> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sajn.se/llms.txt
> Use this file to discover all available pages before exploring further.

# Reject an approval request

> Rejects the request as the authenticated user, who must be an approver in the current stage. A comment is required. One rejection rejects the whole request, and the document returns to `DRAFT` so the requester can edit it and resubmit.

**Permission required:** `APPROVE_DOCUMENT` on the workspace.



## OpenAPI

````yaml /api/openapi.json post /api/v1/approval-requests/{id}/reject
openapi: 3.1.0
info:
  title: sajn API
  version: 2026-10
  description: >-
    # sajn - API v1


    With the sajn REST API, you can add digital document signing to your own
    applications.


    ## Overview


    sajn is a Swedish digital document signing platform. With the API, you can:

    - Create and manage documents and templates

    - Add the parties who sign, review, or organize a document

    - Send documents for signing by email or SMS

    - Track document status and signatures

    - Manage contacts and companies

    - Organize documents with tags and custom fields

    - Verify identities with sajn ID, through BankID and other eIDs


    ## Authentication


    Every endpoint (except the health check) requires a bearer token in the
    Authorization header:


    ```

    Authorization: Bearer YOUR_TOKEN

    ```


    Two kinds of token are accepted:


    - **Personal API key** (`sajn_sk_...`) — generated from your workspace
    developer settings. Acts as the issuing user; can reach any endpoint the
    user's workspace role permits.

    - **OAuth 2.0 access token** — issued via the authorization-code flow (PKCE
    for public clients) to a connected application. Bound to one workspace and
    limited to the **scopes** the user granted at consent — effective access is
    *workspace role ∩ granted scopes*.


    Each operation lists the OAuth scopes it requires in its security section.
    The scopes are coarse and resource-oriented (e.g. `documents:read`,
    `documents:write`, `documents:delete`, `contacts:read`). Personal API keys
    are not scope-limited; OAuth tokens are.


    ## Rate Limiting


    Limits apply per organization and scale with the plan:


    | Plan | Per minute | Per day |

    |---|---|---|

    | Basic | 60 | 2 000 |

    | Solo | 120 | 10 000 |

    | Team | 600 | 100 000 |

    | Enterprise | 2 000 | 2 000 000 |

    | Sandbox | 60 | 2 000 |


    Every response carries `X-RateLimit-Limit`, `X-RateLimit-Remaining` and
    `X-RateLimit-Reset` for the minute window, and `X-RateLimit-Daily-Limit`,
    `X-RateLimit-Daily-Remaining` and `X-RateLimit-Daily-Reset` for the daily
    quota. A `429` response includes `Retry-After` in seconds.


    ## Query parameters


    Query parameters are plain strings, such as
    `?externalId=12345&archived=false`:

    - Booleans are `true` or `false`.

    - Dates are ISO 8601 dates (`2026-10-01`) or date-times
    (`2026-10-01T08:00:00Z`). A date-time without an offset is UTC.

    - Filters that take several values accept a comma-separated list
    (`status=PENDING,COMPLETED`) or a repeated parameter
    (`status=PENDING&status=COMPLETED`).


    An unknown query parameter returns `400`, so a misspelled filter never
    silently returns everything.


    ## Pagination


    Every list returns `{ data, hasMore, nextCursor }`. To walk a list, pass
    `nextCursor` as `cursor` on the next request, keep the other parameters
    unchanged, and stop when `hasMore` is `false`. `limit` sets the page size,
    from 1 to 100, with a default of 25. To get the number of items that match
    the filters, pass `include=total`, and the response adds `total`.


    Lists sort newest first. To sort another way, pass `orderBy` and
    `orderDirection` where the list takes them. A list bounded by its parent,
    such as a document's parties, returns every item in one response, with
    `hasMore` set to `false` and `nextCursor` set to `null`.


    On the documents list, the cursor is keyset-based: it stays correct while
    documents are created and updated between requests. To mirror documents into
    your own system, sort by `updatedAt` and use the `updatedAfter` filter.


    ## Idempotent requests


    Send an `Idempotency-Key` header (any unique string up to 255 characters,
    for example a UUID) on `POST`, `PATCH` or `DELETE` requests to make retries
    safe. The first request runs normally and its response is stored for 24
    hours, errors included. A retry with the same key and the same method, path
    and body returns the stored response with the header `Idempotent-Replayed:
    true`. Reusing a key with a different request returns `400
    IDEMPOTENCY_KEY_REUSED`; retrying while the first request is still running
    returns `409 IDEMPOTENCY_KEY_IN_USE` with `Retry-After`. Responses with a
    `429` or `5xx` status aren't stored, so the retry runs again. Keys are
    scoped to the workspace.


    ## Versioning


    The API is versioned by date (`YYYY-MM`), and this reference documents
    version `2026-10`. To choose the version for a request, send the
    `Sajn-Version` header:


    ```

    Sajn-Version: 2026-10

    ```


    Without the header, a request uses your organization's default version. An
    organization without a default is pinned to the latest version by its first
    request. Every response returns the version that served it in
    `Sajn-Version`. On a deprecated version, responses also carry `Deprecation`
    and `Sunset` headers, and from the sunset date its requests return `400`.
    For details, see https://docs.sajn.se/api-reference/versioning.


    ## Webhooks


    Each webhook endpoint has its own API version, set when you create it, that
    decides the payload shape. Deliveries carry it in the `Sajn-Version` header.


    The delivery body is the event, `{ id, type, createdAt, apiVersion,
    workspaceId, environment, actor, data }`, signed according to [Standard
    Webhooks](https://www.standardwebhooks.com) in the `webhook-id`,
    `webhook-timestamp` and `webhook-signature` headers. Common document events:

    - `document.created` - A document is created.

    - `document.sent` - A document is sent for signing.

    - `document.party.opened` - A party opens the document.

    - `document.party.signed` - A party signs the document.

    - `document.fully_signed` - Every signer has signed, before the document is
    sealed.

    - `document.completed` - The document is sealed and complete.

    - `document.rejected` - A party rejects the document.


    For every event type, see `POST /api/v1/webhooks`.


    ## Error Handling


    Every error response has the same JSON shape:


    ```json

    {
      "code": "NOT_FOUND",
      "message": "Document not found",
      "userMessage": "Dokumentet hittades inte.",
      "requestId": "req_V1StGXR8Z5jdHi6BmyT2",
      "resource": "document"
    }

    ```


    - `code` is always present and comes from the closed list in the following
    table. Branch on it, not on the status or the message.

    - `message` is English text for developers. When the operation has no more
    specific text, it's the meaning of `code` from the following table. Its
    wording can change, so don't parse it.

    - `userMessage` is always present. It's text that is safe to show your
    users, usually in Swedish.

    - `requestId` identifies the request and matches the `Sajn-Request-Id`
    header, which every response carries. Quote it when you contact support. On
    a replayed idempotent response, it identifies the original request.


