> ## Documentation Index
> Fetch the complete documentation index at: https://docs.photon.codes/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Use Stable documentation by default. Honor an explicit Beta request or a URL under /docs/beta/. If the requested version conflicts with the installed CLI package or API origin, clarify the target before writing integration code.
> Pages under /docs/beta/ document Beta; other product pages document Stable. Keep the CLI package, commands, API origin, and credentials within the selected version. State the documentation version in your answer.
> For MCP search, always pass version: Stable or version: Beta. Unfiltered search mixes both versions. For filesystem reads, keep Beta queries under /beta/ and exclude /beta/ from Stable queries; discover paths before reading them.
> The public docs base is https://photon.codes/docs. Convert MCP page paths to public URLs under that base, preserving /beta/ when present. Read https://photon.codes/docs/skill.md for version selection and https://photon.codes/docs/llms.txt for the version indexes.

# List attachments

> Lists the Project's Attachment metadata, with optional time filters.



## OpenAPI

````yaml https://api.photon.codes/openapi.json get /v1/projects/{id}/attachments
openapi: 3.1.0
info:
  title: Photon API
  version: 1.0.0
servers:
  - url: https://api.photon.codes
security: []
paths:
  /v1/projects/{id}/attachments:
    get:
      tags:
        - Attachments
      summary: List attachments
      description: Lists the Project's Attachment metadata, with optional time filters.
      operationId: listAttachments
      parameters:
        - in: path
          name: id
          required: true
          schema:
            pattern: ^pho_prj_[0-7][0-9a-hjkmnp-tv-z]{25}$
            type: string
        - description: >-
            Exclusive upper bound on createdAt, RFC 3339. Cannot combine with
            updatedAt bounds.
          in: query
          name: createdBefore
          schema:
            format: date-time
            pattern: >-
              ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
            type: string
        - description: >-
            Inclusive lower bound on createdAt, RFC 3339. Cannot combine with
            updatedAt bounds.
          in: query
          name: createdSince
          schema:
            format: date-time
            pattern: >-
              ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
            type: string
        - description: Direction along orderBy; desc, the default, is newest first
          in: query
          name: order
          schema:
            $ref: '#/components/schemas/SortOrder'
        - description: >-
            Sort timestamp; defaults to the filtered timestamp, otherwise
            created_at. Must match the time bounds.
          in: query
          name: orderBy
          schema:
            $ref: '#/components/schemas/TimestampOrderBy'
        - description: Items per page. A value above 100 returns at most 100 items.
          in: query
          name: pageSize
          schema:
            maximum: 9007199254740991
            minimum: 0
            type: integer
        - description: Token from nextPageToken. Keep the same Project and query.
          in: query
          name: pageToken
          schema:
            maxLength: 4096
            minLength: 1
            pattern: ^[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+$
            type: string
        - description: >-
            Exclusive upper bound on updatedAt, RFC 3339. Cannot combine with
            createdAt bounds.
          in: query
          name: updatedBefore
          schema:
            format: date-time
            pattern: >-
              ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
            type: string
        - description: >-
            Inclusive lower bound on updatedAt, RFC 3339. Cannot combine with
            createdAt bounds.
          in: query
          name: updatedSince
          schema:
            format: date-time
            pattern: >-
              ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AttachmentPage'
          description: A page of Project Attachments in the requested order.
          headers:
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Idempotent-Replayed:
              $ref: '#/components/headers/Idempotent-Replayed'
            Link:
              $ref: '#/components/headers/Link'
            RateLimit:
              $ref: '#/components/headers/RateLimit'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Retry-After:
              $ref: '#/components/headers/Retry-After'
            Sunset:
              $ref: '#/components/headers/Sunset'
            X-Request-ID:
              $ref: '#/components/headers/X-Request-ID'
            X-Trace-ID:
              $ref: '#/components/headers/X-Trace-ID'
        '401':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/NotAuthenticatedProblem'
          description: 'NOT_AUTHENTICATED: Not Authenticated'
          headers:
            Link:
              description: Optional related resources.
              schema:
                type: string
            RateLimit:
              description: Optional rate limit information.
              schema:
                type: string
            RateLimit-Policy:
              description: Optional rate limit policy.
              schema:
                type: string
            Retry-After:
              description: Optional retry delay or HTTP date.
              schema:
                type: string
            WWW-Authenticate:
              required: true
              schema:
                type: string
            X-Request-ID:
              description: Application request identifier.
              schema:
                type: string
        '403':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ListAttachmentsForbiddenProblem'
          description: >-
            FORBIDDEN: Forbidden; RESOURCE_MISMATCH: Resource Mismatch


            FORBIDDEN: Forbidden; INSUFFICIENT_SCOPE: Insufficient Scope;
            ORGANIZATION_SSO_REQUIRED: Organization SSO Required
          headers:
            Deprecation:
              description: >-
                RFC 9745 structured-field Date at which the operation was or
                will be deprecated: `@` followed by Unix seconds, for example
                `@1767225599`.
              schema:
                pattern: ^@-?[0-9]+$
                type: string
            Idempotent-Replayed:
              description: True when this response was replayed from an earlier attempt.
              schema:
                type: boolean
            Link:
              description: |-
                Links related to lifecycle or remediation documentation.

