# AdvicePay > AdvicePay is a fee-for-service billing, payment processing and engagement-management platform for > financial advisors, RIAs and broker-dealers. Firms invoice clients for financial planning advice, > collect card and ACH payments, run recurring subscriptions, capture eSignatures, and track > engagement workflows, deliverables and compliance oversight. It publishes a public REST API > (v1.0.1) covering admins, advisors, agreements, clients, custom attributes, deliverables, > engagements, invoices, notifications, offices, subscriptions and transfers. This file is generated by API Evangelist from the public AdvicePay surface. It is not published by AdvicePay — https://advicepay.com/llms.txt returns 404. ## What an agent needs to know first - The API is an **Enterprise-plan capability**. The documentation is fully public and needs no login, but calling the API requires an Enterprise contract and OAuth credentials provisioned in the developer console (partner clients: enterprise@advicepay.com). - Base URL (live): `https://app.advicepay.com/api/public/v1` - Base URL (test): `https://demo.advicepay.com/api/public/v1` — does not touch live data or banking networks. - Auth: OAuth 2.0 bearer. Authorization-code and client-credentials flows. **Access tokens expire after 5 minutes.** Refresh tokens are single-use, rotate on every use and expire after 30 days — persist the new refresh token after each refresh or you will lock out. - Only one scope exists: `all`. What a token can reach is decided by the authorizing user's role. Call `GET /api/public/v1/me` to discover which identity a token carries. - Rate limits: 10 requests/sec on everything except the agreement download endpoint, which is 1 request/sec. `X-RateLimit-*` headers on success, `Retry-After` on 429. - **There is no idempotency mechanism.** No Idempotency-Key header, no request key, no de-duplication window — on any endpoint, including the ones that move money. A retried POST can double-charge. Reconcile by reading back before retrying. - **There are no webhooks.** Change notification is polling-only: `GET /api/public/v1/notifications` with `createdAfter` / `createdBefore` Unix timestamps. - Money is integer cents. All dates are integer Unix timestamps. Ids are plain integers with no type prefix. - Pagination has two modes chosen with `pageMode`: `offset` (page/perPage/totalItems/totalPages, the default, slower at scale) and `keyset` (lastID/perPage/hasMore — use this for a full sweep). - Errors are a proprietary `{code, message, details}` JSON envelope, not RFC 9457. ## Active deprecation The invoice status `canceled` is deprecated in favour of `voided`. Filtering accepts both today. Pass `useVoidedStatus=true` to receive `voided` in payloads now. **On 2026-12-02 the API stops accepting and returning `canceled`, and `useVoidedStatus` is removed.** ## APIs - [AdvicePay API](https://docs.advicepay.com/#introduction): REST API v1.0.1 — 55 documented operations over 13 resources at `/api/public/v1`. ## Docs - [API reference](https://docs.advicepay.com/): full operation reference with request samples in Go, C#, HTTP, Java, JavaScript, Python and Ruby. - [Authentication](https://docs.advicepay.com/#authentication): OAuth 2.0 flows, client authentication methods (client_secret_post, client_secret_jwt, private_key_jwt), JWT claims. - [Common responses](https://docs.advicepay.com/#common-responses): the global error set and the rate-limit headers. - [Single sign-on](https://docs.advicepay.com/#single-sign-on): SAML 2.0 SSO and deep linking. - [Knowledge base](https://advicepay.helpscoutdocs.com/) - [Status page](https://status.advicepay.com/) — Atlassian Statuspage, machine-readable at `/api/v2/summary.json`. - [Changelog](https://advicepay.com/changelog) - [Pricing](https://advicepay.com/pricing/): Essential $10/mo, Professional $50/user/mo, Enterprise custom. Transaction fees 3.5% + $0.30 card, 1.5% ACH (min $0.30). - [Security and compliance](https://advicepay.com/security/): SOC 2 Type II (KirkpatrickPrice), PCI SAQ A, annual third-party penetration tests. Report vulnerabilities to support@advicepay.com. ## Specs AdvicePay publishes **no** machine-readable API description. Probed on 2026-09-09 across advicepay.com, app.advicepay.com, demo.advicepay.com and docs.advicepay.com: no OpenAPI or Swagger (`/openapi.json`, `/openapi.yaml`, `/swagger.json`, `/v1/openapi.json`, `/api-docs`, `/redoc` all miss), no AsyncAPI, no GraphQL, no MCP server, no A2A agent card, and no `/.well-known/` documents of any kind on any host. The reference is a server-rendered Slate page. Integrators must transcribe the contract from HTML by hand. ## API Evangelist artifacts - [Authentication profile](authentication/advicepay-authentication.yml) - [OAuth scopes](scopes/advicepay-scopes.yml) - [Error catalog](errors/advicepay-problem-types.yml) - [Rate limits](rate-limits/advicepay-rate-limits.yml) - [API conventions, idempotency and reversibility](conventions/advicepay-conventions.yml) - [Lifecycle, deprecation and status](lifecycle/advicepay-lifecycle.yml) - [Conformance and compliance](conformance/advicepay-conformance.yml) - [Data model](data-model/advicepay-data-model.yml) - [Sandbox and test environment](sandbox/advicepay-sandbox.yml) - [Plans and pricing](plans/advicepay-plans-pricing.yml) - [Changelog](changelog/advicepay-changelog.yml) - [Packages](packages/advicepay-packages.yml) — none exist - [Well-known probe](well-known/advicepay-well-known.yml) — all misses - [Candidate MCP tool list](mcp/advicepay-mcp.yml) — derived, not published by AdvicePay