    A `400 VALIDATION_FAILED` lists every problem in `issues`: `[{ "path":
    "parties.0.email", "code": "INVALID_FORMAT", "message": "Invalid email
    address" }]`. An issue `code` is one of `INVALID_TYPE`, `INVALID_FORMAT`,
    `INVALID_VALUE`, `TOO_SMALL`, `TOO_BIG` or `UNRECOGNIZED_KEY`, and an issue
    that no single input caused has an empty `path`. A `404 NOT_FOUND` names the
    type of the missing resource in `resource`, such as `document` or `party`,
    or `null` when the API can't tell. A `403 INSUFFICIENT_SCOPE` includes
    `requiredScopes` and `grantedScopes`.


    A `401 UNAUTHORIZED` always means the credential itself is missing, invalid,
    expired or revoked. A valid token that isn't allowed to do something gets a
    `403`. A `409 INVALID_STATE` means the resource's state doesn't allow the
    operation; change the state first, then retry. A `503 UPSTREAM_UNAVAILABLE`
    is safe to retry with exponential backoff, and so is a `429` after
    `Retry-After` seconds.


    The API returns the following codes:


    | Code | Status | Meaning |

    |---|---|---|

    | `VALIDATION_FAILED` | 400 | The request failed validation. `issues` lists
    every problem. |

    | `INVALID_JSON` | 400 | The request body isn't valid JSON. |

    | `EXPIRED` | 400 | The link, code or resource has expired. |

    | `IDEMPOTENCY_KEY_REUSED` | 400 | The `Idempotency-Key` was already used
    with a different request. |

    | `INVALID_API_VERSION` | 400 | The `Sajn-Version` header names a version
    that doesn't exist. |

    | `API_VERSION_SUNSET` | 400 | The requested version, or your organization's
    default, is past its sunset date. |

    | `UNAUTHORIZED` | 401 | The API token is missing, invalid, expired or
    revoked. |

    | `PERMISSION_DENIED` | 403 | The token's user isn't allowed to perform the
    operation, for example because their workspace role lacks a permission. |

    | `INSUFFICIENT_SCOPE` | 403 | The OAuth token wasn't granted a scope the
    operation requires. See `requiredScopes` and `grantedScopes`. |

    | `PLAN_REQUIRED` | 403 | The organization's plan doesn't include API access
    or the feature. |

    | `ACCOUNT_INACTIVE` | 403 | The organization, user or membership behind the
    token is deactivated or suspended. |

    | `ACCOUNT_SETUP_REQUIRED` | 403 | The organization must finish its setup,
    such as verifying an accountable person, first. |

    | `LIMIT_EXCEEDED` | 403 | A plan limit was reached, such as the monthly
    number of sent documents. |

    | `APPROVAL_REQUIRED` | 409 | The operation needs an approval first, such as
    sending a document that the workspace requires an approval for. Request one
    with `POST /api/v1/approval-requests`. |

    | `NOT_FOUND` | 404 | The resource doesn't exist, or the token can't access
    it. `resource` names its type, such as `document`, or is `null` when the API
    can't tell. |

    | `ROUTE_NOT_FOUND` | 404 | No endpoint matches the method and path in the
    requested API version. |

    | `INVALID_STATE` | 409 | The resource's current state doesn't allow the
    operation, such as editing a document that was already sent or downloading a
    file that isn't produced yet. |

    | `ALREADY_EXISTS` | 409 | A resource with the same unique value, such as
    `externalId`, already exists. |

    | `IDEMPOTENCY_KEY_IN_USE` | 409 | A request with the same `Idempotency-Key`
    is still running. Retry after `Retry-After` seconds. |

    | `RATE_LIMITED` | 429 | The per-minute rate limit was reached. Retry after
    `Retry-After` seconds. |

    | `DAILY_QUOTA_EXCEEDED` | 429 | The daily request quota was reached. Retry
    after `Retry-After` seconds. |

    | `INTERNAL_ERROR` | 500 | Something went wrong on sajn's side. Quote
    `requestId` when you contact support. |

    | `UPSTREAM_UNAVAILABLE` | 503 | A service the operation depends on, such as
    an eID provider or a connected integration, failed or is unavailable. Retry
    with exponential backoff. |


    ## Support


    For API support, documentation, or questions:

    - Email: dev@sajn.se

    - Documentation: https://docs.sajn.se

    - Status: https://status.sajn.se
  contact:
    name: sajn Support
    email: dev@sajn.se
    url: https://www.sajn.se/support
  license:
    name: Policy
    url: https://www.sajn.se/allmanna-villkor
servers:
  - url: https://app.sajn.se
    description: Production server
security: []
tags:
  - name: Health
    description: API health and version information
  - name: Documents
    description: Create, manage, and send documents for signing
  - name: Templates
    description: Create and manage templates that can be used to spin up new documents
  - name: Parties
    description: Manage document parties (signers and other participants)
  - name: Contacts
    description: Manage contacts and contact information
  - name: Companies
    description: Manage companies and organizations
  - name: Fields
    description: Manage document fields and sections
  - name: Tags
    description: Organize documents with tags
  - name: Custom Fields
    description: Define and manage custom fields for documents
  - name: sajn ID
    description: Identity verification with Swedish BankID
  - name: Files
    description: >-
      Upload and manage files. `POST /api/v1/files` returns a presigned URL that
      you upload the bytes to.
  - name: Folders
    description: Organize documents and templates into hierarchical folders
  - name: Comments
    description: Thread-based discussion on documents
  - name: Reminders
    description: Send and inspect signing reminders on a document
  - name: Helpers
    description: 'Reference data: languages, countries, currencies, timezones'
  - name: Organization
    description: Authenticated organization metadata and branding
  - name: Webhook Deliveries
    description: Inspect and retry past webhook deliveries
  - name: Delegations
    description: Read-only access to signer delegation events on a document
  - name: Blocks
    description: Reusable library blocks for templates
paths:
  /api/v1/approval-requests/{id}/reject:
    post:
      summary: Reject an approval request
      description: >-
        Rejects the request as the authenticated user, who must be an approver
        in the current stage. A comment is required. One rejection rejects the
        whole request, and the document returns to `DRAFT` so the requester can
        edit it and resubmit.


        **Permission required:** `APPROVE_DOCUMENT` on the workspace.
      operationId: rejectApprovalRequest
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
          description: The approval ID.
          example: cm4k2x9p10029abcd1234efgh
        - name: Sajn-Version
          in: header
          required: false
          schema:
            type: string
            enum:
              - 2026-09
              - 2026-10
          description: >-
            API version for this request. Without it, the request uses the
            organization's default version; an organization without a default is
            pinned to the latest version by its first request.
