> ## Documentation Index
> Fetch the complete documentation index at: https://docs.go.aiinsurance.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List Policy Contacts

> Returns the policy's **current** contacts: the Directory People linked to
it, each with their display name. Contacts are an unversioned association
(they are not part of any transaction or segment), so the same list applies
whichever policy version or effective date you are looking at. Deleted
People are omitted.

The same person IDs also appear as the read-only `contacts` array in every
segment's `data` on the policy read and list endpoints, for callers holding
`person.view`.

**Required permission:** `policy.view` — the caller must also hold
`person.view` to read Directory People.




## OpenAPI

````yaml /openapi/generated-external-api.yaml get /api/v1/companies/{companyId}/policies/{policyId}/contacts
openapi: 3.0.3
info:
  title: AI Insurance External API
  description: External API for AI Insurance platform
  version: 1.0.0
  contact:
    email: support@aiinsurance.io
servers:
  - url: https://go.aiinsurance.io
    description: Production
security:
  - ApiKeyAuth: []
paths:
  /api/v1/companies/{companyId}/policies/{policyId}/contacts:
    get:
      tags:
        - Field Model Policy Transactions
      summary: List Policy Contacts
      description: >
        Returns the policy's **current** contacts: the Directory People linked
        to

        it, each with their display name. Contacts are an unversioned
        association

        (they are not part of any transaction or segment), so the same list
        applies

        whichever policy version or effective date you are looking at. Deleted

        People are omitted.


        The same person IDs also appear as the read-only `contacts` array in
        every

        segment's `data` on the policy read and list endpoints, for callers
        holding

        `person.view`.


        **Required permission:** `policy.view` — the caller must also hold

        `person.view` to read Directory People.
      operationId: listPolicyContacts
      parameters:
        - $ref: '#/components/parameters/companyId'
        - $ref: '#/components/parameters/policyIdPath'
      responses:
        '200':
          description: The policy's current contacts
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyContactsResponse'
              examples:
                withContacts:
                  summary: Two linked people
                  value:
                    contacts:
                      - personId: 550e8400-e29b-41d4-a716-446655440101
                        displayName: Jane Doe
                      - personId: 550e8400-e29b-41d4-a716-446655440102
                        displayName: John Smith
                noContacts:
                  summary: Policy with no contacts
                  value:
                    contacts: []
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          description: Policy not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                policyNotFound:
                  summary: Policy does not exist in this company
                  value:
                    error:
                      code: NOT_FOUND
                      message: Policy not found
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  parameters:
    companyId:
      name: companyId
      in: path
      required: true
      schema:
        type: string
        format: uuid
      description: Company identifier
    policyIdPath:
      name: policyId
      in: path
      required: true
      schema:
        type: string
        format: uuid
      description: Policy identifier
  schemas:
    PolicyContactsResponse:
      type: object
      description: >-
        A policy's current Directory contacts. Every contacts operation answers
        the full current association set after the call, in a stable order.
      required:
        - contacts
      properties:
        contacts:
          type: array
          items:
            type: object
            required:
              - personId
              - displayName
            properties:
              personId:
                type: string
                format: uuid
                description: The linked Directory Person's `id`
              displayName:
                type: string
                description: >-
                  The Person's display name as the app shows it; falls back to
                  the `personId` when the Person has no name.
    ErrorResponse:
      type: object
      description: Standard error response for all external API endpoints
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              description: Machine-readable error code
              example: VALIDATION_ERROR
            message:
              type: string
              description: Human-readable error message
              example: 'submissionId: Required field is missing'
            userMessages:
              type: array
              description: >-
                Clean, verbatim-displayable messages — one entry per failure,
                free of error-code tags, field paths, and internal noise.
                Suitable for showing to end users as-is.
              items:
                type: string
              example:
                - Exposures of type 'company' require an address
            details:
              type: array
              description: Additional details for validation errors (field-level errors)
              items:
                type: object
                properties:
                  field:
                    type: string
                    description: The field that caused the error
                    example: submissionId
                  code:
                    type: string
                    description: Stable problem code for this individual validation failure
                    example: BLANK_LIST_ELEMENT
                  reason:
                    type: string
                    description: Stable reason the value violates its canonical contract
                    example: blank-list-element
                  expected:
                    type: string
                    description: The expected canonical value contract
                    example: nonblank trimmed string
                  message:
                    type: string
                    description: Description of the field error
                    example: Required field is missing
  responses:
    Unauthorized:
      description: Unauthorized - Invalid or missing API key
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            missingApiKey:
              summary: Missing API key
              value:
                error:
                  code: AuthenticationError
                  message: API key authentication required
                  userMessages:
                    - API key authentication required
            invalidApiKey:
              summary: >-
                Invalid API key (e.g. unknown key, or a Bearer token used
                instead of an API key)
              value:
                error:
                  code: AuthenticationError
                  message: Invalid API key
                  userMessages:
                    - Invalid API key
    Forbidden:
      description: Forbidden - Insufficient permissions
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            insufficientPermissions:
              summary: Insufficient permissions
              value:
                error:
                  code: AuthorizationError
                  message: User is not authorized to perform the requested action
                  userMessages:
                    - User is not authorized to perform the requested action
            companyMismatch:
              summary: A valid API key naming another company in the URL
              value:
                error:
                  code: AuthorizationError
                  message: API key is not scoped to the requested company
                  userMessages:
                    - API key is not scoped to the requested company
    InternalServerError:
      description: Internal Server Error - Unexpected error occurred
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            internalError:
              summary: Unexpected server error
              value:
                error:
                  code: UncaughtActionError
                  message: Uncaught error occurred in <actionName>
                  userMessages:
                    - An unexpected error occurred. Please try again later.
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        API key authentication. Send your raw API key as the `Authorization`
        header value with NO scheme prefix — `Authorization: YOUR-API-KEY`. Do
        NOT prefix it with `Bearer ` or `ApiKey `, and do not use an `X-API-Key`
        header; those are not accepted.

````