                Optional related resources.
              schema:
                type: string
            RateLimit:
              description: |-
                Current rate-limit state.

                Optional rate limit information.
              schema:
                type: string
            RateLimit-Policy:
              description: |-
                Rate-limit policy applied by the gateway.

                Optional rate limit policy.
              schema:
                type: string
            Retry-After:
              description: |-
                Delay before retrying, in seconds or as an HTTP date.

                Optional retry delay or HTTP date.
              schema:
                type: string
            Sunset:
              description: >-
                RFC 8594 HTTP-date (IMF-fixdate) after which the operation may
                become unavailable, for example `Thu, 31 Dec 2026 23:59:59 GMT`.
              schema:
                pattern: >-
                  ^(Mon|Tue|Wed|Thu|Fri|Sat|Sun), [0-9]{2}
                  (Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec) [0-9]{4}
                  [0-9]{2}:[0-9]{2}:[0-9]{2} GMT$
                type: string
            X-Request-ID:
              description: |-
                Identifier for this HTTP attempt.

                Application request identifier.
              schema:
                type: string
            X-Trace-ID:
              description: >-
                Trace ID of this request. Sent alongside X-Request-ID when a
                middleware published a trace ID for the request.
              schema:
                pattern: ^(?!0{32}$)[0-9a-f]{32}$
                type: string
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ValidationFailedProblem'
          description: 'VALIDATION_FAILED: Request Validation Failed'
          headers:
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Idempotent-Replayed:
              $ref: '#/components/headers/Idempotent-Replayed'
            Link:
              $ref: '#/components/headers/Link'
            RateLimit:
              $ref: '#/components/headers/RateLimit'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Retry-After:
              $ref: '#/components/headers/Retry-After'
            Sunset:
              $ref: '#/components/headers/Sunset'
            X-Request-ID:
              $ref: '#/components/headers/X-Request-ID'
            X-Trace-ID:
              $ref: '#/components/headers/X-Trace-ID'
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ListAttachmentsInternalServerErrorProblem'
          description: |-
            INVALID_AUTH_CONTEXT: Invalid Authentication Context

            INTERNAL_ERROR: Internal Server Error
          headers:
            Deprecation:
              description: >-
                RFC 9745 structured-field Date at which the operation was or
                will be deprecated: `@` followed by Unix seconds, for example
                `@1767225599`.
              schema:
                pattern: ^@-?[0-9]+$
                type: string
            Idempotent-Replayed:
              description: True when this response was replayed from an earlier attempt.
              schema:
                type: boolean
            Link:
              description: |-
                Links related to lifecycle or remediation documentation.

                Optional related resources.
              schema:
                type: string
            RateLimit:
              description: |-
                Current rate-limit state.

                Optional rate limit information.
              schema:
                type: string
            RateLimit-Policy:
              description: |-
                Rate-limit policy applied by the gateway.

                Optional rate limit policy.
              schema:
                type: string
            Retry-After:
              description: |-
                Delay before retrying, in seconds or as an HTTP date.

                Optional retry delay or HTTP date.
              schema:
                type: string
            Sunset:
              description: >-
                RFC 8594 HTTP-date (IMF-fixdate) after which the operation may
                become unavailable, for example `Thu, 31 Dec 2026 23:59:59 GMT`.
              schema:
                pattern: >-
                  ^(Mon|Tue|Wed|Thu|Fri|Sat|Sun), [0-9]{2}
                  (Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec) [0-9]{4}
                  [0-9]{2}:[0-9]{2}:[0-9]{2} GMT$
                type: string
            X-Request-ID:
              description: |-
                Identifier for this HTTP attempt.

