1/companies/mor/onboarding-suppliers/{uuid}/notes/{note_uuid}/ #
PUT /api/v1/companies/mor/onboarding-suppliers/{uuid}/notes/{note_uuid}/ #
DELETE /api/v1/companies/mor/onboarding-suppliers/{uuid}/notes/{note_uuid}/ #
GET /api/v1/companies/mor/suppliers/{uuid}/notes/ #
POST /api/v1/companies/mor/suppliers/{uuid}/notes/ #
GET /api/v1/companies/mor/suppliers/{uuid}/notes/{note_uuid}/ #
PUT /api/v1/companies/mor/suppliers/{uuid}/notes/{note_uuid}/ #
DELETE /api/v1/companies/mor/suppliers/{uuid}/notes/{note_uuid}/ #
GET /api/v1/companies/supplier-document-types/ #
GET /api/v1/companies/supplier-document-types/{uuid}/ #
GET /api/v1/companies/suppliers/{supplier_uuid}/supplier-documents/ #
POST /api/v1/companies/suppliers/{supplier_uuid}/supplier-documents/ #
GET /api/v1/companies/suppliers/{supplier_uuid}/supplier-documents/{uuid}/ #
PUT /api/v1/companies/suppliers/{supplier_uuid}/supplier-documents/{uuid}/ #
PATCH /api/v1/companies/suppliers/{supplier_uuid}/supplier-documents/{uuid}/ #
DELETE /api/v1/companies/suppliers/{supplier_uuid}/supplier-documents/{uuid}/ #
GET /api/v1/companies/suppliers/{supplier_uuid}/supplier-documents/available-sites/ Get available sites for document upload #
GET /api/v1/companies/suppliers/{supplier_uuid}/supplier-documents/available-types/ #
GET /api/v1/companies/suppliers/{supplier_uuid}/supplier-documents/sites/ #
GET /api/v1/cortex/jobs/ #
POST /api/v1/cortex/jobs/ #
GET /api/v1/cortex/jobs/{uuid}/ #
PUT /api/v1/cortex/jobs/{uuid}/ #
PATCH /api/v1/cortex/jobs/{uuid}/ #
DELETE /api/v1/cortex/jobs/{uuid}/ #
GET /api/v1/cortex/jobs/executing/ #
GET /api/v1/cortex/workflows/ #
POST /api/v1/cortex/workflows/ #
GET /api/v1/cortex/workflows/{uuid}/ #
PUT /api/v1/cortex/workflows/{uuid}/ #
PATCH /api/v1/cortex/workflows/{uuid}/ #
DELETE /api/v1/cortex/workflows/{uuid}/ #
GET /api/v1/crm/companies/ #
POST /api/v1/crm/companies/ #
DELETE /api/v1/crm/companies/{uuid}/ #
GET /api/v1/crm/companies/{uuid}/scoring-debug/ Get ICP scoring breakdown for a company #
POST /api/v1/crm/companies/bulk-import/ #
POST /api/v1/crm/companies/enrichment-run/{uuid}/callback/ Enrichment callback from the enrichment subsystem #
GET /api/v1/crm/companies/field-values/ #
POST /api/v1/crm/companies/hubspot-create-leads/ Create leads in HubSpot for selected companies #
GET /api/v1/crm/companies/hubspot-create-leads/{run_uuid}/status/ Get HubSpot Create Leads run status #
GET /api/v1/crm/companies/hubspot-owners/ List available HubSpot owners #
GET /api/v1/crm/companies/hubspot-pipelines/ List available HubSpot lead pipelines #
POST /api/v1/crm/companies/import-file/ #
GET /api/v1/crm/companies/import-file/status/{task_id}/ #
GET /api/v1/crm/contacts/ #
DELETE /api/v1/crm/contacts/{uuid}/ #
POST /api/v1/crm/contacts/{uuid}/enrich/ #
POST /api/v1/crm/contacts/{uuid}/request-enrichment/ #
POST /api/v1/crm/contacts/bulk-import/ #
GET /api/v1/crm/custom-columns/ #
POST /api/v1/crm/custom-columns/ #
GET /api/v1/crm/custom-columns/{uuid}/ #
PUT /api/v1/crm/custom-columns/{uuid}/ #
PATCH /api/v1/crm/custom-columns/{uuid}/ #
DELETE /api/v1/crm/custom-columns/{uuid}/ #
GET /api/v1/crm/enrichment-runs/ #
GET /api/v1/crm/enrichment-runs/{uuid}/ #
GET /api/v1/crm/hubspot-sync-runs/ #
GET /api/v1/crm/hubspot-sync-runs/{uuid}/ #
GET /api/v1/crm/import-runs/ #
GET /api/v1/crm/import-runs/{uuid}/ #
GET /api/v1/crm/saved-views/ #
POST /api/v1/crm/saved-views/ #
GET /api/v1/crm/saved-views/{uuid}/ #
PUT /api/v1/crm/saved-views/{uuid}/ #
