{
  "openapi": "3.1.0",
  "info": {
    "title": "Cargo Tracking API",
    "version": "1.0",
    "description": "Track parcels through a strict state machine (label-created → picked-up → in-transit → out-for-delivery → delivered). Reads are public; every write needs the header X-API-Key: cargo-key-123 — a different auth style than the Bearer tokens used elsewhere."
  },
  "servers": [
    {
      "url": "https://funapi.dev/api/cargo/v1"
    }
  ],
  "tags": [
    {
      "name": "tracking",
      "description": "where is my package"
    },
    {
      "name": "operations",
      "description": "writes, gated by X-API-Key"
    }
  ],
  "paths": {
    "/shipments": {
      "get": {
        "tags": [
          "tracking"
        ],
        "summary": "List shipments, filter by status",
        "operationId": "cg-list",
        "responses": {
          "200": {
            "description": "Shipment list",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "400": {
            "description": "Unknown status value",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "parameters": [
          {
            "name": "status",
            "in": "query",
            "required": false,
            "description": "label-created, picked-up, in-transit, out-for-delivery, delivered or returned-to-sender.",
            "schema": {
              "type": "string"
            }
          }
        ]
      },
      "post": {
        "tags": [
          "operations"
        ],
        "summary": "Create a shipping label (X-API-Key)",
        "operationId": "cg-create",
        "responses": {
          "201": {
            "description": "Label created",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            },
            "headers": {
              "Location": {
                "schema": {
                  "type": "string",
                  "format": "uri-reference"
                }
              }
            }
          },
          "400": {
            "description": "Missing sender/recipient/destination",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "Missing or wrong X-API-Key",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "parameters": [
          {
            "name": "X-API-Key",
            "in": "header",
            "required": true,
            "description": "API key auth — a different scheme than Bearer. The only valid key is cargo-key-123; anything else → 401.",
            "schema": {
              "type": "string"
            },
            "example": "cargo-key-123"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "sender": {
                    "type": "string"
                  },
                  "recipient": {
                    "type": "string"
                  },
                  "destination": {
                    "type": "string"
                  }
                },
                "required": [
                  "sender",
                  "recipient",
                  "destination"
                ],
                "additionalProperties": false
              },
              "example": {
                "sender": "Acme Corp",
                "recipient": "R. Runner",
                "destination": "Somewhere fast, Arizona"
              }
            }
          }
        },
        "security": [
          {
            "apiKeyAuth": []
          }
        ]
      }
    },
    "/shipments/{id}": {
      "get": {
        "tags": [
          "tracking"
        ],
        "summary": "Track one shipment",
        "operationId": "cg-get",
        "responses": {
          "200": {
            "description": "The shipment with its ETag (version)",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "404": {
            "description": "Unknown tracking id",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "Tracking id, e.g. TRK123456. Unknown ids are presumed lost in the warehouse.",
            "schema": {
              "type": "string"
            },
            "example": "TRK123456"
          }
        ]
      }
    },
    "/shipments/{id}/events": {
      "get": {
        "tags": [
          "tracking"
        ],
        "summary": "Tracking history",
        "operationId": "cg-events",
        "responses": {
          "200": {
            "description": "Event list, oldest first",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "404": {
            "description": "Unknown tracking id",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "Tracking id.",
            "schema": {
              "type": "string"
            },
            "example": "TRK777777"
          }
        ]
      }
    },
    "/shipments/{id}/eta": {
      "get": {
        "tags": [
          "tracking"
        ],
        "summary": "Estimated delivery (deterministic-mode friendly)",
        "operationId": "cg-eta",
        "responses": {
          "200": {
            "description": "An ETA of questionable accuracy",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "404": {
            "description": "Unknown tracking id",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "Tracking id.",
            "schema": {
              "type": "string"
            },
            "example": "TRK123456"
          }
        ]
      }
    },
    "/shipments/{id}/advance": {
      "post": {
        "tags": [
          "operations"
        ],
        "summary": "Advance the state machine one step (X-API-Key)",
        "operationId": "cg-advance",
        "responses": {
          "200": {
            "description": "Moved to the next state",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "401": {
            "description": "Missing or wrong X-API-Key",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "Unknown tracking id",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "409": {
