{
  "openapi": "3.1.0",
  "info": {
    "title": "Vayu Digital Goods Gateway API",
    "version": "1.0.0",
    "description": "B2B API для цифровых товаров. Денежные суммы передаются строками с двумя десятичными знаками. Клиентский API использует x-api-key или веб-сессию; для запросов с веб-сессией, меняющих данные, нужен x-csrf-token из GET /auth/me. Для каждого логического заказа и пополнения используйте уникальный Idempotency-Key. Реальный провайдер обязан поддерживать идемпотентность по ID заказа."
  },
  "servers": [
    {
      "url": "/",
      "description": "Текущий сервер"
    }
  ],
  "tags": [
    {
      "name": "Authentication",
      "description": "Подтверждение email, Telegram OIDC, сессия и ключ API"
    },
    {
      "name": "Client",
      "description": "Каталог, баланс и заказы клиента"
    },
    {
      "name": "Admin",
      "description": "Управление клиентами, провайдерами и балансами"
    },
    {
      "name": "API Keys",
      "description": "Управление собственными API-ключами по подтверждённой веб-сессии"
    }
  ],
  "components": {
    "securitySchemes": {
      "ClientApiKey": {
        "type": "apiKey",
        "in": "header",
        "name": "x-api-key",
        "description": "Ключ vcmd-…, выдаётся один раз на странице /keys или администратором."
      },
      "AdminSecret": {
        "type": "apiKey",
        "in": "header",
        "name": "x-admin-secret",
        "description": "Секрет для автоматизации админских операций. Веб-панель использует админскую сессию."
      },
      "SessionCookie": {
        "type": "apiKey",
        "in": "cookie",
        "name": "__Host-vayu_session",
        "description": "Защищённая cookie сессии. В localhost-разработке имя vayu_session."
      }
    },
    "parameters": {
      "IdempotencyKey": {
        "name": "Idempotency-Key",
        "in": "header",
        "required": true,
        "schema": {
          "type": "string",
          "maxLength": 128
        },
        "description": "Один ключ на одну логическую операцию. Повтор с тем же телом безопасен."
      },
      "CsrfToken": {
        "name": "x-csrf-token",
        "in": "header",
        "required": false,
        "schema": {
          "type": "string"
        },
        "description": "Обязателен для POST/PATCH, если аутентификация идёт по cookie сессии. Получите через GET /auth/me."
      }
    },
    "schemas": {
      "Error": {
        "type": "object",
        "required": [
          "error"
        ],
        "properties": {
          "error": {
            "type": "string"
          }
        }
      },
      "Money": {
        "type": "string",
        "pattern": "^\\d{1,16}(\\.\\d{1,2})?$",
        "example": "100.00"
      },
      "Product": {
        "type": "object",
        "required": [
          "id",
          "name",
          "provider_id",
          "final_price"
        ],
        "properties": {
          "id": {
            "type": "string",
            "format": "uuid"
          },
          "name": {
            "type": "string"
          },
          "provider_id": {
            "type": "string",
            "format": "uuid"
          },
          "final_price": {
            "$ref": "#/components/schemas/Money"
          }
        }
      },
      "Order": {
        "type": "object",
        "required": [
          "order_id",
          "product_id",
          "target_account",
          "status",
          "price_charged",
          "created_at",
          "updated_at"
        ],
        "properties": {
          "order_id": {
            "type": "string",
            "format": "uuid"
          },
          "product_id": {
            "type": "string",
            "format": "uuid"
          },
          "target_account": {
            "type": "string"
          },
          "status": {
            "type": "string",
            "enum": [
              "PENDING",
              "PROCESSING",
              "COMPLETED",
              "FAILED",
              "REFUNDED"
            ]
          },
          "price_charged": {
            "$ref": "#/components/schemas/Money"
          },
          "external_order_id": {
            "type": [
              "string",
              "null"
            ]
          },
          "created_at": {
            "type": "string",
            "format": "date-time"
          },
          "updated_at": {
            "type": "string",
            "format": "date-time"
          }
        }
      }
    },
    "responses": {
      "Unauthorized": {
        "description": "Нет доступа",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/Error"
            }
          }
        }
      },
      "BadRequest": {
        "description": "Ошибка в запросе",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/Error"
            }
          }
        }
      }
    }
  },
  "paths": {
    "/auth/methods": {
      "get": {
        "tags": [
          "Authentication"
        ],
        "summary": "Доступные способы входа",
        "responses": {
          "200": {
            "description": "Флаги email и telegram",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "required": [
                    "email",
                    "telegram"
                  ],
                  "properties": {
                    "email": {
                      "type": "boolean"
                    },
                    "telegram": {
                      "type": "boolean"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/auth/email/request": {
      "post": {
        "tags": [
          "Authentication"
        ],
        "summary": "Отправить одноразовый код на email",
        "description": "Создаёт код на 10 минут. Лимит: 3 письма на адрес за 15 минут, 10 запросов на IP. Если пользователь вошёл, запускает привязку email и требует CSRF.",
        "parameters": [
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "email"
                ],
                "properties": {
                  "email": {
                    "type": "string",
                    "format": "email"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Код отправлен"
          },
          "429": {
