# Aaron's > Aaron's is a lease-to-own retailer of furniture, consumer electronics, home appliances and > accessories across the United States and Canada. It runs no public developer program. This file was > GENERATED by API Evangelist from probed evidence and from the one machine-readable contract Aaron's > actually publishes — it is not published by Aaron's, and Aaron's serves no llms.txt of its own > (https://www.aarons.com/llms.txt returns 404). Generated: 2026-08-29 · Method: generated · Source: this repository (all/aarons) ## What is actually callable Nothing, without credentials Aaron's does not issue. Every API surface below is live and real, and every one of them is gated. There is no developer portal, no signup, no API key, no documentation. - [Hosted Payment Page contract](https://hpp.aarons.com/openapi.json): Swagger 2.0, 15 paths, self-describing as `host: hpp.aarons.com`. The only machine-readable API contract Aaron's publishes. Bearer-token auth; tokens are not issued to third parties. - [OpenID Connect discovery](https://login.aarons.com/.well-known/openid-configuration): Okta on Aaron's custom domain. Anonymous, complete, standards-conformant. - [OAuth 2.0 authorization-server metadata](https://login.aarons.com/.well-known/oauth-authorization-server): RFC 8414. - Storefront commerce API: Salesforce B2C Commerce OCAPI **21.3** at `https://www.aarons.com/s/Aarons/dw/shop/v21_3/` — live, standards-shaped, requires a client ID Aaron's does not publish. - API gateway: `https://api.aarons.com` — Azure API Management. Live, undocumented, JSON fault envelope on every path. ## Contract - [openapi/aarons-hpp-openapi.json](openapi/aarons-hpp-openapi.json): the verbatim Hosted Payment Page Swagger 2.0 document, saved exactly as served. - [overlays/aarons-hpp-overlay.yaml](overlays/aarons-hpp-overlay.yaml): OpenAPI Overlay 1.0.0 adding the descriptions, contact and tag semantics the generated upstream document lacks. The original is never mutated. - [data-model/aarons-data-model.yml](data-model/aarons-data-model.yml): 46 entities, 28 relationships derived from the contract's `$ref` graph. ## Semantics an agent needs before calling anything - [conventions/aarons-conventions.yml](conventions/aarons-conventions.yml): no idempotency anywhere, no request tracing, no rate-limit signalling, and a `reversibility` grade of **undocumented** on a contract that authorises payments and stores cards. - [errors/aarons-problem-types.yml](errors/aarons-problem-types.yml): four incompatible error envelopes across four hosts. None is RFC 9457. The published contract declares only `200` responses. - [authentication/aarons-authentication.yml](authentication/aarons-authentication.yml) and [scopes/aarons-scopes.yml](scopes/aarons-scopes.yml): the Okta OIDC/OAuth model and the one custom Aaron's scope (`interclient_access`). - [asyncapi/aarons-hpp-webhooks.yml](asyncapi/aarons-hpp-webhooks.yml): three inbound Fiserv/Repay postback contracts. Inbound — Aaron's receives these, it does not emit events to subscribers. - [conformance/aarons-conformance.yml](conformance/aarons-conformance.yml): OAuth 2.0, OIDC, PKCE and OCAPI 21.3 conformances, all evidence-backed. No published compliance certification. - [lifecycle/aarons-lifecycle.yml](lifecycle/aarons-lifecycle.yml): no versioning policy, no deprecation policy, no SLA, no status page. ## Agent skills - [skills/aarons-hpp-payment-session.md](skills/aarons-hpp-payment-session.md) - [skills/aarons-hpp-gateway-postbacks.md](skills/aarons-hpp-gateway-postbacks.md) - [skills/aarons-hpp-autopay-retry.md](skills/aarons-hpp-autopay-retry.md) ## Human surfaces - [Aaron's](https://www.aarons.com) - [Apply / discover leasing power](https://www.aarons.com/apply) - [Customer sign in](https://login.aarons.com) - [My account](https://myaccount.aarons.com) - [EZPay](https://www.aarons.com/ezpay.html) - [Store locator](https://www.aarons.com/locations/search) - [FAQ](https://www.aarons.com/FAQ) - [Contact us](https://www.aarons.com/contact) - [Terms of service](https://www.aarons.com/terms-of-service.html) - [Privacy policy](https://www.aarons.com/privacy-policy.html) - [Privacy request portal](https://privacy.aarons.com) ## Optional - [Press releases](https://www.aarons.com/press-releases.html): corporate news, not an API changelog. - Blog: `https://blog.aarons.com/` is linked from the Aaron's homepage but currently fails TLS — the host is still serving the wildcard certificate that expired 2026-08-25. Do not fetch it. ## Not present No MCP server. No A2A agent card. No GraphQL. No gRPC or SOAP contract. No AsyncAPI. No SDK on any registry. No public GitHub organisation. No security.txt on any host. No status page. No sandbox. No CLI. No published pricing or rate limits for any API.