Skip to main content

Developers

REST API documentation

A JSON-over-HTTPS API for Attorly's legal AI. It runs the same operations as the MCP server, with the same keys, scopes, limits and billing.

Quickstart

Upload a contract and analyse it in four steps.

  1. 1. Create a key

    Create a key in Settings › Developers and choose REST API. The same key works for the MCP server. Keep it in an environment variable:

    bash
    export ATTORLY_API_KEY=lbmcp_your_api_key
  2. 2. Upload a document

    Send the file as multipart/form-data. The response's data.id is the document's id. analyze=false stores it without starting the background analysis, because the next step runs one.

    bash
    curl -X POST https://attorly.ai/api/v1/documents \
      -H "Authorization: Bearer $ATTORLY_API_KEY" \
      -H "Idempotency-Key: $(uuidgen)" \
      -F "file=@nda.pdf" \
      -F "type=NDA" \
      -F "analyze=false"
  3. 3. Analyse it

    Prefer: wait=30 waits up to 30 seconds for the result. A finished analysis comes back as 200 with the result in data. If it takes longer, you get 202 Accepted with a Location header pointing to the operation.

    bash
    curl -i -X POST https://attorly.ai/api/v1/documents/$DOCUMENT_ID/analyses \
      -H "Authorization: Bearer $ATTORLY_API_KEY" \
      -H "Idempotency-Key: $(uuidgen)" \
      -H "Prefer: wait=30" \
      -H "Content-Type: application/json" \
      -d '{ "mode": "full", "options": { "partyRole": "BUYER" } }'
  4. 4. Collect the result

    Poll the operation until its status is succeeded or failed. The analysis is in result. Retry-After says how many seconds to wait between polls.

    bash
    curl https://attorly.ai/api/v1/operations/$OPERATION_ID \
      -H "Authorization: Bearer $ATTORLY_API_KEY"

Authentication

Send a credential in the Authorization header as a Bearer token. Keys from Settings › Developers start with lbmcp_ and work on Pro and Enterprise, for the REST API and the MCP server alike. Enterprise organization keys start with atly_ (atly_rk_ for restricted keys, atly_test_ for test mode); older lb_ keys keep working. Apps that act for a person use OAuth.

http
Authorization: Bearer atly_live_…   # or lbmcp_…, atly_test_…, an OAuth access token

Scopes

Each endpoint needs the scopes listed next to it. A key without them gets 403 insufficient_scope, and requiredScopes in the error lists every scope the call needs. Organization API keys and OAuth use these scope names:

ScopeOrganization API key scope
DOCUMENTS_READdocuments:read
DOCUMENTS_WRITEdocuments:write
DOCUMENTS_DELETEdocuments:delete
DOCUMENTS_ANALYZEanalysis:create
CLAUSES_READclauses:read
RESEARCH_READresearch:read
REDLINES_GENERATEredlines:write
NEGOTIATIONS_READnegotiations:read
WORKFLOWS_EXECUTEworkflows:execute
DUE_DILIGENCE_FULLdue-diligence:write
TEMPLATES_READtemplates:read
TEMPLATES_DRAFTdrafts:write

Errors

Every error has the same shape: a stable code to branch on, a message for people, and a requestId to quote to support.

http
HTTP/1.1 403 Forbidden
Content-Type: application/json
Request-Id: req_7Hq2LmN4pX9sT1vB3cD5eF6g
Attorly-Version: 2026-11-01

{
  "error": {
    "type": "permission_error",
    "code": "insufficient_scope",
    "message": "Insufficient permissions. Missing scope: redlines:write.",
    "requiredScopes": ["redlines:write"],
    "docUrl": "https://attorly.ai/docs/api/errors#insufficient_scope",
    "requestId": "req_7Hq2LmN4pX9sT1vB3cD5eF6g"
  }
}

Each code is explained, with what to do about it, on the error codes page

Versioning

The API is versioned by date. Send Attorly-Version to choose a version for one request; without it, a request uses the version its key was created with (keys created before versioning use 2026-10-01). Every response says which version answered. Breaking changes only come in a new version, and the changelog lists them.

http
curl https://attorly.ai/api/v1/documents \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Attorly-Version: 2026-11-01"

HTTP/1.1 200 OK
Attorly-Version: 2026-11-01
Request-Id: req_…

Idempotency

Send an Idempotency-Key header, for example a UUID, on POST, PATCH and DELETE requests. A retry with the same key and the same request gets the first response back with Idempotent-Replayed: true, and the work is not run or billed again. A key reused for a different request gets 422 idempotency_key_reused, and one still running gets 409 or, for a long-running call, the same operation. Server errors are not stored, so their retry runs again. Keys are kept for 24 hours.

bash
curl -X POST https://attorly.ai/api/v1/redlines \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $IDEMPOTENCY_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "documentId": "doc_123", "partyRole": "BUYER" }'

# IDEMPOTENCY_KEY=$(uuidgen) once per logical request; a retry with the same key and body:
HTTP/1.1 202 Accepted
Idempotent-Replayed: true

Long-running requests

From version 2026-11-01, full analyses, redlines, negotiation playbooks, workflows, due diligence reports and AI drafts answer 202 Accepted with an operation at once. Send Prefer: wait=30 to wait up to 30 seconds (at most 60) for the result first, or Prefer: respond-async to ask for 202 on any write. Poll the Location until status is succeeded or failed, or subscribe to operation.succeeded. Results are kept for 24 hours. At most 5 long-running AI operations run per organization at a time; more get 429 concurrency_limit_exceeded.

http
HTTP/1.1 202 Accepted
Location: /api/v1/operations/op_abc123
Retry-After: 2

{ "data": { "id": "op_abc123", "object": "operation", "status": "running", "resultUrl": "/api/v1/operations/op_abc123", … } }

Pagination

Lists return { object: "list", data, hasMore, nextCursor } and take limit (1 to 100, default 20) and cursor. To get the next page, send nextCursor as cursor. On the last page, nextCursor is null. Cursors stay valid while new items are added.

