{
  "openapi": "3.1.0",
  "info": {
    "title": "Auth Playground API",
    "version": "1.0",
    "description": "A simulated OAuth 2.0 authorization server. Practice the client-credentials and authorization-code grants, token expiry, refresh tokens, and the standard invalid_client / invalid_grant error shapes — independent of the qa-admin-token / qa-viewer-token used elsewhere on this site. The \"real tokens\" tag issues a working token from /login (or /firebase-token) that unlocks every 🔒 endpoint across this playground."
  },
  "servers": [
    {
      "url": "https://funapi.dev/api/auth/v1"
    }
  ],
  "tags": [
    {
      "name": "oauth",
      "description": "client demo-client / secret demo-secret"
    },
    {
      "name": "real tokens",
      "description": "log in for a token that works on the 🔒 endpoints site-wide"
    }
  ],
  "paths": {
    "/login": {
      "post": {
        "tags": [
          "real tokens"
        ],
        "summary": "Log in as a demo user and get a working token (roles: admin / viewer)",
        "operationId": "auth-login",
        "responses": {
          "200": {
            "description": "Token issued — use it as Authorization: Bearer <token>",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "400": {
            "description": "Missing username or password",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "Unknown user or wrong password",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "username": {
                    "type": "string"
                  },
                  "password": {
                    "type": "string"
                  }
                },
                "required": [
                  "username",
                  "password"
                ],
                "additionalProperties": false
              },
              "example": {
                "username": "admin",
                "password": "admin123"
              }
            }
          }
        }
      }
    },
    "/firebase-token": {
      "post": {
        "tags": [
          "real tokens"
        ],
        "summary": "Mint a simulated Firebase-style token whose role claim grants admin or viewer",
        "operationId": "auth-firebase",
        "responses": {
          "200": {
            "description": "Token minted — use it as Authorization: Bearer <token>",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "400": {
            "description": "role must be \"admin\" or \"viewer\"",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "role": {
                    "type": "string"
                  }
                },
                "required": [
                  "role"
                ],
                "additionalProperties": false
              },
              "example": {
                "role": "viewer"
              }
            }
          }
        }
      }
    },
    "/me": {
      "get": {
        "tags": [
          "real tokens"
        ],
        "summary": "Inspect the token you are sending (role, kind, subject)",
        "operationId": "auth-me",
        "responses": {
          "200": {
            "description": "Who the playground thinks you are",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid token",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "security": [
          {
            "bearerAuth": []
          }
        ]
      }
    },
    "/oauth/authorize": {
      "post": {
        "tags": [
          "oauth"
        ],
        "summary": "Step 1: request an authorization code",
        "operationId": "oa-authorize",
        "responses": {
          "200": {
            "description": "Authorization code issued (valid 60s, single use)",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "400": {
            "description": "invalid_client — unknown clientId",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "clientId": {
                    "type": "string"
                  },
                  "redirectUri": {
                    "type": "string"
                  }
                },
                "required": [
                  "clientId",
                  "redirectUri"
                ],
                "additionalProperties": false
              },
              "example": {
                "clientId": "demo-client",
                "redirectUri": "https://example.com/callback"
              }
            }
          }
        }
      }
    },
    "/oauth/token": {
      "post": {
        "tags": [
          "oauth"
        ],
        "summary": "Step 2: exchange for a token (client_credentials / authorization_code / refresh_token)",
        "operationId": "oa-token",
        "responses": {
          "200": {
            "description": "Token issued",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "400": {
            "description": "invalid_request (missing grantType), invalid_client, or invalid_grant (bad/expired/used code, wrong clientId for the code, or bad refresh token)",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "grantType": {
                    "type": "string"
                  },
                  "clientId": {
                    "type": "string"
                  },
                  "clientSecret": {
                    "type": "string"
                  }
                },
                "required": [
                  "grantType",
                  "clientId",
                  "clientSecret"
                ],
                "additionalProperties": false
              },
              "example": {
                "grantType": "client_credentials",
                "clientId": "demo-client",
                "clientSecret": "demo-secret"
              }
            }
          }
        }
      }
    },
    "/oauth/protected-resource": {
      "get": {
        "tags": [
          "oauth"
        ],
        "summary": "A resource protected by a token from this flow (not the site-wide Authorize button)",
        "operationId": "oa-protected",
        "responses": {
          "200": {
            "description": "Protected data",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "401": {
            "description": "invalid_token — missing, malformed, unknown, or expired",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "parameters": [
          {
            "name": "Authorization",
            "in": "header",
            "required": true,
            "description": "Pass \"Bearer <access_token>\" from a /oauth/token response.",
            "schema": {
              "type": "string"
            },
            "example": "Bearer "
          }
        ]
      }
    }
  },
  "components": {
    "securitySchemes": {
      "bearerAuth": {
        "type": "http",
        "scheme": "bearer",
        "bearerFormat": "JWT",
        "description": "Use qa-admin-token / qa-viewer-token, or a JWT from POST /auth/v1/login."
      },
      "apiKeyAuth": {
        "type": "apiKey",
        "in": "header",
        "name": "X-API-Key",
        "description": "Cargo demo key: cargo-key-123."
      }
    },
    "schemas": {
      "Error": {
        "type": "object",
        "required": [
          "error",
          "message"
        ],
        "properties": {
          "error": {
            "type": "string"
          },
          "message": {
            "type": "string"
          },
          "requestId": {
            "type": "string"
          }
        },
        "additionalProperties": true
      }
    }
  }
}
