# API reference

Download the [OpenAPI snapshot](https://docs.masheev.com/openapi.json) for the
request and response schemas generated from the product routes. The snapshot
is public; actual operations still require authentication and account permission.

Start with [authentication](https://docs.masheev.com/authentication.md).
Organization API keys use `X-API-Key` and a matching `orgId`. Check
[availability](https://docs.masheev.com/capabilities.md) before implementing an
operation. Schemas can include disabled or beta functionality.

The interactive [API explorer](https://docs.masheev.com/api-reference) displays
the same snapshot. Only execute operations against workspaces you are authorized
to use. Do not share keys, browser cookies or customer data in prompts or issue reports.

## AI-generated messages

Message objects returned by the Messages API (`GET /messages/{id}`, the message
list, create and status-update operations) include `aiGenerated`, a boolean. It is
`true` when the Masheev AI agent wrote the message and `false` for messages from
your team, your contacts or the system. The `ai.turn.completed` webhook payload
always carries `aiGenerated: true`.

Use this flag to label AI-written content in your own interface or records.

Email replies written by the AI agent carry the `X-Masheev-AI-Generated: true` and
`Auto-Submitted: auto-generated` headers when sent through Masheev or a connected
Gmail inbox. Replies sent from a connected Microsoft 365 inbox may not carry these
headers yet; they still include the visible AI footer.

## Outbound and server workflows

See [Outbound and server workflows](https://docs.masheev.com/outbound.md) for preparation, read-only batch previews, event admission, durable waits, result reconciliation, and external booking integration dependencies. Calling, transactional SMS and outgoing webhook capabilities remain off.
