{
  "openapi": "3.1.1",
  "info": {
    "title": "HorizonSuite API Server",
    "version": "0.1.0",
    "description": "Connect, gRPC-Web, and native gRPC contracts for tenant administration, licensing, devices, and live sessions. Unary methods use ProtoJSON over HTTP POST. Bidirectional streaming methods require a native gRPC client.",
    "contact": {
      "name": "HorizonSuite",
      "url": "https://github.com/horizonsuite/api-documentation"
    }
  },
  "externalDocs": {
    "description": "Canonical Protocol Buffer contracts",
    "url": "https://github.com/horizonsuite/api-documentation/tree/main/proto"
  },
  "servers": [
    {
      "url": "https://api.horizonsuite.de",
      "description": "Production"
    }
  ],
  "tags": [
    {
      "name": "HealthService",
      "description": "Service health and release identity."
    },
    {
      "name": "CustomerAdminService",
      "description": "Tenant hierarchy, membership, roles, and restrictions."
    },
    {
      "name": "LicenseService",
      "description": "Device activation, entitlements, and live application sessions."
    },
    {
      "name": "BillingService",
      "description": "Trusted, idempotent billing event ingestion."
    }
  ],
  "paths": {
    "/horizon.api.v1.HealthService/Check": {
      "post": {
        "tags": [
          "HealthService"
        ],
        "summary": "Check",
        "description": "Liveness and version check for the public API service.",
        "operationId": "horizon.api.v1.HealthService.Check",
        "security": [],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/HealthRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HealthResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.CustomerAdminService/CreateCustomerAccount": {
      "post": {
        "tags": [
          "CustomerAdminService"
        ],
        "summary": "Create Customer Account",
        "description": "Creates or reconciles the contract account owned by the authenticated dashboard user.",
        "operationId": "horizon.api.v1.CustomerAdminService.CreateCustomerAccount",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateCustomerAccountRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/CustomerAccount"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.CustomerAdminService/CreateInstallationGroup": {
      "post": {
        "tags": [
          "CustomerAdminService"
        ],
        "summary": "Create Installation Group",
        "description": "Creates a group that shares device and module quotas across its installations.",
        "operationId": "horizon.api.v1.CustomerAdminService.CreateInstallationGroup",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateInstallationGroupRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/InstallationGroup"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.CustomerAdminService/CreateInstallation": {
      "post": {
        "tags": [
          "CustomerAdminService"
        ],
        "summary": "Create Installation",
        "description": "Creates an installation or site inside an installation group.",
        "operationId": "horizon.api.v1.CustomerAdminService.CreateInstallation",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/CreateInstallationRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Installation"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.CustomerAdminService/AssignRole": {
      "post": {
        "tags": [
          "CustomerAdminService"
        ],
        "summary": "Assign Role",
        "description": "Assigns a role at customer, group, or installation scope. Delegation is limited to the caller's own permissions.",
        "operationId": "horizon.api.v1.CustomerAdminService.AssignRole",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/AssignRoleRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AssignRoleResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.CustomerAdminService/RevokeRoleAssignment": {
      "post": {
        "tags": [
          "CustomerAdminService"
        ],
        "summary": "Revoke Role Assignment",
        "description": "Revokes one role assignment and terminates sessions that no longer remain authorized.",
        "operationId": "horizon.api.v1.CustomerAdminService.RevokeRoleAssignment",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RevokeRoleAssignmentRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RevokeRoleAssignmentResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.CustomerAdminService/InviteMember": {
      "post": {
        "tags": [
          "CustomerAdminService"
        ],
        "summary": "Invite Member",
        "description": "Creates or locates an Auth account and assigns it to a tenant scope.",
        "operationId": "horizon.api.v1.CustomerAdminService.InviteMember",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/InviteMemberRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/InviteMemberResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.CustomerAdminService/RemoveMember": {
      "post": {
        "tags": [
          "CustomerAdminService"
        ],
        "summary": "Remove Member",
        "description": "Revokes matching assignments and terminates affected live sessions.",
        "operationId": "horizon.api.v1.CustomerAdminService.RemoveMember",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RemoveMemberRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RemoveMemberResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.CustomerAdminService/ApplyScopeRestriction": {
      "post": {
        "tags": [
