> ## Documentation Index
> Fetch the complete documentation index at: https://docs.go.aiinsurance.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Touch Generated Form

> Brings a **generated form** up to date in place: converges any legacy-style
smart-tag anchors in its editable draft to the current hashed identity
format, and refreshes the form's cached smart-tag metadata from the
converged document. The request has no body.

**Idempotent.** A form that is already up to date reports
`changed: false` and nothing is written — so re-running a touch (or a whole
migration sweep) is safe, and a fleet-wide pass that reports `changed:
false` everywhere proves every anchor RESOLVABLE against the company's
current field configuration is converged. Anchors naming a field the
configuration does not define are deliberately left unrenamed (readable,
repairable) and do not count as changes.

The form's **content is never altered**: only the internal identity of each
smart-tag anchor changes; displayed text, substituted values, and tag
display names are preserved. A form with a finalized (bound) copy keeps
that copy byte-for-byte untouched — only the editable draft converges.
Static (PDF) forms have no smart-tag anchors and always report a clean
no-op.

**Required permission:** `forms:update`




## OpenAPI

````yaml /openapi/generated-external-api.yaml post /api/v1/companies/{companyId}/forms/generated/{id}/touch
openapi: 3.0.3
info:
  title: AI Insurance External API
  description: External API for AI Insurance platform
  version: 1.0.0
  contact:
    email: support@aiinsurance.io
servers:
  - url: https://go.aiinsurance.io
    description: Production
security:
  - ApiKeyAuth: []
paths:
  /api/v1/companies/{companyId}/forms/generated/{id}/touch:
    post:
      tags:
        - Forms
      summary: Touch Generated Form
      description: >
        Brings a **generated form** up to date in place: converges any
        legacy-style

        smart-tag anchors in its editable draft to the current hashed identity

        format, and refreshes the form's cached smart-tag metadata from the

        converged document. The request has no body.


        **Idempotent.** A form that is already up to date reports

        `changed: false` and nothing is written — so re-running a touch (or a
        whole

        migration sweep) is safe, and a fleet-wide pass that reports `changed:

        false` everywhere proves every anchor RESOLVABLE against the company's

        current field configuration is converged. Anchors naming a field the

        configuration does not define are deliberately left unrenamed (readable,

        repairable) and do not count as changes.


        The form's **content is never altered**: only the internal identity of
        each

        smart-tag anchor changes; displayed text, substituted values, and tag

        display names are preserved. A form with a finalized (bound) copy keeps

        that copy byte-for-byte untouched — only the editable draft converges.

        Static (PDF) forms have no smart-tag anchors and always report a clean

        no-op.


        **Required permission:** `forms:update`
      operationId: touchGeneratedForm
      parameters:
        - $ref: '#/components/parameters/companyId'
        - $ref: '#/components/parameters/generatedFormId'
      responses:
        '200':
          description: |
            The touch outcome. `changed` is true when anything was written —
            anchors renamed in the draft and/or metadata refreshed.
          content:
            application/json:
              schema:
                type: object
                required:
                  - id
                  - changed
                  - renamedTags
                  - metadataRefreshed
                properties:
                  id:
                    type: string
                    format: uuid
                    description: The touched generated form's id.
                  changed:
                    type: boolean
                    description: >-
                      True when the touch wrote anything (anchors renamed and/or
                      metadata refreshed); false when the form was already up to
                      date.
                  renamedTags:
                    type: array
                    items:
                      type: string
                    description: >-
                      The legacy smart-tag identities that were converged to the
                      hashed format, one entry per unique identity. Empty when
                      the draft was already converged.
                  metadataRefreshed:
                    type: boolean
                    description: >-
                      True when the form's cached smart-tag metadata was brought
                      up to date. Always false for forms with a finalized
                      (bound) copy, whose metadata is frozen.
              examples:
                converged:
                  summary: A legacy-anchor form was converged
                  value:
                    id: 550e8400-e29b-41d4-a716-446655440077
                    changed: true
                    renamedTags:
                      - AIIFmv1NamedInsured
                    metadataRefreshed: true
                alreadyUpToDate:
                  summary: Nothing to do — the form was already up to date
                  value:
                    id: 550e8400-e29b-41d4-a716-446655440077
                    changed: false
                    renamedTags: []
                    metadataRefreshed: false
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          description: >-
            No live generated form carries the given id (`form-not-found`), or
            the form's row exists but its stored draft file is missing from
            storage (`form-file-missing`).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                notFound:
                  summary: Unknown or deleted form id
                  value:
                    error:
                      code: form-not-found
                      message: >-
                        No generated form with id
                        550e8400-e29b-41d4-a716-446655440077 was found.
