# PPWR Link — Integrator guide — choose your workflow

PPWR Link API connects packaging, documents and events with store, ERP or WMS workflows. An operation is an HTTP method and path, not a separate business module. Implement the areas your integration needs; the specialised PPWR registers are optional for other workflows. Documentation is public; organisation data requires a key.

PPWR Link organization API. Resource identifiers are UUIDs. Each key belongs to one organization; both token abilities and user permissions apply. Writes require Idempotency-Key unless stated otherwise. Send decimal masses as strings. Assessment status is not automatic certification of compliance.

## Before your first request
1. Create a separate integration key under Administration → Organizations → API keys. A key belongs to a user and one organisation. Token scope, organisation permission, active membership, verified email and any MFA/IP policy must all pass. An owner role does not bypass token scopes.
2. Send `GET /organizations` with `Authorization: Bearer <key>` and `Accept: application/json`. Use `data[0].id` as `organizationId`, not a company slug or numeric ID. API calls require no session, cookies or CSRF token.
3. Retrieve `/organizations/{organizationId}/dictionaries` for material, country and published rule codes. Consult each operation schema for its enums.
4. Use `Content-Type: application/json` for JSON. Uploads use `multipart/form-data` with the file in `file`; let the HTTP library generate the boundary. Set `X-Locale: pl|en` for messages.

## Formats and dependencies
- Detail reads return a plain object. Most lists return `data`, `links.next` and `requestId`. Follow `links.next` until null. BDO sources instead use `page`, `total` and `summary`; the organisation list is not paginated.
- IDs and resource references are public UUIDs. `catalogItemId` identifies packaging; `recordId` identifies the resource in the URL. `parentId` can be a report, not packaging. References must be accessible within the key’s organisation, except explicit passport sharing.
- Catalogue fields use camelCase (`massG`, `internalCode`, `stockUnit`); most other resources use snake_case. Follow the schema exactly. Document `version`, record `revision` and historical `data_version` are distinct values.
- Use decimal points. Masses typed as strings must be JSON strings. Packaging mass is grams per base unit. Base units: `piece`, `m`, `m2`, `kg`, `l`, `m3`. Retrieve item-specific conversions from `/inventory`. Do not use `pcs` instead of `piece`. Dimension units are included in field names (`length_mm`, `thickness_um`).
- Replace example UUIDs, revisions and hashes with actual API values. Synthetic references will not work. Event dates represent actual activity dates; check `before_or_equal:today` constraints.

## Writes, retries and statuses
- Supply `Idempotency-Key` where the operation lists it. Store a random 16–100 character key with the payload. After a timeout retry the same operation, payload and key. A different body with the same key returns 409. Replays represent the original response; use GET for current state.
- Catalogue PATCH uses `If-Match` from the latest GET ETag. Other operations use `revision`, `catalog_revision` or `market_revision`. Never increment revisions yourself. On conflict fetch current state and reconcile the change.
- 200: completed read/action; 201: record created; 202: queued work accepted. File uploads may return 201 before scanning completes. Document review and file processing have separate statuses.
- 401: invalid/missing key; 403: scope, role, IP or access policy; 404: missing or inaccessible resource; 409: revision/configuration/idempotency conflict; 422: field or business validation; 429: rate limit, honour `Retry-After`; 500: reconcile current state and retry with the same idempotency key. Errors contain `error.code`, `error.message`, `error.fields`, `error.requestId`. Keep `X-Request-ID` for support. General limit: 120 requests/minute per user; packing recommendations additionally 10/minute.

## Interface boundaries
Only listed methods are exposed; do not assume matching PUT/DELETE endpoints exist. User, role, key and webhook configuration management remains in the panel. OpenAPI `webhooks` describes outbound events, not webhook configuration endpoints. This API does not collect/refund deposits or automatically file annual BDO reports. An internal record/review is not an authority decision. Each area documents its own limitations.

## Receiving webhooks

An authorised user configures the HTTPS endpoint, events and signing secret under Administration → Integrations. Verify X-PPWR-Signature as t=TIMESTAMP,v1=HEX: HMAC-SHA256 over timestamp + dot + raw body, using the complete whsec_… secret without decoding. Compare in constant time and allow at most 300 seconds of clock skew. Durably deduplicate on body event id, validate schema_version and organization_id, and return 2xx only after enqueueing durably. Ordering is not guaranteed. Retries keep event id/body but use fresh signatures. Fetch changed resource state through the API; events do not carry complete document contents. See the contract’s Webhooks section for payload schema and event types.

Full field schemas, enums, conditional requirements and response formats: see the OpenAPI contract.

https://ppwrlink.pl/api/openapi.json?locale=en

Paths below are relative to /api/v1/organizations/{organizationId}, unless stated otherwise. Each Swagger operation lists its exact fields and permissions.

## Order packing and inventory

Catalogue + available stock → set configuration → reservation → consume or release. Alternatively consume a set without a reservation or submit explicit packing-consumptions lines. Choose one path per parcel.

1. `GET /catalog-items`
2. `GET /catalog-items/{catalogItemId}/inventory`
3. `GET /packaging-systems/{recordId}/configuration`
4. `POST /packaging-systems/{recordId}/reservations`
5. `POST /packing-reservations/{recordId}/consume`
6. `GET /packaging-systems/{systemId}/usages`

## Files, evidence and links

Upload → version processing state → document review → analysis/proposals → fact decision → evidence linkage. Documents, versions and facts have distinct IDs/statuses.

1. `POST /documents`
2. `GET /document-versions/{recordId}`
3. `POST /document-versions/{recordId}/decision`
4. `POST /document-versions/{recordId}/analyze`
5. `GET /evidence-proposals?item={catalogItemId}`
6. `POST /evidence-proposals/{proposalId}/decision`

## Imports and templates

Retrieve an available template → upload → wait for preview → inspect rows → apply → read status/errors. Upload alone does not commit changes.

1. `POST /imports`
2. `GET /imports/{recordId}`
3. `GET /imports/{importId}/rows`
4. `POST /imports/{recordId}/apply`
5. `GET /imports/{recordId}/result.csv`

## Passports and recipient access

Data/evidence → draft → publish → recipient grant. New versions need separate access. Subscriptions/updates belong to the key’s user; following is not data adoption.

1. `POST /passports`
2. `POST /passports/{recordId}/publish`
3. `POST /passports/{recordId}/shares`
4. `GET /sharing-grants`
5. `POST /sharing-grants/{recordId}/revoke`

## Reports, EPR, BDO and recycled content

Catalogue/assessment/flow exports are queued. EPR/waste: header → lines → review → export. BDO: sources → classification → snapshot → export. None automatically files a declaration with an authority.

1. `POST /reports`
2. `GET /reports/{recordId}`
3. `GET /reports/{recordId}/download`

## Factors and material carbon footprint

Read sources → prepare factors → select item/set and optional historical basis → calculate → read snapshot. Results do not automatically cover the entire life cycle.

1. `GET /carbon-factors/reference`
2. `POST /carbon-factors`
3. `POST /carbon-calculations`
4. `GET /carbon-calculations/{recordId}`

## Packaging catalogue and structure

Order: partners and optional folders/families → catalogue → components and markets. Data history later identifies operation inputs.

1. `GET /dictionaries`
2. `POST /parties`
3. `POST /catalog-items`
4. `POST /catalog-items/{catalogItemId}/components`
5. `PUT /catalog-items/{catalogItemId}/markets`
6. `GET /catalog-items/{catalogItemId}/data-versions`

## Physical movements and reporting flows

supply-events tracks events/balance; flows represents reporting data. A movement can already generate a flow: do not submit both for the same activity.

1. `POST /catalog-items/{catalogItemId}/supply-events`
2. `GET /catalog-items/{catalogItemId}/supply-summary`
3. `GET /catalog-items/{catalogItemId}/inventory`
4. `GET /flows`

## Supplier collaboration and gaps

Create request → inspect lines → send email → receive files → review responses. Suppliers use a public link; integrators use an organisation key.

1. `GET /issues`
2. `POST /supplier-requests`
3. `GET /supplier-requests/{requestId}/lines`
4. `POST /supplier-requests/{recordId}/send`
5. `POST /supplier-requests/{recordId}/lines/{lineId}/review`

## PPWR assessments and technical evidence

Establish packaging, market and role; prepare reviewed sources. Create registers relevant to the use case. Recording, review and rule results are separate stages. A dossier precedes its EU declaration.

1. `GET /catalog-items/{catalogItemId}/markets`
2. `POST /assessments`
3. `GET /assessments/{recordId}`
4. `POST /assessments/{recordId}/review`
5. `GET /catalog-items/{catalogItemId}/ppwr-summary`

## Reuse systems and returnable units

Circulation system → evidence/market confirmations → units → circulation events/review → aggregates and periodic targets. A circulation system is not a packing recipe.

1. `POST /ppwr/reuse-systems`
2. `POST /catalog-items/{catalogItemId}/ppwr/reuse-units`
3. `GET /ppwr/reuse-statistics`

## Deposits, hospitality and information

Specialised documentary registers. Deposit records describe packaging/membership without handling money; hospitality/end-user information records store assessments/evidence.

1. `POST /ppwr/deposit-schemes`
2. `GET /ppwr/deposit-schemes/{recordId}`
3. `POST /ppwr/deposit-schemes/{recordId}/review`

## Cases, submissions and audit

Register request/case → add responses/events and delivery evidence → review where exposed. External submissions document actions performed outside the application.

1. `POST /ppwr/authority-requests`
2. `GET /ppwr/authority-requests/{recordId}`
3. `GET /audit-log`

## Dossier and EU declaration

A dossier organises packaging technical evidence. A reviewed dossier can support an EU declaration; PDF generation is separate. EU declarations linked to the item’s dossier, contents, signatory and evidence. Creating a record does not sign for the manufacturer.