        - name: Idempotency-Key
          in: header
          required: false
          schema:
            type: string
            maxLength: 255
          description: >-
            Makes retries safe. A retry with the same key and the same request
            replays the stored response for 24 hours (header
            `Idempotent-Replayed: true`); the same key with a different request
            returns 400.
      requestBody:
        description: Body
        content:
          application/json:
            schema:
              type: object
              properties:
                comment:
                  type: string
                  minLength: 1
                  description: Required comment explaining why the document was rejected
              required:
                - comment
              description: Reject a document
            example:
              comment: Godkänt enligt lönepolicyn.
      responses:
        '200':
          description: An internal approval request for a document
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                    description: Approval request ID
                  documentId:
                    type: string
                    description: The document ID.
                  status:
                    type: string
                    enum:
                      - DRAFT
                      - PENDING
                      - APPROVED
                      - REJECTED
                      - CANCELLED
                    description: >-
                      `DRAFT` while the document is a draft and the request
                      isn't submitted, such as approvers a template added or a
                      request whose document was withdrawn; `PENDING` while it
                      waits for approvers; `APPROVED` once every stage approves;
                      `REJECTED` after any approver rejects; `CANCELLED` only in
                      the response to the cancel request and in the
                      `approval_request.cancelled` event, because a cancelled
                      request is deleted.
                  autoSend:
                    type: boolean
                    description: >-
                      If true, sajn sends the document for signing when the
                      request is approved. If false, the document waits for you
                      to send it.
                  customMessage:
                    description: >-
                      The message included in the signing invitation when the
                      document is sent
                    type:
                      - string
                      - 'null'
                  requestedBy:
                    type: object
                    properties:
                      id:
                        type: string
                        description: User ID
                      email:
                        type: string
                      name:
                        description: Full name. Null when the user has no name.
                        type:
                          - string
                          - 'null'
                    required:
                      - id
                      - email
                      - name
                    additionalProperties: false
                    description: The user who submitted the request
                  approvers:
                    type: array
                    items:
                      type: object
                      properties:
                        user:
                          type: object
                          properties:
                            id:
                              type: string
                              description: User ID
                            email:
                              type: string
                            name:
                              description: Full name. Null when the user has no name.
                              type:
                                - string
                                - 'null'
                          required:
                            - id
                            - email
                            - name
                          additionalProperties: false
                          description: The approver
                        stage:
                          type: integer
                          minimum: -9007199254740991
                          maximum: 9007199254740991
                          description: >-
                            Stages run in ascending order. Approvers in the same
                            stage approve in parallel.
                        orGroup:
                          description: >-
                            Approvers in the same stage with the same `orGroup`
                            need only one approval between them. Null when this
                            approver's approval is required.
                          type:
                            - string
                            - 'null'
                        status:
                          type: string
                          enum:
                            - PENDING
                            - APPROVED
                            - REJECTED
                          description: This approver's decision
                        comment:
                          description: The approver's comment
                          type:
                            - string
                            - 'null'
                        resolvedAt:
                          description: When the approver decided
                          type:
                            - string
                            - 'null'
                          format: date-time
                      required:
                        - user
                        - stage
                        - orGroup
                        - status
                        - comment
                        - resolvedAt
                      additionalProperties: false
                    description: The approvers, ordered by stage
                  createdAt:
                    type: string
                    format: date-time
                    description: When the approval was created.
                  updatedAt:
                    type: string
                    format: date-time
                    description: When the approval was last updated.
                required:
                  - id
                  - documentId
                  - status
                  - autoSend
                  - customMessage
                  - requestedBy
                  - approvers
                  - createdAt
                  - updatedAt
                additionalProperties: false
                description: An internal approval request for a document
              example:
                id: cm4k2x9p10029abcd1234efgh
                documentId: cm4k2x9p10003abcd1234efgh
                status: APPROVED
                autoSend: false
                customMessage: >-
                  Påminnelse: signera ditt anställningsavtal senast den 28
                  oktober.
                requestedBy:
                  id: cm4k2x9p10002abcd1234efgh
                  email: alex@example.com
                  name: Alex Berg
                approvers:
                  - user:
                      id: cm4k2x9p10002abcd1234efgh
                      email: alex@example.com
                      name: Alex Berg
                    stage: 1
                    orGroup: Quinn Holm
                    status: APPROVED
                    comment: Godkänt enligt lönepolicyn.
                    resolvedAt: '2026-09-29T07:41:00.000Z'
                createdAt: '2026-09-28T09:12:00.000Z'
                updatedAt: '2026-09-28T09:15:00.000Z'
          headers:
            Sajn-Version:
              description: API version that served the request.
              schema:
                type: string
            Deprecation:
              description: >-
                Present only when the version is deprecated: when it was
                deprecated, as `@<unix seconds>`.
              schema:
                type: string
            Sunset:
              description: >-
                Present only when the version is deprecated: the HTTP date from
                which requests on this version return 400 `API_VERSION_SUNSET`.
              schema:
                type: string
            Sajn-Request-Id:
              description: >-
                Identifier of the request. Error bodies repeat it as
                `requestId`; quote it when you contact support.
              schema:
                type: string
            X-RateLimit-Limit:
              description: Requests allowed per minute.
              schema:
                type: integer
            X-RateLimit-Remaining:
              description: Requests left in the current minute.
              schema:
                type: integer
            X-RateLimit-Reset:
              description: When the minute window resets, in Unix seconds.
              schema:
                type: integer
            X-RateLimit-Daily-Limit:
              description: >-
                Requests allowed per day. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Remaining:
              description: >-
                Requests left today. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Reset:
              description: >-
                When the daily quota resets, in Unix seconds. Absent for
                first-party connectors and negotiated limits.
              schema:
                type: integer
            Idempotent-Replayed:
              description: >-
                `true` when the response is a stored response replayed for a
                repeated `Idempotency-Key`.
              schema:
                type: string
        '400':
          description: Error response
          content:
            application/json:
              schema:
                type: object
                properties:
                  code:
                    type: string
                    enum:
                      - VALIDATION_FAILED
                      - INVALID_JSON
                      - EXPIRED
                      - IDEMPOTENCY_KEY_REUSED
                      - INVALID_API_VERSION
                      - API_VERSION_SUNSET
                      - UNAUTHORIZED
                      - PERMISSION_DENIED
                      - INSUFFICIENT_SCOPE
                      - PLAN_REQUIRED
                      - ACCOUNT_INACTIVE
                      - ACCOUNT_SETUP_REQUIRED
                      - LIMIT_EXCEEDED
                      - APPROVAL_REQUIRED
                      - NOT_FOUND
                      - ROUTE_NOT_FOUND
                      - INVALID_STATE
                      - ALREADY_EXISTS
                      - IDEMPOTENCY_KEY_IN_USE
                      - RATE_LIMITED
                      - DAILY_QUOTA_EXCEEDED
                      - INTERNAL_ERROR
                      - UPSTREAM_UNAVAILABLE
                    description: >-
                      Machine-readable error code from a closed list. Branch on
                      it, never on `message`.
                  message:
                    type: string
                    description: >-
                      What went wrong, in English, for developers. Its wording
                      can change; don't parse it.
