# Customer endpoints: API reference

> Called with an organization API key (or, from the website, a signed-in session). Everything you need to create, check, submit and follow a case.

Source: https://evictionsapi.com/docs/api/customer

Called with an organization API key (or, from the website, a signed-in session). Everything you need to create, check, submit and follow a case.

The examples use https://api.evictionsapi.com and placeholder keys. The conventions shared by all endpoints, the error codes and the rate limits are in https://evictionsapi.com/docs/api.md

## Endpoints

### GET /v1/jurisdictions/resolve

Whether a jurisdiction is served, and its notice rules

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `state` | query | string | Yes | Two-letter state code. In test mode, ZZ is the fictional sandbox state. |
| `county` | query | string | No | County name, to include county-level rules. |
| `city` | query | string | No | City name, to include city-level rules. |

```sh
curl "https://api.evictionsapi.com/v1/jurisdictions/resolve?state=ZZ" \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` Served status, `handling`, jurisdiction ids and the grounds. In live mode every US state and DC is served with `handling: "attorney_direct"`, `action: null` and, for each ground, `notice: null` and the facts intake requires (`requiredFacts`); anything else is `served: false`. In test mode (`handling: "automated"`) the sandbox jurisdiction answers with its notice rules for each ground. Body: object.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/cases

Create a draft case. In live mode the property must be in a US state or DC (422 `unsupported_state`) and the case is an attorney-direct case

Credential: API key (`Authorization: Bearer eak_test_...`).

```sh
curl -X POST https://api.evictionsapi.com/v1/cases \
  -H "Authorization: Bearer eak_test_..." \
  -H "Content-Type: application/json" \
  -d '{
  "ground": "nonpayment",
  "entryPoint": "notice",
  "property": {
    "line1": "1 Main St",
    "city": "Testville",
    "state": "ZZ",
    "zip": "00000",
    "ownerOfRecord": "Pat Landlord"
  },
  "parties": [
    { "role": "plaintiff", "name": "Pat Landlord" },
    { "role": "defendant", "name": "Terry Tenant" }
  ],
  "lease": { "startDate": "2025-01-01", "monthlyRentCents": 150000 },
  "ledger": [
    { "date": "2026-09-01", "type": "charge", "amountCents": 150000 },
    { "date": "2026-10-01", "type": "charge", "amountCents": 150000 },
    { "date": "2026-10-02", "type": "payment", "amountCents": 50000 }
  ],
  "amountOwedCents": 250000,
  "attestations": {
    "authority": true,
    "notRetaliatory": true,
    "notDiscriminatory": true,
    "servicemember": "no",
    "caresCovered": false
  }
}'
```

Responses:

- `201` The draft case. Body: Case.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### GET /v1/cases

List the cases of the key's organization and mode

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `cursor` | query | string | No | The nextCursor of the previous page. Omit it for the first page. |
| `limit` | query | string | No | Page size, 1 to 100. Default 20; a larger value is treated as 100. |

```sh
curl "https://api.evictionsapi.com/v1/cases?limit=20" \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` A page of cases, newest first. Body: { items: Case[], nextCursor: string | null }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### GET /v1/cases/{id}

Get a case

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl https://api.evictionsapi.com/v1/cases/case_... \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The case. Body: Case.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### PATCH /v1/cases/{id}

Change the facts of a draft case

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl -X PATCH https://api.evictionsapi.com/v1/cases/case_... \
  -H "Authorization: Bearer eak_test_..." \
  -H "Content-Type: application/json" \
  -d '{ "amountOwedCents": 250000 }'
```

Responses:

- `200` The updated case. Body: Case.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/cases/{id}/documents

Upload evidence for a draft case: a PDF, JPEG or PNG, decided by the file's contents (415 `unsupported_media_type` otherwise, for a live case). For a live case, `purpose: "other"` files can also be added after submission, until the case is finished

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl -X POST https://api.evictionsapi.com/v1/cases/case_.../documents \
  -H "Authorization: Bearer eak_test_..." \
  -H "Content-Type: application/json" \
  -d '{
  "filename": "deed.pdf",
  "purpose": "authority",
  "contentBase64": "ZGVlZA=="
}'
```

Responses:

- `201` The stored document. Body: Document.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### GET /v1/cases/{id}/documents/{docId}

Download a document of the case

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |
| `docId` | path | string | Yes | The document id. |

```sh
curl https://api.evictionsapi.com/v1/cases/case_.../documents/doc_... \
  -H "Authorization: Bearer eak_test_..." \
  -o document.pdf
```

Responses:

- `200` The document bytes, with the stored `Content-Type`: `application/pdf`, `image/jpeg` or `image/png`. Body: binary.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `410` `erased`: the details of the case were erased, and the document's content with them. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/cases/{id}/validate

Run the submission gates on a draft

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl -X POST https://api.evictionsapi.com/v1/cases/case_.../validate \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The gate results. Body: GateResults.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/cases/{id}/submit

Submit a draft that passes every gate. A live case moves to `submitted`, its platform fee becomes a due charge, and we engage a licensed attorney in the property's state; nothing is served or filed until that attorney has reviewed it. A test case enters the sandbox review

