> ## Documentation Index
> Fetch the complete documentation index at: https://docs.whop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update App Permissions

> Replaces the set of permissions the app requests from users when they install it. Requires a user session: the `developer:update_app_authorization` scope cannot be delegated to API keys.



## OpenAPI

````yaml /openapi/api-v1-native.json patch /apps/{id}/permissions
openapi: 3.1.0
info:
  description: >-
    The Whop REST API. Please see
    https://docs.whop.com/developer/api/getting-started for more details.
  termsOfService: https://whop.com/tos-developer-api/
  title: Whop API
  version: 1.0.0
  x-api-version-date: '2026-07-22'
servers:
  - description: Production Whop API
    url: https://api.whop.com/api/v1
  - description: Sandbox Whop API
    url: https://sandbox-api.whop.com/api/v1
security: []
tags:
  - description: >
      An Account represents a person or business on Whop that can have its own
      profile, wallet, and account-scoped settings. Use accounts for customers,
      creators, merchants, sellers, or connected businesses your integration
      supports.


      Use the Accounts API to create accounts, list accounts visible to your
      credentials, retrieve or update an account, and retrieve the account
      associated with the current API key.
    name: Accounts
    x-whop-summary: 'A business on Whop: profile, wallet, capabilities, settings.'
  - description: >
      A User represents a person on Whop. Users have a public profile and can
      buy products, join accounts, and access experiences.


      Use the Users API to search for users, retrieve or update profiles, and
      check whether a user has access to an account, product, or experience.
    name: Users
    x-whop-summary: 'A person on Whop: profile and connected identities.'
  - description: >
      A Team Member is a member of an account's team: the link between a user
      and an account, carrying the role that controls what they can do. Roles
      are either system roles (like `admin` or `moderator`) or `custom` roles
      managed from the dashboard.


      Use the Team Members API to list an account's team, add a user to the team
      with a system role, change a member's role, and remove members. Adding a
      user who has not yet accepted sends an invitation instead.
    name: Team Members
    x-whop-summary: An account's team members and the roles that scope their access.
  - name: Webhooks
    x-whop-summary: Event notifications pushed to your server as things happen.
  - description: >
      Stats represent aggregated activity for an account over time. They help
      you understand revenue, transactions, disputes, members, referrals, and
      advertising performance across reporting periods like days, weeks, or
      months.


      Use the Stats API to list available metrics and their filterable
      properties, then retrieve time-series values for a date range.
    name: Stats
    x-whop-summary: Aggregated financial, audience, and traffic reporting.
  - description: >
      A Verification represents a legal identity for a person or business.
      Accounts and users complete verification when Whop needs to confirm who
      they are before enabling payouts or compliance-sensitive workflows.


      Use the Verifications API to start or resume a hosted verification
      session, check review status, and submit requested details or documents.
      If `requested_information` contains items, submit answers with [Update
      Verification](/api-reference/beta/verifications/update-verification).
    name: Verifications
    x-whop-summary: Legal identity required before payouts and card issuing.
  - description: >
      A Ledger Activity row is a single financial event on an account's ledger —
      a payment, withdrawal, refund, transfer, on-chain deposit, swap, or card
      transaction. Each row is derived from the underlying ledger lines and
      carries a typed `resource` and `source` so you can present and link the
      event without extra lookups.


      Use Ledger Activity to build a statement or transaction feed for an
      account or user. Reconcile against your own records with `amount` (signed,
      in the currency's smallest precision units) and `posted_at`, and use
      `available_at` to know when inflows became withdrawable.
    name: Ledgers
    x-whop-summary: The activity feed behind an account or user's balance.
  - description: >
      Payouts represent money sent from an account or user balance to an
      external destination, such as a bank account, wallet, or other saved
      payout method.


      Use the Payouts API to create payouts from stablecoin accounts, list
      payout history for accounts or users, monitor payout statuses, and show
      expected arrival details for funds leaving Whop.
    name: Payouts
    x-whop-summary: Send money from a balance to a bank or wallet.
  - description: >
      Cards represent Whop-issued virtual payment cards that spend from an
      account or user balance. Cards can be assigned to cardholders and
      configured with spending limits for controlled spending.


