RunBuggy · OpenAPI Overlay 1.0.0

API Evangelist enhancements for the RunBuggy Authentication API

3 actions 3 updates update extends ../openapi/runbuggy-authentication.json
Generated by API Evangelist Written by API Evangelist tooling for RunBuggy's API. It is a proposal applied on top of the contract, not a document RunBuggy publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-environmentx-environment-notex-recovered-fromx-docs-node-statusx-consequencex-agentic-notex-token-lifetimex-rotation

Targets 2

$.info
$.paths['/login'].post

OpenAPI Overlay

Raw ↑
overlay: 1.0.0
info:
  title: API Evangelist enhancements for the RunBuggy Authentication API
  version: 1.0.0
extends: ../openapi/runbuggy-authentication.json
x-generated: '2026-08-05'
x-method: generated
x-source: openapi/runbuggy-authentication.json + https://docs.runbuggy.com/docs/shipping/b6b6c2d4906e9-authentication
x-note: 'Non-mutating record of API Evangelist findings. Provenance caveat: this
  definition is no longer reachable through the docs.runbuggy.com table of contents —
  the Client Generation guide still links to it, but that node returns 404. It was
  recovered verbatim from RunBuggy''s own public repository,
  github.com/runbuggyinc/api-doc-src (shippers/schemas/Auth.json).'
actions:
- target: $.info
  description: Record provenance and environment.
  update:
    x-environment: staging
    x-environment-note: Declared host ng-staging.runbuggy.com with basePath
      /staging/api/auth is a staging environment.
    x-recovered-from: https://github.com/runbuggyinc/api-doc-src/blob/master/shippers/schemas/Auth.json
    x-docs-node-status: 'The Stoplight node docs.runbuggy.com/docs/shipping/fe79c06697037-authentication-api,
      which the Client Generation guide links to, returned 404 on 2026-08-05. The
      Authentication service is missing from the published project table of contents.'
- target: $.paths['/login'].post
  description: Clarify what the token is for and how it is used.
  update:
    x-consequence: medium
    x-agentic-note: 'Returns the Bearer token every other RunBuggy operation requires.
      Send it as `Authorization: Bearer {token}` — the Orders and Companies definitions
      declare that header as an apiKey, so the "Bearer " prefix is the caller''s
      responsibility.'
    x-token-lifetime: not documented
    x-rotation: not documented
- target: $.info
  description: Note the auth surfaces this definition does NOT cover.
  update:
    x-uncovered-auth-surfaces:
    - 'order-status iframe: POST {host}/api/oauth2/token with body {"scope":"openid"},
      returns a 60-second JWT. Documented in prose only.'
    - 'mcp-datascience: full OAuth 2.1 with dynamic client registration and PKCE at
      https://apps.runbuggy.com/runbuggy/mcp-datascience — undocumented entirely.'