Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

Authorization-code grant with PKCE S256, exact scopes, explicit resource audience and a persisted consent grant. Obtain endpoint URLs from server discovery in the target environment. Refresh tokens remain client-bound.

FlowAuthorization Code
Authorization URL
/oauth/authorize
Token URL
/oauth/token
Refresh URL
/oauth/token
Scopes1
calendar:write
Manage calendar and slots.

Headers

Idempotency-Key
string
required

Opaque client command key of 1 to 128 visible ASCII characters. UUID recommended; reuse only for the same command.

Required string length: 1 - 128
Pattern: ^[!-~]+$

Path Parameters

profile_id
string<uuid>
required

Profile UUID; must be in the grant allowlist and currently accessible to the actor.

Body

application/json
slot_ids
string<uuid>[]
required
Required array length: 1 - 100 elements

Response

Exact accepted/skipped slot selection and durable receipt.

data
object
required
meta
object
required