      Use the Cards API to issue cards, list cards for an account or user, and
      retrieve active card details such as the card number and CVC.
    name: Cards
    x-whop-summary: Issue cards that spend from a balance.
  - description: >
      Transfers move value between identities on Whop. They are used for
      account-to-account money movement, user payouts inside Whop, crypto
      transfers, and claim links depending on the destination type.


      Use the Transfers API to create a transfer, list previous transfers, and
      retrieve a transfer by ID when reconciling money movement between accounts
      or users.
    name: Transfers
    x-whop-summary: Move funds between Whop accounts and users.
  - description: >
      Deposits describe ways to add funds to an account balance, including
      hosted deposit pages, bank deposit instructions, and supported crypto
      wallet addresses.


      Use the Deposits API to create deposit instructions for an account.
    name: Deposits
    x-whop-summary: Add funds to a balance.
  - description: >
      Swaps convert value between supported tokens, chains, or wallet
      destinations for an account. A swap quote describes the expected output,
      fees, and approval requirements before you create the swap.


      Use the Swaps API to quote a conversion, create the swap, list recent
      swaps, and retrieve status until the transaction completes.
    name: Swaps
    x-whop-summary: Convert a balance between currencies.
  - description: >
      A Product is a digital good or service sold on Whop. Products may contain
      plans for pricing and/or experiences for content delivery.


      Use the Products API to create products, list products visible to your
      credentials, retrieve product details, update product metadata or
      merchandising fields, and delete products that should no longer be sold.
    name: Products
    x-whop-summary: The things you sell. Each owns plans and a store page.
  - description: >
      A Plan defines how customers buy a product. It controls pricing, billing
      cadence, availability, tax behavior, checkout fields, and purchase
      visibility.


      Use the Plans API to create plans for products, list existing plans,
      retrieve or update plan configuration, calculate tax for checkout, and
      delete plans that should no longer be offered.
    name: Plans
    x-whop-summary: 'Pricing for a product: one-time, recurring, trials, stock.'
  - description: >
      A Checkout Configuration is a reusable checkout link owned by an account.
      In `payment` mode it sells a specific plan; in `setup` mode it collects
      and saves payment details without charging. Each configuration can also
      override which payment methods are accepted and how 3D Secure is enforced
      for that checkout.


      Use the Checkout Configurations API to create checkout links for an
      existing or inline plan, list configurations for an account, retrieve the
      configuration behind a checkout URL, and delete links that should no
      longer be used.
    name: Checkout Configurations
    x-whop-summary: Turn a plan into a shareable, prefilled checkout link.
  - description: >
      The Partners API covers your Whop partner activity: the users you referred
      onto Whop, the businesses you referred and the earnings generated from
      their processing volume, and the partner leaderboard.


      Use it to enroll as a Whop partner, list the users you referred, list your
      referred businesses and review their earnings, and see the partner
      leaderboard.
    name: Partners
    x-whop-summary: >-
      The users and businesses you referred to Whop, and what you earn from
      them.
  - description: >
      A Bounty is a paid task posted by an account or user. The reward is held
      in escrow when the bounty publishes, workers submit proof of completed
      work, and each accepted submission is paid out until every winner slot
      fills.


      Use the Bounties API to create and publish a bounty, list an account's
      bounties for reporting or dashboards, list the bounties a user can work or
      has participated in, and retrieve a single bounty by ID.
    name: Bounties
    x-whop-summary: Paid tasks with reviewed submissions and escrowed rewards.
  - description: >
      A Bounty Submission is one worker's attempt on a bounty. It starts as an
      in-progress attempt, enters the review queue when proof is submitted, and
      ends approved (paid from the bounty's escrowed pool) or denied.


      Use the Bounty Submissions API to submit proof of completed work to a
      bounty, list the submissions you authored, and review the submissions on
      your bounties — across every bounty or narrowed to one.
    name: Bounty Submissions
    x-whop-summary: Work submitted to a bounty, from attempt to payout.
  - description: >
      A Person is an identity-linked profile of a visitor or customer of an
      account, assembled from every [event](/api-reference/beta/events/event)
      the person generated — pixel page views, ad clicks, leads, identifies, and
      payments. Each profile carries the person's known identities (names,
      emails, phones, user IDs), purchase history and LTV, geo/device profile,
      traffic sources, and the first and last marketing touches that reached
      them.


