> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gtm-api.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set account smart limits

> Switch smart-limit governance on or off for the WHOLE account, every bucket at once (no per-bucket toggle). The switch remembers nothing: a real flip in EITHER direction first resets every limit row to the platform defaults (daily_limit = the bucket's platform max, delay / burst = the enum pair, target_limit = the platform default, hold cleared). ON: the warmup then sets every row's daily_limit / delay_in_seconds / batch_size (re-derived from the latest snapshot) and update_linkedin_account_smart_limit refuses those fields with 409 smart_limits_governed; target_limit and learning_enabled stay yours. The seeded target_limit is a target the warmup climbs toward, never a limit somebody set. OFF: every cap runs exactly as typed and the account loses the warmup ban protection: say so first, read the rows' recommended_* before typing caps. Idempotent. SINGLE account: a fleet is a mass action with step linkedin-accounts.set-smart-limits (scope objects, args {enabled}), run BEFORE a limit-row run on the same senders.

Contract:
- MCP tool `set_linkedin_account_smart_limits`, registry package `mcp.linkedin/linkedin_accounts`, mount `linkedin.accounts`.
- Operation `action`, response envelope `action`.
- Flags: dangerous: the MCP layer gates it behind a preview/commit token, and the effect cannot be undone through this API; step eligible: gtm.service.orchestration can run this verb as a mass-action plan step, once per item.



## OpenAPI

````yaml /api-reference/linkedin/openapi.yaml post /api/linkedin-accounts/{sid}/set-smart-limits
openapi: 3.0.3
info:
  title: 'GTM API public contract: gtm.service.linkedin'
  description: >-
    Connected LinkedIn accounts and everything driven through them: account
    health and smart limits, conversations and messages, the connection graph,
    outbound posting, scraping, profile and company enrichment, and the
    antidetect browsers that execute it all.


    GENERATED. This document is projected from the Zod MCP tool registry in
    `product/mcp/gtm.mcp` (one tool per public endpoint, 1:1). Do not edit it by
    hand; edit the tool definition and regenerate with `pnpm openapi:public`.


    Surface: the public `/api` contract of `gtm.service.linkedin`, 182
    operations. This is the only OpenAPI document the platform publishes.
    Internal (`/internal`) and health endpoints are deliberately absent: they
    are not part of any contract, they can change without notice, and the
    service source is their only description.


    Conventions:

    - Auth is a bearer JWT, optionally narrowed by the `Team-SID` header.

    - Every success body is an MCP envelope: `success: true` plus one typed
    `operation` shape (`search`, `get`, `create`, `update`, `delete`, `metrics`,
    `group_by`, `action`), and a `meta` block with `trace_id` for support.

    - Every failure is the same `McpError` envelope with a code from a fixed
    16-code taxonomy, so a client maps errors once.

    - Lists page with `page_size` (0 to 500, default 50) plus an opaque forward
    `cursor`; `page_size: 0` returns counts only.

    - On `GET` and `DELETE`, object-valued query parameters (`filter`, `sort`)
    travel as JSON text and array-valued ones repeat as `name[]=value`.

    - The MCP-only `_meta` field (usage analytics) never reaches the backend and
    is not part of this contract.
  version: '1.0'
  contact:
    name: GTM API
    url: https://gtm-api.com
    email: support@gtm-api.com
  license:
    name: Proprietary
    url: https://gtm-api.com/license
servers:
  - url: https://app.gtm-api.com/linkedin/v4
    description: Production, through the app.gtm-api.com gateway
security:
  - BearerJwt: []
    TeamSid: []
tags:
  - name: antidetect_browser_logs
    description: >-
      Registry package `mcp.linkedin/antidetect_browser_logs`, served on MCP
      mount `linkedin.browsers`.
  - name: antidetect_browser_proxies
    description: >-
      Registry package `mcp.linkedin/antidetect_browser_proxies`, served on MCP
      mount `linkedin.browsers`.
  - name: antidetect_browsers
    description: >-
      Registry package `mcp.linkedin/antidetect_browsers`, served on MCP mount
      `linkedin.browsers`.
