# Agiloft

**Canonical:** https://apis.io/providers/agiloft/  
**Website:** https://www.agiloft.com/  
**APIs profiled:** 3

Agiloft is a Redwood City, California software company that sells an enterprise Contract Lifecycle Management (CLM) platform built on a no-code business process engine, used by legal, procurement, finance and IT teams to request, author, negotiate, approve, execute, store and report on agreements. Every deployment is a customer-specific knowledgebase (KB) whose tables and fields are configured per tenant, so the API surface is generated from that live configuration rather than published as one fixed catalog contract. Agiloft exposes three machine interfaces on each KB: an OpenAPI/Swagger interface generated from the tenant's own tables (browsable and downloadable inside the KB at Setup > System > View REST documentation), a stable operation-style REST interface under /ewws/ covering create, read, update, delete, upsert, select, search, attachment, lock, table introspection and action-button execution, and a legacy SOAP interface whose WSDL is likewise generated per knowledgebase. Authorization is OAuth 2.0 (authorization code, authorization code with PKCE, and client credentials) or JWT bearer tokens, with a REST operation scope list and group permissions layered on top. Agiloft also ships an outbound webhook service with URL verification and retry, and SCIM 2.0 user provisioning at /scim/v2.

## Kin Score — 49.1 / 100 (developing)

Scored 2026-09-12 under rubric 0.22.0.

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 41.6 |
| Contract Governance | 18.2 |
| Operational Transparency | 23.7 |
| Developer Ergonomics | 66.1 |
| Access Clarity | 60.5 |

## Agent readiness — 32.2 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | documented |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | yes |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (3)

- **Agiloft CLM REST API** — The Agiloft REST interface, served from every Agiloft knowledgebase under /ewws/. It exposes twenty documented operations — EWCreate, EWRead, EWUpdate, EWDelete, EWUpsert, EWSel...
- **Agiloft CLM Webhooks** — Agiloft's outbound event surface. A webhook is registered per table and event type (Create, Update or Delete), optionally filtered by a record-filter expression and by modificat...
- **Agiloft CLM SCIM 2.0 Service** — Agiloft's SCIM 2.0 user provisioning endpoint, served per knowledgebase at /scim/v2 and authenticated with a bearer token generated from the KB's SCIM profile. An identity provi...

## Security (3)

- **Agiloft Authentication** — oauth2/http/apiKey · 7 schemes
- **Agiloft Domain Security** — TLSv1.3 · HSTS · DMARC
- **Agiloft Trust Center** — SOC 1, SOC 2, ISO 27001, ISO 27701

## Plans (1)

- **Agiloft Plans Pricing**

## Tags

Contract Lifecycle Management, Contract Management, Legal, Procurement, Enterprise Software, No-Code, Workflow Automation, Document Automation, Webhooks, SCIM, Company

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/agiloft/). Scores are computed from the provider's own public artifacts under a published rubric.