            "$ref": "#/components/responses/BadRequest"
          },
          "503": {
            "description": "SMTP не настроен или недоступен"
          }
        }
      }
    },
    "/auth/email/verify": {
      "post": {
        "tags": [
          "Authentication"
        ],
        "summary": "Проверить код и войти или привязать email",
        "parameters": [
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "email",
                  "code"
                ],
                "properties": {
                  "email": {
                    "type": "string",
                    "format": "email"
                  },
                  "code": {
                    "type": "string",
                    "pattern": "^\\d{6}$"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Сессия создана или email привязан; возвращает csrf_token при входе"
          },
          "400": {
            "$ref": "#/components/responses/BadRequest"
          }
        }
      }
    },
    "/auth/telegram/start": {
      "get": {
        "tags": [
          "Authentication"
        ],
        "summary": "Начать вход через Telegram",
        "description": "Перенаправляет на Telegram OIDC Authorization Code Flow с PKCE.",
        "responses": {
          "302": {
            "description": "Перенаправление в Telegram"
          },
          "503": {
            "description": "Telegram не настроен"
          }
        }
      }
    },
    "/auth/telegram/link/start": {
      "post": {
        "tags": [
          "Authentication"
        ],
        "summary": "Начать привязку Telegram к текущему аккаунту",
        "security": [
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "responses": {
          "200": {
            "description": "Возвращает authorization_url для перехода в Telegram"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          }
        }
      }
    },
    "/auth/telegram/callback": {
      "get": {
        "tags": [
          "Authentication"
        ],
        "summary": "Callback Telegram OIDC",
        "description": "Обрабатывается браузером автоматически; сверяет state, PKCE, подпись JWT, issuer, audience и срок действия.",
        "parameters": [
          {
            "name": "code",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "state",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "302": {
            "description": "Возврат в панель"
          }
        }
      }
    },
    "/auth/me": {
      "get": {
        "tags": [
          "Authentication"
        ],
        "summary": "Текущий пользователь и CSRF-токен",
        "security": [
          {
            "SessionCookie": []
          }
        ],
        "responses": {
          "200": {
            "description": "Профиль, роль, привязки и csrf_token"
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          }
        }
      }
    },
    "/auth/logout": {
      "post": {
        "tags": [
          "Authentication"
        ],
        "summary": "Завершить сессию",
        "security": [
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "responses": {
          "200": {
            "description": "Сессия удалена"
          }
        }
      }
    },
    "/api/v1/catalog": {
      "get": {
        "tags": [
          "Client"
        ],
        "summary": "Получить доступные товары",
        "security": [
          {
            "ClientApiKey": []
          },
          {
            "SessionCookie": []
          }
        ],
        "responses": {
          "200": {
            "description": "Товары из локальной БД",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "products": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/Product"
                      }
                    }
                  }
                }
              }
            }
          },
          "401": {
            "$ref": "#/components/responses/Unauthorized"
          }
        }
      }
    },
    "/api/v1/balance": {
      "get": {
        "tags": [
          "Client"
        ],
        "summary": "Получить баланс",
        "security": [
          {
            "ClientApiKey": []
          },
          {
            "SessionCookie": []
          }
        ],
        "responses": {
          "200": {
            "description": "Баланс",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "balance": {
                      "$ref": "#/components/schemas/Money"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/api/v1/orders": {
      "get": {
        "tags": [
          "Client"
        ],
        "summary": "Последние 20 заказов",
        "security": [
          {
            "ClientApiKey": []
          },
          {
            "SessionCookie": []
          }
        ],
        "responses": {
          "200": {
            "description": "Заказы клиента",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "orders": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/Order"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      },
      "post": {
        "tags": [
          "Client"
        ],
        "summary": "Создать заказ",
        "description": "Цена определяется сервером. Списание, заказ и запись в журнале создаются в одной транзакции. После коммита заказ ставится в BullMQ. Для API-ключа применяются лимиты расходов за UTC день, UTC месяц и всё время. Возвращённые заказы исключаются из расходов.",
        "security": [
          {
            "ClientApiKey": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          },
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "product_id",
                  "target_account"
                ],
                "properties": {
                  "product_id": {
                    "type": "string",
                    "format": "uuid"
                  },
                  "target_account": {
                    "type": "string",
                    "maxLength": 2000
                  },
                  "expected_price": {
                    "type": "string",
                    "pattern": "^\\d{1,16}(\\.\\d{1,2})?$",
                    "description": "Optional catalog price in RUB. If the current server price differs, returns 409 without debiting balance."
