{
  "openapi": "3.1.1",
  "info": {
    "title": "HorizonSuite Auth Server",
    "version": "0.1.0",
    "description": "OAuth 2.0, OpenID Connect, account security, and service-backplane contracts. Public clients use Authorization Code with PKCE S256 and never embed a client secret.",
    "contact": {
      "name": "HorizonSuite",
      "url": "https://github.com/horizonsuite/api-documentation"
    }
  },
  "externalDocs": {
    "description": "Canonical Protocol Buffer contracts",
    "url": "https://github.com/horizonsuite/api-documentation/tree/main/proto"
  },
  "servers": [
    {
      "url": "https://auth.horizonsuite.de",
      "description": "Production"
    }
  ],
  "tags": [
    {
      "name": "OIDC",
      "description": "OAuth 2.0 and OpenID Connect endpoints used by browser and desktop clients."
    },
    {
      "name": "HealthService",
      "description": "Service health and release identity."
    },
    {
      "name": "AuthInternalService",
      "description": "Private service-backplane operations. These routes are blocked at the public origin."
    },
    {
      "name": "AuthPublicService",
      "description": "Authenticated account security operations."
    }
  ],
  "paths": {
    "/horizon.auth.v1.HealthService/Check": {
      "post": {
        "tags": [
          "HealthService"
        ],
        "summary": "Check",
        "description": "Liveness and version check for the Auth RPC service.",
        "operationId": "horizon.auth.v1.HealthService.Check",
        "security": [],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/HealthRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/HealthResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.auth.v1.AuthInternalService/Introspect": {
      "post": {
        "tags": [
          "AuthInternalService"
        ],
        "summary": "Introspect",
        "description": "Validates a reference access token for an exact client ID. Internal backplane only.",
        "operationId": "horizon.auth.v1.AuthInternalService.Introspect",
        "security": [
          {
            "InternalServiceToken": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/IntrospectRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/IntrospectResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        },
        "x-horizonsuite-internal-only": true
      }
    },
    "/horizon.auth.v1.AuthInternalService/ApplyAccountRestriction": {
      "post": {
        "tags": [
          "AuthInternalService"
        ],
        "summary": "Apply Account Restriction",
        "description": "Applies an account restriction and publishes a monotonic security event. Internal backplane only.",
        "operationId": "horizon.auth.v1.AuthInternalService.ApplyAccountRestriction",
        "security": [
          {
            "InternalServiceToken": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ApplyAccountRestrictionRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ApplyAccountRestrictionResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        },
        "x-horizonsuite-internal-only": true
      }
    },
    "/horizon.auth.v1.AuthInternalService/RemoveAccountRestriction": {
      "post": {
        "tags": [
          "AuthInternalService"
        ],
        "summary": "Remove Account Restriction",
        "description": "Removes an account restriction and publishes a monotonic security event. Internal backplane only.",
        "operationId": "horizon.auth.v1.AuthInternalService.RemoveAccountRestriction",
        "security": [
          {
            "InternalServiceToken": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RemoveAccountRestrictionRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RemoveAccountRestrictionResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        },
        "x-horizonsuite-internal-only": true
      }
    },
    "/horizon.auth.v1.AuthInternalService/SetDashboardAccess": {
      "post": {
        "tags": [
          "AuthInternalService"
        ],
        "summary": "Set Dashboard Access",
        "description": "Changes dashboard access and revokes incompatible sessions. Internal backplane only.",
        "operationId": "horizon.auth.v1.AuthInternalService.SetDashboardAccess",
        "security": [
          {
            "InternalServiceToken": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/SetDashboardAccessRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/SetDashboardAccessResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        },
        "x-horizonsuite-internal-only": true
      }
    },
    "/horizon.auth.v1.AuthInternalService/InviteAccount": {
      "post": {
        "tags": [
          "AuthInternalService"
        ],
        "summary": "Invite Account",
        "description": "Creates or reconciles an invited account. Internal backplane only.",
        "operationId": "horizon.auth.v1.AuthInternalService.InviteAccount",
        "security": [
          {
            "InternalServiceToken": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/InviteAccountRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/InviteAccountResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        },
        "x-horizonsuite-internal-only": true
      }
    },
    "/horizon.auth.v1.AuthInternalService/WatchSecurityEvents": {
      "post": {
        "tags": [
          "AuthInternalService"
        ],
        "summary": "Watch Security Events",
        "description": "Resumable server-streaming security event feed. Internal backplane only; Swagger UI cannot execute streaming RPCs.",
        "operationId": "horizon.auth.v1.AuthInternalService.WatchSecurityEvents",
        "security": [
          {
            "InternalServiceToken": []
          }
        ],
        "parameters": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/WatchSecurityEventsRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Streaming response. Use a native gRPC client.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/SecurityEvent"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        },