                Application request identifier.
              schema:
                type: string
            X-Trace-ID:
              description: >-
                Trace ID of this request. Sent alongside X-Request-ID when a
                middleware published a trace ID for the request.
              schema:
                pattern: ^(?!0{32}$)[0-9a-f]{32}$
                type: string
        '502':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/UpstreamFailureProblem'
          description: 'UPSTREAM_FAILURE: Upstream Service Failure'
          headers:
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Idempotent-Replayed:
              $ref: '#/components/headers/Idempotent-Replayed'
            Link:
              $ref: '#/components/headers/Link'
            RateLimit:
              $ref: '#/components/headers/RateLimit'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Retry-After:
              $ref: '#/components/headers/Retry-After'
            Sunset:
              $ref: '#/components/headers/Sunset'
            X-Request-ID:
              $ref: '#/components/headers/X-Request-ID'
            X-Trace-ID:
              $ref: '#/components/headers/X-Trace-ID'
        '503':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/UpstreamUnavailableProblem'
          description: 'UPSTREAM_UNAVAILABLE: Upstream Service Unavailable'
          headers:
            Deprecation:
              description: >-
                RFC 9745 structured-field Date at which the operation was or
                will be deprecated: `@` followed by Unix seconds, for example
                `@1767225599`.
              schema:
                pattern: ^@-?[0-9]+$
                type: string
            Idempotent-Replayed:
              description: True when this response was replayed from an earlier attempt.
              schema:
                type: boolean
            Link:
              description: |-
                Links related to lifecycle or remediation documentation.

                Optional related resources.
              schema:
                type: string
            RateLimit:
              description: |-
                Current rate-limit state.

                Optional rate limit information.
              schema:
                type: string
            RateLimit-Policy:
              description: |-
                Rate-limit policy applied by the gateway.

                Optional rate limit policy.
              schema:
                type: string
            Retry-After:
              description: |-
                Delay before retrying, in seconds or as an HTTP date.

                Optional retry delay or HTTP date.
              schema:
                type: string
            Sunset:
              description: >-
                RFC 8594 HTTP-date (IMF-fixdate) after which the operation may
                become unavailable, for example `Thu, 31 Dec 2026 23:59:59 GMT`.
              schema:
                pattern: >-
                  ^(Mon|Tue|Wed|Thu|Fri|Sat|Sun), [0-9]{2}
                  (Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec) [0-9]{4}
                  [0-9]{2}:[0-9]{2}:[0-9]{2} GMT$
                type: string
            X-Request-ID:
              description: |-
                Identifier for this HTTP attempt.

                Application request identifier.
              schema:
                type: string
            X-Trace-ID:
              description: >-
                Trace ID of this request. Sent alongside X-Request-ID when a
                middleware published a trace ID for the request.
              schema:
                pattern: ^(?!0{32}$)[0-9a-f]{32}$
                type: string
        '504':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ListAttachmentsGatewayTimeoutProblem'
          description: >-
            UPSTREAM_TIMEOUT: Upstream Service Timeout; REQUEST_TIMEOUT: Request
            Timeout
          headers:
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Idempotent-Replayed:
              $ref: '#/components/headers/Idempotent-Replayed'
            Link:
              $ref: '#/components/headers/Link'
            RateLimit:
              $ref: '#/components/headers/RateLimit'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Retry-After:
              $ref: '#/components/headers/Retry-After'
            Sunset:
              $ref: '#/components/headers/Sunset'
            X-Request-ID:
              $ref: '#/components/headers/X-Request-ID'
            X-Trace-ID:
              $ref: '#/components/headers/X-Trace-ID'
      security:
        - accountServiceKey: []
        - projectApiKey: []
components:
  schemas:
    SortOrder:
      enum:
        - asc
        - desc
      type: string
    TimestampOrderBy:
      enum:
        - created_at
        - updated_at
      type: string
    AttachmentPage:
      additionalProperties: false
      properties:
        items:
          items:
            $ref: '#/components/schemas/Attachment'
          type: array
        nextPageToken:
          description: >-
            Continue with this token, even if items is empty. Omitted when no
            more pages remain.
          maxLength: 4096
          minLength: 1
          pattern: ^[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+$
          type: string
      required:
        - items
      type: object
    NotAuthenticatedProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: NOT_AUTHENTICATED
        status: 401
        title: Not Authenticated
        type: https://photon.codes/docs/problems/not-authenticated
      properties:
        code:
          const: NOT_AUTHENTICATED
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 401
          type: number
        title:
          const: Not Authenticated
          type: string
        type:
          const: https://photon.codes/docs/problems/not-authenticated
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    ListAttachmentsForbiddenProblem:
      oneOf:
        - $ref: '#/components/schemas/ForbiddenProblem'
        - $ref: '#/components/schemas/InsufficientScopeProblem'
        - $ref: '#/components/schemas/OrganizationSsoRequiredProblem'
        - $ref: '#/components/schemas/ResourceMismatchProblem'
    ValidationFailedProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: VALIDATION_FAILED
        issues:
          - code: invalid_type
            location: json
            message: Expected a string.
