{"openapi":"3.0.0","info":{"title":"FlowSync API","version":"1.0.0","description":"\n        API para gestión multi-tenant de cuentas bancarias, transacciones y mensajería ISO 20022.\n        Incluye autenticación JWT, criptografía post-cuántica (PQC) y análisis con IA.\n\n        ## Autenticación\n        - **Cookie httpOnly** (web app): la cookie `flowsync_auth` se fija automáticamente en login.\n        - **Bearer Token** (SDKs/servidores): header `Authorization: Bearer <jwt>`.\n\n        ## Multi-tenancy\n        Todas las rutas (excepto `/auth`, `/demo`, `/health`) filtran por `companyId` del JWT.\n        El panel `/admin` requiere `ADMIN_EMAIL` configurado (super-admin global).\n\n        ## Transferencias seguras\n        POST /transactions requiere el header Idempotency-Key: un UUID nuevo por operación.\n        Reutiliza exactamente la misma clave y el mismo cuerpo al reintentar tras un corte de red.\n        Respuestas: 201 al crear, 200 al recuperar el comprobante original, 409 si cambia el cuerpo.\n        Ambas cuentas deben estar activas, pertenecer a la empresa y usar la misma moneda.\n        Envía amount como texto decimal: USD admite dos decimales; CLP, pesos enteros.\n        Los campos amountExact y balanceExact conservan la precisión decimal en las consultas.\n\n        ## Rate Limiting\n        - Login: 5 req/15min por IP+email\n        - Register: 10 req/min por IP\n        - APIs autenticadas: 100 req/min por usuario\n\n        ## Códigos de error comunes\n        | Código | Significado |\n        |--------|-------------|\n        | 400 | Validación (Zod) fallida |\n        | 401 | Token inválido/expirado |\n        | 403 | Sin permisos (rol o multi-tenant) |\n        | 404 | Recurso no encontrado |\n        | 429 | Rate limit excedido |\n        | 500 | Error interno del servidor |\n      ","contact":{"name":"FlowSync Team","email":"support@flowsync.example.com"},"license":{"name":"Proprietary"}},"servers":[{"url":"/api","description":"API base path (relative)"},{"url":"https://api.flowsync.example.com/api","description":"Production (example)"}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT","description":"JWT token en header Authorization: Bearer <token>"},"cookieAuth":{"type":"apiKey","in":"cookie","name":"flowsync_auth","description":"Cookie httpOnly establecida por /api/auth (login/register)"}},"schemas":{"Error":{"type":"object","properties":{"error":{"type":"string","example":"Credenciales inválidas"},"details":{"type":"array","items":{"type":"string"},"example":["Email inválido","Password muy corto"]}}},"User":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"email":{"type":"string","format":"email"},"name":{"type":"string","nullable":true},"role":{"type":"string","enum":["USER","ADMIN"]},"companyId":{"type":"string","format":"uuid"},"lastLogin":{"type":"string","format":"date-time","nullable":true},"createdAt":{"type":"string","format":"date-time"}}},"Company":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"name":{"type":"string"},"taxId":{"type":"string","nullable":true},"countryCode":{"type":"string","example":"MX"},"industry":{"type":"string","nullable":true},"tier":{"type":"string","enum":["FREE","PRO","ENTERPRISE"]},"createdAt":{"type":"string","format":"date-time"},"updatedAt":{"type":"string","format":"date-time"}}},"BankAccount":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"companyId":{"type":"string","format":"uuid"},"bankName":{"type":"string"},"accountNumber":{"type":"string"},"iban":{"type":"string","nullable":true},"swiftCode":{"type":"string","nullable":true},"currency":{"type":"string","example":"MXN"},"balance":{"type":"string","format":"decimal","example":"123456.78"},"isActive":{"type":"boolean"},"lastSync":{"type":"string","format":"date-time","nullable":true},"createdAt":{"type":"string","format":"date-time"},"updatedAt":{"type":"string","format":"date-time"}}},"Transaction":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"companyId":{"type":"string","format":"uuid"},"fromAccountId":{"type":"string","format":"uuid","nullable":true},"toAccountId":{"type":"string","format":"uuid","nullable":true},"amount":{"type":"string","format":"decimal","example":"1000.00"},"currency":{"type":"string","example":"MXN"},"exchangeRate":{"type":"string","format":"decimal","nullable":true},"fee":{"type":"string","format":"decimal","nullable":true},"transactionType":{"type":"string","nullable":true},"status":{"type":"string","enum":["PENDING","COMPLETED","FAILED","CANCELLED"]},"referenceNumber":{"type":"string","nullable":true},"description":{"type":"string","nullable":true},"counterpartyName":{"type":"string","nullable":true},"counterpartyIban":{"type":"string","nullable":true},"createdAt":{"type":"string","format":"date-time"},"processedAt":{"type":"string","format":"date-time","nullable":true},"settledAt":{"type":"string","format":"date-time","nullable":true}}},"PqcSeal":{"type":"object","description":"Sello post-cuántico generado client-side (ML-KEM-768 + X25519)","properties":{"algo":{"type":"string","example":"ML-KEM-768 + X25519 (híbrido)"},"standard":{"type":"string","example":"NIST FIPS 203"},"timestamp":{"type":"string","format":"date-time"},"messageHash":{"type":"string","pattern":"^[a-f0-9]+$"},"publicKeyFingerprint":{"type":"string","pattern":"^[a-f0-9]{32}$"},"publicKeyHex":{"type":"string","pattern":"^[a-f0-9]+$"},"cipherTextFingerprint":{"type":"string","pattern":"^[a-f0-9]{32}$"},"cipherTextHex":{"type":"string","pattern":"^[a-f0-9]+$"},"sharedFingerprint":{"type":"string","pattern":"^[a-f0-9]{32}$"},"seal":{"type":"string","pattern":"^[a-f0-9]{64}$"},"verified":{"type":"boolean"}}},"PqcServerNegotiation":{"type":"object","description":"Resultado de negociación PQC server-side","properties":{"algo":{"type":"string","example":"ML-KEM-768 + X25519 (híbrido)"},"standard":{"type":"string","example":"NIST FIPS 203"},"timestamp":{"type":"string","format":"date-time"},"handshakeHash":{"type":"string","pattern":"^[a-f0-9]{32}$"},"serverPublicKeyFingerprint":{"type":"string","pattern":"^[a-f0-9]{32}$"},"cipherTextFingerprint":{"type":"string","pattern":"^[a-f0-9]{32}$"},"sharedFingerprint":{"type":"string","pattern":"^[a-f0-9]{32}$"},"verified":{"type":"boolean"}}}}},"security":[{"bearerAuth":[]},{"cookieAuth":[]}],"tags":[{"name":"Auth","description":"Autenticación y registro"},{"name":"Companies","description":"Gestión de empresas"},{"name":"Accounts","description":"Cuentas bancarias"},{"name":"Transactions","description":"Transacciones y pagos"},{"name":"ISO20022","description":"Mensajería ISO 20022 (pain.001, pacs.008, camt.053)"},{"name":"AI","description":"Análisis y generación con Gemini"},{"name":"Quantum","description":"Criptografía post-cuántica (PQC)"},{"name":"Loans","description":"Préstamos y pagos"},{"name":"Reports","description":"Reportes y exportaciones"},{"name":"Admin","description":"Panel global (solo super-admin)"},{"name":"Demo","description":"Captura de leads"},{"name":"Health","description":"Health checks"}],"paths":{}}