                      userMessages:
                        - >-
                          No generated form with id
                          550e8400-e29b-41d4-a716-446655440077 was found.
                fileMissing:
                  summary: Live form whose stored draft file is gone
                  value:
                    error:
                      code: form-file-missing
                      message: >-
                        The form is missing its stored file, so it cannot be
                        touched.
                      userMessages:
                        - >-
                          The form is missing its stored file, so it cannot be
                          touched.
        '409':
          description: >-
            The stored draft was modified while it was being touched (e.g. a
            live editing session saved concurrently). Nothing was overwritten —
            retry the touch.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                concurrentModification:
                  summary: Draft changed mid-touch
                  value:
                    error:
                      code: form-file-concurrently-modified
                      message: >-
                        The form was modified while it was being touched. Retry
                        the touch.
                      userMessages:
                        - >-
                          The form was modified while it was being touched.
                          Retry the touch.
        '422':
          description: >-
            The stored draft could not be parsed as a `.docx`, so its smart tags
            cannot be converged.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                unreadable:
                  summary: Stored bytes are not a readable .docx
                  value:
                    error:
                      code: form-file-unreadable
                      message: >-
                        The form’s stored file could not be read as a .docx, so
                        it cannot be touched.
                      userMessages:
                        - >-
                          The form’s stored file could not be read as a .docx,
                          so it cannot be touched.
components:
  parameters:
    companyId:
      name: companyId
      in: path
      required: true
      schema:
        type: string
        format: uuid
      description: Company identifier
    generatedFormId:
      name: id
      in: path
      required: true
      schema:
        type: string
        format: uuid
      description: >
        The generated form's `id` (as returned by the List Generated Forms

        endpoint). Identifies one generated form instance — not a template;
        templates

        are addressed by their `FM-XXXX` number instead.
  responses:
    Unauthorized:
      description: Unauthorized - Invalid or missing API key
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            missingApiKey:
              summary: Missing API key
              value:
                error:
                  code: AuthenticationError
                  message: API key authentication required
                  userMessages:
                    - API key authentication required
            invalidApiKey:
              summary: >-
                Invalid API key (e.g. unknown key, or a Bearer token used
                instead of an API key)
              value:
                error:
                  code: AuthenticationError
                  message: Invalid API key
                  userMessages:
                    - Invalid API key
    Forbidden:
      description: Forbidden - Insufficient permissions
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            insufficientPermissions:
              summary: Insufficient permissions
              value:
                error:
                  code: AuthorizationError
                  message: User is not authorized to perform the requested action
                  userMessages:
                    - User is not authorized to perform the requested action
            companyMismatch:
              summary: A valid API key naming another company in the URL
              value:
                error:
                  code: AuthorizationError
                  message: API key is not scoped to the requested company
                  userMessages:
                    - API key is not scoped to the requested company
  schemas:
    ErrorResponse:
      type: object
      description: Standard error response for all external API endpoints
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              description: Machine-readable error code
              example: VALIDATION_ERROR
            message:
              type: string
              description: Human-readable error message
              example: 'submissionId: Required field is missing'
            userMessages:
              type: array
              description: >-
                Clean, verbatim-displayable messages — one entry per failure,
                free of error-code tags, field paths, and internal noise.
                Suitable for showing to end users as-is.
              items:
                type: string
              example:
                - Exposures of type 'company' require an address
            details:
              type: array
              description: Additional details for validation errors (field-level errors)
              items:
                type: object
                properties:
                  field:
                    type: string
                    description: The field that caused the error
                    example: submissionId
                  message:
                    type: string
                    description: Description of the field error
                    example: Required field is missing
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        API key authentication. Send your raw API key as the `Authorization`
        header value with NO scheme prefix — `Authorization: YOUR-API-KEY`. Do
        NOT prefix it with `Bearer ` or `ApiKey `, and do not use an `X-API-Key`
        header; those are not accepted.

````