> ## Documentation Index
> Fetch the complete documentation index at: https://docs.spott.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit spontaneous application

> Submit a spontaneous application. The CV is optional: without one, the candidate is created from the submitted details. An existing candidate with the same email, phone number or LinkedIn URL is reused. Requires open applications to be enabled for the organization.



## OpenAPI

````yaml /api-reference/openapi.json post /candidate-portal/open-application
openapi: 3.1.0
info:
  title: Spott API Reference
  version: '0.1'
servers:
  - url: https://api.gospott.com
security: []
tags: []
paths:
  /candidate-portal/open-application:
    post:
      tags:
        - Candidate Portal
      summary: Submit spontaneous application
      description: >-
        Submit a spontaneous application. The CV is optional: without one, the
        candidate is created from the submitted details. An existing candidate
        with the same email, phone number or LinkedIn URL is reused. Requires
        open applications to be enabled for the organization.
      operationId: handleCandidatePortalOpenApplication
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CandidatePortalOpenApplicationDto'
      responses:
        '200':
          description: Application submitted successfully.
        '400':
          description: >-
            Bad request - missing or invalid fields, the CV has no readable
            text, the CV and cover letter reference the same attachment, or the
            LinkedIn URL is not a profile URL
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/ExceptionBaseDto'
                  - type: object
                    properties:
                      statusCode:
                        type: number
                        example: 400
                      message:
                        type: string
                        example: Invalid email format
                      error:
                        type: string
                        example: Bad Request
        '401':
          description: Unauthorized - invalid or missing authentication
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExceptionBaseDto'
        '403':
          description: Open applications are not enabled for this organization
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExceptionBaseDto'
        '404':
          description: CV or cover letter attachment not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExceptionBaseDto'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GlobalConflictApiErrorDto'
        '500':
          description: Error response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InternalServerErrorDto'
      security:
        - x-api-key: []
components:
  schemas:
    CandidatePortalOpenApplicationDto:
      type: object
      properties:
        firstName:
          type: string
          minLength: 1
          maxLength: 100
          pattern: ^(?=.*\p{L})[\p{L}\p{M} '’.-]+$
        lastName:
          type: string
          minLength: 1
          maxLength: 100
          pattern: ^(?=.*\p{L})[\p{L}\p{M} '’.-]+$
        cvAttachmentId:
          anyOf:
            - type: string
              minLength: 1
              maxLength: 100
            - type: 'null'
        coverLetterAttachmentId:
          anyOf:
            - type: string
              minLength: 1
              maxLength: 100
            - type: 'null'
        email:
          type: string
          minLength: 3
          maxLength: 254
          format: email
          pattern: >-
            ^(?:[A-Za-z0-9_'+\-]+\.)*[A-Za-z0-9_'+\-]*[A-Za-z0-9_+-]@(?:[A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$
        phoneNumber:
          $ref: '#/components/schemas/PhoneNumber'
        linkedinUrl:
          anyOf:
            - type: string
              maxLength: 2048
            - type: 'null'
        location:
          anyOf:
            - $ref: '#/components/schemas/CreateLocationDto'
            - type: 'null'
        dateOfBirth:
          anyOf:
            - $ref: '#/components/schemas/DateISO'
            - type: 'null'
      required:
        - firstName
        - lastName
        - coverLetterAttachmentId
        - email
        - phoneNumber
        - linkedinUrl
        - location
    ExceptionBaseDto:
      type: object
      properties:
        status:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        category:
          $ref: '#/components/schemas/ApiErrorCategoryDto'
        message:
          type: string
        requestId:
          type: string
      required:
        - status
        - message
        - requestId
    GlobalConflictApiErrorDto:
      anyOf:
        - $ref: '#/components/schemas/ResourceAlreadyExistsApiErrorDto'
        - $ref: '#/components/schemas/ResourceLockTimeoutApiErrorDto'
    InternalServerErrorDto:
      type: object
      properties:
        status:
          type: number
          const: 500
        category:
          type: string
          enum:
            - INTERNAL_ERROR
        message:
          type: string
          enum:
            - Internal server error
        requestId:
          type: string
      required:
        - status
        - category
        - message
        - requestId
    PhoneNumber:
      description: Phone number in E.164 format
      type: string
    CreateLocationDto:
      type: object
      properties:
        street1:
          type:
            - string
            - 'null'
        street2:
          type:
            - string
            - 'null'
        postalCode:
          type:
            - string
            - 'null'
        city:
          type:
            - string
            - 'null'
        region:
          type:
            - string
            - 'null'
        state:
          type:
            - string
            - 'null'
        country:
          deprecated: true
          description: >-
            Deprecated: use `countryCode` instead. When omitted, the country
            name is derived from `countryCode`.
          type:
            - string
            - 'null'
        countryCode:
          anyOf:
            - $ref: '#/components/schemas/CountryCode'
            - type: 'null'
        latitude:
          anyOf:
            - type: number
              minimum: -90
              maximum: 90
            - type: 'null'
        longitude:
          anyOf:
            - type: number
              minimum: -180
              maximum: 180
            - type: 'null'
        type:
          anyOf:
            - $ref: '#/components/schemas/LocationType'
            - type: 'null'
    DateISO:
      format: date-time
      anyOf:
        - type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z))$
        - type: string
          format: date
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))$
    ApiErrorCategoryDto:
      type: string
      enum:
        - MALFORMED_REQUEST
        - SCHEMA_VALIDATION_FAILED
        - DOMAIN_VALIDATION_FAILED
        - OPERATION_LIMIT_EXCEEDED
        - AUTHENTICATION_REQUIRED
        - AUTHENTICATION_FAILED
        - SECURITY_CHALLENGE_REQUIRED
        - SECURITY_CHALLENGE_FAILED
        - PERMISSION_DENIED
        - ENTITLEMENT_REQUIRED
        - PROVIDER_AUTHENTICATION_REQUIRED
        - PROVIDER_AUTHENTICATION_FAILED
        - CONFIGURATION_REQUIRED
        - RESOURCE_NOT_FOUND
        - RESOURCE_ALREADY_EXISTS
        - RESOURCE_EXPIRED
        - RESOURCE_BUSY
        - RESOURCE_STATE_CONFLICT
        - QUOTA_EXCEEDED
        - RATE_LIMITED
        - UNSUPPORTED_OPERATION
        - UPSTREAM_REJECTED
        - TIMEOUT
        - TEMPORARILY_UNAVAILABLE
        - INTERNAL_ERROR
    ResourceAlreadyExistsApiErrorDto:
      type: object
      properties:
        status:
          type: number
          const: 409
        category:
          type: string
          enum:
            - RESOURCE_ALREADY_EXISTS
        message:
          type: string
          enum:
            - Resource already exists
        requestId:
          type: string
      required:
        - status
        - category
        - message
        - requestId
    ResourceLockTimeoutApiErrorDto:
      type: object
      properties:
        status:
          type: number
          const: 409
        category:
          type: string
          enum:
            - RESOURCE_BUSY
        message:
          type: string
          enum:
            - >-
              Lock could not be acquired for this resource, please try again
              later.
        requestId:
          type: string
      required:
        - status
        - category
        - message
        - requestId
    CountryCode:
      type: string
      enum:
        - AF
        - AX
        - AL
        - DZ
        - AS
        - AD
        - AO
        - AI
        - AQ
        - AG
        - AR
        - AM
        - AW
        - AU
        - AT
        - AZ
        - BS
        - BH
        - BD
        - BB
        - BY
        - BE
        - BZ
        - BJ
        - BM
        - BT
        - BO
        - BQ
        - BA
        - BW
        - BV
        - BR
        - IO
        - BN
        - BG
        - BF
        - BI
        - KH
        - CM
        - CA
        - CV
        - KY
        - CF
        - TD
        - CL
        - CN
        - CX
        - CC
        - CO
        - KM
        - CG
        - CD
        - CK
        - CR
        - CI
        - HR
        - CU
        - CW
        - CY
        - CZ
        - DK
        - DJ
        - DM
        - DO
        - EC
        - EG
        - SV
        - GQ
        - ER
        - EE
        - ET
        - FK
        - FO
        - FJ
        - FI
        - FR
        - GF
        - PF
        - TF
        - GA
        - GM
        - GE
        - DE
        - GH
        - GI
        - GR
        - GL
        - GD
        - GP
        - GU
        - GT
        - GG
        - GN
        - GW
        - GY
        - HT
        - HM
        - VA
        - HN
        - HK
        - HU
        - IS
        - IN
        - ID
        - IR
        - IQ
        - IE
        - IM
        - IL
        - IT
        - JM
        - JP
        - JE
        - JO
        - KZ
        - KE
        - KI
        - KP
        - KR
        - KW
        - KG
        - LA
        - LV
        - LB
        - LS
        - LR
        - LY
        - LI
        - LT
        - LU
        - MO
        - MK
        - MG
        - MW
        - MY
        - MV
        - ML
        - MT
        - MH
        - MQ
        - MR
        - MU
        - YT
        - MX
        - FM
        - MD
        - MC
        - MN
        - ME
        - MS
        - MA
        - MZ
        - MM
        - NA
        - NR
        - NP
        - NL
        - NC
        - NZ
        - NI
        - NE
        - NG
        - NU
        - NF
        - MP
        - 'NO'
        - OM
        - PK
        - PW
        - PS
        - PA
        - PG
        - PY
        - PE
        - PH
        - PN
        - PL
        - PT
        - PR
        - QA
        - RE
        - RO
        - RU
        - RW
        - BL
        - SH
        - KN
        - LC
        - MF
        - PM
        - VC
        - WS
        - SM
        - ST
        - SA
        - SN
        - RS
        - SC
        - SL
        - SG
        - SX
        - SK
        - SI
        - SB
        - SO
        - ZA
        - GS
        - SS
        - ES
        - LK
        - SD
        - SR
        - SJ
        - SZ
        - SE
        - CH
        - SY
        - TW
        - TJ
        - TZ
        - TH
        - TL
        - TG
        - TK
        - TO
        - TT
        - TN
        - TR
        - TM
        - TC
        - TV
        - UG
        - UA
        - AE
        - GB
        - US
        - UM
        - UY
        - UZ
        - VU
        - VE
        - VN
        - VG
        - VI
        - WF
        - EH
        - XK
        - YE
        - ZM
        - ZW
    LocationType:
      type: string
      enum:
        - primary_home
        - secondary_home
        - primary_work
        - headquarters
        - regional_office
  securitySchemes:
    x-api-key:
      type: apiKey
      name: x-api-key
      in: header
      description: >-
        API key for authentication. Get your API key from Settings → API Keys in
        your Spott dashboard.

````