          "CustomerAdminService"
        ],
        "summary": "Apply Scope Restriction",
        "description": "Applies a fail-closed restriction to a customer, group, or installation scope.",
        "operationId": "horizon.api.v1.CustomerAdminService.ApplyScopeRestriction",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ApplyScopeRestrictionRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ApplyScopeRestrictionResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.CustomerAdminService/RemoveScopeRestriction": {
      "post": {
        "tags": [
          "CustomerAdminService"
        ],
        "summary": "Remove Scope Restriction",
        "description": "Removes a previously applied scope restriction.",
        "operationId": "horizon.api.v1.CustomerAdminService.RemoveScopeRestriction",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RemoveScopeRestrictionRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RemoveScopeRestrictionResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.CustomerAdminService/RestrictContractOwner": {
      "post": {
        "tags": [
          "CustomerAdminService"
        ],
        "summary": "Restrict Contract Owner",
        "description": "Coordinates an owner account restriction in Auth with a customer-wide service restriction in API.",
        "operationId": "horizon.api.v1.CustomerAdminService.RestrictContractOwner",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RestrictContractOwnerRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RestrictContractOwnerResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.CustomerAdminService/LiftContractRestriction": {
      "post": {
        "tags": [
          "CustomerAdminService"
        ],
        "summary": "Lift Contract Restriction",
        "description": "Removes the coordinated Auth and API restriction pair.",
        "operationId": "horizon.api.v1.CustomerAdminService.LiftContractRestriction",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/LiftContractRestrictionRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/LiftContractRestrictionResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.LicenseService/ActivateDevice": {
      "post": {
        "tags": [
          "LicenseService"
        ],
        "summary": "Activate Device",
        "description": "Activates an installation instance while atomically enforcing group and installation device quotas.",
        "operationId": "horizon.api.v1.LicenseService.ActivateDevice",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ActivateDeviceRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Device"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.LicenseService/DeactivateDevice": {
      "post": {
        "tags": [
          "LicenseService"
        ],
        "summary": "Deactivate Device",
        "description": "Deactivates a device and terminates its live sessions.",
        "operationId": "horizon.api.v1.LicenseService.DeactivateDevice",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/DeactivateDeviceRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/DeactivateDeviceResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.LicenseService/GetEntitlements": {
      "post": {
        "tags": [
          "LicenseService"
        ],
        "summary": "Get Entitlements",
        "description": "Returns effective modules, quota use, and restriction state for a device.",
        "operationId": "horizon.api.v1.LicenseService.GetEntitlements",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/GetEntitlementsRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/GetEntitlementsResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.api.v1.LicenseService/ConnectSession": {
      "post": {
        "tags": [
          "LicenseService"
        ],
        "summary": "Connect Session",
        "description": "Bidirectional native gRPC stream. The first client message is OPEN or RESUME; later messages are HEARTBEAT. Swagger UI cannot execute streaming RPCs.",
        "operationId": "horizon.api.v1.LicenseService.ConnectSession",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/SessionClientMessage"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Streaming response. Use a native gRPC client.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/SessionServerMessage"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        },
        "x-horizonsuite-streaming": "bidirectional",
        "x-horizonsuite-try-it-out": false
      }
    },
    "/horizon.api.v1.BillingService/ApplyBillingEvent": {
      "post": {
        "tags": [
          "BillingService"
        ],
        "summary": "Apply Billing Event",
        "description": "Applies an ordered, idempotent subscription event from a trusted billing backend.",
        "operationId": "horizon.api.v1.BillingService.ApplyBillingEvent",
        "security": [
          {
            "BillingServiceToken": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ApplyBillingEventRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ApplyBillingEventResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "HealthRequest": {
        "type": "object",
        "description": "Health Request encoded with ProtoJSON field names.",
        "properties": {},
        "additionalProperties": false
      },
      "HealthResponse": {
        "type": "object",
        "description": "Health Response encoded with ProtoJSON field names.",
        "properties": {
          "status": {
            "type": "string"
          },
          "service": {