                  userMessage:
                    type: string
                    description: >-
                      Text that is safe to show to an end user, usually in
                      Swedish
                  requestId:
                    type: string
                    description: >-
                      Identifier of the request, the same value as the
                      `Sajn-Request-Id` header. Quote it when you contact
                      support.
                  resource:
                    description: >-
                      On a 404 `NOT_FOUND`, the type of the missing resource,
                      such as `document` or `party`; `null` when the API can't
                      tell
                    type:
                      - string
                      - 'null'
                  issues:
                    description: Every validation issue, on a 400 `VALIDATION_FAILED`
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                          description: >-
                            Dotted path to the invalid value, such as
                            `parties.0.email`; empty when no single input caused
                            the issue
                        code:
                          type: string
                          enum:
                            - INVALID_TYPE
                            - INVALID_FORMAT
                            - INVALID_VALUE
                            - TOO_SMALL
                            - TOO_BIG
                            - UNRECOGNIZED_KEY
                        message:
                          type: string
                          description: What is wrong with the value, in English
                      required:
                        - path
                        - code
                        - message
                      additionalProperties: false
                  requiredScopes:
                    description: >-
                      OAuth scopes the endpoint requires, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                  grantedScopes:
                    description: >-
                      OAuth scopes the token was granted, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                required:
                  - code
                  - message
                  - userMessage
                  - requestId
                additionalProperties: {}
                description: Error response
              example:
                code: VALIDATION_FAILED
                message: 'Invalid input: expected string, received undefined'
                userMessage: Förfrågan innehåller ogiltiga värden.
                requestId: req_V1StGXR8Z5jdHi6BmyT2
                issues:
                  - path: comment
                    code: INVALID_TYPE
                    message: 'Invalid input: expected string, received undefined'
          headers:
            Sajn-Version:
              description: API version that served the request.
              schema:
                type: string
            Deprecation:
              description: >-
                Present only when the version is deprecated: when it was
                deprecated, as `@<unix seconds>`.
              schema:
                type: string
            Sunset:
              description: >-
                Present only when the version is deprecated: the HTTP date from
                which requests on this version return 400 `API_VERSION_SUNSET`.
              schema:
                type: string
            Sajn-Request-Id:
              description: >-
                Identifier of the request. Error bodies repeat it as
                `requestId`; quote it when you contact support.
              schema:
                type: string
            X-RateLimit-Limit:
              description: Requests allowed per minute.
              schema:
                type: integer
            X-RateLimit-Remaining:
              description: Requests left in the current minute.
              schema:
                type: integer
            X-RateLimit-Reset:
              description: When the minute window resets, in Unix seconds.
              schema:
                type: integer
            X-RateLimit-Daily-Limit:
              description: >-
                Requests allowed per day. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Remaining:
              description: >-
                Requests left today. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Reset:
              description: >-
                When the daily quota resets, in Unix seconds. Absent for
                first-party connectors and negotiated limits.
              schema:
                type: integer
            Idempotent-Replayed:
              description: >-
                `true` when the response is a stored response replayed for a
                repeated `Idempotency-Key`.
              schema:
                type: string
        '401':
          description: Error response
          content:
            application/json:
              schema:
                type: object
                properties:
                  code:
                    type: string
                    enum:
                      - VALIDATION_FAILED
                      - INVALID_JSON
                      - EXPIRED
                      - IDEMPOTENCY_KEY_REUSED
                      - INVALID_API_VERSION
                      - API_VERSION_SUNSET
                      - UNAUTHORIZED
                      - PERMISSION_DENIED
                      - INSUFFICIENT_SCOPE
                      - PLAN_REQUIRED
                      - ACCOUNT_INACTIVE
                      - ACCOUNT_SETUP_REQUIRED
                      - LIMIT_EXCEEDED
                      - APPROVAL_REQUIRED
                      - NOT_FOUND
                      - ROUTE_NOT_FOUND
                      - INVALID_STATE
                      - ALREADY_EXISTS
                      - IDEMPOTENCY_KEY_IN_USE
                      - RATE_LIMITED
                      - DAILY_QUOTA_EXCEEDED
                      - INTERNAL_ERROR
                      - UPSTREAM_UNAVAILABLE
                    description: >-
                      Machine-readable error code from a closed list. Branch on
                      it, never on `message`.
                  message:
                    type: string
                    description: >-
                      What went wrong, in English, for developers. Its wording
                      can change; don't parse it.
                  userMessage:
                    type: string
                    description: >-
                      Text that is safe to show to an end user, usually in
                      Swedish
                  requestId:
                    type: string
                    description: >-
                      Identifier of the request, the same value as the
                      `Sajn-Request-Id` header. Quote it when you contact
                      support.
                  resource:
                    description: >-
                      On a 404 `NOT_FOUND`, the type of the missing resource,
                      such as `document` or `party`; `null` when the API can't
                      tell
                    type:
                      - string
                      - 'null'
                  issues:
                    description: Every validation issue, on a 400 `VALIDATION_FAILED`
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                          description: >-
                            Dotted path to the invalid value, such as
                            `parties.0.email`; empty when no single input caused
                            the issue
                        code:
                          type: string
                          enum:
                            - INVALID_TYPE
                            - INVALID_FORMAT
                            - INVALID_VALUE
                            - TOO_SMALL
                            - TOO_BIG
                            - UNRECOGNIZED_KEY
                        message:
                          type: string
                          description: What is wrong with the value, in English
                      required:
                        - path
                        - code
                        - message
                      additionalProperties: false
                  requiredScopes:
                    description: >-
                      OAuth scopes the endpoint requires, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                  grantedScopes:
                    description: >-
                      OAuth scopes the token was granted, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                required:
                  - code
                  - message
                  - userMessage
                  - requestId
                additionalProperties: {}
                description: Error response
              example:
                code: UNAUTHORIZED
                message: Invalid API token
                userMessage: Ogiltig API-nyckel
                requestId: req_V1StGXR8Z5jdHi6BmyT2
          headers:
            Sajn-Version:
              description: API version that served the request.
              schema:
                type: string
            Deprecation:
              description: >-
                Present only when the version is deprecated: when it was
                deprecated, as `@<unix seconds>`.
              schema:
                type: string
            Sunset:
              description: >-
                Present only when the version is deprecated: the HTTP date from
                which requests on this version return 400 `API_VERSION_SUNSET`.
              schema:
                type: string
            Sajn-Request-Id:
              description: >-
                Identifier of the request. Error bodies repeat it as
                `requestId`; quote it when you contact support.
              schema:
                type: string
            X-RateLimit-Limit:
              description: Requests allowed per minute.
              schema:
                type: integer
            X-RateLimit-Remaining:
              description: Requests left in the current minute.
              schema:
                type: integer
            X-RateLimit-Reset:
              description: When the minute window resets, in Unix seconds.
              schema:
                type: integer
            X-RateLimit-Daily-Limit:
              description: >-
                Requests allowed per day. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Remaining:
              description: >-
                Requests left today. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Reset:
              description: >-
                When the daily quota resets, in Unix seconds. Absent for
                first-party connectors and negotiated limits.