  - name: cloud_browser_sessions
    description: >-
      Registry package `mcp.linkedin/cloud_browser_sessions`, served on MCP
      mount `linkedin.browsers`.
  - name: cloud_browsers
    description: >-
      Registry package `mcp.linkedin/cloud_browsers`, served on MCP mount
      `linkedin.browsers`.
  - name: data_requests
    description: >-
      Registry package `mcp.linkedin/data_requests`, served on MCP mount
      `linkedin.data`.
  - name: linkedin_account_activity_log
    description: >-
      Registry package `mcp.linkedin/linkedin_account_activity_log`, served on
      MCP mount `linkedin.account-monitor`.
  - name: linkedin_account_block_log
    description: >-
      Registry package `mcp.linkedin/linkedin_account_block_log`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_account_quota_hits
    description: >-
      Registry package `mcp.linkedin/linkedin_account_quota_hits`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_account_smart_limits
    description: >-
      Registry package `mcp.linkedin/linkedin_account_smart_limits`, served on
      MCP mount `linkedin.accounts`.
  - name: linkedin_account_snapshots
    description: >-
      Registry package `mcp.linkedin/linkedin_account_snapshots`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_account_sync_runs
    description: >-
      Registry package `mcp.linkedin/linkedin_account_sync_runs`, served on MCP
      mount `linkedin.account-monitor`.
  - name: linkedin_accounts
    description: >-
      Registry package `mcp.linkedin/linkedin_accounts`, served on MCP mount
      `linkedin.accounts`.
  - name: linkedin_auto_scrape_results
    description: >-
      Registry package `mcp.linkedin/linkedin_auto_scrape_results`, served on
      MCP mount `linkedin.auto-scrapes`.
  - name: linkedin_auto_scrape_runs
    description: >-
      Registry package `mcp.linkedin/linkedin_auto_scrape_runs`, served on MCP
      mount `linkedin.auto-scrapes`.
  - name: linkedin_auto_scrapes
    description: >-
      Registry package `mcp.linkedin/linkedin_auto_scrapes`, served on MCP mount
      `linkedin.auto-scrapes`.
  - name: linkedin_benchmarks
    description: >-
      Registry package `mcp.linkedin/linkedin_benchmarks`, served on MCP mount
      `linkedin.account-monitor`.
  - name: linkedin_connection_invitations
    description: >-
      Registry package `mcp.linkedin/linkedin_connection_invitations`, served on
      MCP mount `linkedin.network`.
  - name: linkedin_connection_requests
    description: >-
      Registry package `mcp.linkedin/linkedin_connection_requests`, served on
      MCP mount `linkedin.network`.
  - name: linkedin_connections
    description: >-
      Registry package `mcp.linkedin/linkedin_connections`, served on MCP mount
      `linkedin.network`.
  - name: linkedin_conversations
    description: >-
      Registry package `mcp.linkedin/linkedin_conversations`, served on MCP
      mount `linkedin.messaging`.
  - name: linkedin_custom_requests
    description: >-
      Registry package `mcp.linkedin/linkedin_custom_requests`, served on MCP
      mount `linkedin.platform`.
  - name: linkedin_enrichment
    description: >-
      Registry package `mcp.linkedin/linkedin_enrichment`, served on MCP mount
      `linkedin.enrichment`.
  - name: linkedin_followers
    description: >-
      Registry package `mcp.linkedin/linkedin_followers`, served on MCP mount
      `linkedin.network`.
  - name: linkedin_messages
    description: >-
      Registry package `mcp.linkedin/linkedin_messages`, served on MCP mount
      `linkedin.messaging`.
  - name: linkedin_posting
    description: >-
      Registry package `mcp.linkedin/linkedin_posting`, served on MCP mount
      `linkedin.content`.