        "x-horizonsuite-streaming": "server",
        "x-horizonsuite-try-it-out": false,
        "x-horizonsuite-internal-only": true
      }
    },
    "/horizon.auth.v1.AuthPublicService/GetMySecurityProfile": {
      "post": {
        "tags": [
          "AuthPublicService"
        ],
        "summary": "Get My Security Profile",
        "description": "Returns the authenticated user's verification, MFA, Passkey, session, and restriction status.",
        "operationId": "horizon.auth.v1.AuthPublicService.GetMySecurityProfile",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/MySecurityProfileRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MySecurityProfileResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/horizon.auth.v1.AuthPublicService/RevokeMySessions": {
      "post": {
        "tags": [
          "AuthPublicService"
        ],
        "summary": "Revoke My Sessions",
        "description": "Revokes the user's sessions, optionally retaining the current web session.",
        "operationId": "horizon.auth.v1.AuthPublicService.RevokeMySessions",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/ConnectProtocolVersion"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/RevokeMySessionsRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Successful ProtoJSON response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/RevokeMySessionsResponse"
                }
              }
            }
          },
          "default": {
            "$ref": "#/components/responses/ConnectError"
          }
        }
      }
    },
    "/.well-known/openid-configuration": {
      "get": {
        "tags": [
          "OIDC"
        ],
        "summary": "Discover the OpenID Provider",
        "operationId": "oidcDiscovery",
        "security": [],
        "responses": {
          "200": {
            "description": "OpenID Provider metadata.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/OidcDiscovery"
                }
              }
            }
          }
        }
      }
    },
    "/healthz": {
      "get": {
        "tags": [
          "HealthService"
        ],
        "summary": "Check the Auth web service",
        "operationId": "authWebHealth",
        "security": [],
        "responses": {
          "200": {
            "description": "Healthy service.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "status",
                    "service",
                    "version"
                  ],
                  "properties": {
                    "status": {
                      "type": "string",
                      "const": "ok"
                    },
                    "service": {
                      "type": "string",
                      "const": "auth-server"
                    },
                    "version": {
                      "type": "string"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/auth": {
      "get": {
        "tags": [
          "OIDC"
        ],
        "summary": "Start Authorization Code with PKCE",
        "operationId": "oidcAuthorize",
        "security": [],
        "parameters": [
          {
            "name": "response_type",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string",
              "const": "code"
            }
          },
          {
            "name": "client_id",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string",
              "enum": [
                "horizon-dashboard",
                "horizon-desktop"
              ]
            }
          },
          {
            "name": "redirect_uri",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uri"
            }
          },
          {
            "name": "scope",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string",
              "example": "openid profile email offline_access"
            }
          },
          {
            "name": "state",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "code_challenge",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "code_challenge_method",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string",
              "const": "S256"
            }
          }
        ],
        "responses": {
          "302": {
            "description": "Redirects into the protected login and consent interaction."
          },
          "default": {
            "description": "Invalid OAuth request."
          }
        }
      }
    },
    "/token": {
      "post": {
        "tags": [
          "OIDC"
        ],
        "summary": "Exchange an authorization code or refresh token",
        "operationId": "oidcToken",
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "type": "object",
                "required": [
                  "grant_type",
                  "client_id"
                ],
                "properties": {
                  "grant_type": {
                    "type": "string",
                    "enum": [
                      "authorization_code",
                      "refresh_token"
                    ]
                  },
                  "client_id": {
                    "type": "string"
                  },
                  "code": {
                    "type": "string"
                  },
                  "redirect_uri": {
                    "type": "string",
                    "format": "uri"
                  },
                  "code_verifier": {
                    "type": "string"
                  },
                  "refresh_token": {
                    "type": "string"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Token response.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/TokenResponse"
                }
              }
            }
          },
          "default": {
            "description": "OAuth token error."
