> ## Documentation Index
> Fetch the complete documentation index at: https://docs.conare.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the action contract

> Discover whether this end user's connected account supports
transactional writes and, when it does, the live request contract:
provider base URL, allowed write methods, body/query shapes, blocked
headers, payload limits, timeout, and per-connection rate limit.

This is the source of truth for executable writes.
`catalog[].capabilities.push` describes modeled destination-sync
support for a connector TYPE; it does not imply that this particular
connected account can execute transactional actions.

Requires an Integration credential with `connectors:write`. Connector
plane ids, credentials, and inherited secret values are never exposed.
Reading the contract does not enable the action gateway or call the
provider.




## OpenAPI

````yaml /api/openapi.yaml get /api/v1/connectors/{type}/actions
openapi: 3.1.0
info:
  title: Conare API
  version: 1.3.0
  summary: Per-end-user memory and connected-app actions for AI applications.
  description: >
    The Conare API gives your application a persistent, personalized

    memory layer. Production applications authenticate as an organization-owned

    Integration. Every request names an `endUserId`, and

    that end user's memory lives in its own isolated ConareDB namespace. The

    physical tenant is an opaque HMAC derived from the Integration and end-user

    ID; clients cannot select namespaces or address another tenant.


    On top of storage the API provides hybrid retrieval (vector + BM25, fused
    and

    reranked, sub-second), LLM-synthesized **deep recall**, **proactive

    suggestions** grounded in a user's memory, and explicitly scoped,

    idempotent writes through an end user's connected apps.


    Authentication normally uses a scoped server-side Integration Bearer key
    (`cint_...`).

    The secret is shown once and persisted by Conare only as a SHA-256 digest.

    Keep it in a server-side secret manager; never ship it to the browser.

    Legacy personal `cmem_...` keys remain accepted during migration.


    The stateless embeddings endpoint also accepts the platform key

    (`sk-conare-...`) that ConareDB accepts directly. A search service can use

    that one bearer for both embedding and database requests.


    Every response includes `X-Request-Id`. Send a caller-generated safe value

    (1–128 characters; first alphanumeric, then `A-Za-z0-9._:-`) to correlate

    one request through the Conare edge and memory plane; otherwise Conare
    generates one. Errors use a

    stable `{ statusCode, code, message, requestId, details? }` envelope and

    never include internal tenant IDs or backend error text.
  contact:
    name: Conare
    url: https://conare.ai
    email: artem@conare.ai
servers:
  - url: https://api.conare.ai
    description: Production (dedicated partner-API host)
  - url: https://conare.ai
    description: Production (alias — same API, on the main host)
security:
  - bearerAuth: []
tags:
  - name: Integration
    description: Credential, configuration, and backend readiness.
  - name: Memories
    description: Write and search a single end user's memory.
  - name: Recall
    description: LLM-synthesized personalization primitives.
  - name: Embeddings
    description: Embed text with Conare's own retrieval embedding model.
  - name: Reranking
    description: Rerank caller-owned candidates with Conare's live retrieval model.
  - name: Connectors
    description: >-
      Let end users sync ~200 data sources into memory and execute scoped writes
      through supported connected accounts.
  - name: Users
    description: End-user lifecycle (GDPR).
paths:
  /api/v1/connectors/{type}/actions:
    get:
      tags:
        - Connectors
      summary: Get the action contract
      description: |
        Discover whether this end user's connected account supports
        transactional writes and, when it does, the live request contract:
        provider base URL, allowed write methods, body/query shapes, blocked
        headers, payload limits, timeout, and per-connection rate limit.

        This is the source of truth for executable writes.
        `catalog[].capabilities.push` describes modeled destination-sync
        support for a connector TYPE; it does not imply that this particular
        connected account can execute transactional actions.

        Requires an Integration credential with `connectors:write`. Connector
        plane ids, credentials, and inherited secret values are never exposed.
        Reading the contract does not enable the action gateway or call the
        provider.
      operationId: getConnectorActionContract
      parameters:
        - name: type
          in: path
          required: true
          schema:
            $ref: '#/components/schemas/ConnectorType'
        - name: endUserId
          in: query
          required: true
          schema:
            $ref: '#/components/schemas/EndUserId'
      responses:
        '200':
          description: The connected account's transactional action contract.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConnectorActionContractResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          description: >-
            The source is not connected for this end user
            (`connector_not_connected`).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          $ref: '#/components/responses/RateLimited'
        '503':
          $ref: '#/components/responses/ServiceUnavailable'
components:
  schemas:
    ConnectorType:
      type: string
      pattern: ^[a-z0-9][a-z0-9_-]{0,63}$
      description: |
        Data-source type id. Any source-capable type in the connector catalog
        (~200 sources — Gmail, Slack, HubSpot, Notion, Linear, Salesforce,
        warehouses, …); enumerate them via `GET /api/v1/connectors/catalog`.
