{
  "openapi": "3.1.0",
  "info": {
    "title": "RSquared Studios Assets API",
    "version": "1.0.0",
    "description": "Public asset delivery plus an exact-object management API. Trusted services call /api/v1 with a Cloudflare Access Service Token kept on the server. The human /admin portal uses an interactive Access session and calls the same contract through the same-origin /admin/api/v1 wrapper."
  },
  "externalDocs": {
    "description": "Integration documentation",
    "url": "https://assets.rsquaredstudios.net/docs/"
  },
  "servers": [
    {
      "url": "https://assets.rsquaredstudios.net"
    }
  ],
  "components": {
    "schemas": {
      "Asset": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "contentType",
          "etag",
          "key",
          "size",
          "uploaded",
          "visibility"
        ],
        "properties": {
          "contentType": {
            "type": "string"
          },
          "downloadUrl": {
            "type": "string",
            "format": "uri"
          },
          "etag": {
            "type": "string",
            "description": "Quoted strong object ETag."
          },
          "key": {
            "type": "string"
          },
          "size": {
            "type": "integer",
            "minimum": 0
          },
          "uploaded": {
            "type": "string",
            "format": "date-time"
          },
          "url": {
            "type": "string",
            "format": "uri"
          },
          "visibility": {
            "type": "string",
            "enum": [
              "public",
              "private"
            ]
          }
        },
        "anyOf": [
          {
            "required": [
              "url"
            ]
          },
          {
            "required": [
              "downloadUrl"
            ]
          }
        ]
      },
      "AssetResponse": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "asset"
        ],
        "properties": {
          "asset": {
            "$ref": "#/components/schemas/Asset"
          }
        }
      },
      "UploadResponse": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "asset",
          "operationId"
        ],
        "properties": {
          "asset": {
            "$ref": "#/components/schemas/Asset"
          },
          "operationId": {
            "type": "string",
            "format": "uuid"
          }
        }
      },
      "ErrorResponse": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "error"
        ],
        "properties": {
          "error": {
            "type": "object",
            "additionalProperties": false,
            "required": [
              "code",
              "message"
            ],
            "properties": {
              "code": {
                "type": "string"
              },
              "message": {
                "type": "string"
              }
            }
          }
        }
      }
    },
    "securitySchemes": {
      "AccessClientId": {
        "type": "apiKey",
        "in": "header",
        "name": "CF-Access-Client-Id",
        "description": "Cloudflare Access Service Token client ID."
      },
      "AccessClientSecret": {
        "type": "apiKey",
        "in": "header",
        "name": "CF-Access-Client-Secret",
        "description": "Cloudflare Access Service Token secret. Never expose it to browser clients."
      }
    }
  },
  "paths": {
    "/api/v1/assets/{visibility}/{assetPath}": {
      "get": {
        "summary": "Get exact-object metadata",
        "security": [
          {
            "AccessClientId": [],
            "AccessClientSecret": []
          }
        ],
        "parameters": [
          {
            "description": "R2 namespace exposed by the API.",
            "in": "path",
            "name": "visibility",
            "required": true,
            "schema": {
              "type": "string",
              "enum": [
                "public",
                "private"
              ]
            }
          },
          {
            "allowReserved": true,
            "description": "Slash-separated asset key without the public/ or private/ prefix.",
            "in": "path",
            "name": "assetPath",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Asset metadata.",
            "headers": {
              "ETag": {
                "schema": {
                  "type": "string"
                }
              },
              "Location": {
                "schema": {
                  "type": "string"
                }
              }
            },
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/AssetResponse"
                }
              }
            }
          },
          "401": {
            "description": "Cloudflare Access authentication failed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "403": {
            "description": "The authenticated service cannot access this object.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "404": {
            "description": "Asset not found.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "502": {
            "description": "R2 request failed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "503": {
            "description": "Access, policy, or storage configuration is unavailable.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          }
        }
      },
      "head": {
        "summary": "Get exact-object metadata headers",
        "description": "Returns the same status and metadata headers as GET without a response body.",
        "security": [
          {
            "AccessClientId": [],
            "AccessClientSecret": []
          }
        ],
        "parameters": [
          {
            "description": "R2 namespace exposed by the API.",
            "in": "path",
            "name": "visibility",
            "required": true,
            "schema": {
              "type": "string",
              "enum": [
                "public",
                "private"
              ]
            }
          },
          {
            "allowReserved": true,
            "description": "Slash-separated asset key without the public/ or private/ prefix.",
            "in": "path",
            "name": "assetPath",
            "required": true,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "Asset metadata headers."
          },
          "401": {
            "description": "Cloudflare Access authentication failed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "403": {
            "description": "The authenticated service cannot access this object.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "404": {
            "description": "Asset not found.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "502": {
            "description": "R2 request failed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "503": {
            "description": "Access, policy, or storage configuration is unavailable.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          }
        }
      },
      "put": {
        "summary": "Create an asset or conditionally replace a private asset",
        "description": "Send the asset bytes as the raw request body. Public uploads are create-only and require If-None-Match: *. Private uploads use If-None-Match: * to create or one strong If-Match ETag to replace the exact existing object.",
        "security": [
          {
            "AccessClientId": [],
            "AccessClientSecret": []
          }
        ],
        "parameters": [
          {
            "description": "R2 namespace exposed by the API.",
            "in": "path",
            "name": "visibility",
            "required": true,
            "schema": {
              "type": "string",
              "enum": [
                "public",
                "private"
              ]
            }
          },
          {
            "allowReserved": true,
            "description": "Slash-separated asset key without the public/ or private/ prefix.",
            "in": "path",
            "name": "assetPath",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "Required with value * when creating an object.",
            "in": "header",
            "name": "If-None-Match",
            "schema": {
              "type": "string",
              "const": "*"
            }
          },
          {
            "description": "A single strong ETag accepted only when replacing a private object.",
            "in": "header",
            "name": "If-Match",
            "schema": {
              "type": "string"
            }
          },
          {
            "description": "Required positive byte length of the raw upload body.",
            "in": "header",
            "name": "Content-Length",
            "required": true,
            "schema": {
              "type": "integer",
              "minimum": 1,
              "maximum": 94371840
            }
          }
        ],
        "requestBody": {
          "required": true,
          "description": "Raw asset bytes using the asset's actual Content-Type.",
          "content": {
            "*/*": {
              "schema": {
                "type": "string",
                "format": "binary",
                "maxLength": 94371840
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Existing private asset conditionally replaced.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/UploadResponse"
                }
              }
            }
          },
          "201": {
            "description": "New asset created.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/UploadResponse"
                }
              }
            }
          },
          "400": {
            "description": "Malformed request or invalid upload headers.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "401": {
            "description": "Cloudflare Access authentication failed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "403": {
            "description": "The authenticated service cannot write this object.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "409": {
            "description": "Replacement was attempted for an immutable public asset.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "411": {
            "description": "Content-Length is missing or invalid.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "412": {
            "description": "Write precondition failed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "413": {
            "description": "Upload exceeds the configured size limit.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "415": {
            "description": "The public media type is not allowlisted or does not match the key.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "428": {
            "description": "A write precondition is required.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "502": {
            "description": "R2 request failed.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          },
          "503": {
            "description": "Access, policy, or storage configuration is unavailable.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/ErrorResponse"
                }
              }
            }
          }
        }
      }
    }
  }
}