PATCH /api/v1/crm/saved-views/{uuid}/ #
DELETE /api/v1/crm/saved-views/{uuid}/ #
POST /api/v1/crm/saved-views/{uuid}/enrich/ Trigger enrichment on a saved view #
GET /api/v1/crm/saved-views/{uuid}/enrich/{run_uuid}/status/ Get enrichment run status and progress #
POST /api/v1/crm/saved-views/{uuid}/hubspot-sync/ Re-trigger HubSpot View Sync for a saved view #
GET /api/v1/crm/saved-views/{uuid}/hubspot-sync/{run_uuid}/status/ Get HubSpot View Sync run status and progress #
GET /api/v1/crm/settings/ #
PUT /api/v1/crm/settings/ #
PATCH /api/v1/crm/settings/ #
GET /api/v1/insights/{uuid}/ #
GET /api/v1/integrations/ #
GET /api/v1/integrations/{provider}/ #
DELETE /api/v1/integrations/{provider}/ #
POST /api/v1/integrations/{provider}/agent-token/ #
GET /api/v1/integrations/{provider}/callback/ #
POST /api/v1/integrations/{provider}/connect/ #
POST /api/v1/integrations/{provider}/verify/ #
POST /api/v1/integrations/plaid/disconnect/ #
POST /api/v1/integrations/plaid/exchange/ #
DELETE /api/v1/integrations/plaid/items/{item_uuid}/ #
POST /api/v1/integrations/plaid/webhook/ #
POST /api/v1/integrations/unleashed/connect/ #
POST /api/v1/integrations/unleashed/disconnect/ #
POST /api/v1/mcp #
DELETE /api/v1/mcp #
POST /api/v1/mcp/ #
DELETE /api/v1/mcp/ #
GET /api/v1/mcp/access-requests/ #
POST /api/v1/mcp/access-requests/ #
PATCH /api/v1/mcp/access-requests/{uuid}/review/ #
GET /api/v1/mcp/audit-log/ #
GET /api/v1/mcp/tools/ #
POST /api/v1/mcp/unleashed #
DELETE /api/v1/mcp/unleashed #
POST /api/v1/mcp/unleashed/ #
DELETE /api/v1/mcp/unleashed/ #
GET /api/v1/mcp/user-access/ #
POST /api/v1/mcp/user-access/ #
PATCH /api/v1/mcp/user-access/{uuid}/ #
DELETE /api/v1/mcp/user-access/{uuid}/ #
GET /api/v1/mcp/user-access/me/ #
POST /api/v1/mcp/zendesk #
DELETE /api/v1/mcp/zendesk #
POST /api/v1/mcp/zendesk/ #
DELETE /api/v1/mcp/zendesk/ #
GET /api/v1/oauth/applications/ #
POST /api/v1/oauth/applications/ #
DELETE /api/v1/oauth/applications/{id}/ #
POST /api/v1/oauth/register/ #
POST /api/v1/rapyd/cypress/create_beneficiary #
POST /api/v1/rapyd/cypress/force_kyb #
POST /api/v1/recommendations/ #
GET /api/v1/research/feedbacks/ #
POST /api/v1/research/feedbacks/ #
GET /api/v1/research/feedbacks/{uuid}/ #
PUT /api/v1/research/feedbacks/{uuid}/ #
PATCH /api/v1/research/feedbacks/{uuid}/ #
DELETE /api/v1/research/feedbacks/{uuid}/ #
GET /api/v1/taxonomy/get-tree/ Get category taxonomy #
GET /api/v2/notifications/company-overrides/ #
POST /api/v2/notifications/company-overrides/ #
GET /api/v2/notifications/company-overrides/{id}/ #
PATCH /api/v2/notifications/company-overrides/{id}/ #
DELETE /api/v2/notifications/company-overrides/{id}/ #
POST /api/v2/notifications/debug-dispatch/ #
GET /api/v2/notifications/me/ #
GET /api/v2/notifications/me/{uuid}/ #
POST /api/v2/notifications/me/{uuid}/archive/ #
POST /api/v2/notifications/me/{uuid}/read/ #
POST /api/v2/notifications/me/mark-all-read/ #
GET /api/v2/notifications/me/unread-count/ #
GET /api/v2/notifications/preferences/ #
POST /api/v2/notifications/preferences/ #
GET /api/v2/notifications/preferences/{id}/ #
PUT /api/v2/notifications/preferences/{id}/ #
PATCH /api/v2/notifications/preferences/{id}/ #
DELETE /api/v2/notifications/preferences/{id}/ #
GET /api/v2/notifications/preferences/categories/ #
PUT /api/v2/notifications/preferences/upsert/ #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/opply-api-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

