late 0.0.772

API reference for Zernio. Authenticate with a Bearer API key. Base URL: https://zernio.com/api Versioning and deprecation: all endpoints are versioned in the URL path (current version: /v1). Breaking changes only ship in a new path version; existing versions keep working. Deprecated operations are marked 'deprecated: true' in this spec and announced in the changelog (https://zernio.com/changelog) before removal. Errors: every 4xx/5xx response is application/json with a machine-readable 'code' and a human-readable 'error' message (see the ErrorResponse schema).
Documentation
/*
 * Zernio API
 *
 * API reference for Zernio. Authenticate with a Bearer API key. Base URL: https://zernio.com/api  Versioning and deprecation: all endpoints are versioned in the URL path (current version: /v1). Breaking changes only ship in a new path version; existing versions keep working. Deprecated operations are marked 'deprecated: true' in this spec and announced in the changelog (https://zernio.com/changelog) before removal.  Errors: every 4xx/5xx response is application/json with a machine-readable 'code' and a human-readable 'error' message (see the ErrorResponse schema).
 *
 * The version of the OpenAPI document: 1.0.4
 * Contact: support@zernio.com
 * Generated by: https://openapi-generator.tech
 */

use crate::models;
use serde::{Deserialize, Serialize};

#[derive(Clone, Default, Debug, PartialEq, Serialize, Deserialize)]
pub struct ApiKey {
    #[serde(rename = "id", skip_serializing_if = "Option::is_none")]
    pub id: Option<String>,
    #[serde(rename = "name", skip_serializing_if = "Option::is_none")]
    pub name: Option<String>,
    #[serde(rename = "keyPreview", skip_serializing_if = "Option::is_none")]
    pub key_preview: Option<String>,
    #[serde(rename = "expiresAt", skip_serializing_if = "Option::is_none")]
    pub expires_at: Option<String>,
    #[serde(rename = "createdAt", skip_serializing_if = "Option::is_none")]
    pub created_at: Option<String>,
    /// Returned only once, on creation
    #[serde(rename = "key", skip_serializing_if = "Option::is_none")]
    pub key: Option<String>,
    /// 'full' grants access to all profiles, 'profiles' restricts to specific profiles
    #[serde(rename = "scope", skip_serializing_if = "Option::is_none")]
    pub scope: Option<Scope>,
    /// Profiles this key can access (populated with name and color). Only present when scope is 'profiles'.
    #[serde(rename = "profileIds", skip_serializing_if = "Option::is_none")]
    pub profile_ids: Option<Vec<models::ApiKeyProfileIdsInner>>,
    /// 'read-write' allows all operations, 'read' restricts to GET requests only
    #[serde(rename = "permission", skip_serializing_if = "Option::is_none")]
    pub permission: Option<Permission>,
    /// Resource groups this key can NOT access (opt-out denylist). Absent or empty means legacy full access. A key with any group disabled is a restricted key (zrk_ prefix) and can never manage API keys, invites, or member identity. Each operation's group is published as x-resource-group. With 'messages' disabled, the key cannot read or send private messages through any API surface, and it cannot create or edit a webhook subscription broader than itself: it cannot subscribe to, test-fire, redeliver, or read delivery logs for message events. Subscriptions created earlier, from the dashboard, or with a full-access key keep delivering whatever their own `disabledResourceGroups` allows, so restricting an existing integration end to end means restricting the subscription too. OAuth connector tokens (AI assistants and MCP clients) resolve against the same registry, but their groups are not settable yet: treat an authorized connector as full access.
    #[serde(
        rename = "disabledResourceGroups",
        skip_serializing_if = "Option::is_none"
    )]
    pub disabled_resource_groups: Option<Vec<DisabledResourceGroups>>,
}

impl ApiKey {
    pub fn new() -> ApiKey {
        ApiKey {
            id: None,
            name: None,
            key_preview: None,
            expires_at: None,
            created_at: None,
            key: None,
            scope: None,
            profile_ids: None,
            permission: None,
            disabled_resource_groups: None,
        }
    }
}
/// 'full' grants access to all profiles, 'profiles' restricts to specific profiles
#[derive(Clone, Copy, Debug, Eq, PartialEq, Ord, PartialOrd, Hash, Serialize, Deserialize)]
pub enum Scope {
    #[serde(rename = "full")]
    Full,
    #[serde(rename = "profiles")]
    Profiles,
}

impl Default for Scope {
    fn default() -> Scope {
        Self::Full
    }
}
/// 'read-write' allows all operations, 'read' restricts to GET requests only
#[derive(Clone, Copy, Debug, Eq, PartialEq, Ord, PartialOrd, Hash, Serialize, Deserialize)]
pub enum Permission {
    #[serde(rename = "read-write")]
    ReadWrite,
    #[serde(rename = "read")]
    Read,
}

impl Default for Permission {
    fn default() -> Permission {
        Self::ReadWrite
    }
}
/// Resource groups this key can NOT access (opt-out denylist). Absent or empty means legacy full access. A key with any group disabled is a restricted key (zrk_ prefix) and can never manage API keys, invites, or member identity. Each operation's group is published as x-resource-group. With 'messages' disabled, the key cannot read or send private messages through any API surface, and it cannot create or edit a webhook subscription broader than itself: it cannot subscribe to, test-fire, redeliver, or read delivery logs for message events. Subscriptions created earlier, from the dashboard, or with a full-access key keep delivering whatever their own `disabledResourceGroups` allows, so restricting an existing integration end to end means restricting the subscription too. OAuth connector tokens (AI assistants and MCP clients) resolve against the same registry, but their groups are not settable yet: treat an authorized connector as full access.
#[derive(Clone, Copy, Debug, Eq, PartialEq, Ord, PartialOrd, Hash, Serialize, Deserialize)]
pub enum DisabledResourceGroups {
    #[serde(rename = "publishing")]
    Publishing,
    #[serde(rename = "engagement")]
    Engagement,
    #[serde(rename = "messages")]
    Messages,
    #[serde(rename = "contacts")]
    Contacts,
    #[serde(rename = "analytics")]
    Analytics,
    #[serde(rename = "ads")]
    Ads,
    #[serde(rename = "telephony")]
    Telephony,
    #[serde(rename = "accounts")]
    Accounts,
    #[serde(rename = "billing")]
    Billing,
    #[serde(rename = "webhooks")]
    Webhooks,
}

impl Default for DisabledResourceGroups {
    fn default() -> DisabledResourceGroups {
        Self::Publishing
    }
}