{
  "schemaVersion": 1,
  "operation": {
    "operationId": "validateCredentialDraft",
    "method": "POST",
    "path": "/api/v1/projects/{project}/targets/{target}/connection-bindings/{connection}/credential-drafts/{version}/validate",
    "summary": "Validate a saved connection credential draft",
    "description": "Requires both connection.manage and connection.use on the exact connection. Probes only the saved PostgreSQL password version against the server-owned binding at expectedBindingRevision; it never changes running pools. Every explicit submission performs a fresh probe; Idempotency-Key is forbidden. A lost response may leave a receipt without returning it. Success means validated, not in use.",
    "tags": [
      "Credentials"
    ],
    "effect": "write",
    "confirmation": "conditional",
    "authorization": {
      "action": "connection.manage",
      "mode": "privilege",
      "privilege": "RESOURCE_MANAGE",
      "resolver": "connection"
    },
    "parameters": [
      {
        "name": "project",
        "in": "path",
        "required": true,
        "description": "",
        "schema": {
          "maxLength": 200,
          "minLength": 1,
          "pattern": "^[A-Za-z0-9][A-Za-z0-9_.:-]*$",
          "type": "string"
        }
      },
      {
        "name": "target",
        "in": "path",
        "required": true,
        "description": "",
        "schema": {
          "maxLength": 200,
          "minLength": 1,
          "pattern": "^[A-Za-z0-9][A-Za-z0-9_.:-]*$",
          "type": "string"
        }
      },
      {
        "name": "connection",
        "in": "path",
        "required": true,
        "description": "",
        "schema": {
          "maxLength": 200,
          "minLength": 1,
          "pattern": "^[A-Za-z0-9][A-Za-z0-9_.:-]*$",
          "type": "string"
        }
      },
      {
        "name": "version",
        "in": "path",
        "required": true,
        "description": "",
        "schema": {
          "maxLength": 36,
          "minLength": 36,
          "pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$",
          "type": "string"
        }
      }
    ],
    "requestBody": {
      "required": true,
      "description": "",
      "content": [
        {
          "contentType": "application/json",
          "schema": {
            "$ref": "#/components/schemas/CredentialValidationRequest"
          }
        }
      ]
    },
    "responses": [
      {
        "status": "200",
        "description": "The request has succeeded.",
        "content": [
          {
            "contentType": "application/json",
            "schema": {
              "$ref": "#/components/schemas/CredentialValidationResponse"
            }
          }
        ]
      },
      {
        "status": "400",
        "description": "The server could not understand the request due to invalid syntax.",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "401",
        "description": "Access is unauthorized.",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "403",
        "description": "Access is forbidden.",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "404",
        "description": "The server cannot find the requested resource.",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "409",
        "description": "The request conflicts with the current state of the server.",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "412",
        "description": "Precondition failed.",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "413",
        "description": "Client error",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "415",
        "description": "Client error",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "422",
        "description": "Client error",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "429",
        "description": "Client error",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "500",
        "description": "Server error",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "502",
        "description": "Server error",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      },
      {
        "status": "503",
        "description": "Service unavailable.",
        "content": [
          {
            "contentType": "application/problem+json",
            "schema": {
              "$ref": "#/components/schemas/ProblemDetails"
            }
          }
        ]
      }
    ]
  },
  "schemas": {
    "CredentialValidationRequest": {
      "example": {
        "expectedBindingRevision": 1
      },
      "properties": {
        "expectedBindingRevision": {
          "example": 1,
          "format": "int64",
          "minimum": 1,
          "type": "integer"
        }
      },
      "required": [
        "expectedBindingRevision"
      ],
      "type": "object"
    },
    "CredentialValidationResponse": {
      "description": "Observation from an isolated probe of this saved version and binding revision. Validation does not activate the credential or permit revoking the previous credential. The receipt expires after five minutes and can become stale sooner if configuration or authority changes.",
      "example": {
        "bindingRevision": 1,
        "expiresAt": "2026-01-02T15:04:05Z",
        "receiptId": "example",
        "state": "example",
        "validatedAt": "2026-01-02T15:04:05Z",
        "versionId": "example"
      },
      "properties": {
        "bindingRevision": {
          "example": 1,
          "format": "int64",
          "type": "integer"
        },
        "expiresAt": {
          "example": "2026-01-02T15:04:05Z",
          "format": "date-time",
          "type": "string"
        },
        "receiptId": {
          "example": "example",
          "maxLength": 36,
          "minLength": 36,
          "pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$",
          "type": "string"
        },
        "state": {
          "enum": [
            "validated"
          ],
          "example": "example",
          "type": "string"
        },
        "validatedAt": {
          "example": "2026-01-02T15:04:05Z",
          "format": "date-time",
          "type": "string"
        },
        "versionId": {
          "example": "example",
          "maxLength": 36,
          "minLength": 36,
          "pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$",
          "type": "string"
        }
      },
      "required": [
        "receiptId",
        "versionId",
        "bindingRevision",
        "validatedAt",
        "expiresAt",
        "state"
      ],
      "type": "object"
    },
    "ProblemDetails": {
      "example": {
        "code": "example",
        "detail": "example",
        "errors": [
          {
            "code": "example",
            "detail": "example",
            "field": "example"
          }
        ],
        "instance": "example",
        "requestId": "example",
        "status": 1,
        "title": "example",
        "type": "example"
      },
      "properties": {
        "code": {
          "example": "example",
          "type": "string"
        },
        "detail": {
          "example": "example",
          "type": "string"
        },
        "errors": {
          "example": [
            {
              "code": "example",
              "detail": "example",
              "field": "example"
            }
          ],
          "items": {
            "$ref": "#/components/schemas/ProblemFieldError"
          },
          "type": "array"
        },
        "instance": {
          "example": "example",
          "type": "string"
        },
        "requestId": {
          "example": "example",
          "type": "string"
        },
        "status": {
          "example": 1,
          "format": "int32",
          "type": "integer"
        },
        "title": {
          "example": "example",
          "type": "string"
        },
        "type": {
          "example": "example",
          "type": "string"
        }
      },
      "required": [
        "type",
        "title",
        "status",
        "detail",
        "instance",
        "code",
        "requestId",
        "errors"
      ],
      "type": "object"
    },
    "ProblemFieldError": {
      "example": {
        "code": "example",
        "detail": "example",
        "field": "example"
      },
      "properties": {
        "code": {
          "example": "example",
          "type": "string"
        },
        "detail": {
          "example": "example",
          "type": "string"
        },
        "field": {
          "example": "example",
          "type": "string"
        }
      },
      "required": [
        "field",
        "code",
        "detail"
      ],
      "type": "object"
    }
  }
}