opply-api-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Opply Activity Feed API
  version: 0.0.0
servers:
- url: https://api.opply.com
  description: Base URL declared by the provider in apis.yml (roadmap#122).
tags:
- name: api
paths:
  /api/schema/:
    get:
      operationId: api_schema_retrieve
      description: 'OpenApi3 schema for this API. Format can be selected via content negotiation.


        - YAML: application/vnd.oai.openapi

        - JSON: application/vnd.oai.openapi+json'
      parameters:
      - in: query
        name: format
        schema:
          type: string
          enum:
          - json
          - yaml
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      - {}
      responses:
        '200':
          content:
            application/vnd.oai.openapi:
              schema:
                type: object
                additionalProperties: {}
            application/yaml:
              schema:
                type: object
                additionalProperties: {}
            application/vnd.oai.openapi+json:
              schema:
                type: object
                additionalProperties: {}
            application/json:
              schema:
                type: object
                additionalProperties: {}
          description: ''
  /api/v1/agents/agent-task-runs/{run_uuid}/claim/:
    post:
      operationId: api_v1_agents_agent_task_runs_claim_create
      description: 'Atomic ``dispatching → running`` transition. The agent-side dedup point.


        Called by the task-runner harness immediately on workflow entry. The

        first invocation wins (status flips, 200 returned); any duplicate

        dispatch for the same ``run_uuid`` loses the status guard and gets

        409. Resolves the historical "delivery state unknown" ambiguity

        when the dispatcher''s POST to AgentCore times out and Celery

        autoretries — both invocations may execute, but only one claims.'
      parameters:
      - in: path
        name: run_uuid
        schema:
          type: string
          format: uuid
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          description: Claim succeeded — run advanced to running.
        '403':
          description: Run is not owned by the caller installation.
        '404':
          description: Run not found.
        '409':
          description: Lost claim race — run is not in dispatching.
  /api/v1/agents/agent-task-runs/{run_uuid}/complete/:
    post:
      operationId: api_v1_agents_agent_task_runs_complete_create
      description: Agent-only callback to mark an ``AgentTaskRun`` terminal.
      parameters:
      - in: path
        name: run_uuid
        schema:
          type: string
          format: uuid
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          description: Run marked terminal (idempotent on double-complete).
        '400':
          description: Invalid request body.
        '403':
          description: Run is not owned by the caller installation.
        '404':
          description: Run not found.
        '409':
          description: Run is not in running state — claim must precede complete.
  /api/v1/agents/agent-task-runs/{run_uuid}/heartbeat/:
    post:
      operationId: api_v1_agents_agent_task_runs_heartbeat_create
      description: 'Refresh ``last_heartbeat_at`` on a running run.