                  }
                }
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Заказ принят",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Order"
                }
              }
            }
          },
          "402": {
            "description": "Недостаточно средств или превышен лимит API-ключа"
          },
          "409": {
            "description": "Ключ использован с другим телом"
          },
          "503": {
            "description": "Заказ сохранён, очередь недоступна; повторите с тем же ключом"
          }
        }
      }
    },
    "/api/v1/orders/{id}": {
      "get": {
        "tags": [
          "Client"
        ],
        "summary": "Статус заказа",
        "security": [
          {
            "ClientApiKey": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Заказ",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Order"
                }
              }
            }
          },
          "404": {
            "description": "Заказ не найден у клиента"
          }
        }
      }
    },
    "/admin/overview": {
      "get": {
        "tags": [
          "Admin"
        ],
        "summary": "Счётчики панели",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "responses": {
          "200": {
            "description": "Клиенты, провайдеры, товары и заказы"
          }
        }
      }
    },
    "/admin/clients": {
      "get": {
        "tags": [
          "Admin"
        ],
        "summary": "Последние 100 клиентов",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "responses": {
          "200": {
            "description": "Список клиентов"
          }
        }
      },
      "post": {
        "tags": [
          "Admin"
        ],
        "summary": "Создать клиента без API-ключа",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "name"
                ],
                "properties": {
                  "name": {
                    "type": "string",
                    "maxLength": 200
                  }
                }
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Клиент создан; ключ назначается отдельно"
          }
        }
      }
    },
    "/admin/clients/{id}": {
      "patch": {
        "tags": [
          "Admin"
        ],
        "summary": "Активировать или отключить клиента",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          },
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "is_active"
                ],
                "properties": {
                  "is_active": {
                    "type": "boolean"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Состояние клиента"
          }
        }
      }
    },
    "/admin/clients/{id}/balance": {
      "post": {
        "tags": [
          "Admin"
        ],
        "summary": "Ручное пополнение подтверждённого платежа",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          },
          {
            "$ref": "#/components/parameters/IdempotencyKey"
          },
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "amount"
                ],
                "properties": {
                  "amount": {
                    "$ref": "#/components/schemas/Money"
                  },
                  "description": {
                    "type": "string",
                    "maxLength": 1000
                  }
                }
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Баланс изменён и создана запись TOP_UP"
          },
          "200": {
            "description": "Повтор того же пополнения"
          }
        }
      }
    },
    "/admin/providers": {
      "get": {
        "tags": [
          "Admin"
        ],
        "summary": "Список провайдеров без секретов",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "responses": {
          "200": {
            "description": "Провайдеры"
          }
        }
      },
      "post": {
        "tags": [
          "Admin"
        ],
        "summary": "Добавить провайдера",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "name",
                  "api_url",
                  "api_key"
                ],
                "properties": {
                  "name": {
                    "type": "string"
                  },
                  "api_url": {
                    "type": "string",
                    "format": "uri"
                  },
                  "api_key": {
                    "type": "string"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Секрет провайдера шифруется перед сохранением"
          }
        }
      }
    },
    "/admin/providers/{id}": {
      "patch": {
        "tags": [
          "Admin"
        ],
        "summary": "Активировать провайдера или заменить его ключ",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          },
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "is_active": {
                    "type": "boolean"
                  },
                  "api_key": {
                    "type": "string"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Провайдер обновлён"
          }
        }
      }
    },
    "/admin/orders": {
      "get": {
        "tags": [
          "Admin"
        ],
        "summary": "Последние 100 заказов",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "responses": {
          "200": {
            "description": "Заказы"
          }
        }
      }
    },
    "/admin/orders/{id}/retry": {
      "post": {
        "tags": [
          "Admin"
        ],
        "summary": "Повторить неопределённый заказ",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          },
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "responses": {
          "202": {
            "description": "Задание поставлено в очередь или уже выполняется"
          },
          "409": {