http
GET /api/v1/documents?limit=2

{
  "object": "list",
  "data": [ { "id": "doc_2", … }, { "id": "doc_1", … } ],
  "hasMore": true,
  "nextCursor": "eyJ0IjoiMjAyNi0xMC0xMVQxMDowMDowMC4wMDBaIiwiaWQiOiJkb2NfMSJ9"
}

GET /api/v1/documents?limit=2&cursor=eyJ0IjoiMjAy…

Rate limits

A request counts against several windows: the key's hourly limit, 300 a minute per person, 600 a minute per organization, a per-minute limit per key for reads, writes and AI calls, and each operation's own limit. REST and MCP share the same counters. The RateLimit-Policy and RateLimit headers show every window; X-RateLimit-* shows the one closest to running out. Over a limit you get 429 with Retry-After.

http
RateLimit-Policy: "key-hour";q=1000;w=3600, "user-minute";q=300;w=60, "org-minute";q=600;w=60, "ai-minute";q=30;w=60, "tool";q=10;w=60
RateLimit: "key-hour";r=998;t=3412, "user-minute";r=297;t=41, "org-minute";r=590;t=41, "ai-minute";r=29;t=41, "tool";r=9;t=41
X-RateLimit-Limit: 10
X-RateLimit-Remaining: 9
X-RateLimit-Reset: 1791720000

Webhooks

Create an endpoint with POST /api/v1/webhook-endpoints to be told when work finishes, instead of polling. Attorly sends a POST with a JSON event and signs it per Standard Webhooks with the endpoint's whsec_ secret. Verify the signature before you trust the body, answer 2xx within 15 seconds and deduplicate on webhook-id: failed deliveries are retried for 72 hours. You can roll the secret, send a test event and see every delivery.

typescript
import crypto from 'node:crypto';

// Standard Webhooks: verify before you parse. secret is the endpoint's whsec_… value.
export function verifyAttorlyWebhook(rawBody: string, headers: Headers, secret: string): unknown {
  const id = headers.get('webhook-id');
  const timestamp = headers.get('webhook-timestamp');
  const signatures = headers.get('webhook-signature') ?? '';
  if (!id || !timestamp) throw new Error('Missing webhook headers');
  if (Math.abs(Date.now() / 1000 - Number(timestamp)) > 300) throw new Error('Timestamp too old');

  const key = Buffer.from(secret.replace(/^whsec_/, ''), 'base64');
  const expected = crypto.createHmac('sha256', key).update(`${id}.${timestamp}.${rawBody}`).digest();
  const valid = signatures.split(' ').some((entry) => {
    const [version, value] = entry.split(',');
    const given = Buffer.from(value ?? '', 'base64');
    return version === 'v1' && given.length === expected.length && crypto.timingSafeEqual(given, expected);
  });
  if (!valid) throw new Error('Invalid signature');
  return JSON.parse(rawBody); // Deduplicate on webhook-id: a delivery can arrive more than once.
}

Test mode

Test keys (atly_test_…) reach every endpoint, but work on separate test data and return fixed sample results: no AI runs and no credits are used. A test key never sees live data. Put a magic value such as __fail_credits__, __fail_consent__ or __slow__ in any text field to get that failure or delay. DELETE /api/v1/test-data clears everything a test key created.

bash
curl -X POST https://attorly.ai/api/v1/analyses \
  -H "Authorization: Bearer atly_test_…" \
  -H "Content-Type: application/json" \
  -d '{ "mode": "quick", "content": "__fail_credits__" }'

HTTP/1.1 402 Payment Required
{ "error": { "code": "insufficient_credits", "message": "Test mode: the AI credits are used up …" } }

OAuth

Apps that act for an Attorly user sign in with OAuth 2.1: discovery at /.well-known/oauth-authorization-server, dynamic client registration, and the authorization code flow with PKCE (S256). Ask for resource=https://attorly.ai/api/v1 to get a token for the REST API; a token issued for the MCP server is refused here. Add offline_access to get a refresh token. The person picks the organization and can narrow the scopes on the consent screen.

http
GET https://attorly.ai/.well-known/oauth-protected-resource/api/v1
GET https://attorly.ai/.well-known/oauth-authorization-server

GET https://attorly.ai/api/oauth/authorize?response_type=code&client_id=…&redirect_uri=…
    &code_challenge=…&code_challenge_method=S256&scope=documents:read%20offline_access
    &resource=https://attorly.ai/api/v1&state=…

POST https://attorly.ai/api/oauth/token
grant_type=authorization_code&code=…&code_verifier=…&redirect_uri=…&client_id=…&resource=https://attorly.ai/api/v1

Billing

Operations that run AI draw on the same AI credits as the Attorly app, from the key owner's wallet or their organization's, whether you call them over REST or MCP. When the credits run out you get 402 insufficient_credits. Test-mode calls are free.

Plans

The API is included in Pro and Enterprise. If the key owner's plan no longer includes API access, or the owner has left the organization, requests are refused with 403.

Reference

Every operation, generated from the OpenAPI document the API serves. Paths are relative to https://attorly.ai. Successful responses wrap the result in data. Field descriptions are in English.

Documents

GET/api/v1/documentslistDocuments

List the stored documents the key can read, newest first.

Scope:DOCUMENTS_READ
Query parameters
FieldTypeDescription
type"EMPLOYMENT_CONTRACT" | "LEASE_AGREEMENT" | "PURCHASE_AGREEMENT" | "NDA" | "TERMS_OF_SERVICE" | "EMAIL" | …Only documents of this kind
status"PENDING" | "PROCESSING" | "ANALYZED" | "FAILED"Only documents in this processing state
querystringOnly documents whose name contains this text
includeArchivedbooleanAlso list archived documents (left out by default)
limitinteger
cursorstringPass the nextCursor of the previous page to get the next one
curl
curl "https://attorly.ai/api/v1/documents?limit=20" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
POST/api/v1/documentsuploadDocument

Upload a document as multipart/form-data, or as JSON with base64 content or plain text. It is analysed in the background unless analyze is false.