      Use the People API to list and segment the people of an account — filter
      by activity, purchases, traffic source, location, or marketing touch, and
      sort by value — or retrieve one person by person ID, user ID, email
      address, or phone number.
    name: People
    x-whop-summary: >-
      Visitors and customers of an account, with identity, purchase, and traffic
      profiles.
  - description: >
      An Event records conversion or engagement activity for an account, such as
      page views, purchases, or leads. Each event ties the action to the
      [person](/api-reference/beta/people/person) who took it, so activity can
      be attributed to the ads and links that drove it.


      Use the Events API to send new tracking events, list recent
      identity-linked events for an account, and inspect the events recorded for
      a person.
    name: Events
    x-whop-summary: Conversion and engagement events tracked for attribution.
  - description: >
      An Ad is the individual creative unit delivered by an [ad
      group](/api-reference/beta/ad-groups/ad-group). It holds the copy,
      creative assets, and destination URL for one ad.


      Use the Ads API to list ads for an account, create ads inside ad groups,
      retrieve or update creative details, delete ads that should stop running,
      and pause or resume delivery.
    name: Ads
    x-whop-summary: 'The creative: copy, assets, and destination URL.'
  - description: >
      An Ad Campaign is the top-level container for paid ads on an ad network.
      It sets the platform, objective, and budget strategy shared by its [ad
      groups](/api-reference/beta/ad-groups/ad-group) and ads.


      Use the Ad Campaigns API to create campaigns, list campaigns for an
      account, retrieve or update campaign settings, and pause or resume
      campaign delivery.
    name: Ad Campaigns
    x-whop-summary: Platform, objective, and budget for a set of ads.
  - description: >
      An Ad Group sits inside an [ad
      campaign](/api-reference/beta/ad-campaigns/ad-campaign) and controls
      delivery for [ads](/api-reference/beta/ads/ad). It sets the audience,
      placements, schedule, budget, and optimization goal for its ads.


      Use the Ad Groups API to create ad groups in campaigns, list or retrieve
      targeting and delivery settings, update budgets or targeting, delete
      groups that should stop running, and pause or resume delivery. It can also
      search the ad platform's targeting taxonomy for options to target and
      estimate how many people a draft targeting spec can reach.
    name: Ad Groups
    x-whop-summary: Audience, placements, and schedule within a campaign.
  - description: >
      An Audience represents a customer list uploaded to Whop for ad targeting.
      Audiences belong to an account and sync to supported ad platforms as
      custom audiences.


      Use the Audiences API to create audiences from CSV uploads, monitor
      processing status, and list or delete audiences for an account. Created
      audiences are usable for targeting after processing reaches `ready` or
      `partial`.
    name: Audiences
    x-whop-summary: Reusable targeting lists for ad groups.
  - description: >
      A Media Asset is an AI-generated image or video created from a prompt and
      billed from an account balance. When generation finishes, the asset
      includes a file that can be attached anywhere Whop accepts files.


      Use the Media API to start a generation job and retrieve the asset while
      it processes or after it is ready.
    name: Media
    x-whop-summary: >-
      AI-generated assets, billed from a balance, attachable wherever files are
      accepted.
  - description: >
      A Social Account represents an external profile connected to a Whop
      account or user, such as a Facebook page or Instagram account. Connecting
      a social account lets Whop run [ads](/api-reference/beta/ads/ad) under
      that profile's identity and promote its existing posts.


      Use the Social Accounts API to list connected accounts, create a
      Whop-managed Facebook page, start an OAuth connection, disconnect a social
      account, and list a connected profile's posts or a Facebook page's lead
      forms.
    name: Social Accounts
    x-whop-summary: Connected Facebook and Instagram accounts that run ads.
  - description: >
      An App is software you build on Whop. It can be a hosted web app served at
      `<route>.whop.app` or an API integration installed as an experience, and
      it belongs to the account that owns its credentials, settings, builds, and
      runtime logs.


      Use the Apps API to manage app configuration and, for hosted apps, read
      server runtime logs for console output, uncaught exceptions, and failed
      requests. Logs are retained for 7 days and can be filtered by build,
      level, time window, and message text.
    name: Apps
    x-whop-summary: 'Apps you build on Whop: metadata, hosted builds, runtime logs.'
