Developer API

Build on Docsliy.

In-house drafting, e-signature and audit-trail logic can cost months to build right — and duct-taping together separate document, e-sign and storage APIs just trades that cost for fragile integration surface area. Docsliy replaces both paths with one clean REST API for the whole contract lifecycle, built into your own product.

40+REST endpoints
99.99%API uptime SLA
<200msAvg. response time
Quickstart

Skip the drafting engine. One API call, done.

No prompt pipeline or PDF renderer to build yourself — send a prompt and party details, get back a fully-drafted, risk-scored contract ready for signature.

Request — cURL
# Draft a contract from a plain-language prompt
curl -X POST https://api.docsliy.io/v1/contracts \
  -H "Authorization: Bearer sk_live_••••••••••" \
  -H "Content-Type: application/json" \
  -d '{
    "template": "vendor_nda",
    "prompt": "12-month vendor NDA with mutual
      confidentiality and 30-day termination",
    "parties": [
      { "name": "Acme Inc.", "role": "disclosing_party" },
      { "name": "Nova Health", "role": "receiving_party" }
    ]
  }'
Response — 201 Created
{
  "id": "ctr_8f2ae61c",
  "status": "drafted",
  "risk_score": 96,
  "template": "vendor_nda",
  "created_at": "2026-08-12T14:02:11Z",
  "download_url": "https://api.docsliy.io/v1/
    contracts/ctr_8f2ae61c/pdf",
  "parties": [
    { "name": "Acme Inc.", "role": "disclosing_party" },
    { "name": "Nova Health", "role": "receiving_party" }
  ]
}
Core Endpoints

Nothing locked behind a UI. The API does everything too.

Most vendor APIs expose signing and little else, leaving you to script around whatever the UI can do that the API can't. Not here — anything you can do by hand in Docsliy, you can automate through the API.

GET /v1/contracts List all contracts with status, risk score and metadata
POST /v1/contracts Draft a new contract from a prompt or template
GET /v1/contracts/{id} Retrieve a single contract, including full clause history
PUT /v1/contracts/{id} Update contract terms or trigger a fresh risk re-scan
POST /v1/contracts/{id}/send Route a drafted contract for signature
GET /v1/templates List available clause and contract templates
POST /v1/signatures Request a signature event at SES, AES or QES strength
GET /v1/signatures/{id} Check signature status and retrieve the full audit trail
GET /v1/risk-scans/{contractId} Retrieve the latest AI risk score and flagged clauses
POST /v1/webhooks Register a webhook endpoint for real-time events
DELETE /v1/webhooks/{id} Remove a webhook subscription
Zero Compromises

Built for production traffic.

Too many vendor APIs are treated as a second-class add-on — thinner security, spottier reliability than the core product they sit next to. The same infrastructure and security controls that back the Docsliy product back the API too.

Authentication built for production

A leaked key shouldn't be a live-data incident. Every Docsliy key is scoped to a workspace and environment, so a leaked test key can never touch live data.

  • API keys scoped per workspace and environment (test / live)
  • OAuth 2.0 for user-delegated access in your own app
  • Rotate or revoke any key instantly from the dashboard
API Keys OAuth 2.0 Scoped Permissions

Reliable at scale

Code that passes in sandbox and breaks in production is every integration's worst surprise. Docsliy's sandbox behaves exactly like production, so what works in test ships with confidence.

  • 99.99% uptime SLA on Business and Enterprise plans
  • Automatic webhook retries with exponential backoff
  • A full sandbox environment that mirrors production exactly
  • Rate limits shown live in every response header
99.99% Uptime Auto-retry Webhooks Sandbox Mode
Real-Time Events

Never wonder if the event fired. It's the moment it happens.

A "signed" webhook that silently fails to fire is worse than no webhook at all — you find out days later, from a client. Every Docsliy event ships with automatic retries and a full delivery log, so register once and trust it landed.

Contract events

  • contract.created — a new draft is generated
  • contract.updated — terms or clauses change
  • contract.risk_flagged — a clause fails your policy
  • contract.archived — a contract is closed out

Signature events

  • signature.requested — sent for signing
  • signature.completed — fully executed
  • signature.declined — a signer declines
  • signature.expired — the signing link expires

Account & team events

  • user.invited — a teammate joins the workspace
  • workspace.plan_changed — plan upgrades or downgrades
  • api_key.rotated — a key is rotated or revoked
  • audit.export_ready — an audit log export is ready
Getting Started

No sales call, no approval queue. Live in three steps.

Most API onboarding means a signed contract and a week of waiting before you write a line of code. Here, it's a self-serve key and three steps.

1

Get an API key

Create a free workspace and grab a test key from the dashboard — no approval process, no waiting.

2

Make your first call

Use cURL or an official SDK to draft a contract in the sandbox — it behaves exactly like production.

3

Go live

Swap your test key for a live one and register a webhook — no code changes required.

Inconsistent, half-documented SDKs are their own tax on integration time. Every official Docsliy SDK is documented and versioned alongside the API itself, plus a Postman collection to explore endpoints by hand.

Node.js Python Ruby Go PHP cURL / REST
FAQ

API questions, answered.

What developers usually want settled before they start building against us.

Starter and Growth plans are limited to 120 requests per minute per API key; Enterprise plans get a custom limit tuned to your traffic. Every response includes rate-limit headers so you can back off before hitting the ceiling.
Yes — every workspace gets a sandbox environment with its own test API keys. It mirrors production behavior exactly, including webhooks, so what works in test works in live with just a key swap.
The current version is v1, included in every endpoint path. We don't make breaking changes to a published version — new capabilities are added additively, and any breaking change ships as a new version with advance notice.
Failed webhook deliveries are retried automatically with exponential backoff for up to 24 hours. You can also replay any missed event manually from the dashboard's webhook log.
Yes — every official SDK is open source and versioned alongside the API itself, so you can see exactly what a call does before you run it.
Reach the API support desk through our contact page — Business and Enterprise plans get a dedicated Slack channel with the integrations team.
Get Started Today

Ready to build on Docsliy?

No sales call, no credit card — grab a free API key and draft your first contract in under a minute.