Scope:DOCUMENTS_WRITEUses AI creditsAccepts file uploads
Request body
FieldTypeDescription
filenamerequiredstringThe file name with its extension, e.g. "nda.pdf"; the extension decides the file type when mimeType is absent
contentBase64stringThe file, base64-encoded
textstringPlain text to store as a .txt document, instead of contentBase64
mimeTypestringThe file's MIME type; checked against its content
namestringDisplay name; defaults to the file name
type"EMPLOYMENT_CONTRACT" | "LEASE_AGREEMENT" | "PURCHASE_AGREEMENT" | "NDA" | "TERMS_OF_SERVICE" | "EMAIL" | …What the document is
urlstring (uri)An https URL Attorly downloads the file from (public hosts only, up to 10 MB), instead of contentBase64 or text
analyzebooleanAnalyse the document in the background after upload, as the app does (uses AI credits). false stores it only
Response data (201)
FieldTypeDescription
idrequiredstring
namerequiredstring
originalNamerequiredstring
typerequired"EMPLOYMENT_CONTRACT" | "LEASE_AGREEMENT" | "PURCHASE_AGREEMENT" | "NDA" | "TERMS_OF_SERVICE" | "EMAIL" | …
sizerequiredinteger
statusrequired"PENDING" | "PROCESSING" | "ANALYZED" | "FAILED"PENDING until processing starts; ANALYZED once the analysis is stored
analysisQueuedrequiredbooleantrue when the background analysis was started
createdAtrequiredstringISO 8601 date-time
urlrequiredstringWhere the document opens in Attorly
curl
curl -X POST "https://attorly.ai/api/v1/documents" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "filename": "nda.txt",
  "text": "This Mutual Non-Disclosure Agreement is entered into by…",
  "type": "NDA"
}'
GET/api/v1/documents/searchsearchDocuments

Search the text of the documents the key can read, by meaning and by exact words.

Scope:DOCUMENTS_READ
Query parameters
FieldTypeDescription
queryrequiredstringWhat to look for, in plain language or exact words
type"EMPLOYMENT_CONTRACT" | "LEASE_AGREEMENT" | "PURCHASE_AGREEMENT" | "NDA" | "TERMS_OF_SERVICE" | "EMAIL" | …Only documents of this kind
limitinteger
cursorstringPass the nextCursor of the previous page to get the next one
curl
curl "https://attorly.ai/api/v1/documents/search?query=limitation+of+liability&limit=10" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
GET/api/v1/documents/{documentId}getDocument

Get a document, its processing status and its latest analysis.

Scope:DOCUMENTS_READ
Path parameters
FieldTypeDescription
documentIdrequiredstring
Response data (200)
FieldTypeDescription
idrequiredstring
namerequiredstring
originalNamerequiredstring
typerequired"EMPLOYMENT_CONTRACT" | "LEASE_AGREEMENT" | "PURCHASE_AGREEMENT" | "NDA" | "TERMS_OF_SERVICE" | "EMAIL" | …
mimeTyperequiredstring
sizerequiredinteger
statusrequired"PENDING" | "PROCESSING" | "ANALYZED" | "FAILED"PENDING until processing starts; ANALYZED once the analysis is stored
archivedrequiredboolean
ownedByYourequiredboolean
createdAtrequiredstringISO 8601 date-time
updatedAtrequiredstringISO 8601 date-time
fileAvailablerequiredbooleanfalse when the stored file can no longer be read
governingLawRequiredrequiredbooleantrue when the analysis is held until a governing law is chosen for the document in Attorly
latestAnalysisrequiredobject | null
urlrequiredstringWhere the document opens in Attorly
curl
curl "https://attorly.ai/api/v1/documents/doc_abc123" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
DELETE/api/v1/documents/{documentId}deleteDocument

Permanently delete a document you own.

Scope:DOCUMENTS_DELETE
Path parameters
FieldTypeDescription
documentIdrequiredstring
Response data (200)
FieldTypeDescription
idrequiredstring
deletedrequiredtrue
curl
curl -X DELETE "https://attorly.ai/api/v1/documents/doc_abc123" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)"
POST/api/v1/analysescreateAnalysis

Analyse a document or inline text. mode is full (stored document) or quick.

Scope:DOCUMENTS_ANALYZEDOCUMENTS_READUses AI credits

The body's mode field picks one of: mode: full, mode: quick.

Request body
FieldTypeDescription
mode"full" | "quick"Runs documents_analyze.
documentIdstring
contentstring
mimeTypestring
optionsobject
curl
curl -X POST "https://attorly.ai/api/v1/analyses" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "mode": "quick",
  "content": "This Agreement is entered into by and between…"
}'
GET/api/v1/documents/{documentId}/analyseslistDocumentAnalyses

List a document's stored analyses, newest first.

Scope:DOCUMENTS_READ
Path parameters
FieldTypeDescription
documentIdrequiredstring
Query parameters
FieldTypeDescription
limitinteger
cursorstringPass the nextCursor of the previous page to get the next one
curl
curl "https://attorly.ai/api/v1/documents/doc_abc123/analyses" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
POST/api/v1/documents/{documentId}/analysescreateDocumentAnalysis

Analyse a stored document.

Scope:DOCUMENTS_ANALYZEDOCUMENTS_READUses AI credits
Path parameters
FieldTypeDescription
documentIdrequiredstring

The body's mode field picks one of: mode: full, mode: quick.

Request body
FieldTypeDescription
mode"full" | "quick"Runs documents_analyze.
contentstring
mimeTypestring
optionsobject
curl
curl -X POST "https://attorly.ai/api/v1/documents/doc_abc123/analyses" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "mode": "full",
  "options": {
    "partyRole": "BUYER"
  }
}'
GET/api/v1/documents/{documentId}/textgetDocumentText

Extract the plain text of a stored PDF or DOCX document.