  - description: >
      An App Build is a versioned artifact uploaded for an app — a hosted web
      archive, or an iOS/Android bundle. Builds start as drafts, go through
      review, and one approved build per platform is served to users as the
      production build.


      Use the App Builds API to upload a build for an app, list an app's builds
      with platform and status filters, retrieve a build, and promote a draft or
      approved build to production.
    name: App Builds
    x-whop-summary: Versioned build artifacts deployed to an app's platforms.
  - description: >
      An API Key is a programmatic credential owned by an account or app. Each
      key carries its own permissions policy — explicit permission statements or
      an inherited system role — and can be restricted with an expiration date
      and an IP allowlist.


      Use the API Keys API to list a company or app's keys, create a key (the
      full secret is returned once, on creation), inspect a key's effective
      grants, update its name or restrictions, rotate its secret, and revoke it.
      These endpoints require a user session — they cannot be called with an API
      key.
    name: API Keys
    x-whop-summary: Programmatic credentials for an account or app.
paths:
  /apps/{id}/permissions:
    parameters:
      - $ref: '#/components/parameters/ApiVersionDate'
      - description: App ID, prefixed `app_`.
        in: path
        name: id
        required: true
        schema:
          type: string
    patch:
      tags:
        - Apps
      summary: Update App Permissions
      description: >-
        Replaces the set of permissions the app requests from users when they
        install it. Requires a user session: the
        `developer:update_app_authorization` scope cannot be delegated to API
        keys.
      operationId: updateAppPermissions
      parameters: []
      requestBody:
        content:
          application/json:
            schema:
              properties:
                requested_permissions:
                  description: >-
                    The full set of permissions the app requests on install;
                    permissions not listed are removed.
                  items:
                    properties:
                      action:
                        description: >-
                          The permission action, for example
                          `company:basic:read`.
                        type: string
                      is_required:
                        description: >-
                          Whether installing the app requires granting this
                          permission.
                        type: boolean
                      justification:
                        description: >-
                          Why the app needs this permission (20-512 characters),
                          shown to the installing user.
                        type: string
                    required:
                      - action
                      - is_required
                      - justification
                    type: object
                  type: array
              required:
                - requested_permissions
              type: object
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/App'
          description: requested permissions updated
        '400':
          $ref: '#/components/responses/InvalidParameters'
          description: the request body is invalid
        '401':
          $ref: '#/components/responses/Unauthorized'
          description: missing or invalid authentication
        '403':
          $ref: '#/components/responses/Forbidden'
          description: credential lacks the app-authorization scope
        '404':
          $ref: '#/components/responses/NotFound'
          description: no app with that ID exists
      security:
        - bearerAuth:
            - developer:update_app_authorization
      x-codeSamples:
        - lang: JavaScript
          source: |-
            import Whop from '@whop/sdk';

            const client = new Whop({
              apiKey: process.env['WHOP_API_KEY'], // This is the default and can be omitted
            });

            const app = await client.apps.updatePermissions('id', {
              requested_permissions: [
                {
                  action: 'action',
                  is_required: true,
                  justification: 'justification',
                },
              ],
            });

            console.log(app.id);
components:
  parameters:
    ApiVersionDate:
      description: Pins the request to a dated API version.
      in: header
      name: Api-Version-Date
      required: false
      schema:
        example: '2026-07-22'
        type: string
  schemas:
    App:
      properties:
        account:
          $ref: '#/components/schemas/AccountSummary'
          description: The account that owns the app.
        api_key:
          description: >-
            Legacy app API key used to authenticate requests on the app's
            behalf. `null` when no key exists or the caller lacks the
            `developer:manage_api_key` permission.
          oneOf:
            - $ref: '#/components/schemas/AppApiKey'
            - type: 'null'
        app_store_description:
          description: >-
            Detailed description shown on the app store's in-depth app page, or
            `null` when none has been set.
          type:
            - string
            - 'null'
        app_type:
          description: The type of end-user the app is built for.
          enum:
            - b2b_app
            - b2c_app
            - company_app
            - component
          example: b2b_app
          type: string
        base_url:
          description: >-
            Production base URL where the app is hosted, or `null` if none is
            configured.
          type:
            - string
            - 'null'
        creator:
          $ref: '#/components/schemas/AppCreator'
          description: The user who owns the publishing company.
