Attio Objects API

Top-level data model - people, companies, deals, and custom objects.

Documentation

Specifications

Other Resources

OpenAPI Specification

attio-com-objects-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Attio REST Attributes Objects API
  description: 'The Attio REST API exposes the Attio CRM''s object/attribute/record data model over HTTPS. Attio is an AI-native CRM built on flexible objects (people, companies, deals, users, workspaces, and custom objects), typed attributes, records, and lists. This specification covers the core data-model, activity, collaboration, and platform endpoints: objects, records, attributes, lists, list entries, notes, tasks, comments, threads, webhooks, workspace members, and token identification. All requests are authenticated with a Bearer access token (API key or OAuth) and scoped by granular permissions. Endpoints marked modeled in the repository review were derived from Attio''s published endpoint reference and follow Attio''s documented /v2 path conventions.'
  version: '2.0'
  contact:
    name: Attio
    url: https://attio.com
  license:
    name: Proprietary
    url: https://attio.com/legal
servers:
- url: https://api.attio.com/v2
  description: Attio REST API v2
security:
- bearerAuth: []
tags:
- name: Objects
  description: Top-level data model - people, companies, deals, and custom objects.
paths:
  /objects:
    get:
      operationId: listObjects
      tags:
      - Objects
      summary: List objects
      description: Lists all system-defined and user-defined objects in your workspace.
      responses:
        '200':
          description: A list of objects.
        '401':
          $ref: '#/components/responses/Unauthorized'
    post:
      operationId: createObject
      tags:
      - Objects
      summary: Create an object
      description: Creates a new custom object in your workspace.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
      responses:
        '200':
          description: The created object.
        '401':
          $ref: '#/components/responses/Unauthorized'
  /objects/{object}:
    parameters:
    - $ref: '#/components/parameters/Object'
    get:
      operationId: getObject
      tags:
      - Objects
      summary: Get an object
      description: Gets a single object by its ID or slug.
      responses:
        '200':
          description: The requested object.
        '404':
          $ref: '#/components/responses/NotFound'
    patch:
      operationId: updateObject
      tags:
      - Objects
      summary: Update an object
      description: Updates a single object.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
      responses:
        '200':
          description: The updated object.
components:
  responses:
    NotFound:
      description: The requested resource was not found.
    Unauthorized:
      description: The access token is missing, invalid, or lacks the required scope.
  parameters:
    Object:
      name: object
      in: path
      required: true
      description: The object ID or slug (for example people, companies, deals, or a custom object).
      schema:
        type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Attio access token (API key or OAuth 2.0 bearer token) with the required scopes.
Where this information came from

This is an independent, third-party profile of Attio Objects API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.