1. `POST /catalog-items/{catalogItemId}/ppwr/conformity-dossiers`
2. `POST /catalog-items/{catalogItemId}/ppwr/conformity-dossiers/{recordId}/review`
3. `POST /catalog-items/{catalogItemId}/ppwr/eu-declarations`
4. `POST /catalog-items/{catalogItemId}/ppwr/eu-declarations/{recordId}/review`
5. `POST /catalog-items/{catalogItemId}/generated-documents`

## Annual EPR report

Annual EPR reports with lines and review. Export uses the recorded result; it does not file into a national portal.

1. `POST /ppwr/epr-reports`
2. `POST /ppwr/epr-reports/{parentId}/lines`
3. `GET /ppwr/epr-reports/{parentId}/lines`
4. `POST /ppwr/epr-reports/{recordId}/review`
5. `GET /ppwr/epr-reports/{recordId}/export`

## BDO source data and export

BDO packaging report preparation: sources, classification, snapshot and export. Does not automatically file the annual BDO report or pay fees.

1. `GET /bdo-reports/sources?year=2025`
2. `POST /bdo-reports/classifications`
3. `POST /bdo-reports`
4. `GET /bdo-reports/{recordId}`
5. `GET /bdo-reports/{recordId}/download?format=xlsx`

## All operation descriptions

### Start and dictionaries

Retrieve the key’s organisation, then dictionaries. Persist public UUIDs/codes; names are for display.

#### GET /organizations

Organization ID for API requests

An organisation is an access boundary. A key exposes only its assigned organisation; this resource does not create organisations or memberships.

Start here: retain data[0].id as organizationId. Requires a valid permitted key, without an additional module scope.

#### GET /organizations/{organizationId}/dictionaries

Dictionaries

Countries, materials, packaging categories/formats, economic roles, document types and published rule sets. Send codes rather than translated labels.

Fetch before building forms or mapping source data. rule_sets contains published rules only; absence does not mean a passing assessment.

Token ability: catalog:read. Organization permission: catalog.view.

### Packaging catalogue and structure

Order: partners and optional folders/families → catalogue → components and markets. Data history later identifies operation inputs.

#### GET /organizations/{organizationId}/catalog-items

Catalog — List

A record for one packaging/material type, such as a box, tape or film. Not a store product or individual shipment. Components, documents, markets and movements are separate resources.

List records accessible to the key’s organisation.

Token ability: catalog:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items

Catalog — Create

A record for one packaging/material type, such as a box, tape or film. Not a store product or individual shipment. Components, documents, markets and movements are separate resources.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

Token ability: catalog:write. Organization permission: catalog.create.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "internalCode": "BOX-001",
    "name": "Shipping box",
    "sourcingType": "purchased",
    "massG": "240",
    "mainMaterialCode": "corrugated_cardboard",
    "stockUnit": "piece",
    "stockTracked": true,
    "foodContactStatus": "no",
    "reuseType": "single_use"
}
```

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}

Catalog — Show

A record for one packaging/material type, such as a box, tape or film. Not a store product or individual shipment. Components, documents, markets and movements are separate resources.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: catalog:read. Organization permission: catalog.view.

#### PATCH /organizations/{organizationId}/catalog-items/{catalogItemId}

Catalog — Update

A record for one packaging/material type, such as a box, tape or film. Not a store product or individual shipment. Components, documents, markets and movements are separate resources.

Update this record with its required revision check. Consult the schema: PUT does not imply omitted fields are deleted.

Token ability: catalog:write. Organization permission: catalog.update.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "name": "Shipping box 300 × 200 × 150 mm"
}
```

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/archive

Catalog — Archive

A record for one packaging/material type, such as a box, tape or film. Not a store product or individual shipment. Components, documents, markets and movements are separate resources.

Archive the record while retaining history. Do not select archived resources for new work.

Token ability: catalog:write. Organization permission: catalog.archive.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/components

Components — List

Components belong to one packaging item and carry material/specification data. They are not shipping recipe lines. Adding a component changes the catalogue revision and assessment freshness.

List records accessible to the key’s organisation.

Token ability: catalog:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/components

Components — Create

Components belong to one packaging item and carry material/specification data. They are not shipping recipe lines. Adding a component changes the catalogue revision and assessment freshness.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

Token ability: catalog:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/components/{recordId}

Components — Show

Components belong to one packaging item and carry material/specification data. They are not shipping recipe lines. Adding a component changes the catalogue revision and assessment freshness.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: catalog:read. Organization permission: catalog.view.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/data-versions

Packaging data history — List

Immutable historical packaging basis: revision, specifications, components and hash. The public projection excludes private documents and facts. data_version is not a current revision number.

List records accessible to the key’s organisation.

Token ability: catalog:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/data-versions/{recordId}

Packaging data history — Show

Immutable historical packaging basis: revision, specifications, components and hash. The public projection excludes private documents and facts. data_version is not a current revision number.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: catalog:read. Organization permission: catalog.view.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/markets

Markets — List

Market scenarios record destination, origin, economic role and date. Lists show active scenarios. Adding a market does not create stock receipts or issues.

List records accessible to the key’s organisation.

Token ability: catalog:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### PUT /organizations/{organizationId}/catalog-items/{catalogItemId}/markets

Markets — Update

Market scenarios record destination, origin, economic role and date. Lists show active scenarios. Adding a market does not create stock receipts or issues.

Send the complete desired markets list: omitted countries lose their active scenarios; an empty list removes all. Use the item revision as market_revision; market_details maps country codes to roles/dates.

Token ability: catalog:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "market_revision": 1,
    "markets": [
        "PL"
    ],
    "market_details": {
        "PL": {
            "origin_country": "PL",
            "economic_role": "filler_packer",
            "assessment_date": "2026-09-29"
        }
    }
}
```

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/markets/{recordId}

Markets — Show

Market scenarios record destination, origin, economic role and date. Lists show active scenarios. Adding a market does not create stock receipts or issues.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: catalog:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/restore

Catalog — Restore

A record for one packaging/material type, such as a box, tape or film. Not a store product or individual shipment. Components, documents, markets and movements are separate resources.

Restore an archived record for current use. Obtain the required revision from the latest read.

Token ability: catalog:write. Organization permission: catalog.archive.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/families

Families — List

A family groups packaging under shared manufacturer identity/documentation. It is neither a folder nor a packing recipe.

List records accessible to the key’s organisation.

Token ability: catalog:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/families

Families — Create

A family groups packaging under shared manufacturer identity/documentation. It is neither a folder nor a packing recipe.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

Token ability: catalog:write. Organization permission: catalog.create.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/families/{recordId}

Families — Show

A family groups packaging under shared manufacturer identity/documentation. It is neither a folder nor a packing recipe.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: catalog:read. Organization permission: catalog.view.

#### PUT /organizations/{organizationId}/families/{recordId}

Families — Update

A family groups packaging under shared manufacturer identity/documentation. It is neither a folder nor a packing recipe.

Update this record with its required revision check. Consult the schema: PUT does not imply omitted fields are deleted.

Token ability: catalog:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/folders

Folders — List

An organisation’s custom folder tree organises its catalogue. A folder is not a PPWR category; parent references another folder, and catalogue writes assign items to folders.

List records accessible to the key’s organisation.

Token ability: catalog:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/folders

Folders — Create

An organisation’s custom folder tree organises its catalogue. A folder is not a PPWR category; parent references another folder, and catalogue writes assign items to folders.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

Token ability: catalog:write. Organization permission: catalog.create.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "name": "E-commerce"
}
```

#### GET /organizations/{organizationId}/folders/{recordId}

Folders — Show

An organisation’s custom folder tree organises its catalogue. A folder is not a PPWR category; parent references another folder, and catalogue writes assign items to folders.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: catalog:read. Organization permission: catalog.view.

#### PUT /organizations/{organizationId}/folders/{recordId}

Folders — Update

An organisation’s custom folder tree organises its catalogue. A folder is not a PPWR category; parent references another folder, and catalogue writes assign items to folders.

Update this record with its required revision check. Consult the schema: PUT does not imply omitted fields are deleted.

Token ability: catalog:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### DELETE /organizations/{organizationId}/folders/{recordId}

Folders — Delete

An organisation’s custom folder tree organises its catalogue. A folder is not a PPWR category; parent references another folder, and catalogue writes assign items to folders.

Delete an empty folder using its current revision. A folder with items or subfolders returns 422; move its contents first. Packaging is not deleted.

Token ability: catalog:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/parties

Parties — List

Partners act as suppliers, manufacturers or customers. Their UUID can be linked to packaging. The public API exposes list, detail and creation using schema fields, not the panel’s full address/contact editing or tax-ID lookup.

List records accessible to the key’s organisation.

Token ability: catalog:read. Organization permission: suppliers.manage.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/parties

Parties — Create

Partners act as suppliers, manufacturers or customers. Their UUID can be linked to packaging. The public API exposes list, detail and creation using schema fields, not the panel’s full address/contact editing or tax-ID lookup.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

Token ability: catalog:write. Organization permission: suppliers.manage.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/parties/{recordId}

Parties — Show

Partners act as suppliers, manufacturers or customers. Their UUID can be linked to packaging. The public API exposes list, detail and creation using schema fields, not the panel’s full address/contact editing or tax-ID lookup.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: catalog:read. Organization permission: suppliers.manage.

### Order packing and inventory

Catalogue + available stock → set configuration → reservation → consume or release. Alternatively consume a set without a reservation or submit explicit packing-consumptions lines. Choose one path per parcel.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/inventory

Stock balance

Stock and unit conversions for one item. Distinguish physical, reserved and available quantities; stock_tracked=false does not prove warehouse availability.