            path: /name
        status: 422
        title: Request Validation Failed
        type: https://photon.codes/docs/problems/validation-failed
      properties:
        code:
          const: VALIDATION_FAILED
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        issues:
          items:
            $ref: '#/components/schemas/ValidationIssue'
          type: array
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 422
          type: number
        title:
          const: Request Validation Failed
          type: string
        type:
          const: https://photon.codes/docs/problems/validation-failed
          type: string
      required:
        - issues
        - code
        - status
        - title
        - type
      type: object
    ListAttachmentsInternalServerErrorProblem:
      oneOf:
        - $ref: '#/components/schemas/InternalErrorProblem'
        - $ref: '#/components/schemas/InvalidAuthContextProblem'
    UpstreamFailureProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: UPSTREAM_FAILURE
        status: 502
        title: Upstream Service Failure
        type: https://photon.codes/docs/problems/upstream-failure
      properties:
        code:
          const: UPSTREAM_FAILURE
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 502
          type: number
        title:
          const: Upstream Service Failure
          type: string
        type:
          const: https://photon.codes/docs/problems/upstream-failure
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    UpstreamUnavailableProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: UPSTREAM_UNAVAILABLE
        status: 503
        title: Upstream Service Unavailable
        type: https://photon.codes/docs/problems/upstream-unavailable
      properties:
        code:
          const: UPSTREAM_UNAVAILABLE
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 503
          type: number
        title:
          const: Upstream Service Unavailable
          type: string
        type:
          const: https://photon.codes/docs/problems/upstream-unavailable
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    ListAttachmentsGatewayTimeoutProblem:
      oneOf:
        - $ref: '#/components/schemas/UpstreamTimeoutProblem'
        - $ref: '#/components/schemas/RequestTimeoutProblem'
    Attachment:
      additionalProperties: false
      properties:
        contentType:
          pattern: ^[A-Za-z0-9!#$&^_.+-]+\/[A-Za-z0-9!#$&^_.+-]+$
          type: string
        createdAt:
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d\.\d{3}(?:Z))$
          type: string
        filename:
          minLength: 1
          type: string
        id:
          pattern: ^pho_att_[0-7][0-9a-hjkmnp-tv-z]{25}$
          type: string
        metadata:
          additionalProperties: {}
          propertyNames:
            type: string
          type: object
        projectId:
          pattern: ^pho_prj_[0-7][0-9a-hjkmnp-tv-z]{25}$
          type: string
        sizeBytes:
          exclusiveMinimum: 0
          maximum: 9007199254740991
          type: integer
        updatedAt:
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d\.\d{3}(?:Z))$
          type: string
      required:
        - contentType
        - createdAt
        - id
        - projectId
        - sizeBytes
        - updatedAt
      type: object
    JsonValue:
      anyOf:
        - type: string
        - type: number
        - type: boolean
        - type: 'null'
        - items:
            $ref: '#/components/schemas/JsonValue'
          type: array
        - additionalProperties:
            $ref: '#/components/schemas/JsonValue'
          propertyNames:
            type: string
          type: object
    ForbiddenProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: FORBIDDEN
        status: 403
        title: Forbidden
        type: https://photon.codes/docs/problems/forbidden
      properties:
        code:
          const: FORBIDDEN
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 403
          type: number
        title:
          const: Forbidden
          type: string
        type:
          const: https://photon.codes/docs/problems/forbidden
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    InsufficientScopeProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: INSUFFICIENT_SCOPE
        status: 403
        title: Insufficient Scope
        type: https://photon.codes/docs/problems/insufficient-scope
      properties:
        code:
          const: INSUFFICIENT_SCOPE
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 403
          type: number
        title:
          const: Insufficient Scope
          type: string
        type:
          const: https://photon.codes/docs/problems/insufficient-scope
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    OrganizationSsoRequiredProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: ORGANIZATION_SSO_REQUIRED
        status: 403
        title: Organization SSO Required
        type: https://photon.codes/docs/problems/organization-sso-required
      properties:
        code:
          const: ORGANIZATION_SSO_REQUIRED
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 403
          type: number
        title:
          const: Organization SSO Required
          type: string
        type:
          const: https://photon.codes/docs/problems/organization-sso-required
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    ResourceMismatchProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: RESOURCE_MISMATCH
        status: 403
        title: Resource Mismatch
        type: https://photon.codes/docs/problems/resource-mismatch
      properties:
        code:
          const: RESOURCE_MISMATCH