Scope:DOCUMENTS_READ
Path parameters
FieldTypeDescription
documentIdrequiredstring
Query parameters
FieldTypeDescription
offsetintegerCharacter offset to start from; pass the nextOffset of the previous call to read on
maxCharactersintegerMost characters to return in this call
Response data (200)
FieldTypeDescription
textrequiredstringThe document text from offset (untrusted content)
documentNamerequiredstring
documentTyperequiredstring
mimeTyperequiredstring | null
characterCountrequiredintegerCharacters in the whole document
wordCountrequiredintegerWords in the whole document
offsetrequiredinteger
nextOffsetrequiredinteger | nullPass as offset to read on; null when the text ends here
truncatedrequiredbooleantrue when the text continues past this slice
curl
curl "https://attorly.ai/api/v1/documents/doc_abc123/text" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
GET/api/v1/analyses/{analysisId}getAnalysis

Get a stored analysis: summary, risk, key terms, clauses and recommendations.

Scope:DOCUMENTS_READ
Path parameters
FieldTypeDescription
analysisIdrequiredstring
Response data (200)
FieldTypeDescription
idrequiredstring
documentIdrequiredstring
documentNamerequiredstring
summaryrequiredstring | null
riskLevelrequired"LOW" | "MEDIUM" | "HIGH" | "CRITICAL"
riskScorerequirednumber
keyTermsrequiredarray of any
clausesrequiredarray of any
recommendationsrequiredarray of any
moderequiredstringSINGLE or CONSENSUS
createdAtrequiredstringISO 8601 date-time
urlrequiredstring
curl
curl "https://attorly.ai/api/v1/analyses/your_analysisId" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
POST/api/v1/comparisonscreateComparison

Compare two documents or texts line by line.

Scope:DOCUMENTS_READ
Request body
FieldTypeDescription
sourceDocumentIdstring
sourceContentstring
targetDocumentIdstring
targetContentstring
Response data (200)
FieldTypeDescription
differencesrequiredarray of object
summaryrequiredobject
curl
curl -X POST "https://attorly.ai/api/v1/comparisons" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "sourceDocumentId": "doc_abc123",
  "targetDocumentId": "doc_def456"
}'

Clauses

GET/api/v1/clausessearchClauses

Search the clause library.

Scope:CLAUSES_READ
Query parameters
FieldTypeDescription
queryrequiredstring
category"INDEMNIFICATION" | "LIABILITY" | "TERMINATION" | "CONFIDENTIALITY" | "INTELLECTUAL_PROPERTY" | "PAYMENT" | …
jurisdictionstring
riskLevel"LOW" | "MEDIUM" | "HIGH" | "CRITICAL"
limitinteger
Response data (200)
FieldTypeDescription
clausesrequiredarray of object
countrequiredinteger
curl
curl "https://attorly.ai/api/v1/clauses?query=limitation+of+liability&limit=5" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
POST/api/v1/clauses/risk-assessmentscreateClauseRiskAssessment

Assess the risk of a clause.

Scope:CLAUSES_READ
Request body
FieldTypeDescription
clauseTextrequiredstring
category"INDEMNIFICATION" | "LIABILITY" | "TERMINATION" | "CONFIDENTIALITY" | "INTELLECTUAL_PROPERTY" | "PAYMENT" | …The kind of clause; its risk rules are applied
jurisdictionstringISO 3166-1 alpha-2 country code; defaults to international
contractTypestring
partyRole"BUYER" | "SELLER" | "LANDLORD" | "TENANT" | "EMPLOYER" | "EMPLOYEE" | …
Response data (200)
FieldTypeDescription
clauseTextstring
clauseTyperequiredstring
jurisdictionrequiredstring
overallRiskScorerequirednumber
riskLevelrequired"LOW" | "MEDIUM" | "HIGH" | "CRITICAL"
riskFactorsrequiredarray of object
recommendationsrequiredarray of string
alternativesarray of object
complianceIssuesarray of object
negotiationTipsarray of string
curl
curl -X POST "https://attorly.ai/api/v1/clauses/risk-assessments" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "clauseText": "The Supplier’s total liability shall not exceed the fees paid in the preceding month.",
  "category": "LIABILITY",
  "partyRole": "BUYER"
}'
POST/api/v1/clauses/market-comparisonscreateClauseMarketComparison

Compare a clause with market-standard language.

Scope:CLAUSES_READ
Request body
FieldTypeDescription
clauseTextrequiredstring
categoryrequired"INDEMNIFICATION" | "LIABILITY" | "TERMINATION" | "CONFIDENTIALITY" | "INTELLECTUAL_PROPERTY" | "PAYMENT" | …
contractTypestring
jurisdictionstring
Response data (200)
FieldTypeDescription
inputClauserequiredstring
categoryrequiredstring
marketStandardsrequiredarray of object
comparisonrequiredobject
curl
curl -X POST "https://attorly.ai/api/v1/clauses/market-comparisons" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "clauseText": "Either party may terminate this Agreement on 10 days’ written notice.",
  "category": "TERMINATION"
}'
POST/api/v1/clauses/playbook-checkscreateClausePlaybookCheck

Check a clause against a playbook.

Scope:CLAUSES_READ
Request body
FieldTypeDescription
clauseTextrequiredstring
playbookIdrequiredstring
Response data (200)
FieldTypeDescription
playbookNamerequiredstring
compliantrequiredboolean
violationsrequiredarray of string
warningsrequiredarray of string
rulesCheckedrequiredinteger
curl
curl -X POST "https://attorly.ai/api/v1/clauses/playbook-checks" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "clauseText": "This Agreement is governed by the laws of England.",
  "playbookId": "pb_abc123"
}'

Research

POST/api/v1/research/searchessearchResearch

Search legal sources such as Lovdata, EUR-Lex and CourtListener.