Read stock and units before quantity conversion. Select data_version when multiple historical bases exist; the server does not assume FIFO.

Token ability: flows:read. Organization permission: catalog.view.

#### GET /organizations/{organizationId}/packaging-systems

Packing sets — List

A packaging set is a recipe, such as box + tape + filler. It is not a deposit scheme or reuse system. Use archived to filter archived recipes.

List records accessible to the key’s organisation.

Token ability: catalog:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/packaging-systems

Packing sets — Create

A packaging set holds a parcel recipe. Configuration calculates quantities, mass and availability; only consumption or reservation consumption records material use.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

Token ability: catalog:write. Organization permission: catalog.create.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/packaging-systems/{recordId}

Packing sets — Show

A packaging set is a recipe, such as box + tape + filler. It is not a deposit scheme or reuse system. Use archived to filter archived recipes.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: catalog:read. Organization permission: catalog.view.

#### PUT /organizations/{organizationId}/packaging-systems/{recordId}

Packing sets — Update

A packaging set holds a parcel recipe. Configuration calculates quantities, mass and availability; only consumption or reservation consumption records material use.

Update this record with its required revision check. Consult the schema: PUT does not imply omitted fields are deleted.

Token ability: catalog:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### POST /organizations/{organizationId}/packaging-systems/{recordId}/archive

Packing sets — Archive

A packaging set holds a parcel recipe. Configuration calculates quantities, mass and availability; only consumption or reservation consumption records material use.

Archive the record while retaining history. Do not select archived resources for new work.

Token ability: catalog:write. Organization permission: catalog.archive.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/packaging-systems/{recordId}/configuration

Packing sets — Packing configuration

A packaging set holds a parcel recipe. Configuration calculates quantities, mass and availability; only consumption or reservation consumption records material use.

Read composition, configuration_hash and revision before reserving/consuming. ready describes configuration completeness, not guaranteed stock; inspect available_sets and all_stock_tracked.

Token ability: catalog:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/packaging-systems/{recordId}/consumptions

Packing sets — Record set consumption

A packaging set holds a parcel recipe. Configuration calculates quantities, mass and availability; only consumption or reservation consumption records material use.

Record actual recipe usage for order_reference using configuration revision/hash and sets_count. All ingredients are consumed atomically; do not also send packing-consumptions for the same parcel.

Token ability: flows:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "revision": 1,
    "configuration_hash": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
    "sets_count": 1,
    "order_reference": "STORE-1/ORDER-100/PARCEL-1",
    "event_on": "2026-09-29",
    "country": "PL"
}
```

#### POST /organizations/{organizationId}/packaging-systems/{recordId}/items

Packing sets — Item

A packaging set holds a parcel recipe. Configuration calculates quantities, mass and availability; only consumption or reservation consumption records material use.

Add a recipe line; supplying line updates an existing line. revision refers to the set. Refetch configuration/hash after writing.

Token ability: catalog:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### DELETE /organizations/{organizationId}/packaging-systems/{recordId}/items/{lineId}

Packing sets — Remove component

A packaging set holds a parcel recipe. Configuration calculates quantities, mass and availability; only consumption or reservation consumption records material use.

Remove a set line with its revision check. Returns the set id and new revision. Consumption history remains.

Token ability: catalog:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### POST /organizations/{organizationId}/packaging-systems/{recordId}/reservations

Order reservations — Create

A set reservation holds available materials without recording consumption. States include held, released and consumed; expiry is also determined by expires_at before stored status changes.

Reserve a set for 1–168 hours. All ingredients require tracked stock, current configuration and availability. Keep the reservation UUID for release or consume.

Token ability: flows:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "revision": 1,
    "configuration_hash": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
    "sets_count": 1,
    "order_reference": "STORE-1/ORDER-100/PARCEL-1",
    "country": "PL",
    "expires_in_hours": 24
}
```

#### POST /organizations/{organizationId}/packaging-systems/{recordId}/restore

Packing sets — Restore

A packaging set holds a parcel recipe. Configuration calculates quantities, mass and availability; only consumption or reservation consumption records material use.

Restore an archived record for current use. Obtain the required revision from the latest read.

Token ability: catalog:write. Organization permission: catalog.archive.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/packaging-systems/{systemId}/items

Packing set ingredients — List

Recipe lines: packaging item, quantity, unit, role and outer-packaging flag. item is a catalogue UUID; line is a recipe-line UUID.

List records accessible to the key’s organisation.

Token ability: catalog:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### GET /organizations/{organizationId}/packaging-systems/{systemId}/usages

Set usage — List

Set consumption history contains the frozen recipe and usage events. Do not rebuild historical usage from today’s recipe.

List records accessible to the key’s organisation.

Token ability: flows:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/packing-consumptions

Order packing consumption — Create

One-off packing with explicit material lines rather than a saved recipe. Each line references a packaging item and revision; the write is atomic.

Record usage lines for a unique order/parcel reference. Each item appears once. Tracked items require availability; failure does not partially consume lines.

Token ability: flows:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "order_reference": "STORE-1/ORDER-100/PARCEL-1",
    "event_on": "2026-09-29",
    "country": "PL",
    "lines": [
        {
            "item": "11111111-1111-4111-8111-111111111111",
            "revision": 1,
            "quantity": 1,
            "unit": "piece",
            "reusable": false
        }
    ]
}
```

#### POST /organizations/{organizationId}/packing-recommendations

Packing recommendations — Recommend packaging

Packing recommendations calculate candidates from product dimensions and configured packaging. Results can include exclusions or missing data; they neither reserve stock nor record consumption.

Calculate candidates without writing or Idempotency-Key. Check exclusion reasons, dimensions and quantities; a selected candidate needs separate reservation/consumption. Maximum 100 product units; 10 requests/minute.

Token ability: flows:read. Organization permission: catalog.view.

#### GET /organizations/{organizationId}/packing-reservations

Order reservations — List

A set reservation holds available materials without recording consumption. States include held, released and consumed; expiry is also determined by expires_at before stored status changes.

List records accessible to the key’s organisation.

Token ability: flows:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### GET /organizations/{organizationId}/packing-reservations/{recordId}

Order reservations — Show

A set reservation holds available materials without recording consumption. States include held, released and consumed; expiry is also determined by expires_at before stored status changes.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: flows:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/packing-reservations/{recordId}/consume

Order reservations — Record set consumption

A set reservation holds available materials without recording consumption. States include held, released and consumed; expiry is also determined by expires_at before stored status changes.

Consume a live reservation as actual packing. Returns a set-usage record, not the reservation. Order, country and composition come from the reservation. Expired reservations cannot be consumed.

Token ability: flows:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "revision": 1,
    "event_on": "2026-09-29"
}
```

#### POST /organizations/{organizationId}/packing-reservations/{recordId}/release

Order reservations — Release reservation

A set reservation holds available materials without recording consumption. States include held, released and consumed; expiry is also determined by expires_at before stored status changes.

Release a live reservation using its revision. Restores availability without reporting consumption; does not undo a consumed reservation.

Token ability: flows:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "revision": 1
}
```

### Physical movements and reporting flows

supply-events tracks events/balance; flows represents reporting data. A movement can already generate a flow: do not submit both for the same activity.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/supply-events

Supply events — List

Physical receipts, production, issues, usage, opening balances and adjustments. Stores quantity, unit, counterparty, date and historical basis. Use for stock and traceability.

List records accessible to the key’s organisation.

Token ability: flows:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/supply-events

Supply events — Create

Physical receipts, production, issues, usage, opening balances and adjustments. Stores quantity, unit, counterparty, date and historical basis. Use for stock and traceability.

Select direction. received/supplied need counterparty details; used needs usage_channel and ecommerce also transaction_reference. Send quantity+unit or quantity_units, never both. Adjustments require note. data_version identifies the historical stock basis.

Token ability: flows:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "catalog_revision": 1,
    "direction": "received",
    "quantity": 100,
    "unit": "piece",
    "counterparty_name": "Example supplier",
    "counterparty_country": "PL",
    "counterparty_address": "Example street 1, 00-001 Warsaw",
    "event_on": "2026-09-29",
    "reusable_at_event": "no"
}
```

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/supply-events/{recordId}

Supply events — Show

Physical receipts, production, issues, usage, opening balances and adjustments. Stores quantity, unit, counterparty, date and historical basis. Use for stock and traceability.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: flows:read. Organization permission: catalog.view.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/supply-summary

Supply summary

An item’s event balance, including availability and historical bases. Derived from movements, not an independent stock-write endpoint.

Read the balance before an issue and after writing it. Do not treat a cached balance as immutable stock.

Token ability: flows:read. Organization permission: catalog.view.

#### GET /organizations/{organizationId}/flows

Flows — List

Reporting flows (placed/used) contain quantities and mass. A direct /flows write does not update physical stock. Do not duplicate flows already generated by consumption events.

List records accessible to the key’s organisation.

Token ability: flows:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/flows

Flows — Create

Reporting flows (placed/used) contain quantities and mass. A direct /flows write does not update physical stock. Do not duplicate flows already generated by consumption events.

Create a standalone placed/used reporting flow. Supply mass_g explicitly as this flow’s mass. Does not create a supply-event or decrement stock.

Token ability: flows:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/flows/{recordId}

Flows — Show

Reporting flows (placed/used) contain quantities and mass. A direct /flows write does not update physical stock. Do not duplicate flows already generated by consumption events.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: flows:read. Organization permission: reports.view.

