openapi: 3.0.3
info:
title: Concord Agreements Users API
description: 'The Concord REST API provides programmatic, read-oriented access to a Concord contract lifecycle management (CLM) account. It exposes the authenticated user, the organizations that user belongs to, the agreements (contracts) within an organization, an agreement''s attachments and members, and organization-level reports, groups, and tags. All requests are authenticated with an API key passed in the `X-API-KEY` header; API key generation is available on paid plans only.
Confirmed endpoints below were validated against the live production host (https://api.concordnow.com/api/rest/1), which returns HTTP 401 `{"statusCode":401,"restCode":"unauthorized"}` when called without a valid key. Concord''s public developer reference is a rendered documentation portal (https://api.doc.concordnow.com/) and does not expose a machine-readable OpenAPI file; response schemas here are modeled from documented behavior and connector mappings, not copied from an official spec. The template document-generation operation is documented to exist but its exact path and request body are not published, so it is included and explicitly flagged as modeled/unconfirmed.'
version: '1.0'
contact:
name: Concord
url: https://www.concord.app
servers:
- url: https://api.concordnow.com/api/rest/1
description: Production
- url: https://uat.concordnow.com/api/rest/1
description: UAT / Sandbox
security:
- apiKeyAuth: []
tags:
- name: Users
description: The authenticated user and their organization memberships.
paths:
/user/me:
get:
operationId: getCurrentUser
tags:
- Users
summary: Get the authenticated user
description: Returns the profile of the user that owns the API key. Confirmed live (returns 401 without a valid key).
responses:
'200':
description: The authenticated user.
content:
application/json:
schema:
$ref: '#/components/schemas/User'
'401':
$ref: '#/components/responses/Unauthorized'
/user/me/organizations:
get:
operationId: listUserOrganizations
tags:
- Users
summary: List the user's organizations
description: Lists the organizations the authenticated user belongs to. The response payload nests the list under an `organizations` selector.
responses:
'200':
description: A list of organizations.
content:
application/json:
schema:
type: object
properties:
organizations:
type: array
items:
$ref: '#/components/schemas/Organization'
'401':
$ref: '#/components/responses/Unauthorized'
components:
schemas:
Organization:
type: object
description: Modeled representation of a Concord organization.
properties:
id:
type: string
name:
type: string
User:
type: object
description: Modeled representation of the authenticated user.
properties:
id:
type: string
email:
type: string
format: email
firstName:
type: string
lastName:
type: string
Error:
type: object
description: Modeled from the live 401 response body.
properties:
statusCode:
type: integer
restCode:
type: string
responses:
Unauthorized:
description: Missing or invalid API key. The live API returns `{"statusCode":401,"restCode":"unauthorized"}`.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
securitySchemes:
apiKeyAuth:
type: apiKey
in: header
name: X-API-KEY
description: API key generated in the Concord account (paid plans only) and sent in the `X-API-KEY` request header. Confirmed against the live production host, which returns 401 unauthorized without a valid key.