  - name: linkedin_scraping
    description: >-
      Registry package `mcp.linkedin/linkedin_scraping`, served on MCP mount
      `linkedin.scraping`.
paths:
  /api/linkedin-accounts/{sid}/set-smart-limits:
    post:
      tags:
        - linkedin_accounts
      summary: Set account smart limits
      description: >-
        Switch smart-limit governance on or off for the WHOLE account, every
        bucket at once (no per-bucket toggle). The switch remembers nothing: a
        real flip in EITHER direction first resets every limit row to the
        platform defaults (daily_limit = the bucket's platform max, delay /
        burst = the enum pair, target_limit = the platform default, hold
        cleared). ON: the warmup then sets every row's daily_limit /
        delay_in_seconds / batch_size (re-derived from the latest snapshot) and
        update_linkedin_account_smart_limit refuses those fields with 409
        smart_limits_governed; target_limit and learning_enabled stay yours. The
        seeded target_limit is a target the warmup climbs toward, never a limit
        somebody set. OFF: every cap runs exactly as typed and the account loses
        the warmup ban protection: say so first, read the rows' recommended_*
        before typing caps. Idempotent. SINGLE account: a fleet is a mass action
        with step linkedin-accounts.set-smart-limits (scope objects, args
        {enabled}), run BEFORE a limit-row run on the same senders.


        Contract:

        - MCP tool `set_linkedin_account_smart_limits`, registry package
        `mcp.linkedin/linkedin_accounts`, mount `linkedin.accounts`.

        - Operation `action`, response envelope `action`.

        - Flags: dangerous: the MCP layer gates it behind a preview/commit
        token, and the effect cannot be undone through this API; step eligible:
        gtm.service.orchestration can run this verb as a mass-action plan step,
        once per item.
      operationId: set_linkedin_account_smart_limits
      parameters:
        - name: sid
          in: path
          required: true
          description: LinkedIn account sid (ln_ac_…).
          schema:
            type: string
            minLength: 18
            maxLength: 18
            pattern: ^ln_ac_
            description: LinkedIn account sid (ln_ac_…).
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SetLinkedinAccountSmartLimitsRequest'
      responses:
        '200':
          description: '`action` success envelope.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SetLinkedinAccountSmartLimitsResponse'
        4XX:
          $ref: '#/components/responses/McpClientError'
        5XX:
          $ref: '#/components/responses/McpServerError'
components:
  schemas:
    SetLinkedinAccountSmartLimitsRequest:
      type: object
      description: Request body of `set_linkedin_account_smart_limits`.
      properties:
        enabled:
          type: boolean
          description: >-
            true = the warmup governs every bucket (protection on); false = the
            caps run as typed (protection off).
      required:
        - enabled
    SetLinkedinAccountSmartLimitsResponse:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - true
        operation:
          type: string
          enum:
            - action
        action:
          type: string
          description: kebab-case verb; matches the route segment.
        item:
          type: object
          nullable: true
          properties:
            sid:
              type: string
            team_sid:
              type: string
            antidetect_browser_sid:
              type: string
            status:
              type: string
              enum:
                - new
                - initial_syncing
                - active
                - sync_failed
                - shared_out
                - subscription_required
              description: >-
                Platform lifecycle (onboarding phases and hold states), NOT
                health and NOT login state: a sender signed out of LinkedIn
                still reads "active" here. Login state lives on the bound
                browser, request include antidetect_browser and read its status
                (login_issue means signed out).
            account_share_sid:
              type: string
              nullable: true
            share_role:
              type: string
              nullable: true
              enum:
                - owner
                - holder
                - giver
                - receiver
            ln_id:
              type: string
              nullable: true
            ln_member_id:
              type: string
              nullable: true
            sn_id:
              type: string
              nullable: true
            nickname:
              type: string
              nullable: true
            recruiter_seat_id:
              type: string
              nullable: true
              description: >-
                The account's own LinkedIn Recruiter seat number (the talent
                ts_seat), stamped by the premium check when the recruiter probe
                says yes and cleared when it says no. Every recruiter sync /
                thread read / reply dispatches with it; null with
                recruiter_status set means the seat is not stamped yet: run
                check_linkedin_account_premium_subscription with checks:
                ['recruiter'].
            recruiter_contract_id:
              type: string
              nullable: true
              description: >-
                The Recruiter contract (talent ts_contract number) the stamped
                seat belongs to, from the same seat read. A seat only means
                something inside its contract: hiring-project urns embed it, and
                a member on several contracts holds a different seat on each.