### Files, evidence and links

Upload → version processing state → document review → analysis/proposals → fact decision → evidence linkage. Documents, versions and facts have distinct IDs/statuses.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/generated-documents

Documents — Generate

A document contains metadata linked to packaging; files and review belong to specific versions. Upload, scanning, AI analysis and data acceptance are separate steps.

Generate a supported document kind from the item/catalog_revision. Prerequisites depend on kind; a declaration draft does not become signed through PDF export.

Token ability: documents:upload. Organization permission: documents.upload.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/traceability

Traceability

Identity/document links connect packaging, supplier/manufacturer codes, family and evidence. They do not represent physical transport or stock movements.

Read documentary links valid today. Use supply-events for physical receipts/issues.

Token ability: documents:read. Organization permission: documents.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/traceability

Traceability — Link

Identity/document links connect packaging, supplier/manufacturer codes, family and evidence. They do not represent physical transport or stock movements.

Link an approved document version to packaging with link_type. version is the file-version UUID; revision is the packaging revision.

Token ability: evidence:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/document-versions/{recordId}

Document versions — Show

A document version identifies a file with processing_status, review_status, dates and revision. Approval does not bypass safe file processing.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: documents:read. Organization permission: documents.view.

#### POST /organizations/{organizationId}/document-versions/{recordId}/analyze

Documents — Analyze

A document contains metadata linked to packaging; files and review belong to specific versions. Upload, scanning, AI analysis and data acceptance are separate steps.

Queue analysis of an eligible document version. 200 acknowledges the action, not completed AI work. Read version state and evidence-proposals; proposals require human review.

Token ability: evidence:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### POST /organizations/{organizationId}/document-versions/{recordId}/decision

Documents — Decision

A document contains metadata linked to packaging; files and review belong to specific versions. Upload, scanning, AI analysis and data acceptance are separate steps.

Approve, reject or revoke a version using its revision and reason. Besides documents.view, approved/rejected require documents.approve; revoked requires documents.revoke. Processing must be review_required; approval/rejection applies to unreviewed/in_review, revocation to approved. Under dual_control, approving your own upload requires an owner/admin role; other users need another reviewer. A generated declaration draft cannot be approved as a signed document.

Token ability: documents:review. Organization permission: documents.view.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/document-versions/{recordId}/download

Documents — Download

A document contains metadata linked to packaging; files and review belong to specific versions. Upload, scanning, AI analysis and data acceptance are separate steps.

Download a binary file, not JSON. Errors still return JSON; check HTTP status and Content-Type before saving the response.

Token ability: documents:read. Organization permission: documents.view.

#### POST /organizations/{organizationId}/document-versions/{recordId}/evidence-proposals

Documents — Propose

A document contains metadata linked to packaging; files and review belong to specific versions. Upload, scanning, AI analysis and data acceptance are separate steps.

Propose a value with document location/quotation. The document must link to packaging. Accept it using the separate evidence decision endpoint. source_page must exist in the version’s extracted text and source_text must be an exact quotation. MASS_G uses g; WIDTH_MM/LENGTH_MM/HEIGHT_MM use mm. DfR needs %, exact, a method and a cited result; chemical measurements additionally need a lab report and component UUID. Missing page text is entered in the panel; this API exposes no page transcription endpoint.

Token ability: evidence:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### POST /organizations/{organizationId}/documents

Documents — Upload

A document contains metadata linked to packaging; files and review belong to specific versions. Upload, scanning, AI analysis and data acceptance are separate steps.

Upload a file and metadata. Returns a document version: its id is used for download/analysis/decision, while document identifies the document record. Processing runs in a queue; wait for its status.

Token ability: documents:upload. Organization permission: documents.upload.

Send an actual file using multipart/form-data, not a local path or base64 JSON value. Read the resource UUID and processing status from the response/resource.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/documents

Documents — List

A document contains metadata linked to packaging; files and review belong to specific versions. Upload, scanning, AI analysis and data acceptance are separate steps.

List records accessible to the key’s organisation.

Token ability: documents:read. Organization permission: documents.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### GET /organizations/{organizationId}/documents/{documentId}/versions

Document versions — List

A document version identifies a file with processing_status, review_status, dates and revision. Approval does not bypass safe file processing.

List records accessible to the key’s organisation.

Token ability: documents:read. Organization permission: documents.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### GET /organizations/{organizationId}/documents/{recordId}

Documents — Show

A document contains metadata linked to packaging; files and review belong to specific versions. Upload, scanning, AI analysis and data acceptance are separate steps.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: documents:read. Organization permission: documents.view.

#### POST /organizations/{organizationId}/documents/{recordId}/versions

Documents — Version

A document contains metadata linked to packaging; files and review belong to specific versions. Upload, scanning, AI analysis and data acceptance are separate steps.

Add a file version to the document identified by recordId. Creates separate processing/review state without overwriting history.

Token ability: documents:upload. Organization permission: documents.upload.

Send an actual file using multipart/form-data, not a local path or base64 JSON value. Read the resource UUID and processing status from the response/resource.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/evidence-proposals

Evidence proposals — List

Proposed facts extracted from documents carry sources, values and status. Document sensitivity can restrict visibility. A proposal is not yet approved evidence.

List records accessible to the key’s organisation.

Token ability: evidence:review. Organization permission: evidence.review.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/evidence-proposals/{proposalId}/decision

Evidence — Decision

A fact decision is separate from whole-file approval. Accept a value, accept a correction or reject it with a reason.

Use accepted, acceptedModified or rejected; acceptedModified requires acceptedValue. Supply proposal revision and note. No Idempotency-Key; after a timeout read the proposal before deciding again.

