Claim or reassign an incoming case
POST/admin/callback-incoming/{case_id}/claim
Admin-runtime only; JSON follows x-request-schema. Unknown/duplicate keys are rejected. Authentication precedes strict handler validation. This internal operation deliberately omits executable requestBody validation so the generic pre-auth validator cannot echo sensitive submitted values. x-request-schema is documentation, not a validation bypass. owner_ref and optional actor_ref are service-attested labels; the calling service must authenticate and authorize its human. Core derives machine_actor from the API identity. The command UUID is idempotent only for identical input. Stale version, changed command or closed case conflicts. Atomic audit and ownership update; no financial operation. String limits are UTF-8 bytes, not characters; identifiers/notes exclude controls. Every response uses Cache-Control no-store.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Responses
Section titled “Responses”Confirmed atomic claim receipt.
Invalid JSON command.
Missing or invalid API key.
Caller is not admin-runtime.
Case absent.
Version
Action unconfirmed; retry the same command UUID and exact input.