Scope:RESEARCH_READUses AI credits
Request body
FieldTypeDescription
queryrequiredstring
jurisdictionsarray of stringISO 3166-1 alpha-2 country code to search under, or "EU"; the first entry is used. Defaults to the key owner's country.
sourcesarray of "lovdata" | "eurlex" | "legislation_uk" | "congress_gov" | "courtlistener" | "finlex"Keep only results from these publishers
dateFromstringKeep only dated results on or after this day
dateTostringKeep only dated results on or before this day
limitinteger
Response data (200)
FieldTypeDescription
queryrequiredstring
jurisdictionrequiredstring
resultsrequiredarray of object
totalCountrequiredintegerResults matching the filters, before limit
sourcesstring
curl
curl -X POST "https://attorly.ai/api/v1/research/searches" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "query": "notice period for terminating a commercial lease",
  "jurisdictions": [
    "NO"
  ],
  "limit": 5
}'
GET/api/v1/research/statutesgetStatute

Look up a statute by citation.

Scope:RESEARCH_READUses AI credits
Query parameters
FieldTypeDescription
citationrequiredstring
jurisdictionrequiredstringISO 3166-1 alpha-2 country code, or "EU"
Response data (200)
FieldTypeDescription
idrequiredstring
titlerequiredstring
sourcerequiredstring
jurisdictionstring
citationstring
urlstring
datestring
excerptstring
relevanceScorenumber
attributionstring
asOfstring
curl
curl "https://attorly.ai/api/v1/research/statutes?citation=LOV-1999-03-26-17&jurisdiction=NO" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"

Redlines

POST/api/v1/redlinescreateRedlines

Generate redline suggestions for a document or text.

Scope:REDLINES_GENERATEUses AI credits
Request body
FieldTypeDescription
documentIdstring
contentstring
partyRolerequired"BUYER" | "SELLER" | "LANDLORD" | "TENANT" | "EMPLOYER" | "EMPLOYEE"
riskTolerance"CONSERVATIVE" | "MODERATE" | "AGGRESSIVE"
focusAreasarray of string
playbookIdstringRedline against this playbook's position ladders (own, organisation, system or shared playbooks)
side"OUR_PAPER" | "THEIR_PAPER" | "EITHER"Whose paper the document is, to pick the playbook positions that apply
Response data (200)
FieldTypeDescription
changesrequiredarray of object
summaryobject
negotiationNotesarray of string
statisticsrequiredobject
curl
curl -X POST "https://attorly.ai/api/v1/redlines" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "documentId": "doc_abc123",
  "partyRole": "BUYER",
  "riskTolerance": "CONSERVATIVE"
}'
POST/api/v1/documents/{documentId}/redlines/resolutionsresolveRedlines

Accept or reject redline changes on a document.

Scope:REDLINES_GENERATE
Path parameters
FieldTypeDescription
documentIdrequiredstring
Request body
FieldTypeDescription
changesrequiredarray of object
Response data (200)
FieldTypeDescription
acceptedrequiredinteger
rejectedrequiredinteger
messagerequiredstring
curl
curl -X POST "https://attorly.ai/api/v1/documents/doc_abc123/redlines/resolutions" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "changes": [
    {
      "id": "chg_1",
      "action": "accept"
    },
    {
      "id": "chg_2",
      "action": "reject"
    }
  ]
}'

Negotiations

POST/api/v1/negotiations/position-analysescreateNegotiationPositionAnalysis

Analyse a negotiation position.

Scope:NEGOTIATIONS_READUses AI credits
Request body
FieldTypeDescription
documentIdstring
contentstring
partyRolerequired"BUYER" | "SELLER" | "LANDLORD" | "TENANT" | "EMPLOYER" | "EMPLOYEE"
contextobject
Response data (200)
FieldTypeDescription
overallPositionrequiredstringFAVORABLE, BALANCED or UNFAVORABLE
positionsrequiredarray of object
prioritizedConcessionsarray of string
dealBreakersarray of string
suggestedApproachstring
estimatedOutcomeobject
curl
curl -X POST "https://attorly.ai/api/v1/negotiations/position-analyses" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "documentId": "doc_abc123",
  "partyRole": "BUYER"
}'
POST/api/v1/negotiations/playbookscreateNegotiationPlaybook

Build a negotiation playbook from a strategy.

Scope:NEGOTIATIONS_READUses AI credits
Request body
FieldTypeDescription
strategyrequiredobject
contextobject
Response data (200)
FieldTypeDescription
playbookrequiredarray of object
anticipatedObjectionsrequiredarray of object
recommendationsrequiredarray of string
summaryrequiredobject
curl
curl -X POST "https://attorly.ai/api/v1/negotiations/playbooks" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "strategy": {
    "overallPosition": "collaborative",
    "priorities": [
      "Cap liability at 12 months of fees",
      "Keep Norwegian law"
    ]
  }
}'

Workflows

GET/api/v1/workflows/templateslistWorkflowTemplates

List workflow templates.

Scope:WORKFLOWS_EXECUTE
Query parameters
FieldTypeDescription
category"MA_ACQUISITION" | "MA_MERGER" | "INVESTMENT" | "IPO" | "REAL_ESTATE" | "REGULATORY" | …Due diligence project type the template is built for
limitinteger
cursorstringPass the nextCursor of the previous page to get the next one
curl
curl "https://attorly.ai/api/v1/workflows/templates?limit=20" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
GET/api/v1/workflows/executionslistWorkflowExecutions

List workflow executions, newest first, optionally for one project or status.

Scope:WORKFLOWS_EXECUTE
Query parameters
FieldTypeDescription
projectIdstringOnly executions on this due diligence project
status"PENDING" | "RUNNING" | "WAITING_FOR_INPUT" | "WAITING_FOR_APPROVAL" | "PAUSED" | "COMPLETED" | …
limitinteger
cursorstringPass the nextCursor of the previous page to get the next one
curl
curl "https://attorly.ai/api/v1/workflows/executions?status=COMPLETED&limit=20" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
POST/api/v1/workflows/executionscreateWorkflowExecution

Start a workflow on a due diligence project.