Token ability: evidence:review. Organization permission: evidence.review.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "decision": "accepted",
    "revision": 1,
    "note": "Checked against the cited document page."
}
```

#### GET /organizations/{organizationId}/evidence-proposals/{recordId}

Evidence proposals — Show

Proposed facts extracted from documents carry sources, values and status. Document sensitivity can restrict visibility. A proposal is not yet approved evidence.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: evidence:review. Organization permission: evidence.review.

### Supplier collaboration and gaps

Create request → inspect lines → send email → receive files → review responses. Suppliers use a public link; integrators use an organisation key.

#### GET /organizations/{organizationId}/issues

Issues — List

Gaps and tasks detected for the organisation. The API exposes list/detail reads, not analogous POST/PATCH creation or completion methods.

List records accessible to the key’s organisation.

Token ability: supplier-requests:read. Organization permission: issues.manage.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### GET /organizations/{organizationId}/issues/{recordId}

Issues — Show

Gaps and tasks detected for the organisation. The API exposes list/detail reads, not analogous POST/PATCH creation or completion methods.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: supplier-requests:read. Organization permission: issues.manage.

#### GET /organizations/{organizationId}/supplier-requests

Supplier requests — List

A supplier request collects documents for selected lines. Creating a request does not send mail; a separate action sends it. Suppliers can respond through a public link without an account.

List records accessible to the key’s organisation.

Token ability: supplier-requests:read. Organization permission: supplier_requests.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/supplier-requests

Supplier requests — Create

A supplier request collects documents for selected lines. Creating a request does not send mail; a separate action sends it. Suppliers can respond through a public link without an account.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

Token ability: supplier-requests:write. Organization permission: supplier_requests.create.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/supplier-requests/{recordId}

Supplier requests — Show

A supplier request collects documents for selected lines. Creating a request does not send mail; a separate action sends it. Suppliers can respond through a public link without an account.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: supplier-requests:read. Organization permission: supplier_requests.view.

#### POST /organizations/{organizationId}/supplier-requests/{recordId}/cancel

Supplier requests — Cancel

A supplier request collects documents for selected lines. Creating a request does not send mail; a separate action sends it. Suppliers can respond through a public link without an account.

Cancel the request using its current revision. Does not delete submitted files or response history.

Token ability: supplier-requests:write. Organization permission: supplier_requests.send.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### POST /organizations/{organizationId}/supplier-requests/{recordId}/lines/{lineId}/review

Supplier requests — Review line

A supplier request collects documents for selected lines. Creating a request does not send mail; a separate action sends it. Suppliers can respond through a public link without an account.

Review lineId within this request. revision refers to the request; a line decision is separate from document-version review. accepted requires approved documents and accepted evidence linked to the item; uploading a file alone is insufficient.

Token ability: supplier-requests:write. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### POST /organizations/{organizationId}/supplier-requests/{recordId}/send

Supplier requests — Send

A supplier request collects documents for selected lines. Creating a request does not send mail; a separate action sends it. Suppliers can respond through a public link without an account.

Send a request email to the supplied address using the request revision. This contacts an external recipient; verify content/address and reuse the idempotency key on retries.

Token ability: supplier-requests:write. Organization permission: supplier_requests.send.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/supplier-requests/{requestId}/lines

Request lines — List

Lines describe missing documents for packaging. Responses and decisions belong to the request identified by requestId.

List records accessible to the key’s organisation.

Token ability: supplier-requests:read. Organization permission: supplier_requests.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

### Imports and templates

Retrieve an available template → upload → wait for preview → inspect rows → apply → read status/errors. Upload alone does not commit changes.

#### GET /organizations/{organizationId}/import-templates/codes.csv

Code mapping worksheet — Download

CSV template for packaging/supplier/manufacturer code mappings. populated=1 includes current data; submit the result as a code_mappings import.

Download a binary file, not JSON. Errors still return JSON; check HTTP status and Content-Type before saving the response.

Token ability: imports:run. Organization permission: imports.run.

#### GET /organizations/{organizationId}/import-templates/documents.csv

Document metadata worksheet — Download

CSV template for existing document metadata. populated=1 includes organisation data. It does not upload PDFs.

Download a binary file, not JSON. Errors still return JSON; check HTTP status and Content-Type before saving the response.

Token ability: imports:run. Organization permission: imports.run.

#### GET /organizations/{organizationId}/imports

Imports — List

Imports are jobs with a preview stage before applying changes. Types: catalog, partners, document_metadata, code_mappings. Document metadata import does not upload document files.

List records accessible to the key’s organisation.

Token ability: imports:run. Organization permission: imports.run.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/imports

Imports — Create

Imports are jobs with a preview stage before applying changes. Types: catalog, partners, document_metadata, code_mappings. Document metadata import does not upload document files.

Upload CSV/XLSX with type and optional column mapping. 202 returns an import id; wait for a ready preview, inspect rows, then call apply.

Token ability: imports:run. Organization permission: imports.run.

Send an actual file using multipart/form-data, not a local path or base64 JSON value. Read the resource UUID and processing status from the response/resource.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

202 confirms queued work. Poll the resource by its returned `id` until processing finishes; `queued` does not mean a file is ready.

#### GET /organizations/{organizationId}/imports/{importId}/rows

Import rows — List

Import rows expose input, validation and planned/applied changes. Read them after preview processing and inspect errors before apply.

List records accessible to the key’s organisation.

Token ability: imports:run. Organization permission: imports.run.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### GET /organizations/{organizationId}/imports/{recordId}

Imports — Show

Imports are jobs with a preview stage before applying changes. Types: catalog, partners, document_metadata, code_mappings. Document metadata import does not upload document files.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: imports:run. Organization permission: imports.run.

#### POST /organizations/{organizationId}/imports/{recordId}/apply

Imports — Apply

Imports are jobs with a preview stage before applying changes. Types: catalog, partners, document_metadata, code_mappings. Document metadata import does not upload document files.

Queue application of a prepared import. Check row results and completed/completed_with_errors status; a retry is not an unconditional overwrite.

Token ability: imports:run. Organization permission: imports.run.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

202 confirms queued work. Poll the resource by its returned `id` until processing finishes; `queued` does not mean a file is ready.

#### GET /organizations/{organizationId}/imports/{recordId}/result.csv

Imports — Download

Imports are jobs with a preview stage before applying changes. Types: catalog, partners, document_metadata, code_mappings. Document metadata import does not upload document files.

Download a binary file, not JSON. Errors still return JSON; check HTTP status and Content-Type before saving the response.

Token ability: imports:run. Organization permission: imports.run.

### PPWR assessments and technical evidence

Establish packaging, market and role; prepare reviewed sources. Create registers relevant to the use case. Recording, review and rule results are separate stages. A dossier precedes its EU declaration.

#### GET /organizations/{organizationId}/assessments

Assessments — List

An assessment combines packaging, market scenario, date and rule set. It differs from a specialised PPWR technical record. Review status and result freshness are separate.

List records accessible to the key’s organisation.

Token ability: assessments:read. Organization permission: assessments.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/assessments

Assessments — Create

An assessment combines packaging, market scenario, date and rule set. It differs from a specialised PPWR technical record. Review status and result freshness are separate.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

Token ability: assessments:run. Organization permission: assessments.run.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/assessments/{recordId}

Assessments — Show

An assessment combines packaging, market scenario, date and rule set. It differs from a specialised PPWR technical record. Review status and result freshness are separate.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: assessments:read. Organization permission: assessments.view.

#### POST /organizations/{organizationId}/assessments/{recordId}/review

Assessments — Review

An assessment combines packaging, market scenario, date and rule set. It differs from a specialised PPWR technical record. Review status and result freshness are separate.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

Token ability: assessments:review. Organization permission: assessments.publish.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr-summary

PPWR summary

Current packaging technical summary for a specified date, with screening and recyclability. Does not create/publish assessments; accounts for methodology and source availability.

date selects the summary date, defaulting to today. Interpret the complete recyclability status object, not just the grade letter.

Token ability: ppwr:read. Organization permission: catalog.view.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/biobased

Biobased — List

Records/evidence of bio-based material origin. Not automatically evidence of compostability or recyclability.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/biobased

Biobased — Create

Records/evidence of bio-based material origin. Not automatically evidence of compostability or recyclability.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/biobased/{recordId}

Biobased — Show

Records/evidence of bio-based material origin. Not automatically evidence of compostability or recyclability.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/biobased/{recordId}/review

Biobased — Review

Records/evidence of bio-based material origin. Not automatically evidence of compostability or recyclability.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/chemical-safety

Chemical safety — List

Chemical-safety record: components, measurements, analytical methods, exceptions and evidence. Values require valid sources; creating a record does not publish a compliance rule.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/chemical-safety

Chemical safety — Create

Chemical-safety record: components, measurements, analytical methods, exceptions and evidence. Values require valid sources; creating a record does not publish a compliance rule.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/chemical-safety/{recordId}

Chemical safety — Show

Chemical-safety record: components, measurements, analytical methods, exceptions and evidence. Values require valid sources; creating a record does not publish a compliance rule.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/chemical-safety/{recordId}/review

Chemical safety — Review

Chemical-safety record: components, measurements, analytical methods, exceptions and evidence. Values require valid sources; creating a record does not publish a compliance rule.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/communications

Communications — List

Label/claim text register with language, scope and sources. Schema depends on kind and subject_code. Records communication assessment, not print-ready label production.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/communications

Communications — Create

Label/claim text register with language, scope and sources. Schema depends on kind and subject_code. Records communication assessment, not print-ready label production.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/communications/{recordId}

Communications — Show

Label/claim text register with language, scope and sources. Schema depends on kind and subject_code. Records communication assessment, not print-ready label production.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/communications/{recordId}/review

Communications — Review

Label/claim text register with language, scope and sources. Schema depends on kind and subject_code. Records communication assessment, not print-ready label production.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/compostability

Compostability — List

Compostability record covering use, testing and evidence. A material name alone does not establish requirements are met.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/compostability

Compostability — Create

Compostability record covering use, testing and evidence. A material name alone does not establish requirements are met.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/compostability/{recordId}

Compostability — Show

Compostability record covering use, testing and evidence. A material name alone does not establish requirements are met.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/compostability/{recordId}/review

Compostability — Review

Compostability record covering use, testing and evidence. A material name alone does not establish requirements are met.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/conformity-dossiers

Conformity dossiers — List

A dossier organises packaging technical evidence. A reviewed dossier can support an EU declaration; PDF generation is separate.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/conformity-dossiers

Conformity dossiers — Create

A dossier organises packaging technical evidence. A reviewed dossier can support an EU declaration; PDF generation is separate.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/conformity-dossiers/{recordId}

Conformity dossiers — Show

A dossier organises packaging technical evidence. A reviewed dossier can support an EU declaration; PDF generation is separate.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/conformity-dossiers/{recordId}/review

Conformity dossiers — Review

A dossier organises packaging technical evidence. A reviewed dossier can support an EU declaration; PDF generation is separate.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/empty-space