            "type": "string"
          },
          "version": {
            "type": "string"
          }
        },
        "additionalProperties": false
      },
      "CreateCustomerAccountRequest": {
        "type": "object",
        "description": "Create Customer Account Request encoded with ProtoJSON field names.",
        "properties": {
          "displayName": {
            "type": "string"
          }
        },
        "additionalProperties": false,
        "required": [
          "displayName"
        ]
      },
      "CustomerAccount": {
        "type": "object",
        "description": "Customer Account encoded with ProtoJSON field names.",
        "properties": {
          "id": {
            "type": "string"
          },
          "displayName": {
            "type": "string"
          },
          "ownerAccountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "status": {
            "type": "string"
          },
          "createdAtUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          }
        },
        "additionalProperties": false
      },
      "CreateInstallationGroupRequest": {
        "type": "object",
        "description": "Create Installation Group Request encoded with ProtoJSON field names.",
        "properties": {
          "customerAccountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "displayName": {
            "type": "string"
          },
          "deviceLimit": {
            "type": "integer",
            "format": "int32"
          }
        },
        "additionalProperties": false,
        "required": [
          "customerAccountId",
          "displayName",
          "deviceLimit"
        ]
      },
      "InstallationGroup": {
        "type": "object",
        "description": "Installation Group encoded with ProtoJSON field names.",
        "properties": {
          "id": {
            "type": "string"
          },
          "customerAccountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "displayName": {
            "type": "string"
          },
          "deviceLimit": {
            "type": "integer",
            "format": "int32"
          },
          "activeDeviceCount": {
            "type": "integer",
            "format": "int32"
          },
          "status": {
            "type": "string"
          }
        },
        "additionalProperties": false
      },
      "CreateInstallationRequest": {
        "type": "object",
        "description": "Create Installation Request encoded with ProtoJSON field names.",
        "properties": {
          "installationGroupId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "displayName": {
            "type": "string"
          },
          "optionalDeviceLimit": {
            "type": "integer",
            "format": "int32"
          }
        },
        "additionalProperties": false,
        "required": [
          "installationGroupId",
          "displayName"
        ]
      },
      "Installation": {
        "type": "object",
        "description": "Installation encoded with ProtoJSON field names.",
        "properties": {
          "id": {
            "type": "string"
          },
          "installationGroupId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "displayName": {
            "type": "string"
          },
          "optionalDeviceLimit": {
            "type": "integer",
            "format": "int32"
          },
          "activeDeviceCount": {
            "type": "integer",
            "format": "int32"
          },
          "status": {
            "type": "string"
          }
        },
        "additionalProperties": false
      },
      "AssignRoleRequest": {
        "type": "object",
        "description": "Assign Role Request encoded with ProtoJSON field names.",
        "properties": {
          "accountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "roleKey": {
            "type": "string",
            "enum": [
              "OWNER",
              "GROUP_ADMIN",
              "INSTALLATION_ADMIN",
              "INSTALLATION_HELPER",
              "EMPLOYEE"
            ]
          },
          "scopeType": {
            "type": "string",
            "enum": [
              "CUSTOMER_ACCOUNT",
              "INSTALLATION_GROUP",
              "INSTALLATION"
            ]
          },
          "scopeId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "accountId",
          "roleKey",
          "scopeType",
          "scopeId"
        ]
      },
      "AssignRoleResponse": {
        "type": "object",
        "description": "Assign Role Response encoded with ProtoJSON field names.",
        "properties": {
          "assignmentId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false
      },
      "RevokeRoleAssignmentRequest": {
        "type": "object",
        "description": "Revoke Role Assignment Request encoded with ProtoJSON field names.",
        "properties": {
          "assignmentId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "correlationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "assignmentId",
          "correlationId"
        ]
      },
      "RevokeRoleAssignmentResponse": {
        "type": "object",
        "description": "Revoke Role Assignment Response encoded with ProtoJSON field names.",
        "properties": {
          "revoked": {
            "type": "boolean"
          },
          "terminatedSessions": {
            "type": "integer",
            "format": "int32"
          }
        },
        "additionalProperties": false
      },
      "InviteMemberRequest": {
        "type": "object",