          }
        }
      }
    },
    "/jwks": {
      "get": {
        "tags": [
          "OIDC"
        ],
        "summary": "Read JSON Web Keys",
        "operationId": "oidcJwks",
        "security": [],
        "responses": {
          "200": {
            "description": "Current public signing keys.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/JwkSet"
                }
              }
            }
          }
        }
      }
    },
    "/me": {
      "get": {
        "tags": [
          "OIDC"
        ],
        "summary": "Read OpenID Connect user information",
        "operationId": "oidcUserInfo",
        "security": [
          {
            "OAuth2": [
              "openid",
              "profile",
              "email"
            ]
          }
        ],
        "responses": {
          "200": {
            "description": "Claims for the current subject.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/UserInfo"
                }
              }
            }
          },
          "401": {
            "description": "Missing, invalid, or revoked access token."
          }
        }
      }
    },
    "/token/revocation": {
      "post": {
        "tags": [
          "OIDC"
        ],
        "summary": "Revoke an access or refresh token",
        "operationId": "oidcRevokeToken",
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "type": "object",
                "required": [
                  "token"
                ],
                "properties": {
                  "token": {
                    "type": "string"
                  },
                  "token_type_hint": {
                    "type": "string",
                    "enum": [
                      "access_token",
                      "refresh_token"
                    ]
                  },
                  "client_id": {
                    "type": "string"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The token is now revoked or was already invalid."
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "HealthRequest": {
        "type": "object",
        "description": "Health Request encoded with ProtoJSON field names.",
        "properties": {},
        "additionalProperties": false
      },
      "HealthResponse": {
        "type": "object",
        "description": "Health Response encoded with ProtoJSON field names.",
        "properties": {
          "status": {
            "type": "string"
          },
          "service": {
            "type": "string"
          },
          "version": {
            "type": "string"
          }
        },
        "additionalProperties": false
      },
      "IntrospectRequest": {
        "type": "object",
        "description": "Introspect Request encoded with ProtoJSON field names.",
        "properties": {
          "accessToken": {
            "type": "string"
          },
          "requiredClientId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "accessToken",
          "requiredClientId"
        ]
      },
      "IntrospectResponse": {
        "type": "object",
        "description": "Introspect Response encoded with ProtoJSON field names.",
        "properties": {
          "active": {
            "type": "boolean"
          },
          "subject": {
            "type": "string"
          },
          "email": {
            "type": "string",
            "format": "email",
            "example": "person@example.com"
          },
          "systemRoles": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "restrictionVersion": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$"
          },
          "expiresAtUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          },
          "clientId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false
      },
      "ApplyAccountRestrictionRequest": {
        "type": "object",
        "description": "Apply Account Restriction Request encoded with ProtoJSON field names.",
        "properties": {
          "accountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "type": {
            "type": "string",
            "enum": [
              "RESTRICTION_TYPE_UNSPECIFIED",
              "SECURITY_INCIDENT",
              "ADMINISTRATIVE_HOLD",
              "LEGAL_DISPUTE",
              "PAYMENT_DEFAULT",
              "TERMS_VIOLATION",
              "FRAUD_SUSPECTED",
              "MANUAL_REVIEW",
              "CUSTOM"
            ]
          },
          "mode": {
            "type": "string",
            "enum": [
              "RESTRICTION_MODE_UNSPECIFIED",
              "LOGIN_LIMITED",
              "SERVICE_LOCK",
              "READ_ONLY",
              "FULL_LOCK"
            ]
          },
          "publicReasonCode": {
            "type": "string"
          },
          "internalReason": {
            "type": "string"
          },
          "createdBy": {
            "type": "string"
          },
          "expiresAtUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          },
          "correlationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "accountId",
          "type",
          "mode",
          "publicReasonCode",
          "internalReason",
          "createdBy",
          "correlationId"
        ]
      },
      "ApplyAccountRestrictionResponse": {
        "type": "object",
        "description": "Apply Account Restriction Response encoded with ProtoJSON field names.",
        "properties": {
          "restrictionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "restrictionVersion": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$"
          }
        },
        "additionalProperties": false
      },
      "RemoveAccountRestrictionRequest": {
        "type": "object",
        "description": "Remove Account Restriction Request encoded with ProtoJSON field names.",
        "properties": {