Empty space — List

Technical empty-space assessment using dimensions, contents and method. Not a box recommendation or actual order-packing record.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/empty-space

Empty space — Create

Technical empty-space assessment using dimensions, contents and method. Not a box recommendation or actual order-packing record.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/empty-space/{recordId}

Empty space — Show

Technical empty-space assessment using dimensions, contents and method. Not a box recommendation or actual order-packing record.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/empty-space/{recordId}/review

Empty space — Review

Technical empty-space assessment using dimensions, contents and method. Not a box recommendation or actual order-packing record.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/eu-declarations

Eu declarations — List

EU declarations linked to the item’s dossier, contents, signatory and evidence. Creating a record does not sign for the manufacturer.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/eu-declarations

Eu declarations — Create

EU declarations linked to the item’s dossier, contents, signatory and evidence. Creating a record does not sign for the manufacturer.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/eu-declarations/{recordId}

Eu declarations — Show

EU declarations linked to the item’s dossier, contents, signatory and evidence. Creating a record does not sign for the manufacturer.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/eu-declarations/{recordId}/review

Eu declarations — Review

EU declarations linked to the item’s dossier, contents, signatory and evidence. Creating a record does not sign for the manufacturer.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/minimization

Minimization — List

Mass/volume minimisation assessment with functional criteria and evidence. Results depend on data and review, not merely declared numbers.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/minimization

Minimization — Create

Mass/volume minimisation assessment with functional criteria and evidence. Results depend on data and review, not merely declared numbers.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/minimization/{recordId}

Minimization — Show

Mass/volume minimisation assessment with functional criteria and evidence. Results depend on data and review, not merely declared numbers.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/minimization/{recordId}/review

Minimization — Review

Mass/volume minimisation assessment with functional criteria and evidence. Results depend on data and review, not merely declared numbers.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/packaging-classification

Packaging classification — List

Evidence-backed packaging/use classification. Does not replace catalogue folders.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/packaging-classification

Packaging classification — Create

Evidence-backed packaging/use classification. Does not replace catalogue folders.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/packaging-classification/{recordId}

Packaging classification — Show

Evidence-backed packaging/use classification. Does not replace catalogue folders.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/packaging-classification/{recordId}/review

Packaging classification — Review

Evidence-backed packaging/use classification. Does not replace catalogue folders.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/recyclability

Recyclability — List

Design-for-recycling assessment and evidence. Distinguishes working data from official methodology/results. Does not invent missing official weights or automatically certify a grade.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/recyclability

Recyclability — Create

Design-for-recycling assessment and evidence. Distinguishes working data from official methodology/results. Does not invent missing official weights or automatically certify a grade.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/recyclability/{recordId}

Recyclability — Show

Design-for-recycling assessment and evidence. Distinguishes working data from official methodology/results. Does not invent missing official weights or automatically certify a grade.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/recyclability/{recordId}/review

Recyclability — Review

Design-for-recycling assessment and evidence. Distinguishes working data from official methodology/results. Does not invent missing official weights or automatically certify a grade.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/restricted-formats

Restricted formats — List

Assessment of format restrictions/exceptions for packaging. Requires use context and supporting evidence, not just material codes.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/restricted-formats

Restricted formats — Create

Assessment of format restrictions/exceptions for packaging. Requires use context and supporting evidence, not just material codes.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/restricted-formats/{recordId}

Restricted formats — Show

Assessment of format restrictions/exceptions for packaging. Requires use context and supporting evidence, not just material codes.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/restricted-formats/{recordId}/review

Restricted formats — Review

Assessment of format restrictions/exceptions for packaging. Requires use context and supporting evidence, not just material codes.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/role-duties

Role duties — List

Obligations associated with the company’s role in an active market scenario. scenario must belong to the packaging item; sourcing mode is not an economic role.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/role-duties

Role duties — Create

Obligations associated with the company’s role in an active market scenario. scenario must belong to the packaging item; sourcing mode is not an economic role.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/role-duties/{recordId}

Role duties — Show

Obligations associated with the company’s role in an active market scenario. scenario must belong to the packaging item; sourcing mode is not an economic role.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/role-duties/{recordId}/review

Role duties — Review

Obligations associated with the company’s role in an active market scenario. scenario must belong to the packaging item; sourcing mode is not an economic role.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

### Reuse systems and returnable units

Circulation system → evidence/market confirmations → units → circulation events/review → aggregates and periodic targets. A circulation system is not a packing recipe.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/reuse-assessments

Reuse assessments — List

Assessment of packaging reusability with technical requirements/evidence. Not an individual unit’s circulation history.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/reuse-assessments

Reuse assessments — Create

Assessment of packaging reusability with technical requirements/evidence. Not an individual unit’s circulation history.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/reuse-assessments/{recordId}

Reuse assessments — Show

Assessment of packaging reusability with technical requirements/evidence. Not an individual unit’s circulation history.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/reuse-assessments/{recordId}/review

Reuse assessments — Review

Assessment of packaging reusability with technical requirements/evidence. Not an individual unit’s circulation history.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/reuse-units

Reuse units — List

Individually identified reusable units. item identifies the packaging type; the reusable unit identifies a physical instance and its event history.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/reuse-units

Reuse units — Create

Individually identified reusable units. item identifies the packaging type; the reusable unit identifies a physical instance and its event history.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/catalog-items/{catalogItemId}/ppwr/reuse-units/{recordId}

Reuse units — Show

Individually identified reusable units. item identifies the packaging type; the reusable unit identifies a physical instance and its event history.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### GET /organizations/{organizationId}/ppwr/refill-stations

Refill stations — List

Refill-station records with operating conditions and evidence. Does not control dispensing equipment or retail sales.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/refill-stations

Refill stations — Create

Refill-station records with operating conditions and evidence. Does not control dispensing equipment or retail sales.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/refill-stations/{recordId}

Refill stations — Show

Refill-station records with operating conditions and evidence. Does not control dispensing equipment or retail sales.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### POST /organizations/{organizationId}/ppwr/refill-stations/{recordId}/review

Refill stations — Review

Refill-station records with operating conditions and evidence. Does not control dispensing equipment or retail sales.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/reuse-market-confirmations

Reuse market confirmations — List

Market/period confirmations for a reuse system, linking the system to evidence of specific use.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/reuse-market-confirmations

Reuse market confirmations — Create

Market/period confirmations for a reuse system, linking the system to evidence of specific use.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/reuse-market-confirmations/{recordId}

Reuse market confirmations — Show

Market/period confirmations for a reuse system, linking the system to evidence of specific use.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/ppwr/reuse-market-confirmations/{recordId}/review

Reuse market confirmations — Review

Market/period confirmations for a reuse system, linking the system to evidence of specific use.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/reuse-statistics

Reuse statistics

Aggregates of recorded reuse systems and units. Results reflect the recorded scope, not a replacement for periodic target datasets or full compliance assessment.

Read aggregates of recorded circulation/systems without modifying records or events.

Token ability: ppwr:read. Organization permission: catalog.view.

#### GET /organizations/{organizationId}/ppwr/reuse-systems

Reuse systems — List

A reusable-packaging circulation system and its evidence. Describes participants/return rules, not a box-and-tape recipe in packaging-systems.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/reuse-systems

Reuse systems — Create

A reusable-packaging circulation system and its evidence. Describes participants/return rules, not a box-and-tape recipe in packaging-systems.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/reuse-systems/{recordId}

Reuse systems — Show

A reusable-packaging circulation system and its evidence. Describes participants/return rules, not a box-and-tape recipe in packaging-systems.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/ppwr/reuse-systems/{recordId}/review

Reuse systems — Review

A reusable-packaging circulation system and its evidence. Describes participants/return rules, not a box-and-tape recipe in packaging-systems.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/reuse-targets

Reuse targets — List

Periodic reuse-share dataset. Create the dataset first, add its lines and then review the whole dataset.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/reuse-targets

Reuse targets — Create

Periodic reuse-share dataset. Create the dataset first, add its lines and then review the whole dataset.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/reuse-targets/{parentId}/lines

Reuse target lines — List

Lines of a periodic reuse dataset. parentId identifies the dataset; fields determine contributions to the denominator/numerator as specified.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/reuse-targets/{parentId}/lines

Reuse target lines — Create

Lines of a periodic reuse dataset. parentId identifies the dataset; fields determine contributions to the denominator/numerator as specified.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/reuse-targets/{parentId}/lines/{recordId}

Reuse target lines — Show

Lines of a periodic reuse dataset. parentId identifies the dataset; fields determine contributions to the denominator/numerator as specified.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### GET /organizations/{organizationId}/ppwr/reuse-targets/{recordId}

Reuse targets — Show

Periodic reuse-share dataset. Create the dataset first, add its lines and then review the whole dataset.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### POST /organizations/{organizationId}/ppwr/reuse-targets/{recordId}/review

Reuse targets — Review

Periodic reuse-share dataset. Create the dataset first, add its lines and then review the whole dataset.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/reuse-units/{parentId}/events

Reuse unit events — List

Circulation events for a reusable unit identified by parentId. Recording and reviewing an event are separate operations.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/reuse-units/{parentId}/events

Reuse unit events — Create

Circulation events for a reusable unit identified by parentId. Recording and reviewing an event are separate operations.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: catalog.update.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/reuse-units/{parentId}/events/{recordId}

Reuse unit events — Show

Circulation events for a reusable unit identified by parentId. Recording and reviewing an event are separate operations.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/ppwr/reuse-units/{parentId}/events/{recordId}/review

Reuse unit events — Review

Circulation events for a reusable unit identified by parentId. Recording and reviewing an event are separate operations.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

### Deposits, hospitality and information

Specialised documentary registers. Deposit records describe packaging/membership without handling money; hospitality/end-user information records store assessments/evidence.

#### GET /organizations/{organizationId}/ppwr/deposit-schemes

Packaging deposit-scheme assessments — List

Packaging deposit-scheme assessment records: market, format, capacity, exclusions, membership and evidence. No deposit billing, collection, refunds, return-machine control or operator settlement.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/deposit-schemes

Packaging deposit-scheme assessments — Create

Packaging deposit-scheme assessment records: market, format, capacity, exclusions, membership and evidence. No deposit billing, collection, refunds, return-machine control or operator settlement.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/deposit-schemes/{recordId}

Packaging deposit-scheme assessments — Show

Packaging deposit-scheme assessment records: market, format, capacity, exclusions, membership and evidence. No deposit billing, collection, refunds, return-machine control or operator settlement.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### POST /organizations/{organizationId}/ppwr/deposit-schemes/{recordId}/review

Packaging deposit-scheme assessments — Review

Packaging deposit-scheme assessment records: market, format, capacity, exclusions, membership and evidence. No deposit billing, collection, refunds, return-machine control or operator settlement.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/end-user-information