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl -X POST https://api.evictionsapi.com/v1/cases/case_.../submit \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The case after submission, and the gate results. Body: { case: Case, gates: object[] }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### GET /v1/cases/{id}/events

Customer-visible events of the case, oldest first

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl https://api.evictionsapi.com/v1/cases/case_.../events \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The events. Body: { items: Event[] }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/cases/{id}/report-cure

Report that the tenant has paid or cured. For a live case the report is recorded and passed on to the attorney; the case is not closed automatically

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl -X POST https://api.evictionsapi.com/v1/cases/case_.../report-cure \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The case. Body: Case.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/cases/{id}/withdraw

Withdraw the case. A live case with an attorney already engaged goes `on_hold` with a `withdrawal_requested` event instead, and is withdrawn once the attorney has confirmed that all work has stopped

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl -X POST https://api.evictionsapi.com/v1/cases/case_.../withdraw \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The case: withdrawn, or on hold while the withdrawal is confirmed. Body: Case.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### GET /v1/cases/{id}/charges

The charges on the case, oldest first, and whether online payment is available

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl https://api.evictionsapi.com/v1/cases/case_.../charges \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The charges. `paymentsEnabled` false: charges show as due and `checkout` answers 409 `payments_unavailable`. Body: { items: Charge[], paymentsEnabled: boolean }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/cases/{id}/charges/{chargeId}/checkout

Open a hosted checkout for one due charge. 409 `payments_unavailable` when online payment is off; 409 `charge_not_due` when the charge is paid, void or refunded

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |
| `chargeId` | path | string | Yes |  |

```sh
curl -X POST https://api.evictionsapi.com/v1/cases/case_.../charges/chargeId_.../checkout \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The checkout URL to send the customer to. They return to the case page on the website. Body: { url: string }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/cases/{id}/charges/{chargeId}/confirm

Check with the payment provider whether the charge's checkout was paid, and record it if so. Safe to repeat. 409 `payments_unavailable` when online payment is off

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |
| `chargeId` | path | string | Yes |  |

```sh
curl -X POST https://api.evictionsapi.com/v1/cases/case_.../charges/chargeId_.../confirm \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The charge as it now is. Body: Charge.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### GET /v1/cases/{id}/notes

The messages on the case: the customer's own and ours, oldest first

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl https://api.evictionsapi.com/v1/cases/case_.../notes \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The messages. Body: { items: Note[] }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/cases/{id}/notes

Send us a message about a live case. 409 `attorney_direct_only` for a test case. At most 20 every 10 minutes per organization (429 `rate_limited`)

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl -X POST https://api.evictionsapi.com/v1/cases/case_.../notes \
  -H "Authorization: Bearer eak_test_..." \
  -H "Content-Type: application/json" \
  -d '{
  "body": "The tenant paid half of the balance yesterday. Does that change the next step?"
}'
```

Responses:

- `201` The stored message. Body: Note.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/cases/{id}/advance

Sandbox only: move a test case on by one step. Runs the step the case is waiting for now (the sandbox reviewer's review, a service or filing update, or the end of the notice period on the case's own sandbox clock), or records the next court outcome as the sandbox reviewer. A live case (nothing about a real case is ever advanced automatically), or a case outside the sandbox jurisdiction, gets 409 `sandbox_only`; a draft, a case on hold or a finished case gets 409 `nothing_to_advance`, as does a step whose last try failed, until its automatic retry (`error.details.retryAt`). While the step is already being taken, the case is returned as it is. At most 60 a minute per organization (429 `rate_limited`)

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The case id. |

```sh
curl -X POST https://api.evictionsapi.com/v1/cases/case_.../advance \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The case after the step. Body: Case.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/webhook-endpoints

Register a webhook endpoint

Credential: API key (`Authorization: Bearer eak_test_...`).

```sh
curl -X POST https://api.evictionsapi.com/v1/webhook-endpoints \
  -H "Authorization: Bearer eak_test_..." \
  -H "Content-Type: application/json" \
  -d '{ "url": "https://example.com/webhooks/evictions" }'
```

Responses:

- `201` The endpoint. The signing secret appears in this response only. An `Idempotency-Key` header is ignored: every request creates an endpoint, and no response is stored or replayed. Body: object.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### GET /v1/webhook-endpoints

List the organization's webhook endpoints in the credential's mode. The signing secret is never shown again

Credential: API key (`Authorization: Bearer eak_test_...`).

```sh
curl https://api.evictionsapi.com/v1/webhook-endpoints \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The endpoints, oldest first. Body: { items: object[] }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### GET /v1/api-keys

List the organization's API keys in the credential's mode, newest first, revoked ones included. The secret is never shown again

Credential: API key (`Authorization: Bearer eak_test_...`).