Scope:WORKFLOWS_EXECUTEUses AI credits
Request body
FieldTypeDescription
templateIdrequiredstring
projectIdrequiredstring
inputsrequiredobject
optionsobject
Response data (202)
FieldTypeDescription
executionIdrequiredstring
templateIdrequiredstring
templateNamerequiredstring
statusrequiredstring
startedAtrequiredstringISO 8601 date-time
messagerequiredstring
curl
curl -X POST "https://attorly.ai/api/v1/workflows/executions" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "templateId": "wft_abc123",
  "projectId": "ddp_abc123",
  "inputs": {}
}'
GET/api/v1/workflows/executions/{executionId}getWorkflowExecution

Get the status of a workflow execution.

Scope:WORKFLOWS_EXECUTE
Path parameters
FieldTypeDescription
executionIdrequiredstring
Query parameters
FieldTypeDescription
includeStepsboolean
Response data (200)
FieldTypeDescription
executionIdrequiredstring
templateNamerequiredstring
statusrequiredstring
startedAtstringISO 8601 date-time
completedAtstringISO 8601 date-time
variablesobject
errorstring | null
stepsarray of object
curl
curl "https://attorly.ai/api/v1/workflows/executions/wfx_abc123" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"

Due diligence

GET/api/v1/due-diligence/projectslistDueDiligenceProjects

List due diligence projects, newest first.

Scope:DUE_DILIGENCE_FULL
Query parameters
FieldTypeDescription
status"NOT_STARTED" | "IN_PROGRESS" | "UNDER_REVIEW" | "COMPLETED" | "ON_HOLD" | "CANCELLED"Only projects in this state
limitinteger
cursorstringPass the nextCursor of the previous page to get the next one
curl
curl "https://attorly.ai/api/v1/due-diligence/projects?limit=20" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
POST/api/v1/due-diligence/projectscreateDueDiligenceProject

Create a due diligence project.

Scope:DUE_DILIGENCE_FULL
Request body
FieldTypeDescription
namerequiredstring
dealTyperequired"MA_ACQUISITION" | "MA_MERGER" | "INVESTMENT" | "IPO" | "REAL_ESTATE" | "REGULATORY" | …
targetCompanystring
descriptionstring
settingsobject
Response data (201)
FieldTypeDescription
projectIdrequiredstring
namerequiredstring
projectTyperequiredstring
statusrequiredstring
createdAtrequiredstringISO 8601 date-time
messagerequiredstring
curl
curl -X POST "https://attorly.ai/api/v1/due-diligence/projects" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "Project Falcon",
  "dealType": "MA_ACQUISITION",
  "targetCompany": "Target AS"
}'
GET/api/v1/due-diligence/projects/{projectId}getDueDiligenceProject

Get a due diligence project with its document and finding counts.

Scope:DUE_DILIGENCE_FULL
Path parameters
FieldTypeDescription
projectIdrequiredstring
Response data (200)
FieldTypeDescription
idrequiredstring
namerequiredstring
descriptionrequiredstring | null
projectTyperequiredstring
statusrequiredstring
priorityrequiredstring
targetCompanyrequiredstring | null
dueDaterequiredstring | null
documentCountrequiredinteger
findingCountrequiredinteger
createdAtrequiredstringISO 8601 date-time
updatedAtrequiredstringISO 8601 date-time
completedAtrequiredstring | null
curl
curl "https://attorly.ai/api/v1/due-diligence/projects/ddp_abc123" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
POST/api/v1/due-diligence/projects/{projectId}/documentsaddDueDiligenceDocuments

Add documents to a due diligence project.

Scope:DUE_DILIGENCE_FULL
Path parameters
FieldTypeDescription
projectIdrequiredstring
Request body
FieldTypeDescription
documentIdsrequiredarray of string
categorystring
Response data (200)
FieldTypeDescription
projectIdrequiredstring
documentsAddedrequiredinteger
totalDocumentsrequiredinteger
categoryrequiredstring
messagerequiredstring
curl
curl -X POST "https://attorly.ai/api/v1/due-diligence/projects/ddp_abc123/documents" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "documentIds": [
    "doc_abc123",
    "doc_def456"
  ]
}'
GET/api/v1/due-diligence/projects/{projectId}/findingslistDueDiligenceFindings

List the findings of a due diligence project.

Scope:DUE_DILIGENCE_FULL
Path parameters
FieldTypeDescription
projectIdrequiredstring
Query parameters
FieldTypeDescription
riskLevel"INFO" | "LOW" | "MEDIUM" | "HIGH" | "CRITICAL"
categorystring
limitinteger
Response data (200)
FieldTypeDescription
projectIdrequiredstring
projectNamerequiredstring
findingsrequiredarray of object
riskSummaryrequiredobjectNumber of findings per severity
totalFindingsrequiredinteger
curl
curl "https://attorly.ai/api/v1/due-diligence/projects/ddp_abc123/findings?riskLevel=HIGH" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
POST/api/v1/due-diligence/projects/{projectId}/reportscreateDueDiligenceReport

Generate a due diligence report.

Scope:DUE_DILIGENCE_FULL
Path parameters
FieldTypeDescription
projectIdrequiredstring
Request body
FieldTypeDescription
formatrequired"pdf" | "markdown""markdown" returns the report text; "pdf" also returns the formatted PDF (base64)
sectionsarray of "executive_summary" | "risk_overview" | "findings_detail" | "document_analysis" | "recommendations"
includeRecommendationsboolean
Response data (201)
FieldTypeDescription
reportIdrequiredstring
projectIdrequiredstring
projectNamestring
formatrequired"pdf" | "markdown"
statusrequiredstring
sectionsarray of string
documentCountinteger
findingCountinteger
markdownrequiredstring
attachmentobject
messagestring
curl
curl -X POST "https://attorly.ai/api/v1/due-diligence/projects/ddp_abc123/reports" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "format": "markdown"
}'

Templates and drafts

GET/api/v1/templateslistTemplates

List document templates.

