Create an inquiry on behalf of a walk-in / phone-in client
POST/admin/zfa-direct/inquiries
ZFA staff logs a client contact. Optionally links to an existing Client via clientId; otherwise a new one is created lazily. Sets the inquiry to assigned with the caller as assignee so it doesn't sit in the queue.
Request
Responses
- 201
- 400
- 401
- 403
- 409
- 429
- 500
ClientInquiry created and assigned to the caller.
Payload validation failed.
Missing, malformed, or expired authentication token. Log in via POST /auth/login (or refresh via POST /auth/refresh) and retry with a fresh Authorization: Bearer <accessToken> header.
The authenticated caller does not carry the required permission or is scoped out of this resource by the object-authorization service (e.g. an agent trying to view another agent's referrals). Grant the missing permission via a role change or scope the query to resources the caller owns.
A duplicate client match was ambiguous.
Rate limit exceeded. Global default is 120 requests/minute per IP; auth-flow, OTP, self-registration, WebAuthn, IRA lookup, and public-lead endpoints carry tighter per-endpoint limits. Retry after the delay indicated by the Retry-After header.
Response Headers
Seconds to wait before retrying.
Unhandled server error. The response carries a meta.requestId correlator you can hand to platform operations to trace the failure through structured logs and the hash-chained audit trail. Retry with the same Idempotency-Key header if the endpoint accepts idempotency.