        "description": "Invite Member Request encoded with ProtoJSON field names.",
        "properties": {
          "email": {
            "type": "string",
            "format": "email",
            "example": "person@example.com"
          },
          "displayName": {
            "type": "string"
          },
          "roleKey": {
            "type": "string",
            "enum": [
              "OWNER",
              "GROUP_ADMIN",
              "INSTALLATION_ADMIN",
              "INSTALLATION_HELPER",
              "EMPLOYEE"
            ]
          },
          "scopeType": {
            "type": "string",
            "enum": [
              "CUSTOMER_ACCOUNT",
              "INSTALLATION_GROUP",
              "INSTALLATION"
            ]
          },
          "scopeId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "email",
          "displayName",
          "roleKey",
          "scopeType",
          "scopeId"
        ]
      },
      "InviteMemberResponse": {
        "type": "object",
        "description": "Invite Member Response encoded with ProtoJSON field names.",
        "properties": {
          "accountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "assignmentId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "accountCreated": {
            "type": "boolean"
          }
        },
        "additionalProperties": false
      },
      "RemoveMemberRequest": {
        "type": "object",
        "description": "Remove Member Request encoded with ProtoJSON field names.",
        "properties": {
          "accountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "scopeType": {
            "type": "string",
            "enum": [
              "CUSTOMER_ACCOUNT",
              "INSTALLATION_GROUP",
              "INSTALLATION"
            ]
          },
          "scopeId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "correlationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "accountId",
          "scopeType",
          "scopeId",
          "correlationId"
        ]
      },
      "RemoveMemberResponse": {
        "type": "object",
        "description": "Remove Member Response encoded with ProtoJSON field names.",
        "properties": {
          "revokedAssignments": {
            "type": "integer",
            "format": "int32"
          },
          "terminatedSessions": {
            "type": "integer",
            "format": "int32"
          }
        },
        "additionalProperties": false
      },
      "ActivateDeviceRequest": {
        "type": "object",
        "description": "Activate Device Request encoded with ProtoJSON field names.",
        "properties": {
          "installationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "installationInstanceId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "displayName": {
            "type": "string"
          },
          "operatingSystem": {
            "type": "string",
            "enum": [
              "windows",
              "macos",
              "linux"
            ]
          },
          "appVersion": {
            "type": "string"
          }
        },
        "additionalProperties": false,
        "required": [
          "installationId",
          "installationInstanceId",
          "displayName",
          "operatingSystem",
          "appVersion"
        ]
      },
      "Device": {
        "type": "object",
        "description": "Device encoded with ProtoJSON field names.",
        "properties": {
          "id": {
            "type": "string"
          },
          "installationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "installationInstanceId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "displayName": {
            "type": "string"
          },
          "operatingSystem": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "lastSeenAtUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          }
        },
        "additionalProperties": false
      },
      "DeactivateDeviceRequest": {
        "type": "object",
        "description": "Deactivate Device Request encoded with ProtoJSON field names.",
        "properties": {
          "deviceId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "deviceId"
        ]
      },
      "DeactivateDeviceResponse": {
        "type": "object",
        "description": "Deactivate Device Response encoded with ProtoJSON field names.",
        "properties": {
          "deactivated": {
            "type": "boolean"
          }
        },
        "additionalProperties": false
      },
      "GetEntitlementsRequest": {
        "type": "object",
        "description": "Get Entitlements Request encoded with ProtoJSON field names.",
        "properties": {
          "installationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "deviceId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "installationId",
          "deviceId"
        ]
      },
      "ModuleEntitlement": {
        "type": "object",
        "description": "Module Entitlement encoded with ProtoJSON field names.",
        "properties": {
          "moduleKey": {
            "type": "string"
          },
          "active": {
            "type": "boolean"
          },
          "validUntilUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          }
        },
        "additionalProperties": false
      },
      "GetEntitlementsResponse": {
        "type": "object",
        "description": "Get Entitlements Response encoded with ProtoJSON field names.",
        "properties": {
          "allowed": {
            "type": "boolean"
