{
  "openapi": "3.1.0",
  "info": {
    "title": "Convertify agent API",
    "version": "0.1.0",
    "summary": "MCP server and OAuth 2.1 authorization server for Convertify.",
    "description": "A/B testing for Shopify judged by profit per visitor (GMPV). Read test results and behavioral analytics, and draft, validate, launch and stop tests on a connected store. The API is the Model Context Protocol over Streamable HTTP; the 80 tools are discovered with the MCP `tools/list` method rather than listed here. Versioning follows the MCP-Protocol-Version header. Tool calls are rate limited per token; a limited call returns a tool error with the seconds to wait.",
    "contact": {
      "name": "Convertify support",
      "email": "support@useconvertify.com",
      "url": "https://useconvertify.com/contact"
    },
    "termsOfService": "https://useconvertify.com/terms"
  },
  "externalDocs": {
    "description": "Developer docs",
    "url": "https://useconvertify.com/developers"
  },
  "servers": [
    {
      "url": "https://ai.useconvertify.com",
      "description": "Convertify AI host"
    }
  ],
  "security": [
    {
      "oauth2": [
        "convertify:read"
      ]
    }
  ],
  "paths": {
    "/mcp": {
      "post": {
        "operationId": "mcp",
        "summary": "Model Context Protocol endpoint (JSON-RPC 2.0 over Streamable HTTP)",
        "description": "Send MCP JSON-RPC requests such as initialize, tools/list, tools/call, prompts/list and prompts/get. Each tool requires exactly one of the declared scopes; a missing scope answers 403 insufficient_scope.",
        "security": [
          {
            "oauth2": [
              "convertify:read",
              "convertify:tests:write",
              "convertify:settings:write",
              "convertify:ai"
            ]
          }
        ],
        "parameters": [
          {
            "name": "MCP-Protocol-Version",
            "in": "header",
            "required": false,
            "description": "MCP protocol revision negotiated at initialize. The API is versioned by this header rather than by URL path; an unsupported revision answers 400.",
            "schema": {
              "type": "string",
              "example": "2025-11-25"
            }
          }
        ],
        "requestBody": {
          "required": true,
          "description": "A JSON-RPC 2.0 request.",
          "content": {
            "application/json": {
              "schema": {
                "type": "object"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "A JSON-RPC 2.0 response, as JSON or an SSE stream.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              },
              "text/event-stream": {
                "schema": {
                  "type": "string"
                }
              }
            }
          },
          "400": {
            "description": "Malformed JSON-RPC request or unsupported MCP-Protocol-Version.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "Missing or invalid token. WWW-Authenticate points at the protected resource metadata.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "403": {
            "description": "The token lacks the scope the tool requires (insufficient_scope), or the store plan does not include MCP access (upgrade_required).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      }
    },
    "/mcp/status": {
      "get": {
        "operationId": "mcpStatus",
        "summary": "MCP server health",
        "security": [],
        "responses": {
          "200": {
            "description": "Server status.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    },
    "/oauth/register": {
      "post": {
        "operationId": "registerClient",
        "summary": "Dynamic Client Registration (RFC 7591)",
        "security": [],
        "requestBody": {
          "required": true,
          "description": "Client metadata: client_name, redirect_uris, grant_types, token_endpoint_auth_method.",
          "content": {
            "application/json": {
              "schema": {
                "type": "object"
              }
            }
          }
        },
        "responses": {
          "201": {
            "description": "The registered client, including client_id.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "description": "Invalid client metadata.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "429": {
            "description": "Too many registrations. Retry-After gives the wait in seconds.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      }
    },
    "/oauth/authorize": {
      "get": {
        "operationId": "authorize",
        "summary": "Authorization endpoint (authorization code + PKCE S256)",
        "security": [],
        "parameters": [
          {
            "name": "response_type",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "client_id",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "redirect_uri",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "code_challenge",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "code_challenge_method",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "scope",
            "in": "query",
            "required": false,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "state",
            "in": "query",
            "required": false,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "resource",
            "in": "query",
            "required": false,
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "302": {
            "description": "Redirect to the consent screen, then back to redirect_uri with a code."
          }
        }
      }
    },
    "/oauth/token": {
      "post": {
        "operationId": "token",
        "summary": "Token endpoint (authorization_code and refresh_token grants)",
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "type": "object"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "access_token, refresh_token, expires_in, scope.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "description": "invalid_request, invalid_grant or another RFC 6749 error.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          },
          "401": {
            "description": "invalid_client.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Error"
                }
              }
            }
          }
        }
      }
    },
    "/oauth/revoke": {
      "post": {
        "operationId": "revoke",
        "summary": "Token revocation (RFC 7009)",
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "type": "object"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The token is revoked."
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "Error": {
        "type": "object",
        "description": "OAuth-style error object returned by every non-2xx response.",
        "required": [
          "error"
        ],
        "properties": {
          "error": {
            "type": "string",
            "description": "Machine-readable code, for example invalid_token, insufficient_scope, upgrade_required or not_found."
          },
          "error_description": {
            "type": "string",
            "description": "Human-readable explanation."
          }
        }
      }
    },
    "securitySchemes": {
      "oauth2": {
        "type": "oauth2",
        "description": "OAuth 2.1 authorization code flow with PKCE (S256). Discovery: /.well-known/oauth-authorization-server.",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://ai.useconvertify.com/oauth/authorize",
            "tokenUrl": "https://ai.useconvertify.com/oauth/token",
            "refreshUrl": "https://ai.useconvertify.com/oauth/token",
            "scopes": {
              "convertify:read": "View tests, GMPV analytics, behavioral data, campaigns, and store settings.",
              "convertify:tests:write": "Draft, launch, stop, update, and delete A/B tests and conflict groups.",
              "convertify:settings:write": "Update recording settings, saved funnels/cohorts, the web pixel, and campaign sync.",
              "convertify:ai": "Generate AI summaries, briefings, and chat grounded in your data (spends AI credits)."
            }
          }
        }
      }
    }
  }
}