End user information — List

Register of information provided to end users: content, topic, channel, language and evidence. Not a bulk campaign delivery service.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/end-user-information

End user information — Create

Register of information provided to end users: content, topic, channel, language and evidence. Not a bulk campaign delivery service.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/end-user-information/{recordId}

End user information — Show

Register of information provided to end users: content, topic, channel, language and evidence. Not a bulk campaign delivery service.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### POST /organizations/{organizationId}/ppwr/end-user-information/{recordId}/review

End user information — Review

Register of information provided to end users: content, topic, channel, language and evidence. Not a bulk campaign delivery service.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/horeca

Horeca — List

Hospitality packaging/sales assessments with business scope and exceptions. A documentary register, not a POS system.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/horeca

Horeca — Create

Hospitality packaging/sales assessments with business scope and exceptions. A documentary register, not a POS system.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/horeca/{recordId}

Horeca — Show

Hospitality packaging/sales assessments with business scope and exceptions. A documentary register, not a POS system.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### POST /organizations/{organizationId}/ppwr/horeca/{recordId}/review

Horeca — Review

Hospitality packaging/sales assessments with business scope and exceptions. A documentary register, not a POS system.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

### Reports, EPR, BDO and recycled content

Catalogue/assessment/flow exports are queued. EPR/waste: header → lines → review → export. BDO: sources → classification → snapshot → export. None automatically files a declaration with an authority.

#### POST /organizations/{organizationId}/bdo-reports

Bdo reports — Create

BDO packaging report preparation: sources, classification, snapshot and export. Does not automatically file the annual BDO report or pay fees.

Create a frozen report from the year’s sources/classifications. 201 returns a ReportRun with prepared or needs_review, not queued. settlement_mode controls settlement; not_calculated skips fee calculation. Providing sources/settlement inputs does not submit to BDO.

Token ability: reports:run. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### POST /organizations/{organizationId}/bdo-reports/classifications

Bdo reports — Classify

BDO packaging report preparation: sources, classification, snapshot and export. Does not automatically file the annual BDO report or pay fees.

Classify a source for reporting. Does not modify an existing frozen report; create a new report after classification changes. sources contains flow:UUID or supply:UUID keys from GET sources, not packaging UUIDs.

Token ability: reports:run. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/bdo-reports/sources

Bdo reports — Rows

BDO packaging report preparation: sources, classification, snapshot and export. Does not automatically file the annual BDO report or pay fees.

Retrieve source data for the requested period; follow this operation’s pagination parameters.

Token ability: reports:read. Organization permission: reports.view.

#### GET /organizations/{organizationId}/bdo-reports/{recordId}

Bdo reports — Snapshot

BDO packaging report preparation: sources, classification, snapshot and export. Does not automatically file the annual BDO report or pay fees.

Retrieve the stored snapshot associated with this record. Current catalogue changes do not automatically recalculate it.

Token ability: reports:read. Organization permission: reports.view.

#### GET /organizations/{organizationId}/bdo-reports/{recordId}/download

Bdo reports — Download

BDO packaging report preparation: sources, classification, snapshot and export. Does not automatically file the annual BDO report or pay fees.

Download a binary file, not JSON. Errors still return JSON; check HTTP status and Content-Type before saving the response.

Token ability: reports:read. Organization permission: reports.export.

#### GET /organizations/{organizationId}/ppwr/epr-authorizations

Epr authorizations — List

Producer-responsibility authorisation register and evidence. Recording does not file an authority application or grant authorisation.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/epr-authorizations

Epr authorizations — Create

Producer-responsibility authorisation register and evidence. Recording does not file an authority application or grant authorisation.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/epr-authorizations/{recordId}

Epr authorizations — Show

Producer-responsibility authorisation register and evidence. Recording does not file an authority application or grant authorisation.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### POST /organizations/{organizationId}/ppwr/epr-authorizations/{recordId}/review

Epr authorizations — Review

Producer-responsibility authorisation register and evidence. Recording does not file an authority application or grant authorisation.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/epr-registrations

Epr registrations — List

Producer registrations by market: identity, scope, period and documents. Separate from creating a PPWR Link organisation or user account.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/epr-registrations

Epr registrations — Create

Producer registrations by market: identity, scope, period and documents. Separate from creating a PPWR Link organisation or user account.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/epr-registrations/{recordId}

Epr registrations — Show

Producer registrations by market: identity, scope, period and documents. Separate from creating a PPWR Link organisation or user account.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### POST /organizations/{organizationId}/ppwr/epr-registrations/{recordId}/review

Epr registrations — Review

Producer registrations by market: identity, scope, period and documents. Separate from creating a PPWR Link organisation or user account.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/epr-reports

Epr reports — List

Annual EPR reports with lines and review. Export uses the recorded result; it does not file into a national portal.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/epr-reports

Epr reports — Create

Annual EPR reports with lines and review. Export uses the recorded result; it does not file into a national portal.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/epr-reports/{parentId}/lines

Epr report lines — List

Categories/masses in an annual EPR report. parentId is the report UUID. Complete lines before report review.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/epr-reports/{parentId}/lines

Epr report lines — Create

Categories/masses in an annual EPR report. parentId is the report UUID. Complete lines before report review.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/epr-reports/{parentId}/lines/{recordId}

Epr report lines — Show

Categories/masses in an annual EPR report. parentId is the report UUID. Complete lines before report review.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### GET /organizations/{organizationId}/ppwr/epr-reports/{recordId}

Epr reports — Show

Annual EPR reports with lines and review. Export uses the recorded result; it does not file into a national portal.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### GET /organizations/{organizationId}/ppwr/epr-reports/{recordId}/export

Epr reports — Download

Annual EPR reports with lines and review. Export uses the recorded result; it does not file into a national portal.

Download a binary file, not JSON. Errors still return JSON; check HTTP status and Content-Type before saving the response.

Token ability: reports:read. Organization permission: reports.export.

#### POST /organizations/{organizationId}/ppwr/epr-reports/{recordId}/review

Epr reports — Review

Annual EPR reports with lines and review. Export uses the recorded result; it does not file into a national portal.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/plant-year-pcr

Plant year pcr — List

Plant-year recycled-content record with mass/evidence. Not recycled-feedstock inventory or a complete manufacturing ERP.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/plant-year-pcr

Plant year pcr — Create

Plant-year recycled-content record with mass/evidence. Not recycled-feedstock inventory or a complete manufacturing ERP.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/plant-year-pcr/{recordId}

Plant year pcr — Show

Plant-year recycled-content record with mass/evidence. Not recycled-feedstock inventory or a complete manufacturing ERP.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### POST /organizations/{organizationId}/ppwr/plant-year-pcr/{recordId}/review

Plant year pcr — Review

Plant-year recycled-content record with mass/evidence. Not recycled-feedstock inventory or a complete manufacturing ERP.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/waste-reports

Waste reports — List

Periodic waste-management reports with lines, evidence and review. Export requires an authority or producer audience.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/waste-reports

Waste reports — Create

Periodic waste-management reports with lines, evidence and review. Export requires an authority or producer audience.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/waste-reports/{parentId}/lines

Waste report lines — List

Waste-report lines attached to the report parentId. They are not waste transfer notes in the external BDO system.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/waste-reports/{parentId}/lines

Waste report lines — Create

Waste-report lines attached to the report parentId. They are not waste transfer notes in the external BDO system.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/waste-reports/{parentId}/lines/{recordId}

Waste report lines — Show

Waste-report lines attached to the report parentId. They are not waste transfer notes in the external BDO system.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### GET /organizations/{organizationId}/ppwr/waste-reports/{recordId}

Waste reports — Show

Periodic waste-management reports with lines, evidence and review. Export requires an authority or producer audience.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### GET /organizations/{organizationId}/ppwr/waste-reports/{recordId}/export

Waste reports — Download

Periodic waste-management reports with lines, evidence and review. Export requires an authority or producer audience.

Download a binary file, not JSON. Errors still return JSON; check HTTP status and Content-Type before saving the response.

Token ability: reports:read. Organization permission: reports.export.

#### POST /organizations/{organizationId}/ppwr/waste-reports/{recordId}/review

Waste reports — Review

Periodic waste-management reports with lines, evidence and review. Export requires an authority or producer audience.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/reports

Reports — List

Catalogue, assessment and flow exports to CSV/XLSX. A request freezes inputs; a worker generates the file. Download after completed.

List records accessible to the key’s organisation.

Token ability: reports:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/reports

Reports — Create

Catalogue, assessment and flow exports to CSV/XLSX. A request freezes inputs; a worker generates the file. Download after completed.

Request a catalog, assessments or flows CSV export, or its _xlsx variant. Keep id, poll GET /reports/{id}, then download after completed.

Token ability: reports:run. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

202 confirms queued work. Poll the resource by its returned `id` until processing finishes; `queued` does not mean a file is ready.

#### GET /organizations/{organizationId}/reports/{recordId}

Reports — Show

Catalogue, assessment and flow exports to CSV/XLSX. A request freezes inputs; a worker generates the file. Download after completed.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: reports:read. Organization permission: reports.view.

#### GET /organizations/{organizationId}/reports/{recordId}/download

Reports — Download

Catalogue, assessment and flow exports to CSV/XLSX. A request freezes inputs; a worker generates the file. Download after completed.

Download a binary file, not JSON. Errors still return JSON; check HTTP status and Content-Type before saving the response.

Token ability: reports:read. Organization permission: reports.export.

### Passports and recipient access

Data/evidence → draft → publish → recipient grant. New versions need separate access. Subscriptions/updates belong to the key’s user; following is not data adoption.

#### GET /organizations/{organizationId}/passport-subscriptions

Watched passports — List

Personal subscriptions to a received/shared passport. Requires current access and does not grant future-version access.

List records accessible to the key’s organisation.

Token ability: passports:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/passport-subscriptions/{recordId}/unsubscribe

Watched passports — Stop watching

Personal subscriptions to a received/shared passport. Requires current access and does not grant future-version access.

Disable a personal subscription without revoking the publisher’s sharing grant.

Token ability: passports:write. Organization permission: catalog.view.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/passport-subscriptions/{recordId}/updates

Passport updates — List

Updates for passports followed by the key’s user. Reads recheck access to compared versions; open marks an update as read.

List records accessible to the key’s organisation.

Token ability: passports:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### GET /organizations/{organizationId}/passport-updates/{recordId}

Passport updates — Show

Updates for passports followed by the key’s user. Reads recheck access to compared versions; open marks an update as read.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: passports:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/passport-updates/{recordId}/open

Passport updates — Open update

Updates for passports followed by the key’s user. Reads recheck access to compared versions; open marks an update as read.

Mark an update as opened and return its details after access checks. Does not adopt new data into your own catalogue.

Token ability: passports:write. Organization permission: catalog.view.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/passports

Passports — List

A versioned packaging-data snapshot. Drafting, publishing and granting organisation access are separate. Publishing is not sharing; a new version does not automatically inherit access.

List records accessible to the key’s organisation.

Token ability: passports:read. Organization permission: catalog.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/passports

Passports — Create

A versioned packaging-data snapshot. Drafting, publishing and granting organisation access are separate. Publishing is not sharing; a new version does not automatically inherit access.

Create a draft snapshot from packaging and reviewed data. Retain the passport id; publication requires freshness and review conditions.

Token ability: passports:write. Organization permission: passports.manage.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

This illustrates structure. Replace UUIDs, revisions, dates and configuration_hash with real values; units and materials must match the packaging configuration.