            recruiter_session_expires_at:
              type: string
              nullable: true
              description: >-
                When the Recruiter (enterprise) session of the bound browser
                profile runs out (ISO 8601): the expiry of LinkedIn's li_a
                cookie, read from the antidetect vendor's cookie store by the
                premium check (the clock, never the value). LinkedIn issues that
                session for 30 days when the seat holder enters the LinkedIn
                password on the Recruiter sign-in page. Past this clock the
                account's recruiter_status turns signed_out (the session sweep
                confirms it in the browser's cookie jar within 15 minutes) and
                every recruiter tool answers 409 recruiter_reauth_required,
                whose context.account_url is the account's page where the seat
                holder signs in again through the cloud browser. Null = no clock
                (not read, or the session cookie was not seen, which is not a
                verdict; recruiter_status is the verdict).
            full_name:
              type: string
              nullable: true
            avatar_url:
              type: string
              nullable: true
            label:
              type: string
              nullable: true
            has_premium:
              type: boolean
            has_sn:
              type: boolean
            recruiter_status:
              type: string
              nullable: true
              enum:
                - active
                - signed_out
              description: >-
                The account's LinkedIn Recruiter status. null = no Recruiter
                seat (the premium check's recruiter probe said no, or never
                ran). active = the seat's Recruiter (enterprise) session answers
                talent calls. signed_out = LinkedIn Recruiter asks the seat
                holder for the LinkedIn password again (about every 30 days):
                every recruiter tool answers 409 recruiter_reauth_required and
                the recruiter sync waits until the seat holder signs in through
                the cloud browser from the account's page (the 409's
                context.account_url); the status returns to active by itself
                once they have. Filter on it to find seats that need their
                holder.
            smart_limits_enabled:
              type: boolean
            inmail_credits:
              type: number
              nullable: true
              description: >-
                The Sales Navigator seat's InMail balance (the LSS_INMAIL
                grant), read only while the account holds a seat and cleared
                when the seat goes. Null = never read, the last read failed, or
                the seat was just lost; not zero.
            premium_inmail_credits:
              type: number
              nullable: true
              description: >-
                The Premium plan's own InMail balance (Premium Career /
                Business), read off LinkedIn's Premium page for a Premium
                account WITHOUT a Sales Navigator seat (a seat holder's
                linkedin.com InMail is the seat's grant above) and cleared when
                the plan goes. Null = never read or the last read could not be
                parsed; not zero.
            last_premium_check_at:
              type: string
              nullable: true
            last_connections_sync_at:
              type: string
              nullable: true
            last_conversations_sync_at:
              type: string
              nullable: true
            last_sales_navigator_conversations_sync_at:
              type: string
              nullable: true
            last_recruiter_conversations_sync_at:
              type: string
              nullable: true
            last_connection_requests_sync_at:
              type: string
              nullable: true
            last_connection_invitations_sync_at:
              type: string
              nullable: true
            last_followers_sync_at:
              type: string
              nullable: true
            last_snapshot_at:
              type: string
              nullable: true
            initial_sync_completed_at:
              type: string
              nullable: true
            initial_sync_held_at:
              type: string
              nullable: true
              description: >-
                When THIS onboarding first parked on a smart-limit budget (the
                daily self_account_sync allowance ran out before the initial set
                was done); null = never held. Kept after the latch, cleared by
                reset-sync.
            initial_sync_hold_reason:
              type: string
              nullable: true
              description: >-
                The run's park code at that moment: limit:daily_saturation,
                limit:held or limit:linkedin_quota_hit.
