> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gpuoutlet.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# This document

> Served without authentication, so the contract can be read before a key exists.



## OpenAPI

````yaml https://api.gpuoutlet.ai/v1/openapi.yaml get /openapi.yaml
openapi: 3.1.0
info:
  title: GPU Outlet Partner API
  version: 2.0.0
  description: >
    Programmatic access to the GPU Outlet introduction marketplace: state what
    capacity your company needs, read the opportunities offered to you, follow
    the introductions you are party to, and consult Radar.


    **Authentication.** Every endpoint except this document requires
    `Authorization: Bearer gpk_…`. Mint a key in your dashboard under Settings →
    API keys. The key is shown once, at creation, and is not recoverable — we
    store only its hash.


    **Company context.** A key belongs to a person; the company and the role the
    call acts with are that person's company membership, exactly as in the
    dashboard. A key whose owner is in no company gets `company_required`; a
    role short of the action gets `forbidden_role`. Nothing in a request body
    can name a company.


    **Scopes.** Each endpoint names the scope it needs. A key carries the scopes
    it was minted with and cannot grow one later; a key without the required
    scope gets `insufficient_scope` with `required_scope` in the error.


    **Idempotency.** Every `POST`, `PUT` and `PATCH` under Requests,
    Opportunities and Introductions **requires** `Idempotency-Key`. Generate one
    per intent (a UUID is fine) and reuse it verbatim on every retry of that
    same request: you get the original response back, marked
    `Idempotency-Replayed: true`, and nothing is written twice. The same key
    with a different body is `idempotency_key_reused`; a key whose first attempt
    is still running is `idempotency_key_in_flight` with `Retry-After`. Keys are
    remembered for 24 hours. Radar writes accept the header and echo it but do
    not require it.


    **Rate limits.** Every response carries `RateLimit-Limit`,
    `RateLimit-Remaining` and `RateLimit-Reset`; a 429 adds `Retry-After`.
    Writes have a smaller bucket of their own on top. Limits are enforced per
    API server instance and are approximate — treat `RateLimit-Remaining` as
    advisory, and back off on 429 rather than predicting it.


    **Compatibility.** We may add endpoints, add response fields, add optional
    query parameters, and add values to response enums at any time. Your client
    **must ignore fields it does not recognise.** Removing or renaming a field,
    changing a type, or tightening validation requires a new major version.


    **UI only.** The steps with legal effect stay in the dashboard, behind a
    second factor a key cannot present: accepting an opportunity and revealing
    the buyer, existing-relationship claims, deal reports and receipts, deal and
    success-fee invoices, and signing agreements. This API reads what those
    steps produced; it does not perform them.


    **What we do not publish.** Before a reveal, an opportunity carries the
    buyer's demand and nothing about the buyer — no name, no country, no id.
    Internal identifiers of people are never on the wire. Do not build on
    inferring either.
servers:
  - url: https://api.gpuoutlet.ai/v1
security:
  - bearerAuth: []
tags:
  - name: Account
    description: Facts about the calling key.
  - name: Radar
    description: >
      Curated nodes of reserved capacity — what a signed-in buyer sees on the
      Radar page, and what a seller has proposed to it.
  - name: Requests
    description: >
      Your company's demand. A request is what the operator matches sellers
      against; sellers see an anonymised copy of it as an opportunity.
  - name: Opportunities
    description: >
      The seller's inbox — demand matched to your listing, anonymised until you
      accept it in the dashboard. Declining needs no second factor and is here.
  - name: Introductions
    description: >
      What both parties read after a reveal, and the one move either may make
      without a person present — "we are ready".
paths:
  /openapi.yaml:
    get:
      tags:
        - Account
      summary: This document
      description: >-
        Served without authentication, so the contract can be read before a key
        exists.
      operationId: getOpenApiDocument
      responses:
        '200':
          description: The OpenAPI document, as YAML
          content:
            application/yaml:
              schema:
                type: string
      security: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'An API key from your dashboard, sent as `Authorization: Bearer gpk_…`.'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.