            "description": "Заказ уже завершён"
          }
        }
      }
    },
    "/admin/catalog/sync": {
      "post": {
        "tags": [
          "Admin"
        ],
        "summary": "Запустить синхронизацию каталога",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "responses": {
          "202": {
            "description": "Задание поставлено в очередь"
          }
        }
      }
    },
    "/admin/audit": {
      "get": {
        "tags": [
          "Admin"
        ],
        "summary": "Последние 100 событий администрирования",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "responses": {
          "200": {
            "description": "Журнал действий"
          }
        }
      }
    },
    "/account/api-keys": {
      "get": {
        "tags": [
          "API Keys"
        ],
        "summary": "Ключи, траты и покупки текущего клиента",
        "security": [
          {
            "SessionCookie": []
          }
        ],
        "responses": {
          "200": {
            "description": "keys и daily (последние 30 UTC дней)"
          }
        }
      },
      "post": {
        "tags": [
          "API Keys"
        ],
        "summary": "Создать ключ vcmd-…",
        "description": "До 50 активных ключей. Секрет возвращается один раз; хранится только SHA-256.",
        "security": [
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "name"
                ],
                "properties": {
                  "name": {
                    "type": "string",
                    "maxLength": 100
                  },
                  "daily_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "monthly_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "lifetime_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  }
                }
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "id, api_key и shown_once"
          }
        }
      }
    },
    "/account/api-keys/{id}": {
      "patch": {
        "tags": [
          "API Keys"
        ],
        "summary": "Изменить имя или лимиты",
        "security": [
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          },
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "name": {
                    "type": "string",
                    "maxLength": 100
                  },
                  "daily_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "monthly_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "lifetime_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Ключ обновлён"
          }
        }
      },
      "delete": {
        "tags": [
          "API Keys"
        ],
        "summary": "Отозвать ключ",
        "description": "Доступ прекращается сразу; история заказов остаётся.",
        "security": [
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          },
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "responses": {
          "200": {
            "description": "Ключ отозван"
          }
        }
      }
    },
    "/admin/statistics": {
      "get": {
        "tags": [
          "Admin"
        ],
        "summary": "Общая статистика клиентов и всех API",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "responses": {
          "200": {
            "description": "Клиенты, ключи, покупки и дневные траты"
          }
        }
      }
    },
    "/admin/api-keys": {
      "post": {
        "tags": [
          "Admin"
        ],
        "summary": "Создать API-ключ с назначением клиенту",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "client_id",
                  "name"
                ],
                "properties": {
                  "client_id": {
                    "type": "string",
                    "format": "uuid"
                  },
                  "name": {
                    "type": "string",
                    "maxLength": 100
                  },
                  "daily_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "monthly_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "lifetime_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  }
                }
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "Ключ показан один раз"
          }
        }
      }
    },
    "/admin/api-keys/{id}": {
      "patch": {
        "tags": [
          "Admin"
        ],
        "summary": "Изменить назначенный API-ключ",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          },
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "name"
                ],
                "properties": {
                  "name": {
                    "type": "string",
                    "maxLength": 100
                  },
                  "daily_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "monthly_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "lifetime_limit": {
                    "oneOf": [
                      {
                        "type": "string",
                        "pattern": "^\\d+\\.\\d{2}$",
                        "example": "100.00"
                      },
                      {
                        "type": "null"
                      }
                    ]
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Ключ обновлён"
          }
        }
      },
      "delete": {
        "tags": [
          "Admin"
        ],
        "summary": "Отозвать API-ключ клиента",
        "security": [
          {
            "AdminSecret": []
          },
          {
            "SessionCookie": []
          }
        ],
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "format": "uuid"
            }
          },
          {
            "$ref": "#/components/parameters/CsrfToken"
          }
        ],
        "responses": {
          "200": {
            "description": "Ключ отозван"
          }
        }
      }
    }
  }
}