```sh
curl https://api.evictionsapi.com/v1/api-keys \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The keys, each with the last four characters of its secret (null for a key created before they were recorded) and when it was revoked, if it was. Body: { items: object[] }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/api-keys

Create an API key in the credential's mode. A live key can be created only by an owner of the organization, signed in with a session and `X-Evictions-Mode: live` (403 `forbidden` otherwise, also for a live API key); at most 10 active keys per mode (409 `key_limit`)

Credential: API key (`Authorization: Bearer eak_test_...`).

```sh
curl -X POST https://api.evictionsapi.com/v1/api-keys \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `201` The new key. The secret appears in this response only. An `Idempotency-Key` header is ignored: every request creates a key, and no response is stored or replayed. Body: { id: string, mode: string, secret: string }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### DELETE /v1/api-keys/{id}

Revoke an API key of the organization and the credential's mode. A key cannot revoke itself (409 `cannot_revoke_current_key`)

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The API key id. |

```sh
curl -X DELETE https://api.evictionsapi.com/v1/api-keys/key_... \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `204` The key is revoked and no longer authenticates. Revoking a revoked key is also 204.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### DELETE /v1/webhook-endpoints/{id}

Delete a webhook endpoint. Deliveries still waiting to be retried for it are dropped

Credential: API key (`Authorization: Bearer eak_test_...`).

| Parameter | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string | Yes | The webhook endpoint id. |

```sh
curl -X DELETE https://api.evictionsapi.com/v1/webhook-endpoints/whe_... \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `204` The endpoint and its delivery log are deleted.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### GET /v1/organization

The caller's organization and its members

Credential: API key (`Authorization: Bearer eak_test_...`).

```sh
curl https://api.evictionsapi.com/v1/organization \
  -H "Authorization: Bearer eak_test_..."
```

Responses:

- `200` The organization and its members. Body: { id: string, name: string, verified: boolean, members: object[] }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### PATCH /v1/organization

Rename the organization. Only an owner, signed in with a session; an API key or a plain member gets 403

Credential: Session token (`Authorization: Bearer ess_...`).

```sh
curl -X PATCH https://api.evictionsapi.com/v1/organization \
  -H "Authorization: Bearer ess_..." \
  -H "Content-Type: application/json" \
  -d '{ "name": "Acme Property Management" }'
```

Responses:

- `200` The organization after the change. Body: { id: string, name: string, verified: boolean, members: object[] }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/auth/logout

Revoke the session in use

Credential: Session token (`Authorization: Bearer ess_...`).

```sh
curl -X POST https://api.evictionsapi.com/v1/auth/logout \
  -H "Authorization: Bearer ess_..."
```

Responses:

- `204` The session is revoked.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.

### POST /v1/auth/password-reset/request

Ask for a password reset link by email. No credential. The answer is the same whether or not the address has an account

No credential.

```sh
curl -X POST https://api.evictionsapi.com/v1/auth/password-reset/request \
  -H "Content-Type: application/json" \
  -d '{ "email": "pat@example.com" }'
```

Responses:

- `202` The request was accepted. If the address belongs to an account that signs in to the site, a single-use link valid for one hour was emailed to it. One account is sent at most 3 such emails an hour: a request beyond that gets this same answer and sends nothing. An `Idempotency-Key` header is ignored. Body: { ok: boolean }.
- `400` The request is invalid. Body: Error.
- `413` The request body is too large. Body: Error.
- `429` Too many password reset requests from this address: at most 10 every 10 minutes, counting both reset endpoints. `Retry-After` gives the seconds to wait. Body: Error.

### POST /v1/auth/password-reset/confirm

Set a new password with the token from a reset link. No credential. The token works once; every session of the user is revoked

No credential.

```sh
curl -X POST https://api.evictionsapi.com/v1/auth/password-reset/confirm \
  -H "Content-Type: application/json" \
  -d '{
  "token": "epr_...",
  "password": "a new long passphrase, not this one"
}'
```

Responses:

- `200` The password was changed and every session of the user was revoked. Sign in again with the new password. An `Idempotency-Key` header is ignored. Body: { ok: boolean }.
- `400` `invalid_reset_token`: the token is unknown, already used or expired. `invalid_request`: the password is not 10 to 200 characters (`details.issues` names `password`). Body: Error.
- `413` The request body is too large. Body: Error.
- `429` Too many password reset requests from this address: at most 10 every 10 minutes, counting both reset endpoints. `Retry-After` gives the seconds to wait. Body: Error.
- `503` `busy`: too many password checks are waiting. Nothing was changed and the token is still unused. `Retry-After: 5` gives the seconds to wait; try again. Body: Error.

### GET /v1/me

The signed-in user, their organization and the modes available to it

Credential: Session token (`Authorization: Bearer ess_...`).

```sh
curl https://api.evictionsapi.com/v1/me \
  -H "Authorization: Bearer ess_..."
```

Responses:

- `200` The user with their role, the organization and the modes this server offers. Body: { user: object, organization: object, modes: object }.
- `400` The request is invalid. Body: Error.
- `401` The credential is missing or invalid. Body: Error.
- `403` The credential is not allowed to do this. Body: Error.
- `404` Not found. Body: Error.
- `409` The request conflicts with the current state: for a case, it is not in a state that allows this, or its details were erased (`erased`); for an API key, a limit or the key in use. Body: Error.
- `422` The case did not pass a check. Body: Error.