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 403
          type: number
        title:
          const: Resource Mismatch
          type: string
        type:
          const: https://photon.codes/docs/problems/resource-mismatch
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    ValidationIssue:
      additionalProperties: false
      properties:
        code:
          minLength: 1
          type: string
        location:
          $ref: '#/components/schemas/ValidationLocation'
        message:
          minLength: 1
          type: string
        path:
          type: string
      required:
        - code
        - location
        - message
        - path
      type: object
    InternalErrorProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: INTERNAL_ERROR
        status: 500
        title: Internal Server Error
        type: https://photon.codes/docs/problems/internal-error
      properties:
        code:
          const: INTERNAL_ERROR
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 500
          type: number
        title:
          const: Internal Server Error
          type: string
        type:
          const: https://photon.codes/docs/problems/internal-error
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    InvalidAuthContextProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: INVALID_AUTH_CONTEXT
        status: 500
        title: Invalid Authentication Context
        type: https://photon.codes/docs/problems/invalid-auth-context
      properties:
        code:
          const: INVALID_AUTH_CONTEXT
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 500
          type: number
        title:
          const: Invalid Authentication Context
          type: string
        type:
          const: https://photon.codes/docs/problems/invalid-auth-context
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    UpstreamTimeoutProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: UPSTREAM_TIMEOUT
        status: 504
        title: Upstream Service Timeout
        type: https://photon.codes/docs/problems/upstream-timeout
      properties:
        code:
          const: UPSTREAM_TIMEOUT
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 504
          type: number
        title:
          const: Upstream Service Timeout
          type: string
        type:
          const: https://photon.codes/docs/problems/upstream-timeout
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    RequestTimeoutProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: REQUEST_TIMEOUT
        status: 504
        title: Request Timeout
        type: https://photon.codes/docs/problems/request-timeout
      properties:
        code:
          const: REQUEST_TIMEOUT
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 504
          type: number
        title:
          const: Request Timeout
          type: string
        type:
          const: https://photon.codes/docs/problems/request-timeout
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    ValidationLocation:
      enum:
        - body
        - cookie
        - form
        - header
        - json
        - param
        - query
      type: string
  headers:
    Deprecation:
      description: >-
        RFC 9745 structured-field Date at which the operation was or will be
        deprecated: `@` followed by Unix seconds, for example `@1767225599`.
      schema:
        pattern: ^@-?[0-9]+$
        type: string
    Idempotent-Replayed:
      description: True when this response was replayed from an earlier attempt.
      schema:
        type: boolean
    Link:
      description: Links related to lifecycle or remediation documentation.
      schema:
        type: string
    RateLimit:
      description: Current rate-limit state.
      schema:
        type: string
    RateLimit-Policy:
      description: Rate-limit policy applied by the gateway.
      schema:
        type: string
    Retry-After:
      description: Delay before retrying, in seconds or as an HTTP date.
      schema:
        type: string
    Sunset:
      description: >-
        RFC 8594 HTTP-date (IMF-fixdate) after which the operation may become
        unavailable, for example `Thu, 31 Dec 2026 23:59:59 GMT`.
      schema:
        pattern: >-
          ^(Mon|Tue|Wed|Thu|Fri|Sat|Sun), [0-9]{2}
          (Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec) [0-9]{4}
          [0-9]{2}:[0-9]{2}:[0-9]{2} GMT$
        type: string
    X-Request-ID:
      description: Identifier for this HTTP attempt.
      schema:
        type: string
    X-Trace-ID:
      description: >-
        Trace ID of this request. Sent alongside X-Request-ID when a middleware
        published a trace ID for the request.
      schema:
        pattern: ^(?!0{32}$)[0-9a-f]{32}$
        type: string
  securitySchemes:
    accountServiceKey:
      description: >-
        Account Service Key, prefixed with `pho_ask_`, sent as `Authorization:
        Bearer <key>`. Acts on behalf of its owning account, subject to the
        permissions and credential restrictions of each operation. Account
        access tokens and OAuth grants also use the Bearer header. In
        organizations that require SSO, Account Service Keys are not accepted
        for managing the organization's SSO settings, deleting the organization,
        or checking whether it can be deleted.
      scheme: bearer
      type: http
    projectApiKey:
      description: >-
        Project API key, `pho_sk_` prefixed, sent as `Authorization: Bearer
        <key>`. Bound to one project, so it is accepted only under
        `/v1/projects/{projectId}` and refused everywhere else.
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.