Canopy Connect · OpenAPI Overlay 1.0.0

API Evangelist enhancements for the Canopy Connect API

5 actions 5 updates update extends ../openapi/canopy-openapi.json
Generated by API Evangelist Written by API Evangelist tooling for Canopy Connect's API. It is a proposal applied on top of the contract, not a document Canopy Connect publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-replaced-byx-deprecation-sourcex-apis-io-providerx-api-catalogx-llms-txtx-mcp-serverx-documentationCanopyAppsOAuth2

Targets 5

$.info
$.components.securitySchemes
$.paths['/health'].get
$.paths['/teams/{teamId}/pulls/{pullId}/documents/{documentId}/pdf'].get
$.paths['/policyforms/{policyFormId}/pdf'].get

OpenAPI Overlay

Raw ↑
overlay: 1.0.0
info:
  title: API Evangelist enhancements for the Canopy Connect API
  version: 1.0.0
extends: ../openapi/canopy-openapi.json
x-provenance:
  generated: '2026-09-05'
  method: generated
  source: >-
    Derived from openapi/canopy-openapi.json plus the Canopy Connect docs
    (authentication-guide, apps-api-requests, apps-authorization,
    sandbox-credentials, about-webhooks). Captures API Evangelist annotations
    only; the original specification is never mutated.
actions:
  - target: $.info
    description: Record the machine-readable discovery surface and the OAuth App flow the base spec omits.
    update:
      x-apis-io-provider: canopy
      x-api-catalog: https://docs.usecanopy.com/.well-known/api-catalog
      x-llms-txt: https://docs.usecanopy.com/llms.txt
      x-mcp-server: https://docs.usecanopy.com/mcp
      x-documentation: https://docs.usecanopy.com/reference/getting-started
  - target: $.components.securitySchemes
    description: >-
      Add the OAuth 2.0 Apps flow. The published spec declares only BasicAuth,
      but https://docs.usecanopy.com/reference/apps-authorization documents an
      authorization-code + PKCE flow at https://app.usecanopy.com/oauth2/authorize
      with twelve named scopes, used by third-party Apps acting on another
      Team's behalf.
    update:
      CanopyAppsOAuth2:
        type: oauth2
        description: >-
          OAuth 2.0 authorization code flow with mandatory PKCE, used by Canopy
          Connect Apps to call the API on behalf of another Team. Documented at
          https://docs.usecanopy.com/reference/apps-authorization - not declared
          in the provider's own OpenAPI.
        flows:
          authorizationCode:
            authorizationUrl: https://app.usecanopy.com/oauth2/authorize
            scopes:
              read:pulls: Read Pulls and the documents attached to them
              read:policy_checks: Read Policy Check settings and results
              write:policy_checks: Configure Policy Checks and evaluate them on a Pull
              read:webhooks: Read webhooks created by this App
              write:webhooks: Create, update and delete webhooks created by this App
              read:widgets: Read widgets (links)
              write:widgets: Create, update, delete widgets and upload their logo/icon
              read:driver_license_lookup: Call the driver licence enrichment lookup
              read:driving_record_iq_lookup: Call the driving-record IQ enrichment lookup
              read:household_lookup: Call the household enrichment lookup
              read:property_lookup: Call the property data enrichment lookup
              write:whitelabel: Drive the white-label consent, connect, IDV and servicing flows
  - target: $.paths['/health'].get
    description: Mark the health endpoint as the unauthenticated availability signal (verified live 2026-09-05, 200 {"healthy":true}).
    update:
      x-unauthenticated: true
      x-availability-probe: https://app.usecanopy.com/api/v1.0.0/health
  - target: $.paths['/teams/{teamId}/pulls/{pullId}/documents/{documentId}/pdf'].get
    description: Record the documented replacement for this deprecated operation.
    update:
      x-replaced-by: download-document-by-id
      x-deprecation-source: https://docs.usecanopy.com/reference/get-document-by-id
  - target: $.paths['/policyforms/{policyFormId}/pdf'].get
    description: Record the documented replacement for this deprecated operation.
    update:
      x-replaced-by: download-policy-form-by-id
      x-deprecation-source: https://docs.usecanopy.com/reference/get-policy-form-by-id