        Agent calls this every ~30s while executing. Single UPDATE — no

        SELECT, no transaction — at this cadence the cost matters. A 409

        response is the agent''s signal to abort its loop: the run has been

        re-dispatched as a fresh row, watchdog-timed-out, cancelled, or

        moved out of running for some other reason.'
      parameters:
      - in: path
        name: run_uuid
        schema:
          type: string
          format: uuid
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '204':
          description: Heartbeat refreshed.
        '409':
          description: Run is no longer in running state — agent should abort its loop.
  /api/v1/agents/buyer-onboarding/invocations/:
    post:
      operationId: api_v1_agents_buyer_onboarding_invocations_create
      description: "Streaming proxy for ``POST /api/v1/agents/buyer-onboarding/invocations/``.\n\nBody:\n  - ``prompt``: required str.\n  - ``session_id``: optional; defaults to a fresh ``opply-<uuid4hex>``.\n  - ``batch_uuid``: optional. When present, the proxy validates that\n    the batch belongs to ``request.user_company``, loads its invoices,\n    mints short-TTL presigned URLs, and forwards them as\n    ``invoices: [{uuid, filename, mime, signed_url, page_count}]`` in\n    the upstream payload. Cross-tenant attempts 404.\n\nResponse: ``text/event-stream`` of ``AgentStreamEvent`` frames — see\n``packages/agent-protocol/src/index.ts``. The agent emits the new\n``opplyExtractionStarted | Progress | Complete | Failed`` variants."
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          description: No response body
  /api/v1/agents/feedback/:
    post:
      operationId: api_v1_agents_feedback_create
      description: Create / upsert one feedback row per (user, agent_name, invocation_id).
      tags:
      - api
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AgentResponseFeedbackRequest'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/AgentResponseFeedbackRequest'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/AgentResponseFeedbackRequest'
        required: true
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentResponseFeedback'
          description: New feedback row.
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentResponseFeedback'
          description: Existing row updated (upsert).
        '400':
          description: Invalid request body or cross-polarity tag combination.
        '403':
          description: No company context on the request.
  /api/v1/agents/opply-assistant/invocations/:
    post:
      operationId: api_v1_agents_opply_assistant_invocations_create
      description: 'Streaming proxy for ``POST /api/v1/agents/opply-assistant/invocations/``.


        opply-assistant — orchestrator hosting the buyer-assistant worker. The

        request''s ``channel`` field selects the AgentCore version channel

        (``next`` → the candidate endpoint). See ``_AssistantInvocationsBaseView``

        for the shared chat-proxy contract (auth, throttling, response format,

        request body shape).'
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          description: No response body
  /api/v1/agents/opply-assistant/sessions/me/:
    get:
      operationId: api_v1_agents_opply_assistant_sessions_me_retrieve
      description: '``GET`` / ``DELETE`` the opply-assistant session pointer for the current user.


        See ``_AssistantSessionMeBaseView`` for the shared contract.'
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentSession'
          description: ''
        '204':
          description: No active session yet for this user.
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentDetailError'
          description: An active company is required to access agent sessions.
    delete:
      operationId: api_v1_agents_opply_assistant_sessions_me_destroy
      description: '``GET`` / ``DELETE`` the opply-assistant session pointer for the current user.


        See ``_AssistantSessionMeBaseView`` for the shared contract.'
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '204':
          description: Session cleared (idempotent — same response when no row existed).
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentDetailError'
          description: An active company is required to access agent sessions.
        '502':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentDetailError'
          description: Session clearing is temporarily unavailable. Please try again.
  /api/v1/agents/opply-assistant/sessions/me/events/:
    get:
      operationId: api_v1_agents_opply_assistant_sessions_me_events_retrieve
      description: '``GET`` the opply-assistant conversation transcript for the active session.


        See ``_AssistantSessionEventsBaseView`` for the shared contract.'
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentSessionMessages'
          description: ''
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentDetailError'
          description: An active company is required to access agent sessions.
  /api/v1/agents/unleashed-invoice-assistant/invocations/:
    post:
      operationId: api_v1_agents_unleashed_invoice_assistant_invocations_create
      description: "Streaming proxy for ``POST /api/v1/agents/unleashed-invoice-assistant/invocations/``.\n\nBody:\n  - ``session_id``: optional; defaults to a fresh ``opply-<uuid4hex>``.\n  - ``prompt``: optional; ignored by the agent but forwarded for parity.\n\nResponse: ``text/event-stream`` of ``AgentStreamEvent`` frames. The agent\nemits the ``opplyExtraction*`` variants itself."
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          description: No response body
  /api/v1/agents/xero-invoice-assistant/invocations/:
    post:
      operationId: api_v1_agents_xero_invoice_assistant_invocations_create
      description: "Streaming proxy for ``POST /api/v1/agents/xero-invoice-assistant/invocations/``.\n\nBody:\n  - ``session_id``: optional; defaults to a fresh ``opply-<uuid4hex>``.\n  - ``prompt``: optional; ignored by the agent but forwarded for parity.\n\nResponse: ``text/event-stream`` of ``AgentStreamEvent`` frames. The agent\nemits the ``opplyExtraction*`` variants itself."
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          description: No response body
  /api/v1/agreements/lead-generation-jobs/:
    get:
      operationId: api_v1_agreements_lead_generation_jobs_list
      description: GET and POST API endpoint for LeadGenerationJob - isolated feature
      parameters:
      - name: page
        required: false
        in: query
        description: A page number within the paginated result set.
        schema:
          type: integer
      - name: page_size
        required: false
        in: query
        description: Number of results to return per page.
        schema:
          type: integer
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedLeadGenerationJobList'
          description: ''
    post:
      operationId: api_v1_agreements_lead_generation_jobs_create
      description: GET and POST API endpoint for LeadGenerationJob - isolated feature
      tags:
      - api
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LeadGenerationJob'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/LeadGenerationJob'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/LeadGenerationJob'
        required: true
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LeadGenerationJob'
          description: ''
  /api/v1/app-orders/alerts/:
    get:
      operationId: api_v1_app_orders_alerts_list
      description: GET API endpoint for Alerts - isolated feature
      parameters:
      - name: page
        required: false
        in: query
        description: A page number within the paginated result set.
        schema:
          type: integer
      - name: page_size
        required: false
        in: query
        description: Number of results to return per page.
        schema:
          type: integer
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedAlertsList'
          description: ''
  /api/v1/app-orders/brand/order-adjustments/:
    get:
      operationId: api_v1_app_orders_brand_order_adjustments_list
      description: 'Buyer-side read access to OrderAdjustment.