```json
{
    "item": "11111111-1111-4111-8111-111111111111"
}
```

#### GET /organizations/{organizationId}/passports/{recordId}

Passports — Show

A versioned packaging-data snapshot. Drafting, publishing and granting organisation access are separate. Publishing is not sharing; a new version does not automatically inherit access.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: passports:read. Organization permission: catalog.view.

#### POST /organizations/{organizationId}/passports/{recordId}/publish

Passports — Publish

A versioned packaging-data snapshot. Drafting, publishing and granting organisation access are separate. Publishing is not sharing; a new version does not automatically inherit access.

Publish a draft after access, evidence and freshness checks. Changed inputs can block publication; create a current draft instead of rewriting an old snapshot.

Token ability: passports:write. Organization permission: passports.manage.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### POST /organizations/{organizationId}/passports/{recordId}/shares

Passports — Share

A versioned packaging-data snapshot. Drafting, publishing and granting organisation access are separate. Publishing is not sharing; a new version does not automatically inherit access.

Grant recipient organisation access to a specific version with purpose, expiry and allow_download/allow_adoption options. This is not a blanket public disclosure.

Token ability: passports:write. Organization permission: sharing_grants.manage.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/passports/{recordId}/snapshot

Passports — Snapshot

A versioned packaging-data snapshot. Drafting, publishing and granting organisation access are separate. Publishing is not sharing; a new version does not automatically inherit access.

Retrieve the stored snapshot associated with this record. Current catalogue changes do not automatically recalculate it.

Token ability: passports:read. Organization permission: passports.manage.

#### POST /organizations/{organizationId}/received-passports/{recordId}/subscription

Watched passports — Create

Personal subscriptions to a received/shared passport. Requires current access and does not grant future-version access.

Subscribe to the received passport identified by recordId. The ID refers to the received version; active sharing is rechecked.

Token ability: passports:write. Organization permission: catalog.view.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/sharing-grants

Sharing grants — List

Recipient access to a specific passport version, including purpose, expiry and download/adoption options. Not organisation membership roles.

List records accessible to the key’s organisation.

Token ability: passports:read. Organization permission: sharing_grants.manage.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### GET /organizations/{organizationId}/sharing-grants/{recordId}

Sharing grants — Show

Recipient access to a specific passport version, including purpose, expiry and download/adoption options. Not organisation membership roles.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: passports:read. Organization permission: sharing_grants.manage.

#### POST /organizations/{organizationId}/sharing-grants/{recordId}/revoke

Passports — Revoke

A versioned packaging-data snapshot. Drafting, publishing and granting organisation access are separate. Publishing is not sharing; a new version does not automatically inherit access.

Revoke the grant identified by recordId. Retains passport/history while stopping access through this grant.

Token ability: passports:write. Organization permission: sharing_grants.manage.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

### Factors and material carbon footprint

Read sources → prepare factors → select item/set and optional historical basis → calculate → read snapshot. Results do not automatically cover the entire life cycle.

#### GET /organizations/{organizationId}/carbon-calculations

Carbon calculations — List

Material-acquisition carbon calculation for an item or set using explicit factors. Not a complete transport, energy and end-of-life LCA. incomplete has total_kg_co2e=null.

List records accessible to the key’s organisation.

Token ability: reports:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/carbon-calculations

Carbon calculations — Create

Material-acquisition carbon calculation for an item or set using explicit factors. Not a complete transport, energy and end-of-life LCA. incomplete has total_kg_co2e=null.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

Token ability: reports:run. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/carbon-calculations/{recordId}

Carbon calculations — Show

Material-acquisition carbon calculation for an item or set using explicit factors. Not a complete transport, energy and end-of-life LCA. incomplete has total_kg_co2e=null.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: reports:read. Organization permission: reports.view.

#### GET /organizations/{organizationId}/carbon-factors

Emission factors — List

Sources and versioned emission factors for calculations. Custom factors require units, scope and source; archiving does not change historical results.

List records accessible to the key’s organisation.

Token ability: reports:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/carbon-factors

Emission factors — Create

Sources and versioned emission factors for calculations. Custom factors require units, scope and source; archiving does not change historical results.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

Token ability: reports:run. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/carbon-factors/reference

Emission factors — Reference catalogue

Sources and versioned emission factors for calculations. Custom factors require units, scope and source; archiving does not change historical results.

Retrieve reference factors/scopes/units before selecting factors. Do not assume every material has an available factor for each region/period.

Token ability: reports:read. Organization permission: reports.view.

#### GET /organizations/{organizationId}/carbon-factors/{recordId}

Emission factors — Show

Sources and versioned emission factors for calculations. Custom factors require units, scope and source; archiving does not change historical results.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: reports:read. Organization permission: reports.view.

#### POST /organizations/{organizationId}/carbon-factors/{recordId}/archive

Emission factors — Archive

Sources and versioned emission factors for calculations. Custom factors require units, scope and source; archiving does not change historical results.

Archive the record while retaining history. Do not select archived resources for new work.

Token ability: reports:run. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

### Cases, submissions and audit

Register request/case → add responses/events and delivery evidence → review where exposed. External submissions document actions performed outside the application.

#### GET /organizations/{organizationId}/audit-log

Audit log — List

Organisation audit events with date filters and secret redaction. An audit trail, not a replay or arbitrary undo interface.

List records accessible to the key’s organisation.

Token ability: audit:read. Organization permission: audit.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### GET /organizations/{organizationId}/ppwr/authority-requests

Authority requests — List

Register of received authority requests, deadlines and requested materials. Does not automatically receive official correspondence.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: issues.manage or evidence.review.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/authority-requests

Authority requests — Create

Register of received authority requests, deadlines and requested materials. Does not automatically receive official correspondence.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: issues.manage.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/authority-requests/{parentId}/responses

Authority responses — List

Responses and delivery evidence linked to an authority request. Recording evidence does not transmit a letter through an official channel.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: issues.manage or evidence.review.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/authority-requests/{parentId}/responses

Authority responses — Create

Responses and delivery evidence linked to an authority request. Recording evidence does not transmit a letter through an official channel.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: issues.manage.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/authority-requests/{parentId}/responses/{recordId}

Authority responses — Show

Responses and delivery evidence linked to an authority request. Recording evidence does not transmit a letter through an official channel.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: issues.manage or evidence.review.

#### POST /organizations/{organizationId}/ppwr/authority-requests/{parentId}/responses/{recordId}/review

Authority responses — Review

Responses and delivery evidence linked to an authority request. Recording evidence does not transmit a letter through an official channel.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/authority-requests/{recordId}

Authority requests — Show

Register of received authority requests, deadlines and requested materials. Does not automatically receive official correspondence.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: issues.manage or evidence.review.

#### GET /organizations/{organizationId}/ppwr/external-submissions

External submission records — List

Register of filings performed in external systems, with references and evidence. Creating a record does not submit to those systems.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: reports.view.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/external-submissions

External submission records — Create

Register of filings performed in external systems, with references and evidence. Creating a record does not submit to those systems.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: reports.export.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/external-submissions/{recordId}

External submission records — Show

Register of filings performed in external systems, with references and evidence. Creating a record does not submit to those systems.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: reports.view.

#### POST /organizations/{organizationId}/ppwr/external-submissions/{recordId}/review

External submission records — Review

Register of filings performed in external systems, with references and evidence. Creating a record does not submit to those systems.

Record a review decision and reason. Read the record afterwards for its status. This is an internal register decision.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:review. Organization permission: evidence.review.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/formal-cases

Formal cases — List

Formal cases/corrective actions for packaging. History events record actions/evidence, not authority decisions.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: issues.manage or evidence.review.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/formal-cases

Formal cases — Create

Formal cases/corrective actions for packaging. History events record actions/evidence, not authority decisions.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: issues.manage.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/formal-cases/{parentId}/events

Formal case events — List

Case history: findings, responses, actions and closure according to event type. parentId is the case UUID.

List records accessible to the key’s organisation.

Token ability: ppwr:read. Organization permission: issues.manage or evidence.review.

Uses `per_page` (1–100, default 50) and cursor pagination. Request `links.next` for the next page; null ends the list. Only use filters listed for this operation.

#### POST /organizations/{organizationId}/ppwr/formal-cases/{parentId}/events

Formal case events — Create

Case history: findings, responses, actions and closure according to event type. parentId is the case UUID.

Create a record from requestBody fields. The response provides a public id for subsequent reads and relationships.

For a technical register: prepare packaging or a parent record, required document versions and assessment date; create the record, retain its UUID and call /review if exposed. Sources must meet the register’s requirements. A separate reviewer may be required; 403/422 does not necessarily indicate a broken API key. Recording or reviewing data does not replace a published assessment methodology.

Token ability: ppwr:write. Organization permission: issues.manage.

This operation requires `Idempotency-Key`. Retry with the same method, path, key and data. Use a new key for new work; do not bypass a conflict by generating another key without reconciling the original result.

#### GET /organizations/{organizationId}/ppwr/formal-cases/{parentId}/events/{recordId}

Formal case events — Show

Case history: findings, responses, actions and closure according to event type. parentId is the case UUID.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: issues.manage or evidence.review.

#### GET /organizations/{organizationId}/ppwr/formal-cases/{recordId}

Formal cases — Show

Formal cases/corrective actions for packaging. History events record actions/evidence, not authority decisions.

Retrieve an existing record. Obtain its UUID from the list or creation response for this resource type.

Token ability: ppwr:read. Organization permission: issues.manage or evidence.review.

