Concord Users API

The authenticated user and their organization memberships.

OpenAPI Specification

concord-com-users-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Concord Agreements Users API
  description: 'The Concord REST API provides programmatic, read-oriented access to a Concord contract lifecycle management (CLM) account. It exposes the authenticated user, the organizations that user belongs to, the agreements (contracts) within an organization, an agreement''s attachments and members, and organization-level reports, groups, and tags. All requests are authenticated with an API key passed in the `X-API-KEY` header; API key generation is available on paid plans only.


    Confirmed endpoints below were validated against the live production host (https://api.concordnow.com/api/rest/1), which returns HTTP 401 `{"statusCode":401,"restCode":"unauthorized"}` when called without a valid key. Concord''s public developer reference is a rendered documentation portal (https://api.doc.concordnow.com/) and does not expose a machine-readable OpenAPI file; response schemas here are modeled from documented behavior and connector mappings, not copied from an official spec. The template document-generation operation is documented to exist but its exact path and request body are not published, so it is included and explicitly flagged as modeled/unconfirmed.'
  version: '1.0'
  contact:
    name: Concord
    url: https://www.concord.app
servers:
- url: https://api.concordnow.com/api/rest/1
  description: Production
- url: https://uat.concordnow.com/api/rest/1
  description: UAT / Sandbox
security:
- apiKeyAuth: []
tags:
- name: Users
  description: The authenticated user and their organization memberships.
paths:
  /user/me:
    get:
      operationId: getCurrentUser
      tags:
      - Users
      summary: Get the authenticated user
      description: Returns the profile of the user that owns the API key. Confirmed live (returns 401 without a valid key).
      responses:
        '200':
          description: The authenticated user.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /user/me/organizations:
    get:
      operationId: listUserOrganizations
      tags:
      - Users
      summary: List the user's organizations
      description: Lists the organizations the authenticated user belongs to. The response payload nests the list under an `organizations` selector.
      responses:
        '200':
          description: A list of organizations.
          content:
            application/json:
              schema:
                type: object
                properties:
                  organizations:
                    type: array
                    items:
                      $ref: '#/components/schemas/Organization'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    Organization:
      type: object
      description: Modeled representation of a Concord organization.
      properties:
        id:
          type: string
        name:
          type: string
    User:
      type: object
      description: Modeled representation of the authenticated user.
      properties:
        id:
          type: string
        email:
          type: string
          format: email
        firstName:
          type: string
        lastName:
          type: string
    Error:
      type: object
      description: Modeled from the live 401 response body.
      properties:
        statusCode:
          type: integer
        restCode:
          type: string
  responses:
    Unauthorized:
      description: Missing or invalid API key. The live API returns `{"statusCode":401,"restCode":"unauthorized"}`.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
      description: API key generated in the Concord account (paid plans only) and sent in the `X-API-KEY` request header. Confirmed against the live production host, which returns 401 unauthorized without a valid key.