        Buyers can list and fetch credit/debit notes that belong to their own

        company. VOID rows are hidden — they''re audit history with no buyer-facing

        value. Writes (create / apply / finalise / void) are MoR-only (sc-2888).

        The buyer-facing serializer also strips `supplier_document_url` so the

        supplier''s internal credit/debit note PDF never reaches the buyer.'
      parameters:
      - name: page
        required: false
        in: query
        description: A page number within the paginated result set.
        schema:
          type: integer
      - name: page_size
        required: false
        in: query
        description: Number of results to return per page.
        schema:
          type: integer
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedOrderAdjustmentListList'
          description: ''
  /api/v1/app-orders/brand/order-adjustments/{uuid}/:
    get:
      operationId: api_v1_app_orders_brand_order_adjustments_retrieve
      description: 'Buyer-side read access to OrderAdjustment.


        Buyers can list and fetch credit/debit notes that belong to their own

        company. VOID rows are hidden — they''re audit history with no buyer-facing

        value. Writes (create / apply / finalise / void) are MoR-only (sc-2888).

        The buyer-facing serializer also strips `supplier_document_url` so the

        supplier''s internal credit/debit note PDF never reaches the buyer.'
      parameters:
      - in: path
        name: uuid
        schema:
          type: string
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BuyerOrderAdjustmentDetail'
          description: ''
  /api/v1/app-orders/forecasts/:
    get:
      operationId: api_v1_app_orders_forecasts_list
      description: GET API endpoint for Forecast - isolated feature
      parameters:
      - name: page
        required: false
        in: query
        description: A page number within the paginated result set.
        schema:
          type: integer
      - name: page_size
        required: false
        in: query
        description: Number of results to return per page.
        schema:
          type: integer
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedForecastList'
          description: ''
  /api/v1/app-orders/merchant-of-record/order-adjustments/:
    get:
      operationId: api_v1_app_orders_merchant_of_record_order_adjustments_list
      description: 'MoR-facing endpoints for buyer credit/debit notes (OrderAdjustment).


        Lifecycle: AVAILABLE → APPLIED, AVAILABLE → PENDING_APPLICATION → APPLIED,

        or any → VOID. Provider integration (Stripe / Two) is dispatched by the

        `credit_note_service`; this viewset only orchestrates HTTP I/O and translates

        service-layer exceptions to 4xx responses.'
      parameters:
      - name: page
        required: false
        in: query
        description: A page number within the paginated result set.
        schema:
          type: integer
      - name: page_size
        required: false
        in: query
        description: Number of results to return per page.
        schema:
          type: integer
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedOrderAdjustmentListList'
          description: ''
    post:
      operationId: api_v1_app_orders_merchant_of_record_order_adjustments_create
      description: 'MoR-facing endpoints for buyer credit/debit notes (OrderAdjustment).


