FlowRelay FlowRelay Docs Shopify Flow
All docs pages

START

USE CASES

SET UP

OPERATE

RECOVER

AGENT ACCESS

REFERENCE

Markdown

Plain Markdown for agents, CLIs, MCP clients, and readers who want a copyable text version.

# OpenAPI

Canonical: https://docs.flowrelay.app/reference/openapi/
Markdown: https://docs.flowrelay.app/reference/openapi.md

Generated OpenAPI schema discovery and public contract placement for Agent Operations.

## Schema location
Use the OpenAPI document for exact field names, types, and shapes. Use these prose docs for product meaning, delivery semantics, and safe guidance. The two are complementary; neither replaces the other.

- Artifact: OpenAPI JSON; URL: https://docs.flowrelay.app/reference/openapi/agent-operations.openapi.json
- Artifact: Trigger mapping reference; URL: https://docs.flowrelay.app/setup/trigger-variants-and-event-mapping/
- Artifact: Agent mission playbooks; URL: https://docs.flowrelay.app/agent-access/agent-mission-playbooks/
- Artifact: Availability and refusals; URL: https://docs.flowrelay.app/agent-access/availability-and-refusals/
- Artifact: Agent orientation; URL: https://docs.flowrelay.app/agent-access/agent-orientation/
- Artifact: Docs index; URL: https://docs.flowrelay.app/llms.txt

## Versioning
Generated schema versions move with the Agent Operations contract. Agents re-read the manifest and OpenAPI document before relying on cached operation names or schemas.

## Operation names
Use stable operation IDs for generated clients. Keep docs examples synthetic and redacted, and do not include real tokens, authentication headers, event bodies, or customer records.

## Generated clients
If you generate a client from the schema, preserve refusal handling, idempotency keys, docs URLs in refusals, and the action-preview lifecycle. These behaviors are part of the Agent Operations contract and must remain visible in your client.

## Example Surface
- `GET /reference/openapi/agent-operations.openapi.json`
- `operationId: getAgentManifest`
- `x-flowrelay-docs.docsIndex`

## Safety Boundary
Do not share endpoint secrets, authentication headers, HMAC values, tokens, raw event bodies, customer records, Shopify sessions, store passwords, or database URLs in public examples.