API archive entry · source-reported

Contract.fit API

This OpenAPI describes the API exposed by the contract.fit backend. ## Security ### Authentication All endpoints are protected: you need to make authenticated calls. There are 3 authentication mechanisms: - HTTP Basic (Username + Password) - JWT Token - API-Key By default you should have an account allowing you to bootstrap your tenant and create users and roles, using Basic Auth or after creating a Token - see */auth* endpoints. If you are missing credentials or permissions, please contact us. ### Authorization The security system is RBAC based: users must be granted scoped roles, allowing them to access resources. Each role grants a defined set of permissions, which can be restricted to a given inbox or document - see */roles* endpoints. ## Upload and Processing Below is a short description of common use cases of the API. ### Simple Upload The easiest and simplest way to get started is to use POST /documents : it will make a synchronous upload of your file and wait for the result. This is a simplified version of POST /documents/{inbox_id} with less arguments and settings; it may not be suitable for real workload as it offers less capabilities. ### Upload to Inbox The favored endp

Provider / source website

Plan the first integration safely

The access fields below come from the connected directory. Their likely implementation impact is explained without assuming provider-specific behavior.

Authentication

OAuth is reported. Confirm flows, scopes, consent, token lifetime, and refresh rules.

Transport

HTTPS is not confirmed. Do not send credentials or production data until secure transport is verified.

Browser access

CORS is unknown. Treat direct browser access as unconfirmed and test before choosing a client-only architecture.

First-request sequence

  1. Identify the current base URL, version, and endpoint for the use case.
  2. Confirm how credentials are issued and where they may be stored.
  3. Test success, invalid input, throttling, unavailable data, and timeouts.
  4. Record response fields, pagination, caching, and error shapes.
  5. Add monitoring, retries with backoff, and an appropriate fallback.

Questions to resolve before production

Pricing and quotas

Confirm current plans, free-tier limits, overages, and request ceilings.

Endpoint coverage

Check that the operations and response fields match the intended workload.

Reliability

Look for uptime history, a status page, support routes, and service commitments.

Data and privacy

Review retention, licensing, regional processing, and compliance requirements.

Versioning

Confirm the active version, change policy, deprecation window, and migration guidance.

Developer experience

Validate SDKs, examples, error formats, pagination, and test environments.

Source reference

APIs.guru OpenAPI Directory

This page separates source-reported facts from questions that need live provider verification.