        Lifecycle: AVAILABLE → APPLIED, AVAILABLE → PENDING_APPLICATION → APPLIED,

        or any → VOID. Provider integration (Stripe / Two) is dispatched by the

        `credit_note_service`; this viewset only orchestrates HTTP I/O and translates

        service-layer exceptions to 4xx responses.'
      summary: Create a new OrderAdjustment in AVAILABLE state (multipart upload)
      tags:
      - api
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/OrderAdjustmentCreate'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/OrderAdjustmentCreate'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/OrderAdjustmentCreate'
        required: true
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrderAdjustmentDetail'
          description: ''
        '400':
          description: Validation error (invalid amounts, type, or unsupported provider)
        '404':
          description: Originating order not found in this MoR's scope
  /api/v1/app-orders/merchant-of-record/order-adjustments/{uuid}/:
    get:
      operationId: api_v1_app_orders_merchant_of_record_order_adjustments_retrieve
      description: 'MoR-facing endpoints for buyer credit/debit notes (OrderAdjustment).


        Lifecycle: AVAILABLE → APPLIED, AVAILABLE → PENDING_APPLICATION → APPLIED,

        or any → VOID. Provider integration (Stripe / Two) is dispatched by the

        `credit_note_service`; this viewset only orchestrates HTTP I/O and translates

        service-layer exceptions to 4xx responses.'
      parameters:
      - in: path
        name: uuid
        schema:
          type: string
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrderAdjustmentDetail'
          description: ''
  /api/v1/app-orders/merchant-of-record/order-adjustments/{uuid}/apply/:
    post:
      operationId: api_v1_app_orders_merchant_of_record_order_adjustments_apply_create
      description: 'MoR-facing endpoints for buyer credit/debit notes (OrderAdjustment).


        Lifecycle: AVAILABLE → APPLIED, AVAILABLE → PENDING_APPLICATION → APPLIED,

        or any → VOID. Provider integration (Stripe / Two) is dispatched by the

        `credit_note_service`; this viewset only orchestrates HTTP I/O and translates

        service-layer exceptions to 4xx responses.'
      summary: Apply an AVAILABLE adjustment to a target order
      parameters:
      - in: path
        name: uuid
        schema:
          type: string
        required: true
      tags:
      - api
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/OrderAdjustmentApply'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/OrderAdjustmentApply'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/OrderAdjustmentApply'
        required: true
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrderAdjustmentDetail'
          description: ''
        '400':
          description: Validation error (currency / provider mismatch, invoice state, etc.)
        '404':
          description: Target order not found in this MoR's scope
        '409':
          description: Invalid state transition (e.g. adjustment is not AVAILABLE)
  /api/v1/app-orders/merchant-of-record/order-adjustments/{uuid}/finalise/:
    post:
      operationId: api_v1_app_orders_merchant_of_record_order_adjustments_finalise_create
      description: 'MoR-facing endpoints for buyer credit/debit notes (OrderAdjustment).


        Lifecycle: AVAILABLE → APPLIED, AVAILABLE → PENDING_APPLICATION → APPLIED,

        or any → VOID. Provider integration (Stripe / Two) is dispatched by the

        `credit_note_service`; this viewset only orchestrates HTTP I/O and translates

        service-layer exceptions to 4xx responses.'
      summary: Finalise a PENDING_APPLICATION adjustment now that the target invoice exists
      parameters:
      - in: path
        name: uuid
        schema:
          type: string
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrderAdjustmentDetail'
          description: ''
        '400':
          description: Target invoice not yet ready or other validation error
        '409':
          description: Adjustment not in PENDING_APPLICATION state
  /api/v1/app-orders/merchant-of-record/order-adjustments/{uuid}/supplier-document/:
    get:
      operationId: api_v1_app_orders_merchant_of_record_order_adjustments_supplier_document_retrieve
      description: 'MoR-facing endpoints for buyer credit/debit notes (OrderAdjustment).


        Lifecycle: AVAILABLE → APPLIED, AVAILABLE → PENDING_APPLICATION → APPLIED,

        or any → VOID. Provider integration (Stripe / Two) is dispatched by the

        `credit_note_service`; this viewset only orchestrates HTTP I/O and translates

        service-layer exceptions to 4xx responses.'
      summary: Download the supplier-uploaded credit/debit note file
      parameters:
      - in: path
        name: uuid
        schema:
          type: string
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          description: The supplier-uploaded credit/debit note file
        '404':
          description: Supplier document not found
  /api/v1/app-orders/merchant-of-record/order-adjustments/{uuid}/void/:
    post:
      operationId: api_v1_app_orders_merchant_of_record_order_adjustments_void_create
      description: 'MoR-facing endpoints for buyer credit/debit notes (OrderAdjustment).


