> ## Documentation Index
> Fetch the complete documentation index at: https://docs.go.aiinsurance.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List Entity Types

> Discovery endpoint — returns the fixed set of CRUD entity TYPES
(`Event`, `Exposure`, `Quote`, `Submission`, `Person`, `Organization`),
each with display names, links to its `/entities/{entityType}` collection and
`/entities/{entityType}/configuration` schema, and the per-action permission
keys a client needs.

Custom objects never appear here: they are embedded-only and surface solely
as `Object` / `Object List` field definitions inside an entity's
`/configuration` response, never as a top-level CRUD entity. `Policy` is also
absent — its writes go through the policy transaction endpoints, though it
does expose a read-only `/configuration` schema.

The path segment is `/entity-types` (not `/entities`): this describes entity
SCHEMA/metadata, while `/entities/{entityType}` lists entity INSTANCES of one
type.

**Required permission:** `company.configuration:export`




## OpenAPI

````yaml /openapi/generated-external-api.yaml get /api/v1/companies/{companyId}/entity-types
openapi: 3.0.3
info:
  title: AI Insurance External API
  description: External API for AI Insurance platform
  version: 1.0.0
  contact:
    email: support@aiinsurance.io
servers:
  - url: https://go.aiinsurance.io
    description: Production
security:
  - ApiKeyAuth: []
paths:
  /api/v1/companies/{companyId}/entity-types:
    get:
      tags:
        - Entities
      summary: List Entity Types
      description: >
        Discovery endpoint — returns the fixed set of CRUD entity TYPES

        (`Event`, `Exposure`, `Quote`, `Submission`, `Person`, `Organization`),

        each with display names, links to its `/entities/{entityType}`
        collection and

        `/entities/{entityType}/configuration` schema, and the per-action
        permission

        keys a client needs.


        Custom objects never appear here: they are embedded-only and surface
        solely

        as `Object` / `Object List` field definitions inside an entity's

        `/configuration` response, never as a top-level CRUD entity. `Policy` is
        also

        absent — its writes go through the policy transaction endpoints, though
        it

        does expose a read-only `/configuration` schema.


        The path segment is `/entity-types` (not `/entities`): this describes
        entity

        SCHEMA/metadata, while `/entities/{entityType}` lists entity INSTANCES
        of one

        type.


        **Required permission:** `company.configuration:export`
      operationId: listEntityTypes
      parameters:
        - $ref: '#/components/parameters/companyId'
      responses:
        '200':
          description: The fixed set of CRUD entity-type descriptors.
          content:
            application/json:
              schema:
                type: object
                required:
                  - entityTypes
                properties:
                  entityTypes:
                    type: array
                    items:
                      $ref: '#/components/schemas/EntityTypeDescriptor'
              examples:
                success:
                  summary: Entity types
                  value:
                    entityTypes:
                      - type: Exposure
                        displayName: Exposure
                        pluralDisplayName: Exposures
                        links:
                          collection: >-
                            /api/v1/companies/550e8400-e29b-41d4-a716-446655440000/entities/exposure
                          configuration: >-
                            /api/v1/companies/550e8400-e29b-41d4-a716-446655440000/entities/exposure/configuration
                        permissions:
                          read: company.insured:read
                          create: company.insured:create
                          update: insured:update
                          delete: insured:delete
                      - type: Person
                        displayName: Person
                        pluralDisplayName: People
                        links:
                          collection: >-
                            /api/v1/companies/550e8400-e29b-41d4-a716-446655440000/entities/person
                          configuration: >-
                            /api/v1/companies/550e8400-e29b-41d4-a716-446655440000/entities/person/configuration
                        permissions:
                          read: company.fmv1_custom_object:read
                          create: company.fmv1_custom_object:create
                          update: company.fmv1_custom_object:update
                          delete: company.fmv1_custom_object:delete
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  parameters:
    companyId:
      name: companyId
      in: path
      required: true
      schema:
        type: string
        format: uuid
      description: Company identifier
  schemas:
    EntityTypeDescriptor:
      type: object
      description: >
        Describes one CRUD entity type: its canonical type name, human-readable

        labels, HATEOAS-style links to its collection and configuration
        endpoints, and

        the per-action permission keys a client needs to operate on it. The
        permission

        keys are the exact, in-use strings (they vary per type — e.g. Event maps
        to

        `company.claim:*`, Exposure update/delete are the bare `insured:update`/

        `insured:delete`, Person/Organization reuse