          },
          "denialReason": {
            "type": "string"
          },
          "customerAccountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "installationGroupId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "modules": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/ModuleEntitlement"
            }
          },
          "deviceLimit": {
            "type": "integer",
            "format": "int32"
          },
          "activeDeviceCount": {
            "type": "integer",
            "format": "int32"
          },
          "restrictionMode": {
            "type": "string"
          },
          "readOnly": {
            "type": "boolean"
          }
        },
        "additionalProperties": false
      },
      "SessionClientMessage": {
        "type": "object",
        "description": "Session Client Message encoded with ProtoJSON field names.",
        "properties": {
          "kind": {
            "type": "string",
            "enum": [
              "OPEN",
              "RESUME",
              "HEARTBEAT"
            ]
          },
          "sessionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "resumeToken": {
            "type": "string"
          },
          "installationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "deviceId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "operationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false
      },
      "SessionServerMessage": {
        "type": "object",
        "description": "Session Server Message encoded with ProtoJSON field names.",
        "properties": {
          "kind": {
            "type": "string"
          },
          "sessionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "resumeToken": {
            "type": "string"
          },
          "resumeUntilUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          },
          "reasonCode": {
            "type": "string"
          },
          "serverTimeUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          },
          "restrictionMode": {
            "type": "string"
          },
          "readOnly": {
            "type": "boolean"
          }
        },
        "additionalProperties": false
      },
      "ApplyBillingEventRequest": {
        "type": "object",
        "description": "Apply Billing Event Request encoded with ProtoJSON field names.",
        "properties": {
          "idempotencyKey": {
            "type": "string"
          },
          "externalReference": {
            "type": "string"
          },
          "installationGroupId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "eventType": {
            "type": "string",
            "enum": [
              "SUBSCRIPTION_CREATED",
              "PAYMENT_CONFIRMED",
              "SUBSCRIPTION_RENEWED",
              "PAYMENT_OVERDUE",
              "SUBSCRIPTION_CANCELLED",
              "SUBSCRIPTION_REACTIVATED"
            ]
          },
          "moduleKey": {
            "type": "string"
          },
          "quantity": {
            "type": "integer",
            "format": "int32"
          },
          "validFromUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          },
          "validUntilUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          },
          "providerVersion": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$"
          },
          "occurredAtUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          }
        },
        "additionalProperties": false,
        "required": [
          "idempotencyKey",
          "externalReference",
          "installationGroupId",
          "eventType",
          "moduleKey",
          "quantity",
          "validFromUnix",
          "validUntilUnix",
          "providerVersion",
          "occurredAtUnix"
        ]
      },
      "ApplyBillingEventResponse": {
        "type": "object",
        "description": "Apply Billing Event Response encoded with ProtoJSON field names.",
        "properties": {
          "applied": {
            "type": "boolean"
          },
          "subscriptionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false
      },
      "ApplyScopeRestrictionRequest": {
        "type": "object",
        "description": "Apply Scope Restriction Request encoded with ProtoJSON field names.",
        "properties": {
          "customerAccountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "scopeType": {
            "type": "string",
            "enum": [
              "CUSTOMER_ACCOUNT",
              "INSTALLATION_GROUP",
              "INSTALLATION"
            ]
          },
          "scopeId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "type": {
            "type": "string"
          },
          "mode": {
            "type": "string",
            "enum": [
              "LOGIN_LIMITED",
              "SERVICE_LOCK",
              "READ_ONLY",
              "FULL_LOCK"
            ]
          },
          "publicReasonCode": {
            "type": "string"
          },
          "internalReason": {
            "type": "string"
          },
          "correlationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "expiresAtUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          }
        },
        "additionalProperties": false,
        "required": [
          "customerAccountId",
          "scopeType",
          "scopeId",
          "type",
          "mode",
          "publicReasonCode",
          "internalReason",
          "correlationId"
        ]
      },
      "ApplyScopeRestrictionResponse": {