        Lifecycle: AVAILABLE → APPLIED, AVAILABLE → PENDING_APPLICATION → APPLIED,

        or any → VOID. Provider integration (Stripe / Two) is dispatched by the

        `credit_note_service`; this viewset only orchestrates HTTP I/O and translates

        service-layer exceptions to 4xx responses.'
      summary: Void an adjustment (idempotent on already-VOID rows)
      parameters:
      - in: path
        name: uuid
        schema:
          type: string
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrderAdjustmentDetail'
          description: ''
        '400':
          description: Validation error from the service layer (e.g. unsupported provider/type)
        '409':
          description: Concurrent state change between provider void and persist
  /api/v1/app-orders/trends/:
    get:
      operationId: api_v1_app_orders_trends_list
      description: GET API endpoint for Trends - isolated feature
      parameters:
      - name: page
        required: false
        in: query
        description: A page number within the paginated result set.
        schema:
          type: integer
      - name: page_size
        required: false
        in: query
        description: Number of results to return per page.
        schema:
          type: integer
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedTrendsList'
          description: ''
  /api/v1/companies/document-types/:
    get:
      operationId: api_v1_companies_document_types_list
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/DocumentType'
          description: ''
  /api/v1/companies/document-types/{uuid}/:
    get:
      operationId: api_v1_companies_document_types_retrieve
      parameters:
      - in: path
        name: uuid
        schema:
          type: string
          format: uuid
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DocumentType'
          description: ''
  /api/v1/companies/mor/onboarding-suppliers/{uuid}/notes/:
    get:
      operationId: api_v1_companies_mor_onboarding_suppliers_notes_list
      parameters:
      - in: path
        name: uuid
        schema:
          type: string
          format: uuid
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/MerchantOfRecordNote'
          description: ''
    post:
      operationId: api_v1_companies_mor_onboarding_suppliers_notes_create
      parameters:
      - in: path
        name: uuid
        schema:
          type: string
          format: uuid
        required: true
      tags:
      - api
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MerchantOfRecordNote'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/MerchantOfRecordNote'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/MerchantOfRecordNote'
        required: true
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MerchantOfRecordNote'
          description: ''
  /api/v1/companies/mor/onboarding-suppliers/{uuid}/notes/{note_uuid}/:
    get:
      operationId: api_v1_companies_mor_onboarding_suppliers_notes_retrieve
      parameters:
      - in: path
        name: note_uuid
        schema:
          type: string
          format: uuid
        required: true
      - in: path
        name: uuid
        schema:
          type: string
          format: uuid
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MerchantOfRecordNote'
          description: ''
    put:
      operationId: api_v1_companies_mor_onboarding_suppliers_notes_update
      parameters:
      - in: path
        name: note_uuid
        schema:
          type: string
          format: uuid
        required: true
      - in: path
        name: uuid
        schema:
          type: string
          format: uuid
        required: true
      tags:
      - api
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MerchantOfRecordNote'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/MerchantOfRecordNote'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/MerchantOfRecordNote'
        required: true
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MerchantOfRecordNote'
          description: ''
    delete:
      operationId: api_v1_companies_mor_onboarding_suppliers_notes_destroy
      parameters:
      - in: path
        name: note_uuid
        schema:
          type: string
          format: uuid
        required: true
      - in: path
        name: uuid
        schema:
          type: string
          format: uuid
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '204':
          description: No response body
  /api/v1/companies/mor/suppliers/{uuid}/notes/:
    get:
      operationId: api_v1_companies_mor_suppliers_notes_list
      parameters:
      - in: path
        name: uuid
        schema:
          type: string
          format: uuid
        required: true
      tags:
      - api
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/MerchantOfRecordNote'
          description: ''
    post:
      operationId: api_v1_companies_mor_suppliers_notes_create
      parameters:
      - in: path
        name: uuid
        schema:
          type: string
          format: uuid
        required: true
      tags:
      - api
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MerchantOfRecordNote'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/MerchantOfRecordNote'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/MerchantOfRecordNote'
        required: true
      security:
      - tokenAuth: []
      - cookieAuth: []
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MerchantOfRecordNote'
          description: ''
  /api/v1

# --- truncated at 32 KB (286 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/opply/refs/heads/main/openapi/opply-api-api-openapi.yml