              schema:
                type: integer
            Idempotent-Replayed:
              description: >-
                `true` when the response is a stored response replayed for a
                repeated `Idempotency-Key`.
              schema:
                type: string
        '403':
          description: Error response
          content:
            application/json:
              schema:
                type: object
                properties:
                  code:
                    type: string
                    enum:
                      - VALIDATION_FAILED
                      - INVALID_JSON
                      - EXPIRED
                      - IDEMPOTENCY_KEY_REUSED
                      - INVALID_API_VERSION
                      - API_VERSION_SUNSET
                      - UNAUTHORIZED
                      - PERMISSION_DENIED
                      - INSUFFICIENT_SCOPE
                      - PLAN_REQUIRED
                      - ACCOUNT_INACTIVE
                      - ACCOUNT_SETUP_REQUIRED
                      - LIMIT_EXCEEDED
                      - APPROVAL_REQUIRED
                      - NOT_FOUND
                      - ROUTE_NOT_FOUND
                      - INVALID_STATE
                      - ALREADY_EXISTS
                      - IDEMPOTENCY_KEY_IN_USE
                      - RATE_LIMITED
                      - DAILY_QUOTA_EXCEEDED
                      - INTERNAL_ERROR
                      - UPSTREAM_UNAVAILABLE
                    description: >-
                      Machine-readable error code from a closed list. Branch on
                      it, never on `message`.
                  message:
                    type: string
                    description: >-
                      What went wrong, in English, for developers. Its wording
                      can change; don't parse it.
                  userMessage:
                    type: string
                    description: >-
                      Text that is safe to show to an end user, usually in
                      Swedish
                  requestId:
                    type: string
                    description: >-
                      Identifier of the request, the same value as the
                      `Sajn-Request-Id` header. Quote it when you contact
                      support.
                  resource:
                    description: >-
                      On a 404 `NOT_FOUND`, the type of the missing resource,
                      such as `document` or `party`; `null` when the API can't
                      tell
                    type:
                      - string
                      - 'null'
                  issues:
                    description: Every validation issue, on a 400 `VALIDATION_FAILED`
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                          description: >-
                            Dotted path to the invalid value, such as
                            `parties.0.email`; empty when no single input caused
                            the issue
                        code:
                          type: string
                          enum:
                            - INVALID_TYPE
                            - INVALID_FORMAT
                            - INVALID_VALUE
                            - TOO_SMALL
                            - TOO_BIG
                            - UNRECOGNIZED_KEY
                        message:
                          type: string
                          description: What is wrong with the value, in English
                      required:
                        - path
                        - code
                        - message
                      additionalProperties: false
                  requiredScopes:
                    description: >-
                      OAuth scopes the endpoint requires, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                  grantedScopes:
                    description: >-
                      OAuth scopes the token was granted, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                required:
                  - code
                  - message
                  - userMessage
                  - requestId
                additionalProperties: {}
                description: Error response
              example:
                code: INSUFFICIENT_SCOPE
                message: 'Insufficient OAuth scope: requires documents:write'
                userMessage: Applikationen saknar behörighet (scope) för denna åtgärd.
                requestId: req_V1StGXR8Z5jdHi6BmyT2
                requiredScopes:
                  - documents:write
                grantedScopes:
                  - profile:read
          headers:
            Sajn-Version:
              description: API version that served the request.
              schema:
                type: string
            Deprecation:
              description: >-
                Present only when the version is deprecated: when it was
                deprecated, as `@<unix seconds>`.
              schema:
                type: string
            Sunset:
              description: >-
                Present only when the version is deprecated: the HTTP date from
                which requests on this version return 400 `API_VERSION_SUNSET`.
              schema:
                type: string
            Sajn-Request-Id:
              description: >-
                Identifier of the request. Error bodies repeat it as
                `requestId`; quote it when you contact support.
              schema:
                type: string
            X-RateLimit-Limit:
              description: Requests allowed per minute.
              schema:
                type: integer
            X-RateLimit-Remaining:
              description: Requests left in the current minute.
              schema:
                type: integer
            X-RateLimit-Reset:
              description: When the minute window resets, in Unix seconds.
              schema:
                type: integer
            X-RateLimit-Daily-Limit:
              description: >-
                Requests allowed per day. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Remaining:
              description: >-
                Requests left today. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Reset:
              description: >-
                When the daily quota resets, in Unix seconds. Absent for
                first-party connectors and negotiated limits.
              schema:
                type: integer
            Idempotent-Replayed:
              description: >-
                `true` when the response is a stored response replayed for a
                repeated `Idempotency-Key`.
              schema:
                type: string
        '404':
          description: Error response
          content:
            application/json:
              schema:
                type: object
                properties:
                  code:
                    type: string
                    enum:
                      - VALIDATION_FAILED
                      - INVALID_JSON
                      - EXPIRED
                      - IDEMPOTENCY_KEY_REUSED
                      - INVALID_API_VERSION
                      - API_VERSION_SUNSET
                      - UNAUTHORIZED
                      - PERMISSION_DENIED
                      - INSUFFICIENT_SCOPE
                      - PLAN_REQUIRED
                      - ACCOUNT_INACTIVE
                      - ACCOUNT_SETUP_REQUIRED
                      - LIMIT_EXCEEDED
                      - APPROVAL_REQUIRED
                      - NOT_FOUND
                      - ROUTE_NOT_FOUND
                      - INVALID_STATE
                      - ALREADY_EXISTS
                      - IDEMPOTENCY_KEY_IN_USE
                      - RATE_LIMITED
                      - DAILY_QUOTA_EXCEEDED
                      - INTERNAL_ERROR
                      - UPSTREAM_UNAVAILABLE
                    description: >-
                      Machine-readable error code from a closed list. Branch on
                      it, never on `message`.
                  message:
                    type: string
                    description: >-
                      What went wrong, in English, for developers. Its wording
                      can change; don't parse it.
                  userMessage:
                    type: string
                    description: >-
                      Text that is safe to show to an end user, usually in
                      Swedish
                  requestId:
                    type: string
                    description: >-
                      Identifier of the request, the same value as the
                      `Sajn-Request-Id` header. Quote it when you contact
                      support.
                  resource:
                    description: >-
                      On a 404 `NOT_FOUND`, the type of the missing resource,
                      such as `document` or `party`; `null` when the API can't
                      tell
                    type:
                      - string
                      - 'null'
                  issues:
                    description: Every validation issue, on a 400 `VALIDATION_FAILED`
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                          description: >-
                            Dotted path to the invalid value, such as
                            `parties.0.email`; empty when no single input caused
                            the issue
                        code:
                          type: string
                          enum:
                            - INVALID_TYPE
                            - INVALID_FORMAT
                            - INVALID_VALUE
                            - TOO_SMALL
                            - TOO_BIG
                            - UNRECOGNIZED_KEY
                        message:
                          type: string
                          description: What is wrong with the value, in English
                      required:
                        - path
                        - code
                        - message
                      additionalProperties: false
                  requiredScopes:
                    description: >-
                      OAuth scopes the endpoint requires, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                  grantedScopes:
                    description: >-
                      OAuth scopes the token was granted, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                required:
                  - code
                  - message
                  - userMessage
                  - requestId
                additionalProperties: {}
                description: Error response
              example:
                code: NOT_FOUND
                message: Approval not found
                userMessage: Resursen hittades inte.