Scope:TEMPLATES_READ
Query parameters
FieldTypeDescription
category"NDA" | "EMPLOYMENT" | "SERVICE_AGREEMENT" | "LEASE" | "REAL_ESTATE" | "CORPORATE" | …
jurisdictionstringISO 3166-1 alpha-2 country code (e.g. "NO", "GB"); jurisdiction-neutral templates are always included
languagestringISO 639-1 language code of the template text (e.g. "en", "nb")
limitinteger
cursorstringPass the nextCursor of the previous page to get the next one
curl
curl "https://attorly.ai/api/v1/templates?limit=20" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
POST/api/v1/draftscreateDraft

Create a draft from a template (mode template) or with AI (mode ai).

Scope:TEMPLATES_DRAFTUses AI credits

The body's mode field picks one of: mode: template, mode: ai.

Request body
FieldTypeDescription
mode"template" | "ai"Runs templates_draft.
templateIdstring
variablesobject
optionsobject
documentTypestring
requirementsstring
contextobject
curl
curl -X POST "https://attorly.ai/api/v1/drafts" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "mode": "template",
  "templateId": "tpl_abc123",
  "variables": {
    "partyA": "Acme AS",
    "partyB": "Beta AB"
  }
}'

Operations

GET/api/v1/operations/{operationId}getOperation

Get the status and result of a request sent with Prefer or Idempotency-Key.

Path parameters
FieldTypeDescription
operationIdrequiredstring
Response data (200)
FieldTypeDescription
idrequiredstringop_…
objectrequired"operation"
operationIdrequiredstringThe REST operation that was called, e.g. createRedlines
statusrequired"running" | "succeeded" | "failed"
livemoderequiredboolean
idempotencyKeystring | null
resultUrlrequiredstringWhere to poll: /api/v1/operations/{id}
createdAtrequiredstring (date-time)
completedAtrequiredstring (date-time) | null
expiresAtrequiredstring (date-time)
httpStatusrequiredinteger | null
resultrequiredanyThe data of the successful call
metaobject
errorrequiredobject | null
curl
curl "https://attorly.ai/api/v1/operations/op_abc123" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"

Webhooks

GET/api/v1/webhook-endpointslistWebhookEndpoints

List the webhook endpoints of the key's organization and mode.

curl
curl "https://attorly.ai/api/v1/webhook-endpoints" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
POST/api/v1/webhook-endpointscreateWebhookEndpoint

Create a webhook endpoint. The response holds its signing secret, shown only once.

Request body
FieldTypeDescription
urlrequiredstring (uri)HTTPS URL that receives the events
descriptionstring
enabledEventsrequiredarray of stringEvent types to receive, or ["*"] for all
includeSnapshotsbooleanSend object snapshots instead of thin { id, object } payloads, for operations made with organization API keys (calls made with personal keys and connected apps always send thin payloads). Organization owners and admins only.
Response data (201)
FieldTypeDescription
idrequiredstringwe_…
objectrequired"webhook_endpoint"
urlrequiredstring
descriptionstring | null
enabledEventsrequiredarray of string
statusrequired"enabled" | "disabled"
disabledReasonstring | nulldisabled_by_user or failing_deliveries
livemoderequiredboolean
includeSnapshotsrequiredboolean
apiVersionrequiredstring
failingSincestring (date-time) | null
createdAtrequiredstring (date-time)
updatedAtrequiredstring (date-time)
secretstringwhsec_… — only when the endpoint is created or its secret rolled
curl
curl -X POST "https://attorly.ai/api/v1/webhook-endpoints" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "url": "https://example.com/attorly/webhooks",
  "description": "Production receiver",
  "enabledEvents": [
    "analysis.completed",
    "operation.succeeded",
    "operation.failed"
  ]
}'
GET/api/v1/webhook-endpoints/{endpointId}getWebhookEndpoint

Get a webhook endpoint.

Path parameters
FieldTypeDescription
endpointIdrequiredstring
Response data (200)
FieldTypeDescription
idrequiredstringwe_…
objectrequired"webhook_endpoint"
urlrequiredstring
descriptionstring | null
enabledEventsrequiredarray of string
statusrequired"enabled" | "disabled"
disabledReasonstring | nulldisabled_by_user or failing_deliveries
livemoderequiredboolean
includeSnapshotsrequiredboolean
apiVersionrequiredstring
failingSincestring (date-time) | null
createdAtrequiredstring (date-time)
updatedAtrequiredstring (date-time)
secretstringwhsec_… — only when the endpoint is created or its secret rolled
curl
curl "https://attorly.ai/api/v1/webhook-endpoints/your_endpointId" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
PATCH/api/v1/webhook-endpoints/{endpointId}updateWebhookEndpoint

Change an endpoint's URL, events or snapshots, or disable and enable it.

Path parameters
FieldTypeDescription
endpointIdrequiredstring
Request body
FieldTypeDescription
urlstring (uri)
descriptionstring | null
enabledEventsarray of string
includeSnapshotsboolean
status"enabled" | "disabled"Disable to pause deliveries; enable to resume
Response data (200)
FieldTypeDescription
idrequiredstringwe_…
objectrequired"webhook_endpoint"
urlrequiredstring
descriptionstring | null
enabledEventsrequiredarray of string
statusrequired"enabled" | "disabled"
disabledReasonstring | nulldisabled_by_user or failing_deliveries
livemoderequiredboolean
includeSnapshotsrequiredboolean
apiVersionrequiredstring
failingSincestring (date-time) | null
createdAtrequiredstring (date-time)
updatedAtrequiredstring (date-time)
secretstringwhsec_… — only when the endpoint is created or its secret rolled
curl
curl -X PATCH "https://attorly.ai/api/v1/webhook-endpoints/your_endpointId" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)"
DELETE/api/v1/webhook-endpoints/{endpointId}deleteWebhookEndpoint

Delete a webhook endpoint and its delivery history.

Path parameters
FieldTypeDescription
endpointIdrequiredstring
Response data (200)
FieldTypeDescription
idrequiredstring
objectrequired"webhook_endpoint"
deletedrequiredtrue
curl
curl -X DELETE "https://attorly.ai/api/v1/webhook-endpoints/your_endpointId" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)"
POST/api/v1/webhook-endpoints/{endpointId}/secret-rollsrollWebhookEndpointSecret

Replace the signing secret. The old one keeps signing for 24 hours.