        dashboard_path:
          description: >-
            URL path for the company dashboard view, or `null` when not
            configured.
          type:
            - string
            - 'null'
        default_api_key:
          description: >-
            The app's default API key. `null` when the app has no default key or
            the caller lacks the `developer:manage_api_key` permission;
            `secret_key` is additionally `null` unless the caller could have
            created the key themselves.
          oneOf:
            - $ref: '#/components/schemas/AppDefaultApiKey'
            - type: 'null'
        description:
          description: >-
            Short description shown in listings and search results, or `null` if
            none has been set.
          type:
            - string
            - 'null'
        discover_path:
          description: URL path for the discover view, or `null` when not configured.
          type:
            - string
            - 'null'
        domain_id:
          description: >-
            Subdomain identifier for the app's proxied URL, forming
            https://{domain_id}.apps.whop.com.
          type: string
        experience_path:
          description: >-
            URL path for the member-facing hub view, or `null` when not
            configured.
          type:
            - string
            - 'null'
        hosted_url:
          description: >-
            Full URL where the app's hosted web build is served, or `null` if no
            route is claimed.
          type:
            - string
            - 'null'
        icon:
          $ref: '#/components/schemas/AppIcon'
          description: >-
            The app's icon. Falls back to the default app icon when none is
            uploaded.
        id:
          description: App ID, prefixed `app_`.
          type: string
        marketplace_status:
          description: >-
            Approval status of the app's product listing on the Whop app store,
            or `null` when the app has no associated product.
          enum:
            - not_available
            - pending_review
            - live_marketplace
            - null
          example: not_available
          type:
            - string
            - 'null'
        name:
          description: Display name shown on the app store and in experience navigation.
          type: string
        oauth_client_type:
          description: How the app authenticates at the OAuth token endpoint.
          enum:
            - public
            - confidential
          example: public
          type: string
        openapi_path:
          description: >-
            URL path to the app's OpenAPI spec file, or `null` when not
            configured.
          type:
            - string
            - 'null'
        origin:
          description: >-
            Full origin URL of the app's proxied domain, for example
            https://ab1c2d3e4f.apps.whop.com.
          type:
            - string
            - 'null'
        product_id:
          description: >-
            ID of the app's product listing on the Whop app store, or `null`
            when the app has no associated product.
          type:
            - string
            - 'null'
        production_android_build:
          description: >-
            The approved build currently served on Android, or `null` when none
            is deployed.
          oneOf:
            - $ref: '#/components/schemas/AppProductionBuild'
            - type: 'null'
        production_ios_build:
          description: >-
            The approved build currently served on iOS, or `null` when none is
            deployed.
          oneOf:
            - $ref: '#/components/schemas/AppProductionBuild'
            - type: 'null'
        production_web_build:
          description: >-
            The approved build currently served on web, or `null` when none is
            deployed.
          oneOf:
            - $ref: '#/components/schemas/AppProductionBuild'
            - type: 'null'
        redirect_uris:
          items:
            description: >-
              Whitelisted OAuth callback URLs users are redirected to after
              authorizing the app.
            type: string
          type: array
        requested_permissions:
          items:
            $ref: '#/components/schemas/AppRequestedPermission'
            description: Permissions the app requests on install.
          type: array
        route:
          description: >-
            Claimed subdomain route where hosted web builds are served (`myapp`
            for myapp.whop.app), or `null` if no route is claimed.
          type:
            - string
            - 'null'
        secrets:
          description: >-
            The app's production secrets as an object of string values, injected
            into the hosted server runtime. `null` when the caller lacks the
            `developer:update_app` permission.
          type:
            - object
            - 'null'
        skills_path:
          description: >-
            URL path to the app's skills directory, or `null` when not
            configured.
          type:
            - string
            - 'null'
        status:
          description: >-
            Visibility on the Whop app store: `live` is publicly discoverable,
            `unlisted` is accessible only via direct link, `hidden` is not
            visible anywhere.
          enum:
            - live
            - unlisted
            - hidden
          example: live
          type: string
        verified:
          description: >-
            Whether the app has been verified by Whop and is eligible for the
            featured apps section.
