# Act! CRM > Act! is a CRM and marketing automation platform for small and mid-sized businesses, sold as Act! Advantage (cloud) and Act! Premium Desktop (on-premises). Its integration surface is the **Act! Web API**: a JSON REST API over the Act! database with OData query support, 410 operations across 31 resource areas, described by a Swagger 2.0 document the provider serves publicly. Generated by API Evangelist on 2026-08-13. Act! does not publish an llms.txt of its own (https://www.act.com/llms.txt and https://developer.act.com/llms.txt both return 404, probed 2026-08-13). This file is written from the provider's own published documentation and from the artifacts in this repo. ## What an agent most needs to know first - **There is no single Act! API host.** The Web API is an IIS application deployed per database. Act! Premium Cloud tenants are reached at `https://{server}/{customer}-api/act.web.api`; self-hosted customers run `https://{server}/act.web.api` on their own server. `https://apimta.act.com/act.web.api` is Act!'s public reference instance (Act! Premium Cloud API — US region). Ask the user for their host; do not assume one. - **There are no API keys.** Authentication is the end user's Act! username and password, exchanged for a JWT. That means an integration holds full user credentials — there is no OAuth, no scoped token, and no way to grant an agent narrower access than the human has. - **The schema is per-tenant.** Act! databases carry custom fields and custom entities. Call `GET /api/metadata/fields` and `GET /api/metadata/entities` before assuming a field exists. - **The API build varies by install.** `GET /api/system` is anonymous and returns `apiVersion`/`sdkVersion`. Call it before assuming an operation exists. - **Writes are not idempotent.** No idempotency key exists. A retried POST creates a duplicate record. ## Authenticating ``` GET https://{host}/act.web.api/authorize Authorization: Basic Act-Database-Name: ``` Returns a JWT. Send it on every subsequent request as `Authorization: Bearer `, alongside `Act-Database-Name`. A bearer token may itself be presented to `/authorize` to obtain a fresh one. Auth failure codes published by Act!: `401` unauthorized; `403` forbidden; `4030` incompatibility issue with Act!; `4031` subscription required; `4032` API access permission required. The last two are entitlement walls, not credential problems. ## Querying (OData) Collection GETs accept OData v4 options: `$filter` (eq, ne, lt, le, gt, ge; and/or; contains, startswith, endswith), `$orderby`, `$top`, `$skip`, `$select`, `$expand` (nestable). Only the collections Act! lists support them — see https://apimta.act.com/act.web.api/OData/Index. Anything unlisted throws. Paging is offset-based (`$top`/`$skip`). Responses are **bare JSON arrays** — no envelope, no total, no next link — so a client advances `$skip` until a short page comes back. Batch several requests with `POST /api/$batch` as `multipart/mixed`. ## Resource areas (31) Contacts, Companies, Groups, Opportunities, Tasks, ActivitySeries, Calendar, Notes, History, HistoryTypes, TaskTypes, SecondaryContacts, Products, CustomEntities, Documents, DocumentTypes, SupplementalFiles, MetadataInfo, Database, Users, Teams, Preferences, Configurations, Analytics, Geographics, Import, SyncData, System, Cors, Webhooks, MarketingAutomations. ## Docs - Act! Web API home (auth, error codes, endpoints, rate limits): https://apimta.act.com/act.web.api/ - OData reference: https://apimta.act.com/act.web.api/OData/Index - Webhooks reference: https://apimta.act.com/act.web.api/ActHooks/Index - Swagger UI: https://apimta.act.com/act.web.api/swagger/index.html - Swagger 2.0 document: https://apimta.act.com/act.web.api/swagger/docs/v1 - Developer landing page: https://www.act.com/developer/ - Web API Administrator's Guide (PDF): https://www.act.com/uploads/docs/en/webapi_admin_guide.pdf - Status page: https://status.act.com/ (API tracked as its own component per region) - Support obsolescence policy: https://www.act.com/obsolescence-policy/ - Pricing: https://www.act.com/pricing/ - Free trial (the documented route to API access): https://www.act.com/free-trial/ - Vulnerability disclosure policy: https://www.act.com/act-and-security/vulnerability-disclosure-policy/ ## Repo artifacts - openapi/ — 31 OpenAPI 3.1.0 documents, one per tag, converted from the provider Swagger 2.0 (verbatim original in openapi/_original/) - overlays/act-web-api-overlay.yaml — every enhancement applied on top of the provider document - authentication/act-authentication.yml — the three security schemes - conventions/act-conventions.yml — OData, paging, batching, versioning, error envelope, rate-limit signalling - errors/act-problem-types.yml — status codes, the 403 sub-codes, the ASP.NET error envelope - rate-limits/act-rate-limits.yml — the X-RateLimit-* headers Act! documents (no numbers published) - lifecycle/act-lifecycle.yml — obsolescence schedule, status page, version discovery - changelog/act-changelog.yml — the monthly What's New page - data-model/act-data-model.yml — the entity graph - asyncapi/act-webhooks.yml — the webhook catalog (polled, 15-minute default interval) - plans/act-plans-pricing.yml — product plans (there is no API plan) - packages/act-packages.yml — no first-party SDK in any registry - mcp/act-mcp.yml — no MCP server exists; candidate tools derived from real operationIds - sandbox/act-sandbox.yml — no test mode; demo-data seeding operations - conformance/act-conformance.yml — what Act! does and does not conform to - security/ — domain security probe, vulnerability disclosure, trust center - skills/ — packaged agent skills grounded in real operationIds - well-known/act-well-known.yml — every /.well-known/ path probed (all 404) ## Known gaps (2026-08-13) - No OAuth 2.0 — integrations hold the user's password. - No idempotency keys. - No RFC 9457 problem+json; errors are ASP.NET exception objects, and the public cloud API host returns full .NET stack traces to anonymous callers. - No `/.well-known/security.txt` despite a published disclosure policy. - No first-party SDK in any package registry; the newest downloadable Act! SDK is v23 while the supported product is v26. - No published rate-limit numbers and no documented status code on exhaustion. - Webhooks are polled (default 900s) and unavailable on Act! Premium Cloud. - No MCP server and no A2A agent card.