        "type": "object",
        "description": "Apply Scope Restriction Response encoded with ProtoJSON field names.",
        "properties": {
          "restrictionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "terminatedSessions": {
            "type": "integer",
            "format": "int32"
          }
        },
        "additionalProperties": false
      },
      "RemoveScopeRestrictionRequest": {
        "type": "object",
        "description": "Remove Scope Restriction Request encoded with ProtoJSON field names.",
        "properties": {
          "customerAccountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "restrictionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "correlationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "customerAccountId",
          "restrictionId",
          "correlationId"
        ]
      },
      "RemoveScopeRestrictionResponse": {
        "type": "object",
        "description": "Remove Scope Restriction Response encoded with ProtoJSON field names.",
        "properties": {
          "removed": {
            "type": "boolean"
          }
        },
        "additionalProperties": false
      },
      "RestrictContractOwnerRequest": {
        "type": "object",
        "description": "Restrict Contract Owner Request encoded with ProtoJSON field names.",
        "properties": {
          "customerAccountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "type": {
            "type": "string"
          },
          "mode": {
            "type": "string",
            "enum": [
              "LOGIN_LIMITED",
              "SERVICE_LOCK",
              "READ_ONLY",
              "FULL_LOCK"
            ]
          },
          "publicReasonCode": {
            "type": "string"
          },
          "internalReason": {
            "type": "string"
          },
          "expiresAtUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          },
          "correlationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "customerAccountId",
          "type",
          "mode",
          "publicReasonCode",
          "internalReason",
          "correlationId"
        ]
      },
      "RestrictContractOwnerResponse": {
        "type": "object",
        "description": "Restrict Contract Owner Response encoded with ProtoJSON field names.",
        "properties": {
          "accountRestrictionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "scopeRestrictionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "terminatedSessions": {
            "type": "integer",
            "format": "int32"
          }
        },
        "additionalProperties": false
      },
      "LiftContractRestrictionRequest": {
        "type": "object",
        "description": "Lift Contract Restriction Request encoded with ProtoJSON field names.",
        "properties": {
          "customerAccountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "accountRestrictionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "scopeRestrictionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "correlationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "customerAccountId",
          "accountRestrictionId",
          "scopeRestrictionId",
          "correlationId"
        ]
      },
      "LiftContractRestrictionResponse": {
        "type": "object",
        "description": "Lift Contract Restriction Response encoded with ProtoJSON field names.",
        "properties": {
          "removed": {
            "type": "boolean"
          }
        },
        "additionalProperties": false
      },
      "ConnectError": {
        "type": "object",
        "description": "Connect protocol error envelope.",
        "required": [
          "code",
          "message"
        ],
        "properties": {
          "code": {
            "type": "string",
            "example": "invalid_argument"
          },
          "message": {
            "type": "string"
          },
          "details": {
            "type": "array",
            "items": {
              "type": "object",
              "additionalProperties": true
            }
          }
        },
        "additionalProperties": true
      }
    },
    "parameters": {
      "ConnectProtocolVersion": {
        "name": "Connect-Protocol-Version",
        "in": "header",
        "required": true,
        "description": "Connect unary protocol version.",
        "schema": {
          "type": "string",
          "const": "1",
          "default": "1"
        }
      }
    },
    "responses": {
      "ConnectError": {
        "description": "Connect protocol error.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/ConnectError"
            }
          }
        }
      }
    },
    "securitySchemes": {
      "OAuth2": {
        "type": "oauth2",
        "description": "Authorization Code with PKCE S256. Public clients do not use a client secret.",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://auth.horizonsuite.de/auth",
            "tokenUrl": "https://auth.horizonsuite.de/token",
            "scopes": {
              "openid": "OpenID Connect identity",
              "profile": "Basic profile claims",
              "email": "Email and verification claims",
              "offline_access": "Refresh token access"
            }
          }
        }
      },
      "BillingServiceToken": {
        "type": "apiKey",
        "in": "header",
        "name": "X-Billing-Service-Token",
        "description": "Confidential billing backend credential. Never expose it in frontend code."
      }
    }
  }
}