          "accountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "restrictionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "removedBy": {
            "type": "string"
          },
          "correlationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false,
        "required": [
          "accountId",
          "restrictionId",
          "removedBy",
          "correlationId"
        ]
      },
      "RemoveAccountRestrictionResponse": {
        "type": "object",
        "description": "Remove Account Restriction Response encoded with ProtoJSON field names.",
        "properties": {
          "restrictionVersion": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$"
          }
        },
        "additionalProperties": false
      },
      "SetDashboardAccessRequest": {
        "type": "object",
        "description": "Set Dashboard Access Request encoded with ProtoJSON field names.",
        "properties": {
          "accountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "allowed": {
            "type": "boolean"
          },
          "changedBy": {
            "type": "string"
          }
        },
        "additionalProperties": false,
        "required": [
          "accountId",
          "allowed",
          "changedBy"
        ]
      },
      "SetDashboardAccessResponse": {
        "type": "object",
        "description": "Set Dashboard Access Response encoded with ProtoJSON field names.",
        "properties": {
          "allowed": {
            "type": "boolean"
          }
        },
        "additionalProperties": false
      },
      "InviteAccountRequest": {
        "type": "object",
        "description": "Invite Account Request encoded with ProtoJSON field names.",
        "properties": {
          "email": {
            "type": "string",
            "format": "email",
            "example": "person@example.com"
          },
          "displayName": {
            "type": "string"
          },
          "dashboardAccess": {
            "type": "boolean"
          },
          "invitedBy": {
            "type": "string"
          }
        },
        "additionalProperties": false,
        "required": [
          "email",
          "displayName",
          "dashboardAccess",
          "invitedBy"
        ]
      },
      "InviteAccountResponse": {
        "type": "object",
        "description": "Invite Account Response encoded with ProtoJSON field names.",
        "properties": {
          "accountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "created": {
            "type": "boolean"
          }
        },
        "additionalProperties": false
      },
      "WatchSecurityEventsRequest": {
        "type": "object",
        "description": "Watch Security Events Request encoded with ProtoJSON field names.",
        "properties": {
          "afterSequence": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$"
          }
        },
        "additionalProperties": false
      },
      "SecurityEvent": {
        "type": "object",
        "description": "Security Event encoded with ProtoJSON field names.",
        "properties": {
          "sequence": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$"
          },
          "eventId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "eventType": {
            "type": "string"
          },
          "accountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "restrictionVersion": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$"
          },
          "occurredAtUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          },
          "correlationId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "restrictionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "restrictionType": {
            "type": "integer",
            "format": "int32"
          },
          "restrictionMode": {
            "type": "integer",
            "format": "int32"
          },
          "expiresAtUnix": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$",
            "description": "Unix timestamp in seconds, encoded as a decimal string by ProtoJSON.",
            "example": "1791392400"
          }
        },
        "additionalProperties": false
      },
      "MySecurityProfileRequest": {
        "type": "object",
        "description": "My Security Profile Request encoded with ProtoJSON field names.",
        "properties": {},
        "additionalProperties": false
      },
      "MySecurityProfileResponse": {
        "type": "object",
        "description": "My Security Profile Response encoded with ProtoJSON field names.",
        "properties": {
          "accountId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          },
          "email": {
            "type": "string",
            "format": "email",
            "example": "person@example.com"
          },
          "emailVerified": {
            "type": "boolean"
          },
          "dashboardAccess": {
            "type": "boolean"
          },
          "totpEnabled": {
            "type": "boolean"
          },
          "emailOtpEnabled": {
            "type": "boolean"
          },
          "passkeyCount": {
            "type": "integer",
            "format": "int32"
          },
          "activeSessionCount": {
            "type": "integer",
            "format": "int32"
          },
          "restrictionVersion": {
            "type": "string",
            "format": "int64",
            "pattern": "^-?[0-9]+$"
          }
        },
        "additionalProperties": false
      },
      "RevokeMySessionsRequest": {
        "type": "object",
        "description": "Revoke My Sessions Request encoded with ProtoJSON field names.",
        "properties": {
          "keepSessionId": {
            "type": "string",
            "description": "Opaque server-issued identifier."