            last_heartbeat_at:
              type: string
              nullable: true
            sync_config:
              type: object
              nullable: true
              properties:
                entries:
                  type: object
                  properties:
                    connections:
                      type: object
                      properties:
                        interval_minutes:
                          type: number
                      required:
                        - interval_minutes
                    conversations:
                      type: object
                      properties:
                        interval_minutes:
                          type: number
                      required:
                        - interval_minutes
                    sales_navigator_conversations:
                      type: object
                      properties:
                        interval_minutes:
                          type: number
                      required:
                        - interval_minutes
                    recruiter_conversations:
                      type: object
                      properties:
                        interval_minutes:
                          type: number
                      required:
                        - interval_minutes
                    connection_requests:
                      type: object
                      properties:
                        interval_minutes:
                          type: number
                      required:
                        - interval_minutes
                    connection_invitations:
                      type: object
                      properties:
                        interval_minutes:
                          type: number
                      required:
                        - interval_minutes
                    premium_check:
                      type: object
                      properties:
                        interval_minutes:
                          type: number
                      required:
                        - interval_minutes
                    snapshot_check:
                      type: object
                      properties:
                        interval_minutes:
                          type: number
                      required:
                        - interval_minutes
                  description: Per-track sync-interval overrides, keyed by sync track.
                timezone:
                  type: string
                  description: IANA timezone the window is evaluated in.
                window:
                  type: array
                  items:
                    type: object
                    properties:
                      day_of_week:
                        type: integer
                        minimum: 1
                        maximum: 7
                      start_minute:
                        type: integer
                        minimum: 0
                        maximum: 1439
                      end_minute:
                        type: integer
                        minimum: 1
                        maximum: 1440
                    required:
                      - day_of_week
                      - start_minute
                      - end_minute
                  description: Weekly sync-activity window blocks; empty = always open.
            webhook_config:
              type: object
              nullable: true
              properties:
                connections:
                  type: object
                  properties:
                    enabled:
                      type: boolean
                    since:
                      type: string
                      nullable: true
                  required:
                    - enabled
                    - since
                connection_requests:
                  type: object
                  properties:
                    enabled:
                      type: boolean
                    since:
                      type: string
                      nullable: true
                  required:
                    - enabled
                    - since
                connection_invitations:
                  type: object
                  properties:
                    enabled:
                      type: boolean
                    since:
                      type: string
                      nullable: true
                  required:
                    - enabled
                    - since
                conversations:
                  type: object
                  properties:
                    enabled:
                      type: boolean
                    since:
                      type: string
                      nullable: true
                  required:
                    - enabled
                    - since
                sales_navigator_conversations:
                  type: object
                  properties:
                    enabled:
                      type: boolean
                    since:
                      type: string
                      nullable: true
                  required:
                    - enabled
                    - since
                recruiter_conversations:
                  type: object
                  properties:
                    enabled:
                      type: boolean
                    since:
                      type: string
                      nullable: true
                  required:
                    - enabled
                    - since
                messages:
                  type: object
                  properties:
                    enabled:
                      type: boolean
                    since:
                      type: string
                      nullable: true
                  required:
                    - enabled
                    - since
                followers:
                  type: object
                  properties:
                    enabled:
                      type: boolean
                    since:
                      type: string
                      nullable: true
                  required:
                    - enabled
                    - since
                snapshot:
                  type: object
                  properties:
                    enabled:
                      type: boolean
                    since:
                      type: string
                      nullable: true
                  required:
                    - enabled
                    - since
                strike_log:
                  type: object
                  properties:
                    enabled:
                      type: boolean
                    since:
                      type: string
                      nullable: true
                  required:
                    - enabled
                    - since
                limits:
                  type: object
                  properties:
                    enabled:
                      type: boolean
                    since:
                      type: string
                      nullable: true
                  required:
                    - enabled
                    - since
            created_by:
              type: object
              properties:
                actor_type:
                  type: string
                  enum:
                    - user
                    - support
                    - api_key
                    - system
                    - agent
                actor_sid:
                  type: string
                  nullable: true
                team_sid:
                  type: string
                permissions:
                  type: object
                  additionalProperties: {}
                request_sid:
                  type: string
                  nullable: true
                reason:
                  type: string
                  nullable: true
              required:
                - actor_type
                - actor_sid
                - team_sid
                - permissions
                - reason
            created_at:
              type: string
            updated_at:
              type: string
            deleted_at:
              type: string
              nullable: true
          required:
            - sid
            - team_sid
            - antidetect_browser_sid
            - status
            - account_share_sid
            - share_role
            - ln_id
            - ln_member_id
            - sn_id
            - nickname
            - recruiter_seat_id
            - recruiter_contract_id
            - recruiter_session_expires_at
            - full_name
            - avatar_url
            - label
            - has_premium
            - has_sn
            - recruiter_status
            - smart_limits_enabled
            - inmail_credits
            - premium_inmail_credits
            - last_premium_check_at
            - last_connections_sync_at
            - last_conversations_sync_at
            - last_sales_navigator_conversations_sync_at
            - last_recruiter_conversations_sync_at
            - last_connection_requests_sync_at
            - last_connection_invitations_sync_at
            - last_followers_sync_at
            - last_snapshot_at
            - initial_sync_completed_at
            - initial_sync_held_at
            - initial_sync_hold_reason
            - last_heartbeat_at
            - sync_config
            - webhook_config
            - created_by
            - created_at
            - updated_at
            - deleted_at
        result:
          type: object
          additionalProperties: {}
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            team_sid:
              type: string
              nullable: true
              description: >-
                The team this call ran in (the token team, or the team_sid
                override). Null when unauthenticated; absent from pre-2026-08-20
                backends.