            "description": "Shipment is in a terminal state",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "Tracking id.",
            "schema": {
              "type": "string"
            },
            "example": "TRK000001"
          },
          {
            "name": "X-API-Key",
            "in": "header",
            "required": true,
            "description": "cargo-key-123",
            "schema": {
              "type": "string"
            },
            "example": "cargo-key-123"
          }
        ],
        "security": [
          {
            "apiKeyAuth": []
          }
        ]
      }
    },
    "/shipments/{id}/attempt-delivery": {
      "post": {
        "tags": [
          "operations"
        ],
        "summary": "Attempt delivery — may fail, 3 strikes returns it (X-API-Key)",
        "operationId": "cg-attempt",
        "responses": {
          "200": {
            "description": "Delivered, or recipient not home (attempt logged); third failed attempt returns to sender",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "401": {
            "description": "Missing or wrong X-API-Key",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "Unknown tracking id",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "409": {
            "description": "Not out-for-delivery",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "Tracking id — must be out-for-delivery.",
            "schema": {
              "type": "string"
            },
            "example": "TRK123456"
          },
          {
            "name": "X-API-Key",
            "in": "header",
            "required": true,
            "description": "cargo-key-123",
            "schema": {
              "type": "string"
            },
            "example": "cargo-key-123"
          }
        ],
        "security": [
          {
            "apiKeyAuth": []
          }
        ]
      }
    },
    "/shipments/{id}/address": {
      "put": {
        "tags": [
          "operations"
        ],
        "summary": "Redirect a parcel (X-API-Key + If-Match)",
        "operationId": "cg-address",
        "responses": {
          "200": {
            "description": "Address updated",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "400": {
            "description": "Missing destination",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "Missing or wrong X-API-Key",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "404": {
            "description": "Unknown tracking id",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "409": {
            "description": "Already delivered",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "412": {
            "description": "If-Match does not match current version",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "Tracking id.",
            "schema": {
              "type": "string"
            },
            "example": "TRK123456"
          },
          {
            "name": "X-API-Key",
            "in": "header",
            "required": true,
            "description": "cargo-key-123",
            "schema": {
              "type": "string"
            },
            "example": "cargo-key-123"
          },
          {
            "name": "If-Match",
            "in": "header",
            "required": false,
            "description": "Optimistic concurrency — pass the current version (e.g. v1). Stale → 412.",
            "schema": {
              "type": "string"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "destination": {
                    "type": "string"
                  }
                },
                "required": [
                  "destination"
                ],
                "additionalProperties": false
              },
              "example": {
                "destination": "Top of the mesa, Arizona"
              }
            }
          }
        },
        "security": [
          {
            "apiKeyAuth": []
          }
        ]
      }
    },
    "/rates": {
      "get": {
        "tags": [
          "tracking"
        ],
        "summary": "Shipping quote by weight",
        "operationId": "cg-rates",
        "responses": {
          "200": {
            "description": "Quote for standard and express",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "additionalProperties": true
                }
              }
            }
          },
          "400": {
            "description": "Invalid weight",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        },
        "parameters": [
          {
            "name": "weight",
            "in": "query",
            "required": true,
            "description": "Parcel weight in kg (0.1–1000). Non-numeric or out of range → 400.",
            "schema": {
              "type": "string"
            },
            "example": "2.5"
          }
        ]
      }
    }
  },
  "components": {
    "securitySchemes": {
      "bearerAuth": {
        "type": "http",
        "scheme": "bearer",
        "bearerFormat": "JWT",
        "description": "Use qa-admin-token / qa-viewer-token, or a JWT from POST /auth/v1/login."
      },
      "apiKeyAuth": {
        "type": "apiKey",
        "in": "header",
        "name": "X-API-Key",
        "description": "Cargo demo key: cargo-key-123."
      }
    },
    "schemas": {
      "Error": {
        "type": "object",
        "required": [
          "error",
          "message"
        ],
        "properties": {
          "error": {
            "type": "string"
          },
          "message": {
            "type": "string"
          },
          "requestId": {
            "type": "string"
          }
        },
        "additionalProperties": true
      }
    }
  }
}