Path parameters
FieldTypeDescription
endpointIdrequiredstring
Response data (200)
FieldTypeDescription
idrequiredstringwe_…
objectrequired"webhook_endpoint"
urlrequiredstring
descriptionstring | null
enabledEventsrequiredarray of string
statusrequired"enabled" | "disabled"
disabledReasonstring | nulldisabled_by_user or failing_deliveries
livemoderequiredboolean
includeSnapshotsrequiredboolean
apiVersionrequiredstring
failingSincestring (date-time) | null
createdAtrequiredstring (date-time)
updatedAtrequiredstring (date-time)
secretstringwhsec_… — only when the endpoint is created or its secret rolled
curl
curl -X POST "https://attorly.ai/api/v1/webhook-endpoints/your_endpointId/secret-rolls" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)"
POST/api/v1/webhook-endpoints/{endpointId}/test-eventssendWebhookTestEvent

Send a webhook_endpoint.test event to this endpoint only.

Path parameters
FieldTypeDescription
endpointIdrequiredstring
Response data (202)
FieldTypeDescription
eventIdrequiredstring
curl
curl -X POST "https://attorly.ai/api/v1/webhook-endpoints/your_endpointId/test-events" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)"
GET/api/v1/webhook-endpoints/{endpointId}/deliverieslistWebhookDeliveries

List an endpoint's deliveries, newest first, with their attempts and outcome.

Path parameters
FieldTypeDescription
endpointIdrequiredstring
Query parameters
FieldTypeDescription
limitintegerItems per page, 1–100 (default 20)
cursorstringThe nextCursor of the previous page
status"pending" | "succeeded" | "failed"Only deliveries in this state
curl
curl "https://attorly.ai/api/v1/webhook-endpoints/your_endpointId/deliveries" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"

Events

GET/api/v1/eventslistEvents

List the events of the last 30 days, newest first.

Query parameters
FieldTypeDescription
limitintegerItems per page, 1–100 (default 20)
cursorstringThe nextCursor of the previous page
typestringOnly events of this type, e.g. analysis.completed
curl
curl "https://attorly.ai/api/v1/events" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
GET/api/v1/events/{eventId}getEvent

Get an event as webhook endpoints receive it.

Path parameters
FieldTypeDescription
eventIdrequiredstring
Response data (200)
FieldTypeDescription
idrequiredstringevt_… — also sent as the webhook-id header; deduplicate on it
objectrequired"event"
typerequired"analysis.completed" | "analysis.failed" | "redlines.generated" | "due_diligence.report.completed" | "operation.succeeded" | "operation.failed" | …
apiVersionrequiredstring
createdAtrequiredstring (date-time)
livemoderequiredboolean
datarequiredobject
curl
curl "https://attorly.ai/api/v1/events/your_eventId" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
POST/api/v1/events/{eventId}/redeliveriesredeliverEvent

Send an event again, to one endpoint or to every endpoint subscribed to it.

Path parameters
FieldTypeDescription
eventIdrequiredstring
Request body
FieldTypeDescription
endpointIdstringOnly this endpoint; default every endpoint subscribed to the event
Response data (202)
FieldTypeDescription
eventIdrequiredstring
deliveriesScheduledrequiredinteger
curl
curl -X POST "https://attorly.ai/api/v1/events/your_eventId/redeliveries" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
  "endpointId": "we_abc123"
}'

Account, usage and logs

GET/api/v1/organizationgetOrganization

The key's organization: plan, AI credits, default jurisdiction and what the key may do.

Response data (200)
FieldTypeDescription
organizationrequiredobject
userrequiredobject
planrequiredstringSTANDARD, PRO or ENTERPRISE
billingrequiredobject
defaultJurisdictionrequiredstring | nullISO 3166-1 alpha-2 country used when a document names no governing law
credentialrequiredobject
appUrlrequiredstring
curl
curl "https://attorly.ai/api/v1/organization" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
GET/api/v1/usagegetUsage

Requests per day, key and operation, with error counts, over REST and MCP.

Query parameters
FieldTypeDescription
fromanyISO 8601 date; default 30 days ago (requests are kept 30 days)
toanyISO 8601 date, exclusive; default now
curl
curl "https://attorly.ai/api/v1/usage" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
GET/api/v1/request-logslistRequestLogs

List the organization's API requests of the last 30 days, newest first.

Query parameters
FieldTypeDescription
limitintegerItems per page, 1–100 (default 20)
cursorstringThe nextCursor of the previous page
statusstring2xx, 4xx, 5xx, or an exact status
credentialIdstringOnly requests made with this key (apikey:<id>, or an MCP connection id)
operationIdstringOnly calls of this operation, e.g. createRedlines
requestIdstringOne request, by its Request-Id
sinceanyISO 8601; only requests at or after this time
untilanyISO 8601; only requests before this time
curl
curl "https://attorly.ai/api/v1/request-logs" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
GET/api/v1/audit-eventslistAuditEvents

Who called what, when and with which key. For organization owners and admins.

Query parameters
FieldTypeDescription
limitintegerItems per page, 1–100 (default 20)
cursorstringThe nextCursor of the previous page
statusstring2xx, 4xx, 5xx, or an exact status
credentialIdstringOnly requests made with this key (apikey:<id>, or an MCP connection id)
operationIdstringOnly calls of this operation, e.g. createRedlines
requestIdstringOne request, by its Request-Id
sinceanyISO 8601; only requests at or after this time
untilanyISO 8601; only requests before this time
curl
curl "https://attorly.ai/api/v1/audit-events" \
  -H "Authorization: Bearer $ATTORLY_API_KEY"
DELETE/api/v1/test-datadeleteTestData

Delete every test-mode object, event and operation of the organization. Test keys only.

Response data (200)
FieldTypeDescription
objectrequired"test_data_purge"
deletedrequiredobject
curl
curl -X DELETE "https://attorly.ai/api/v1/test-data" \
  -H "Authorization: Bearer $ATTORLY_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)"