curl --request POST \
--url https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'import requests
url = "https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata"
payload := strings.NewReader("{}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{}")
.asString();require 'uri'
require 'net/http'
url = URI("https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{}"
response = http.request(request)
puts response.read_body{
"version": 7,
"contentHash": "5bdcf0bb62622f29da8ed6d7ed2c0300ff1b934f5b865874b4022541e102721f",
"lastModifiedAt": "2026-06-25T18:32:10.114Z",
"lastImportedAt": "2026-06-20T09:15:00.000Z"
}Get Configuration Metadata
Returns lightweight metadata about the company’s FMV1 configuration — the
latest stored snapshot’s version + contentHash plus
last-modified and last-imported timestamps — without the full
configuration body. Use it for cheap staleness checks and compare-and-set
workflows: compare the contentHash against a previously seen value to
decide whether the configuration CONTENT has changed before pulling the
full export payload. The hash is computed from that current export
representation for the authenticated caller, including when immutable stored
bytes use a different wire shape. Use the same credentials for export,
metadata, and import with expectedContentHash.
Every configuration write stores a new snapshot, so any configuration
change is reflected here.
The metadata reads the configuration state from the database (resolved from the API key’s tenant), so the request needs no body — POST an empty object.
Required permission: configuration.view
This endpoint requires an API key that holds the configuration permissions — the Admin role does. See Authentication for how to create API keys with specific roles.
curl --request POST \
--url https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'import requests
url = "https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata"
payload := strings.NewReader("{}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{}")
.asString();require 'uri'
require 'net/http'
url = URI("https://go.aiinsurance.io/api/v1/companies/{companyId}/configuration/metadata")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{}"
response = http.request(request)
puts response.read_body{
"version": 7,
"contentHash": "5bdcf0bb62622f29da8ed6d7ed2c0300ff1b934f5b865874b4022541e102721f",
"lastModifiedAt": "2026-06-25T18:32:10.114Z",
"lastImportedAt": "2026-06-20T09:15:00.000Z"
}Authorizations
User-principal OAuth 2.0 Bearer authentication. Send a user-scoped Auth0 access token (audience = the app API audience) as Authorization: Bearer <jwt>. The request resolves to the user's identity and is authorized by their Role on the {companyId} in the path — the same role-based permissions the web app enforces. This is the path the MCP connector uses to act on a user's behalf; endpoints that accept it list both BearerAuth and ApiKeyAuth.
Path Parameters
Company identifier
Body
No input is required; the metadata is read from the database. An empty object is accepted.
Response
Configuration metadata returned successfully
Lightweight FMV1 configuration metadata for staleness checks — version identity and timestamps, WITHOUT the full configuration blob.
The monotonic version of the latest stored configuration snapshot (starts at 1; a new snapshot is stored on every configuration import). null when no snapshot has been stored for the company yet. Pair it with contentHash to identify exactly which configuration state you observed.
7
sha256 (lowercase hex) of the latest stored snapshot's canonical current export projection — exactly the body returned by configuration export. Historical immutable snapshots that use a legacy wire shape are projected before hashing, so this token always identifies the public configuration content rather than the raw stored bytes. Use it for compare-and-set workflows (re-importing identical content stores a new version but the SAME contentHash). null when no snapshot has been stored for the company yet. Every configuration write stores a new snapshot, so any configuration change is reflected here.
"5bdcf0bb62622f29da8ed6d7ed2c0300ff1b934f5b865874b4022541e102721f"
ISO 8601 timestamp of the last configuration change — the latest stored snapshot's creation time — or null when the company has no configuration yet.
"2026-06-25T18:32:10.114Z"
ISO 8601 timestamp of the most recent onboarding configuration import, or null when the company has never imported a configuration.
"2026-06-20T09:15:00.000Z"
