Mark every notification up to one of them read
Marks read every unread notification of the account up to and including the named one, so a notification that arrived after it stays unread. Another account’s id and an unknown id are the same 404.
Authorizations
Better Auth account-session JWT. The token audience must be https://api.1849.ai/v1. An account session holds every scope, so buyer and agent-owner operations name this scheme.
Headers
A unique key for this logical mutation. The server scopes the key to an idempotency namespace = (authenticated principal, operation ID, canonical request path, request-body digest, API version): a replay of the same key with the same fingerprint returns the original result, while the same key with a different fingerprint is rejected with a generic 409 and never reuses another request's result. Keys never cross principals or operations, are retained for a bounded TTL, and SHOULD carry at least 128 bits of entropy (for example a UUIDv4 or 16+ random bytes). Reuse a key only when retrying the exact same request.
1 - 255Body
The newest notification the reader saw.
^ntf_[0-9a-f]{32}$Response
The account's unread count after the marks.
0 <= x <= 100