      example: hubspot
    EndUserId:
      type: string
      pattern: ^[A-Za-z0-9@._-]{1,128}$
      minLength: 1
      maxLength: 128
      description: Your stable internal user ID. No colon allowed.
      example: u_123
    ConnectorActionContractResponse:
      type: object
      required:
        - type
        - supported
        - enabled
        - automaticallyEnabledOnExecute
        - provider
        - baseUrl
        - inherited
        - request
      properties:
        type:
          $ref: '#/components/schemas/ConnectorType'
        supported:
          type: boolean
          description: Whether this connected account supports transactional actions.
        enabled:
          type: boolean
          description: Whether its action gateway is currently enabled.
        automaticallyEnabledOnExecute:
          type: boolean
          description: |
            True when a valid execute request can lazily enable the gateway;
            contract discovery itself never enables it.
        provider:
          type: string
          description: Provider/backend identifier, such as `attio`.
        baseUrl:
          type:
            - string
            - 'null'
          description: Fixed provider API base URL. Action paths are appended to it.
        inherited:
          type: object
          required:
            - headerNames
            - queryNames
          description: |
            Names the connection attaches automatically. Values are never
            exposed; authentication headers cannot be overridden.
          properties:
            headerNames:
              type: array
              items:
                type: string
            queryNames:
              type: array
              items:
                type: string
        request:
          type:
            - object
            - 'null'
          description: Null when transactional actions are unsupported.
          properties:
            allowedMethods:
              type: array
              items:
                type: string
                enum:
                  - POST
                  - PUT
                  - PATCH
                  - DELETE
            bodyTypes:
              type: array
              items:
                type: string
            maxRequestBodyBytes:
              type:
                - integer
                - 'null'
            maxResponseBodyBytes:
              type:
                - integer
                - 'null'
            rateLimitPerMinute:
              type:
                - integer
                - 'null'
            timeoutMs:
              type:
                - integer
                - 'null'
            queryModes:
              type: array
              items:
                type: string
            queryValueTypes:
              type: array
              items:
                type: string
            blockedRequestHeaders:
              type: array
              items:
                type: string
            pathRule:
              type:
                - string
                - 'null'
            rawQueryRule:
              type:
                - string
                - 'null'
          required:
            - allowedMethods
            - bodyTypes
            - maxRequestBodyBytes
            - maxResponseBodyBytes
            - rateLimitPerMinute
            - timeoutMs
            - queryModes
            - queryValueTypes
            - blockedRequestHeaders
            - pathRule
            - rawQueryRule
    Error:
      type: object
      properties:
        statusCode:
          type: integer
        code:
          type: string
          description: Stable snake_case machine error code.
        message:
          type: string
        requestId:
          type: string
          description: Correlates this response through Conare services and logs.
        details:
          type: object
          additionalProperties: true
      required:
        - statusCode
        - code
        - message
        - requestId
  responses:
    BadRequest:
      description: Missing or invalid fields (e.g. bad `endUserId`, empty `query`).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Missing or invalid Bearer key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Forbidden:
      description: >-
        The Integration credential does not include the required operation
        scope.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    RateLimited:
      description: >
        Rate limit exceeded (reads 300/min, writes 100/min on the current plan),

        enforced atomically per (account, end user). Rate-window exhaustion
        carries

        a `Retry-After` header (seconds); `details` also has
        `retryAfterSeconds`.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
        X-RateLimit-Limit:
          description: The per-minute request cap for this operation.
          schema:
            type: integer
        X-RateLimit-Remaining:
          description: Requests remaining in the current window.
          schema:
            type: integer
        X-RateLimit-Reset:
          description: Unix-seconds timestamp when the window resets.
          schema:
            type: integer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    ServiceUnavailable:
      description: Integration namespace routing or the memory backend is not ready.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  headers:
    RequestId:
      description: Caller-provided or generated request correlation identifier.
      schema:
        type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: cint_
      description: |
        A scoped Integration key, prefixed `cint_`. Send as
        `Authorization: Bearer cint_...` on every request. Server-side only.
        Legacy personal `cmem_...` keys remain accepted during migration;
        team/org-scoped `cmem_...` keys are not valid on this API.

````