openapi: 3.0.1
info:
title: Evisort Authentication API
description: Partial, externally-reconstructed OpenAPI description of the Evisort REST API (Evisort is now Workday Contract Lifecycle Management, powered by Evisort). The full, authoritative reference lives behind Evisort's developer portals (developers.evisort.com, documents.developers.evisort.com, workflow.developers.evisort.com, admin.developers.evisort.com), which require an authenticated account and are not publicly crawlable. The base URL, the API-key to JWT authentication flow, and the endpoints described here were confirmed from publicly available integration and developer documentation. Endpoints whose exact request and response schemas are not publicly documented are described accurately rather than fabricated.
version: '1.0'
contact:
name: Evisort Developer Support
url: https://developers.evisort.com/
termsOfService: https://www.evisort.com/legal
servers:
- url: https://api.evisort.com/v1
description: Evisort production REST API
security:
- bearerAuth: []
tags:
- name: Authentication
description: Exchange an Evisort API key for a short-lived JWT bearer token.
paths:
/auth/token:
post:
operationId: createToken
tags:
- Authentication
summary: Generate a JWT token from an Evisort API key
description: 'Exchanges an Evisort API key (created in the Evisort UI under the admin console / API management) for a short-lived JWT bearer token. The returned token is supplied as `Authorization: Bearer {token}` on all subsequent requests.'
parameters:
- name: EVISORT-API-KEY
in: header
required: true
description: The Evisort API key issued from the Evisort UI.
schema:
type: string
responses:
'200':
description: A JWT bearer token.
content:
application/json:
schema:
$ref: '#/components/schemas/TokenResponse'
'401':
description: Invalid or missing API key.
components:
schemas:
TokenResponse:
type: object
properties:
token:
type: string
description: A JWT bearer token used on subsequent API calls.
securitySchemes:
bearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
description: JWT bearer token obtained from POST /auth/token by presenting an Evisort API key.