> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dentalspace.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Documentazione di dentalspace. Il testo completo, incluso il riferimento API, è in /llms-full.txt. Per endpoint, campi e codici di errore la fonte di verità è openapi.json: non usare endpoint o campi non documentati.

# La chiave che sta chiamando

> Clinica, chiave (scope, sedi, scadenza), limiti e modalita'. Basta una chiave valida, senza scope.



## OpenAPI

````yaml /openapi.json get /me
openapi: 3.1.0
info:
  title: DentalSpace API
  version: 1.0.0
  description: >-
    API pubblica di DentalSpace. Ogni richiesta porta `Authorization: Bearer
    <chiave>`

    (`dsk_live_…`, o `dsk_test_…` per una clinica di prova: nessun messaggio
    parte verso l'esterno).

    La chiave vede solo la sua clinica (e le sue sedi, se limitata): una risorsa
    di altri e' sempre 404.


    Errori: `{ "error": { "code", "message", "details", "requestId" } }`; `code`
    e' stabile, `message` no.

    Limiti: 100 richieste ogni 10 secondi e 20.000 al giorno (UTC) per clinica,
    60 e 12.000 per chiave;

    header `X-RateLimit-*` su ogni risposta, `Retry-After` sul 429 (che non
    consuma).

    Elenchi a cursore: `limit` 1-200, `cursor` = il `nextCursor` precedente,
    `updatedSince` per sincronizzare.

    `Idempotency-Key` sulle creazioni: la stessa chiave entro 24 ore ripete la
    prima risposta.
servers:
  - url: https://api.dentalspace.ai/v1
security:
  - bearerAuth: []
tags:
  - name: Meta
  - name: Studio
  - name: Pazienti
  - name: Agenda
  - name: Preventivi
  - name: Fatture e pagamenti
  - name: Documenti
  - name: Attività
  - name: Contatti commerciali
  - name: Messaggi WhatsApp
  - name: Telefonate
  - name: Agente vocale
  - name: Webhook ed eventi
paths:
  /me:
    get:
      tags:
        - Meta
      summary: La chiave che sta chiamando
      description: >-
        Clinica, chiave (scope, sedi, scadenza), limiti e modalita'. Basta una
        chiave valida, senza scope.
      operationId: getMe
      parameters: []
      responses:
        '200':
          description: La chiave e la sua clinica.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Me'
        '401':
          description: 'Codici: `unauthenticated`, `api_key_invalid`, `api_key_revoked`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: 'Codici: `plan_required`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: 'Codici: `rate_limited`.'
          headers:
            Retry-After:
              $ref: '#/components/headers/Retry-After'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: 'Codici: `internal_error`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: 'Codici: `unavailable`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearerAuth: []
components:
  headers:
    X-Request-Id:
      description: Identificativo della richiesta, da citare all'assistenza.
      schema:
        type: string
    X-RateLimit-Limit:
      description: Il tetto della finestra piu' stretta.
      schema:
        type: integer
    X-RateLimit-Remaining:
      description: Richieste rimaste nella finestra piu' stretta.
      schema:
        type: integer
    X-RateLimit-Reset:
      description: Quando riparte (secondi epoch, UTC).
      schema:
        type: integer
    Retry-After:
      description: Secondi da aspettare prima di riprovare.
      schema:
        type: integer
  schemas:
    Me:
      type: object
      properties:
        organization:
          type: object
          properties:
            id:
              type: string
              format: uuid
              pattern: >-
                ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12})$
            name:
              type: string
          required:
            - id
            - name
          additionalProperties: false
        apiKey:
          type: object
          properties:
            id:
              type: string
              format: uuid
              pattern: >-
                ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12})$
            name:
              type: string
            prefix:
              description: 'L''inizio della chiave, per riconoscerla: dsk_live_ab12.'
              type: string
            last4:
              description: Le ultime 4 cifre.
              type: string
            scopes:
              type: array
              items:
                type: string
                enum:
                  - patients:read
                  - patients:write
                  - clinical:read
                  - clinical:write
                  - appointments:read
                  - appointments:write
                  - clinic:read
                  - treatment_plans:read
                  - treatment_plans:write
                  - billing:read
                  - billing:write
                  - documents:read
                  - documents:write
                  - tasks:read
                  - tasks:write
                  - leads:read
                  - leads:write
                  - messages:read
                  - messages:write
                  - calls:read
                  - calls:write
                  - webhooks:read
                  - webhooks:write
            facilityIds:
              description: Le sedi a cui e' limitata; null = tutte.
              anyOf:
                - type: array
                  items:
                    type: string
                    format: uuid
                    pattern: >-
                      ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12})$
                - type: 'null'
            expiresAt:
              anyOf:
                - type: string
                - type: 'null'
          required:
            - id
            - name
            - prefix
            - last4
            - scopes
            - facilityIds
            - expiresAt
          additionalProperties: false
        livemode:
          description: >-
            false per una chiave dsk_test_: nessun messaggio parte verso
            l'esterno.
          type: boolean
        rateLimit:
          type: object
          properties:
            organization:
              type: object
              properties:
                per10Seconds:
                  type: integer
                  minimum: -9007199254740991
                  maximum: 9007199254740991
                perDay:
                  type: integer
                  minimum: -9007199254740991
                  maximum: 9007199254740991
              required:
                - per10Seconds
                - perDay
              additionalProperties: false
            apiKey:
              type: object
              properties:
                per10Seconds:
                  type: integer
                  minimum: -9007199254740991
                  maximum: 9007199254740991
                perDay:
                  type: integer
                  minimum: -9007199254740991
                  maximum: 9007199254740991
              required:
                - per10Seconds
                - perDay
              additionalProperties: false
          required:
            - organization
            - apiKey
          additionalProperties: false
      required:
        - organization
        - apiKey
        - livemode
        - rateLimit
      additionalProperties: false
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              description: Codice stabile, da usare nel codice del client.
              type: string
              enum:
                - invalid_request
                - unauthenticated
                - api_key_invalid
                - api_key_revoked
                - forbidden
                - insufficient_scope
                - organization_suspended
                - plan_required
                - not_found
                - no_availability
                - conflict
                - idempotency_in_progress
                - idempotency_key_reused
                - rate_limited
                - internal_error
                - unavailable
            message:
              description: >-
                Spiegazione per una persona (in italiano). Non confrontarla nel
                codice.
              type: string
            details:
              anyOf:
                - type: object
                  propertyNames:
                    type: string
                  additionalProperties: {}
                - type: 'null'
            requestId:
              description: >-
                Lo stesso valore dell'header X-Request-Id: citalo
                all'assistenza.
              type: string
          required:
            - code
            - message
            - details
            - requestId
          additionalProperties: false
      required:
        - error
      additionalProperties: false
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: dsk_live_… / dsk_test_…

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.