                requestId: req_V1StGXR8Z5jdHi6BmyT2
                resource: approval
          headers:
            Sajn-Version:
              description: API version that served the request.
              schema:
                type: string
            Deprecation:
              description: >-
                Present only when the version is deprecated: when it was
                deprecated, as `@<unix seconds>`.
              schema:
                type: string
            Sunset:
              description: >-
                Present only when the version is deprecated: the HTTP date from
                which requests on this version return 400 `API_VERSION_SUNSET`.
              schema:
                type: string
            Sajn-Request-Id:
              description: >-
                Identifier of the request. Error bodies repeat it as
                `requestId`; quote it when you contact support.
              schema:
                type: string
            X-RateLimit-Limit:
              description: Requests allowed per minute.
              schema:
                type: integer
            X-RateLimit-Remaining:
              description: Requests left in the current minute.
              schema:
                type: integer
            X-RateLimit-Reset:
              description: When the minute window resets, in Unix seconds.
              schema:
                type: integer
            X-RateLimit-Daily-Limit:
              description: >-
                Requests allowed per day. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Remaining:
              description: >-
                Requests left today. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Reset:
              description: >-
                When the daily quota resets, in Unix seconds. Absent for
                first-party connectors and negotiated limits.
              schema:
                type: integer
            Idempotent-Replayed:
              description: >-
                `true` when the response is a stored response replayed for a
                repeated `Idempotency-Key`.
              schema:
                type: string
        '409':
          description: Error response
          content:
            application/json:
              schema:
                type: object
                properties:
                  code:
                    type: string
                    enum:
                      - VALIDATION_FAILED
                      - INVALID_JSON
                      - EXPIRED
                      - IDEMPOTENCY_KEY_REUSED
                      - INVALID_API_VERSION
                      - API_VERSION_SUNSET
                      - UNAUTHORIZED
                      - PERMISSION_DENIED
                      - INSUFFICIENT_SCOPE
                      - PLAN_REQUIRED
                      - ACCOUNT_INACTIVE
                      - ACCOUNT_SETUP_REQUIRED
                      - LIMIT_EXCEEDED
                      - APPROVAL_REQUIRED
                      - NOT_FOUND
                      - ROUTE_NOT_FOUND
                      - INVALID_STATE
                      - ALREADY_EXISTS
                      - IDEMPOTENCY_KEY_IN_USE
                      - RATE_LIMITED
                      - DAILY_QUOTA_EXCEEDED
                      - INTERNAL_ERROR
                      - UPSTREAM_UNAVAILABLE
                    description: >-
                      Machine-readable error code from a closed list. Branch on
                      it, never on `message`.
                  message:
                    type: string
                    description: >-
                      What went wrong, in English, for developers. Its wording
                      can change; don't parse it.
                  userMessage:
                    type: string
                    description: >-
                      Text that is safe to show to an end user, usually in
                      Swedish
                  requestId:
                    type: string
                    description: >-
                      Identifier of the request, the same value as the
                      `Sajn-Request-Id` header. Quote it when you contact
                      support.
                  resource:
                    description: >-
                      On a 404 `NOT_FOUND`, the type of the missing resource,
                      such as `document` or `party`; `null` when the API can't
                      tell
                    type:
                      - string
                      - 'null'
                  issues:
                    description: Every validation issue, on a 400 `VALIDATION_FAILED`
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                          description: >-
                            Dotted path to the invalid value, such as
                            `parties.0.email`; empty when no single input caused
                            the issue
                        code:
                          type: string
                          enum:
                            - INVALID_TYPE
                            - INVALID_FORMAT
                            - INVALID_VALUE
                            - TOO_SMALL
                            - TOO_BIG
                            - UNRECOGNIZED_KEY
                        message:
                          type: string
                          description: What is wrong with the value, in English
                      required:
                        - path
                        - code
                        - message
                      additionalProperties: false
                  requiredScopes:
                    description: >-
                      OAuth scopes the endpoint requires, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                  grantedScopes:
                    description: >-
                      OAuth scopes the token was granted, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                required:
                  - code
                  - message
                  - userMessage
                  - requestId
                additionalProperties: {}
                description: Error response
              example:
                code: INVALID_STATE
                message: >-
                  The resource's current state doesn't allow the operation, such
                  as editing a document that was already sent or downloading a
                  file that isn't produced yet.
                userMessage: Åtgärden är inte möjlig i resursens nuvarande status.
                requestId: req_V1StGXR8Z5jdHi6BmyT2
          headers:
            Sajn-Version:
              description: API version that served the request.
              schema:
                type: string
            Deprecation:
              description: >-
                Present only when the version is deprecated: when it was
                deprecated, as `@<unix seconds>`.
              schema:
                type: string
            Sunset:
              description: >-
                Present only when the version is deprecated: the HTTP date from
                which requests on this version return 400 `API_VERSION_SUNSET`.
              schema:
                type: string
            Sajn-Request-Id:
              description: >-
                Identifier of the request. Error bodies repeat it as
                `requestId`; quote it when you contact support.
              schema:
                type: string
            X-RateLimit-Limit:
              description: Requests allowed per minute.
              schema:
                type: integer
            X-RateLimit-Remaining:
              description: Requests left in the current minute.
              schema:
                type: integer
            X-RateLimit-Reset:
              description: When the minute window resets, in Unix seconds.
              schema:
                type: integer
            X-RateLimit-Daily-Limit:
              description: >-
                Requests allowed per day. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Remaining:
              description: >-
                Requests left today. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Reset:
              description: >-
                When the daily quota resets, in Unix seconds. Absent for
                first-party connectors and negotiated limits.
              schema:
                type: integer
            Retry-After:
              description: Seconds to wait before you retry.
              schema:
                type: integer
            Idempotent-Replayed:
              description: >-
                `true` when the response is a stored response replayed for a
                repeated `Idempotency-Key`.
              schema:
                type: string
        '429':
          description: '`RATE_LIMITED` or `DAILY_QUOTA_EXCEEDED`.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  code:
                    type: string
                    enum:
                      - VALIDATION_FAILED
                      - INVALID_JSON
                      - EXPIRED
                      - IDEMPOTENCY_KEY_REUSED
                      - INVALID_API_VERSION
                      - API_VERSION_SUNSET
                      - UNAUTHORIZED
                      - PERMISSION_DENIED
                      - INSUFFICIENT_SCOPE
                      - PLAN_REQUIRED
                      - ACCOUNT_INACTIVE
                      - ACCOUNT_SETUP_REQUIRED
                      - LIMIT_EXCEEDED
                      - APPROVAL_REQUIRED
                      - NOT_FOUND
                      - ROUTE_NOT_FOUND
                      - INVALID_STATE
                      - ALREADY_EXISTS
                      - IDEMPOTENCY_KEY_IN_USE
                      - RATE_LIMITED
                      - DAILY_QUOTA_EXCEEDED
                      - INTERNAL_ERROR
                      - UPSTREAM_UNAVAILABLE
                    description: >-
                      Machine-readable error code from a closed list. Branch on
                      it, never on `message`.