          type: boolean
      required:
        - id
        - name
        - description
        - status
        - base_url
        - domain_id
        - route
        - hosted_url
        - verified
        - app_type
        - origin
        - experience_path
        - discover_path
        - dashboard_path
        - skills_path
        - openapi_path
        - account
        - icon
        - creator
        - app_store_description
        - requested_permissions
        - api_key
        - default_api_key
        - production_web_build
        - production_ios_build
        - production_android_build
        - redirect_uris
        - secrets
        - product_id
        - marketplace_status
        - oauth_client_type
      type: object
    AccountSummary:
      properties:
        id:
          description: Account ID, prefixed `biz_`.
          type: string
        title:
          description: Account display name.
          type: string
      required:
        - id
        - title
      type: object
    AppApiKey:
      properties:
        created_at:
          description: When the key was created, as an ISO 8601 timestamp.
          type: string
        token:
          description: >-
            The key's secret token, sent as a bearer token to authenticate
            requests on the app's behalf.
          type: string
      required:
        - token
        - created_at
      type: object
    AppCreator:
      properties:
        id:
          description: User ID, prefixed `user_`.
          type: string
        name:
          description: Display name.
          type:
            - string
            - 'null'
        username:
          description: Public username.
          type: string
      required:
        - id
        - name
        - username
      type: object
    AppDefaultApiKey:
      properties:
        id:
          description: API key ID, prefixed `apik_`.
          type: string
        name:
          description: >-
            Human-readable name identifying the API key, or `null` when none was
            set.
          type:
            - string
            - 'null'
        obfuscated_secret_key:
          description: >-
            Masked version of the secret key, so the key can be recognized
            without revealing the full secret.
          type: string
        secret_key:
          description: >-
            The full secret used to authenticate requests. `null` unless the
            caller could have created the key themselves.
          type:
            - string
            - 'null'
      required:
        - id
        - name
        - obfuscated_secret_key
        - secret_key
      type: object
    AppIcon:
      properties:
        url:
          description: >-
            Icon image URL. Always present — the default app icon when none is
            uploaded.
          type: string
      required:
        - url
      type: object
    AppProductionBuild:
      properties:
        checksum:
          description: >-
            Client-generated checksum of the build file, used to verify file
            integrity.
          type:
            - string
            - 'null'
        file_url:
          description: URL to download the uploaded build artifact.
          type:
            - string
            - 'null'
        id:
          description: App build ID, prefixed `abld_`.
          type: string
        source_url:
          description: >-
            URL to download the compressed source code archive that produced
            this build, or `null` when the build was uploaded without a source
            archive.
          type:
            - string
            - 'null'
        status:
          description: The build's review status.
          enum:
            - draft
            - pending
            - approved
            - rejected
          example: draft
          type: string
      required:
        - id
        - file_url
        - source_url
        - checksum
        - status
      type: object
    AppRequestedPermission:
      properties:
        is_required:
          description: >-
            Whether the app requires the permission to be granted on install, as
            opposed to requesting it optionally.
          type: boolean
        justification:
          description: >-
            The developer's explanation of why the app needs the permission, or
            `null` when none was provided.
          type:
            - string
            - 'null'
        permission_action:
          $ref: '#/components/schemas/AppRequestedPermissionAction'
          description: The permission action the app requests.
      required:
        - permission_action
        - is_required
        - justification
      type: object
    V1ErrorResponse:
      properties:
        error:
          properties:
            message:
              description: Human-readable error message.
              type: string
            type:
              description: Machine-readable error code.
              type: string
          required:
            - type
            - message
          type: object
      required:
        - error
      type: object
    AppRequestedPermissionAction:
      properties:
        action:
          description: >-
            The permission action's identifier, for example
            `company:basic:read`.
          type: string
        name:
          description: Human-readable name of the action.
          type: string
      required:
        - action
        - name
      type: object
  responses:
    InvalidParameters:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V1ErrorResponse'
      description: Invalid Parameters
    Unauthorized:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V1ErrorResponse'
      description: Unauthorized
    Forbidden:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V1ErrorResponse'
      description: Forbidden
    NotFound:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V1ErrorResponse'
      description: Resource not found
  securitySchemes:
    bearerAuth:
      bearerFormat: auth-scheme
      description: >-
        A company API key, company scoped JWT, app API key, or user OAuth token.
        You must prepend your key/token with the word 'Bearer', which will look
        like `Bearer ***************************`
      scheme: bearer
      type: http

````