            actor_type:
              type: string
              nullable: true
              description: >-
                user | agent | api_key | system. Null when unauthenticated;
                absent from pre-2026-08-20 backends.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
      required:
        - success
        - operation
        - action
        - item
        - result
        - meta
    McpError:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - false
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - validation_failed
                - nothing_to_update
                - not_found
                - relation_not_found
                - invalid_transition
                - limit_exceeded
                - payment_required
                - duplicate_rejected
                - conflict
                - delete_blocked
                - unauthorized
                - forbidden
                - rate_limited
                - internal_error
                - service_unavailable
                - not_implemented
            message:
              type: string
            recoverable:
              type: boolean
            suggestion:
              type: string
            field_errors:
              type: object
              additionalProperties:
                type: array
                items:
                  type: object
                  properties:
                    rule:
                      type: string
                    message:
                      type: string
                  required:
                    - rule
                    - message
            blockers:
              type: array
              items:
                type: object
                properties:
                  type:
                    type: string
                    description: >-
                      Machine-readable blocker type (active_flow, pending_tasks,
                      …).
                  severity:
                    type: string
                    enum:
                      - hard
                      - soft
                    description: >-
                      hard = external action required; soft = acknowledge is
                      enough.
                  description:
                    type: string
                  entity_sid:
                    type: string
                    nullable: true
                  count:
                    type: integer
                  resolution:
                    type: string
                    description: 'Hard: tool name to call. Soft: code for acknowledge[].'
                  resolution_hint:
                    type: string
                required:
                  - type
                  - severity
                  - description
                  - entity_sid
                  - resolution
                  - resolution_hint
            context:
              type: object
              additionalProperties: {}
          required:
            - code
            - message
            - recoverable
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            team_sid:
              type: string
              nullable: true
              description: >-
                The team this call ran in (the token team, or the team_sid
                override). Null when unauthenticated; absent from pre-2026-08-20
                backends.
            actor_type:
              type: string
              nullable: true
              description: >-
                user | agent | api_key | system. Null when unauthenticated;
                absent from pre-2026-08-20 backends.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
      required:
        - success
        - error
  responses:
    McpClientError:
      description: >-
        MCP error envelope. `error.code` is one of validation_failed,
        nothing_to_update, not_found, relation_not_found, invalid_transition,
        limit_exceeded, payment_required, duplicate_rejected, conflict,
        delete_blocked, unauthorized, forbidden, rate_limited, not_implemented.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
    McpServerError:
      description: >-
        MCP error envelope with `error.code` internal_error or
        service_unavailable.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
  securitySchemes:
    BearerJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Access token issued by gtm.service.id. Its `access_identity` claim
        carries `team_sid`, `actor_sid` and `actor_type`, and that team scope is
        authoritative.
    TeamSid:
      type: apiKey
      in: header
      name: Team-SID
      description: >-
        Team scope for tokens that do not carry one. Ignored when the token
        already names a team.

````