                  message:
                    type: string
                    description: >-
                      What went wrong, in English, for developers. Its wording
                      can change; don't parse it.
                  userMessage:
                    type: string
                    description: >-
                      Text that is safe to show to an end user, usually in
                      Swedish
                  requestId:
                    type: string
                    description: >-
                      Identifier of the request, the same value as the
                      `Sajn-Request-Id` header. Quote it when you contact
                      support.
                  resource:
                    description: >-
                      On a 404 `NOT_FOUND`, the type of the missing resource,
                      such as `document` or `party`; `null` when the API can't
                      tell
                    type:
                      - string
                      - 'null'
                  issues:
                    description: Every validation issue, on a 400 `VALIDATION_FAILED`
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                          description: >-
                            Dotted path to the invalid value, such as
                            `parties.0.email`; empty when no single input caused
                            the issue
                        code:
                          type: string
                          enum:
                            - INVALID_TYPE
                            - INVALID_FORMAT
                            - INVALID_VALUE
                            - TOO_SMALL
                            - TOO_BIG
                            - UNRECOGNIZED_KEY
                        message:
                          type: string
                          description: What is wrong with the value, in English
                      required:
                        - path
                        - code
                        - message
                      additionalProperties: false
                  requiredScopes:
                    description: >-
                      OAuth scopes the endpoint requires, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                  grantedScopes:
                    description: >-
                      OAuth scopes the token was granted, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                required:
                  - code
                  - message
                  - userMessage
                  - requestId
                additionalProperties: {}
                description: Error response
              example:
                code: RATE_LIMITED
                message: API rate limit exceeded
                userMessage: För många förfrågningar. Försök igen om en stund.
                requestId: req_V1StGXR8Z5jdHi6BmyT2
          headers:
            Sajn-Version:
              description: API version that served the request.
              schema:
                type: string
            Deprecation:
              description: >-
                Present only when the version is deprecated: when it was
                deprecated, as `@<unix seconds>`.
              schema:
                type: string
            Sunset:
              description: >-
                Present only when the version is deprecated: the HTTP date from
                which requests on this version return 400 `API_VERSION_SUNSET`.
              schema:
                type: string
            Sajn-Request-Id:
              description: >-
                Identifier of the request. Error bodies repeat it as
                `requestId`; quote it when you contact support.
              schema:
                type: string
            X-RateLimit-Limit:
              description: Requests allowed per minute.
              schema:
                type: integer
            X-RateLimit-Remaining:
              description: Requests left in the current minute.
              schema:
                type: integer
            X-RateLimit-Reset:
              description: When the minute window resets, in Unix seconds.
              schema:
                type: integer
            X-RateLimit-Daily-Limit:
              description: >-
                Requests allowed per day. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Remaining:
              description: >-
                Requests left today. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Reset:
              description: >-
                When the daily quota resets, in Unix seconds. Absent for
                first-party connectors and negotiated limits.
              schema:
                type: integer
            Retry-After:
              description: Seconds to wait before you retry.
              schema:
                type: integer
            Idempotent-Replayed:
              description: >-
                `true` when the response is a stored response replayed for a
                repeated `Idempotency-Key`.
              schema:
                type: string
        '500':
          description: '`INTERNAL_ERROR`.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  code:
                    type: string
                    enum:
                      - VALIDATION_FAILED
                      - INVALID_JSON
                      - EXPIRED
                      - IDEMPOTENCY_KEY_REUSED
                      - INVALID_API_VERSION
                      - API_VERSION_SUNSET
                      - UNAUTHORIZED
                      - PERMISSION_DENIED
                      - INSUFFICIENT_SCOPE
                      - PLAN_REQUIRED
                      - ACCOUNT_INACTIVE
                      - ACCOUNT_SETUP_REQUIRED
                      - LIMIT_EXCEEDED
                      - APPROVAL_REQUIRED
                      - NOT_FOUND
                      - ROUTE_NOT_FOUND
                      - INVALID_STATE
                      - ALREADY_EXISTS
                      - IDEMPOTENCY_KEY_IN_USE
                      - RATE_LIMITED
                      - DAILY_QUOTA_EXCEEDED
                      - INTERNAL_ERROR
                      - UPSTREAM_UNAVAILABLE
                    description: >-
                      Machine-readable error code from a closed list. Branch on
                      it, never on `message`.
                  message:
                    type: string
                    description: >-
                      What went wrong, in English, for developers. Its wording
                      can change; don't parse it.
                  userMessage:
                    type: string
                    description: >-
                      Text that is safe to show to an end user, usually in
                      Swedish
                  requestId:
                    type: string
                    description: >-
                      Identifier of the request, the same value as the
                      `Sajn-Request-Id` header. Quote it when you contact
                      support.
                  resource:
                    description: >-
                      On a 404 `NOT_FOUND`, the type of the missing resource,
                      such as `document` or `party`; `null` when the API can't
                      tell
                    type:
                      - string
                      - 'null'
                  issues:
                    description: Every validation issue, on a 400 `VALIDATION_FAILED`
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                          description: >-
                            Dotted path to the invalid value, such as
                            `parties.0.email`; empty when no single input caused
                            the issue
                        code:
                          type: string
                          enum:
                            - INVALID_TYPE
                            - INVALID_FORMAT
                            - INVALID_VALUE
                            - TOO_SMALL
                            - TOO_BIG
                            - UNRECOGNIZED_KEY
                        message:
                          type: string
                          description: What is wrong with the value, in English
                      required:
                        - path
                        - code
                        - message
                      additionalProperties: false
                  requiredScopes:
                    description: >-
                      OAuth scopes the endpoint requires, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                  grantedScopes:
                    description: >-
                      OAuth scopes the token was granted, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                required:
                  - code
                  - message
                  - userMessage
                  - requestId
                additionalProperties: {}
                description: Error response
              example:
                code: INTERNAL_ERROR
                message: Internal server error
                userMessage: Något gick fel.
                requestId: req_V1StGXR8Z5jdHi6BmyT2
          headers:
            Sajn-Version:
              description: API version that served the request.
              schema:
                type: string
            Deprecation:
              description: >-
                Present only when the version is deprecated: when it was
                deprecated, as `@<unix seconds>`.
              schema:
                type: string
            Sunset:
              description: >-
                Present only when the version is deprecated: the HTTP date from
                which requests on this version return 400 `API_VERSION_SUNSET`.
              schema:
                type: string
            Sajn-Request-Id:
              description: >-
                Identifier of the request. Error bodies repeat it as
                `requestId`; quote it when you contact support.
              schema:
                type: string
            X-RateLimit-Limit:
              description: Requests allowed per minute.
              schema:
                type: integer
            X-RateLimit-Remaining:
              description: Requests left in the current minute.
              schema:
                type: integer
            X-RateLimit-Reset:
              description: When the minute window resets, in Unix seconds.
              schema:
                type: integer
            X-RateLimit-Daily-Limit:
              description: >-
                Requests allowed per day. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Remaining:
              description: >-
                Requests left today. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Reset:
              description: >-
                When the daily quota resets, in Unix seconds. Absent for
                first-party connectors and negotiated limits.
              schema:
                type: integer
        '503':
          description: >-
            `UPSTREAM_UNAVAILABLE`: a service the operation depends on failed.
