Skip to main content
POST
Validate Configuration

Authorizations

Authorization
string
header
required

User-principal OAuth 2.0 Bearer authentication. Send a user-scoped Auth0 access token (audience = the app API audience) as Authorization: Bearer <jwt>. The request resolves to the user's identity and is authorized by their Role on the {companyId} in the path — the same role-based permissions the web app enforces. This is the path the MCP connector uses to act on a user's behalf; endpoints that accept it list both BearerAuth and ApiKeyAuth.

Path Parameters

companyId
string<uuid>
required

Company identifier

Body

application/json

A COMPLETE configuration body (the same body import accepts). A delta/patch body is rejected with a 400 — typed changes go to the patch endpoint (POST .../configuration/patch).

fields
object[]
required

Field definitions, keyed by entity + reference id.

pages
object[]
required

Page definitions.

cards
object[]
required

Card definitions.

cardPageRelationships
object[]
required

Placements of cards onto pages.

optionSetTypes
object[]
required

Option-set type declarations.

objectTypes
object[]
required

Custom-object type declarations.

optionSets
object[]
required

Option sets and their options.

objects
object[]
required

Custom-object sub-field definitions, joined to object types.

objectPrimitives
object[]
required

Object-primitive sub-field definitions (Address / Date / Currency).

fieldLocations
object[]
required

Field placements (the layout) onto cards.

ratingWorkflows
object[]
required

Rating workflow definitions.

entityInvariants
object[]
required

Per-entity invariant conditions enforced on every write.

formLogicRules
object[]

Forms-logic rules (quote-flow auto-add rules). Optional — existing payloads predate the "Forms" tab; absent ⇒ no rules.

smartTags
object[]

Smart tags — the named values resolved into generated documents. Optional: existing payloads predate the slice, and absent ⇒ no smart tags, which is also how a company that has not yet moved to this format is recognised.

Omitted from an export when the company has none, rather than emitted as an empty array.

exportSurfaces
object[]

Declared export columns — the tenant-facing column set of each export surface (the seven entity exports plus the bordereau). Optional: existing payloads predate the slice, and absent ⇒ no declared columns, which is also how a surface that still offers every configured field is recognised.

Activation is per surface: a surface with at least one row here resolves its whole tenant column set through those rows, in the order they appear; a surface with none behaves exactly as it did before this section existed.

Omitted from an export when the company has declared none, rather than emitted as an empty array.

Response

Validation completed

Result of validating an FMV1 configuration JSON body. errors collects config-shape findings; isValid is true when every one of them is clean. It reports whether the CONFIGURATION is well-formed and makes no claim about the company's stored records, which are not read.

isValid
boolean
required

Whether the configuration passed every config-shape check

errors
object[]
required

List of validation errors (empty when isValid is true)

warnings
object[]

Validation warnings — reported, never gating: isValid depends on errors alone. A warning flags something worth a look that is nonetheless a valid configuration, such as smart-tag rows sharing a key across form types whose content has diverged.