        `company.fmv1_custom_object:*`).
      required:
        - type
        - displayName
        - pluralDisplayName
        - links
        - permissions
      properties:
        type:
          type: string
          description: Canonical PascalCase entity type.
          enum:
            - Event
            - Exposure
            - Quote
            - Submission
            - Person
            - Organization
        displayName:
          type: string
          description: Singular human-readable label.
        pluralDisplayName:
          type: string
          description: Plural human-readable label.
        links:
          type: object
          description: Links from this entity type to its related endpoints.
          required:
            - collection
            - configuration
          properties:
            collection:
              type: string
              description: Collection endpoint — list/create instances of this type.
            configuration:
              type: string
              description: Configuration (field schema) endpoint for this type.
        permissions:
          type: object
          description: >
            The per-CRUD-action permission keys required to operate on this
            entity

            type. `read` is the collection-read permission gating
            `links.collection`.
          required:
            - read
            - create
            - update
            - delete
          properties:
            read:
              type: string
            create:
              type: string
            update:
              type: string
            delete:
              type: string
    ErrorResponse:
      type: object
      description: Standard error response for all external API endpoints
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              description: Machine-readable error code
              example: VALIDATION_ERROR
            message:
              type: string
              description: Human-readable error message
              example: 'submissionId: Required field is missing'
            userMessages:
              type: array
              description: >-
                Clean, verbatim-displayable messages — one entry per failure,
                free of error-code tags, field paths, and internal noise.
                Suitable for showing to end users as-is.
              items:
                type: string
              example:
                - Exposures of type 'company' require an address
            details:
              type: array
              description: Additional details for validation errors (field-level errors)
              items:
                type: object
                properties:
                  field:
                    type: string
                    description: The field that caused the error
                    example: submissionId
                  message:
                    type: string
                    description: Description of the field error
                    example: Required field is missing
  responses:
    Unauthorized:
      description: Unauthorized - Invalid or missing API key
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            missingApiKey:
              summary: Missing API key
              value:
                error:
                  code: AuthenticationError
                  message: API key authentication required
                  userMessages:
                    - API key authentication required
            invalidApiKey:
              summary: >-
                Invalid API key (e.g. unknown key, or a Bearer token used
                instead of an API key)
              value:
                error:
                  code: AuthenticationError
                  message: Invalid API key
                  userMessages:
                    - Invalid API key
    Forbidden:
      description: Forbidden - Insufficient permissions
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            insufficientPermissions:
              summary: Insufficient permissions
              value:
                error:
                  code: AuthorizationError
                  message: User is not authorized to perform the requested action
                  userMessages:
                    - User is not authorized to perform the requested action
            companyMismatch:
              summary: A valid API key naming another company in the URL
              value:
                error:
                  code: AuthorizationError
                  message: API key is not scoped to the requested company
                  userMessages:
                    - API key is not scoped to the requested company
    InternalServerError:
      description: Internal Server Error - Unexpected error occurred
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            internalError:
              summary: Unexpected server error
              value:
                error:
                  code: UncaughtActionError
                  message: Uncaught error occurred in <actionName>
                  userMessages:
                    - An unexpected error occurred. Please try again later.
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        API key authentication. Send your raw API key as the `Authorization`
        header value with NO scheme prefix — `Authorization: YOUR-API-KEY`. Do
        NOT prefix it with `Bearer ` or `ApiKey `, and do not use an `X-API-Key`
        header; those are not accepted.

````