{
  "openapi": "3.0.1",
  "info": {
    "title": "Croesus Mock SaaS OBO API",
    "description": "Mock Croesus middle-tier API demonstrating the correct On-Behalf-Of (OBO) flow (GET /api/me) versus the gated, deliberate token-replay anti-pattern (POST /api/replay, present only when Demo:EnableReplay is true). All endpoints require an API-audienced bearer token with the access_as_user scope.",
    "version": "v1"
  },
  "paths": {
    "/api/Me": {
      "get": {
        "tags": [
          "Me"
        ],
        "responses": {
          "200": {
            "description": "OK"
          }
        }
      }
    },
    "/api/Replay": {
      "post": {
        "tags": [
          "Replay"
        ],
        "requestBody": {
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/ReplayRequest"
              }
            },
            "text/json": {
              "schema": {
                "$ref": "#/components/schemas/ReplayRequest"
              }
            },
            "application/*+json": {
              "schema": {
                "$ref": "#/components/schemas/ReplayRequest"
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "OK"
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "ReplayRequest": {
        "type": "object",
        "properties": {
          "graphToken": {
            "type": "string",
            "nullable": true
          }
        },
        "additionalProperties": false
      }
    },
    "securitySchemes": {
      "oauth2": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://login.microsoftonline.com/aa93b9d9-037d-4f08-a26d-783cff0e2369/oauth2/v2.0/authorize",
            "tokenUrl": "https://login.microsoftonline.com/aa93b9d9-037d-4f08-a26d-783cff0e2369/oauth2/v2.0/token",
            "scopes": {
              "api://bc6338a5-a02a-4ddf-b1f4-9a9234bed8a8/access_as_user": "Access the Croesus API as the signed-in user"
            }
          }
        }
      }
    }
  },
  "security": [
    {
      "oauth2": [
        "api://bc6338a5-a02a-4ddf-b1f4-9a9234bed8a8/access_as_user"
      ]
    }
  ]
}