curl --request POST \
--url https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/repair \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"kind": "segmentHashes",
"dryRun": true
}
'{
"kind": "segmentHashes",
"scanned": 0,
"mismatched": 0,
"repaired": 0,
"remaining": 0,
"nextCursor": null,
"byCompany": []
}Repair Policies
Company-scoped Policy integrity repair. Choose segmentHashes to recompute stored segment hashes, joinHistory to rebuild relationship history from immutable segments, or fieldValues to rewrite a reviewed field-value manifest across a single Policy’s history.
Segment hashes and join history default to dryRun: true, have a bounded limit, and return an exclusive nextCursor; repeat the same scope with that cursor until it is null. Join history refuses link loss unless allowLinkLoss: true; inspect the dry-run loss samples before applying. A dry run rolls back the rebuilt relationships.
For fieldValues, supply repair.policyId and an explicit repair.dryRun. Preview returns current/projected SHA-256 fingerprints and occurrences. Apply requires both reviewed fingerprints, writes atomically, and returns unchanged on replay. A stale preimage or unexpected postimage returns 409 without changes. Apply records one transactional audit entry. Repairs do not create Policy versions.
Required permission: none — staff level staff (a staff user’s own Bearer token or a verified platform service identity); API keys are rejected.
curl --request POST \
--url https://go.aiinsurance.io/api/v1/companies/{companyId}/policies/repair \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"kind": "segmentHashes",
"dryRun": true
}
'{
"kind": "segmentHashes",
"scanned": 0,
"mismatched": 0,
"repaired": 0,
"remaining": 0,
"nextCursor": null,
"byCompany": []
}Authorizations
User-principal OAuth 2.0 Bearer authentication. Send a user-scoped Auth0 access token (audience = the app API audience) as Authorization: Bearer <jwt>. The request resolves to the user's identity and is authorized by their Role on the {companyId} in the path — the same role-based permissions the web app enforces. This is the path the MCP connector uses to act on a user's behalf; endpoints that accept it list both BearerAuth and ApiKeyAuth.
Path Parameters
Company identifier
Body
Response
Kind-specific repair report. Continue bounded scans until nextCursor is null.
- Option 1
- Option 2
- Option 3
- Option 4
segmentHashes x >= 0x >= 0x >= 0x >= 0Show child attributes
Show child attributes
Show child attributes
Show child attributes