          }
        },
        "additionalProperties": false
      },
      "RevokeMySessionsResponse": {
        "type": "object",
        "description": "Revoke My Sessions Response encoded with ProtoJSON field names.",
        "properties": {
          "revokedCount": {
            "type": "integer",
            "format": "int32"
          }
        },
        "additionalProperties": false
      },
      "ConnectError": {
        "type": "object",
        "description": "Connect protocol error envelope.",
        "required": [
          "code",
          "message"
        ],
        "properties": {
          "code": {
            "type": "string",
            "example": "invalid_argument"
          },
          "message": {
            "type": "string"
          },
          "details": {
            "type": "array",
            "items": {
              "type": "object",
              "additionalProperties": true
            }
          }
        },
        "additionalProperties": true
      },
      "OidcDiscovery": {
        "type": "object",
        "required": [
          "issuer",
          "authorization_endpoint",
          "token_endpoint",
          "jwks_uri"
        ],
        "properties": {
          "issuer": {
            "type": "string",
            "format": "uri"
          },
          "authorization_endpoint": {
            "type": "string",
            "format": "uri"
          },
          "token_endpoint": {
            "type": "string",
            "format": "uri"
          },
          "userinfo_endpoint": {
            "type": "string",
            "format": "uri"
          },
          "jwks_uri": {
            "type": "string",
            "format": "uri"
          },
          "end_session_endpoint": {
            "type": "string",
            "format": "uri"
          },
          "scopes_supported": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "response_types_supported": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "grant_types_supported": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "code_challenge_methods_supported": {
            "type": "array",
            "items": {
              "type": "string"
            }
          }
        },
        "additionalProperties": true
      },
      "TokenResponse": {
        "type": "object",
        "required": [
          "access_token",
          "token_type",
          "expires_in"
        ],
        "properties": {
          "access_token": {
            "type": "string"
          },
          "token_type": {
            "type": "string",
            "example": "Bearer"
          },
          "expires_in": {
            "type": "integer",
            "format": "int32"
          },
          "refresh_token": {
            "type": "string"
          },
          "id_token": {
            "type": "string"
          },
          "scope": {
            "type": "string"
          }
        }
      },
      "UserInfo": {
        "type": "object",
        "required": [
          "sub"
        ],
        "properties": {
          "sub": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "email": {
            "type": "string",
            "format": "email"
          },
          "email_verified": {
            "type": "boolean"
          }
        },
        "additionalProperties": true
      },
      "JwkSet": {
        "type": "object",
        "required": [
          "keys"
        ],
        "properties": {
          "keys": {
            "type": "array",
            "items": {
              "type": "object",
              "additionalProperties": true
            }
          }
        }
      }
    },
    "parameters": {
      "ConnectProtocolVersion": {
        "name": "Connect-Protocol-Version",
        "in": "header",
        "required": true,
        "description": "Connect unary protocol version.",
        "schema": {
          "type": "string",
          "const": "1",
          "default": "1"
        }
      }
    },
    "responses": {
      "ConnectError": {
        "description": "Connect protocol error.",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/ConnectError"
            }
          }
        }
      }
    },
    "securitySchemes": {
      "OAuth2": {
        "type": "oauth2",
        "description": "Authorization Code with PKCE S256. Public clients do not use a client secret.",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://auth.horizonsuite.de/auth",
            "tokenUrl": "https://auth.horizonsuite.de/token",
            "scopes": {
              "openid": "OpenID Connect identity",
              "profile": "Basic profile claims",
              "email": "Email and verification claims",
              "offline_access": "Refresh token access"
            }
          }
        }
      },
      "InternalServiceToken": {
        "type": "apiKey",
        "in": "header",
        "name": "X-Internal-Service-Token",
        "description": "Confidential service-backplane credential. Never expose it in browser or desktop code."
      }
    }
  }
}