            Retry with exponential backoff.
          content:
            application/json:
              schema:
                type: object
                properties:
                  code:
                    type: string
                    enum:
                      - VALIDATION_FAILED
                      - INVALID_JSON
                      - EXPIRED
                      - IDEMPOTENCY_KEY_REUSED
                      - INVALID_API_VERSION
                      - API_VERSION_SUNSET
                      - UNAUTHORIZED
                      - PERMISSION_DENIED
                      - INSUFFICIENT_SCOPE
                      - PLAN_REQUIRED
                      - ACCOUNT_INACTIVE
                      - ACCOUNT_SETUP_REQUIRED
                      - LIMIT_EXCEEDED
                      - APPROVAL_REQUIRED
                      - NOT_FOUND
                      - ROUTE_NOT_FOUND
                      - INVALID_STATE
                      - ALREADY_EXISTS
                      - IDEMPOTENCY_KEY_IN_USE
                      - RATE_LIMITED
                      - DAILY_QUOTA_EXCEEDED
                      - INTERNAL_ERROR
                      - UPSTREAM_UNAVAILABLE
                    description: >-
                      Machine-readable error code from a closed list. Branch on
                      it, never on `message`.
                  message:
                    type: string
                    description: >-
                      What went wrong, in English, for developers. Its wording
                      can change; don't parse it.
                  userMessage:
                    type: string
                    description: >-
                      Text that is safe to show to an end user, usually in
                      Swedish
                  requestId:
                    type: string
                    description: >-
                      Identifier of the request, the same value as the
                      `Sajn-Request-Id` header. Quote it when you contact
                      support.
                  resource:
                    description: >-
                      On a 404 `NOT_FOUND`, the type of the missing resource,
                      such as `document` or `party`; `null` when the API can't
                      tell
                    type:
                      - string
                      - 'null'
                  issues:
                    description: Every validation issue, on a 400 `VALIDATION_FAILED`
                    type: array
                    items:
                      type: object
                      properties:
                        path:
                          type: string
                          description: >-
                            Dotted path to the invalid value, such as
                            `parties.0.email`; empty when no single input caused
                            the issue
                        code:
                          type: string
                          enum:
                            - INVALID_TYPE
                            - INVALID_FORMAT
                            - INVALID_VALUE
                            - TOO_SMALL
                            - TOO_BIG
                            - UNRECOGNIZED_KEY
                        message:
                          type: string
                          description: What is wrong with the value, in English
                      required:
                        - path
                        - code
                        - message
                      additionalProperties: false
                  requiredScopes:
                    description: >-
                      OAuth scopes the endpoint requires, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                  grantedScopes:
                    description: >-
                      OAuth scopes the token was granted, on a 403
                      `INSUFFICIENT_SCOPE`
                    type: array
                    items:
                      type: string
                required:
                  - code
                  - message
                  - userMessage
                  - requestId
                additionalProperties: {}
                description: Error response
              example:
                code: UPSTREAM_UNAVAILABLE
                message: >-
                  A service the operation depends on, such as an eID provider or
                  a connected integration, failed or is unavailable. Retry with
                  exponential backoff.
                userMessage: En extern tjänst svarar inte just nu. Försök igen om en stund.
                requestId: req_V1StGXR8Z5jdHi6BmyT2
          headers:
            Sajn-Version:
              description: API version that served the request.
              schema:
                type: string
            Deprecation:
              description: >-
                Present only when the version is deprecated: when it was
                deprecated, as `@<unix seconds>`.
              schema:
                type: string
            Sunset:
              description: >-
                Present only when the version is deprecated: the HTTP date from
                which requests on this version return 400 `API_VERSION_SUNSET`.
              schema:
                type: string
            Sajn-Request-Id:
              description: >-
                Identifier of the request. Error bodies repeat it as
                `requestId`; quote it when you contact support.
              schema:
                type: string
            X-RateLimit-Limit:
              description: Requests allowed per minute.
              schema:
                type: integer
            X-RateLimit-Remaining:
              description: Requests left in the current minute.
              schema:
                type: integer
            X-RateLimit-Reset:
              description: When the minute window resets, in Unix seconds.
              schema:
                type: integer
            X-RateLimit-Daily-Limit:
              description: >-
                Requests allowed per day. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Remaining:
              description: >-
                Requests left today. Absent for first-party connectors and
                negotiated limits.
              schema:
                type: integer
            X-RateLimit-Daily-Reset:
              description: >-
                When the daily quota resets, in Unix seconds. Absent for
                first-party connectors and negotiated limits.
              schema:
                type: integer
      security:
        - bearerAuth: []
        - oauth2:
            - documents:write
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Personal API key, e.g. `Authorization: Bearer sajn_sk_...`. Not
        scope-limited — acts as the issuing user.
    oauth2:
      type: oauth2
      description: >-
        OAuth 2.0 access token for a connected application. Limited to the
        scopes granted at consent.
      flows:
        authorizationCode:
          authorizationUrl: https://app.sajn.se/oauth/authorize
          tokenUrl: https://app.sajn.se/api/oauth/token
          refreshUrl: https://app.sajn.se/api/oauth/token
          scopes:
            profile:read: >-
              Read the user's profile, including name, phone number and email
              address.
            documents:read: Read documents.
            documents:write: Create documents and edit the documents the user created.
            documents:delete: >-
              Delete documents, files, folders, custom fields and comment
              threads.
            forms:read: Read forms and their settings.
            forms:write: Create, edit and publish forms.
            forms:delete: Permanently delete forms and their submissions.
            forms:submissions:read: Read form submissions and the respondents' contact details.
            templates:read: Read templates.
            templates:write: Create and edit templates.
            contacts:read: Read contacts.
            contacts:write: Create and edit contacts.
            contacts:delete: Delete contacts.
            organization:read: Read information about the organization.
            audit:read: Read document activity and event logs.
            signatures:read: >-
              Read the identity the eID verified at signing, including the
              national identity number.
            sajnid:read: Read sajn ID verifications.
            sajnid:write: Create sajn ID verifications.
            login:read: Read the result of sajn Login sessions.
            login:write: Start sajn Login sessions.
            webhooks:read: Read webhooks and their deliveries.
            webhooks:write: Create, edit and delete webhooks.
            actions:read: Read suggested actions and what each one does.
            actions:write: >-
              Approve, dismiss and snooze suggested actions. An approval can
              send reminders to counterparties, terminate agreements and create
              follow-ups.
            members:read: Read the workspace's members.
            members:write: Invite and manage workspace members.
            roles:read: Read the workspace's roles and permissions.
            roles:write: Create, edit and delete workspace roles.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.