# Agree.com > Contract-to-cash platform combining free unlimited e-signatures with invoicing, billing and > integrated payments (ACH, card, wire). Agree.com gives the signature product away and > monetizes money movement, positioning against DocuSign and Bill.com simultaneously. Raised > $7.2M seed (Pelion Venture Partners, May 2025) after a $3M pre-seed (Better Tomorrow > Ventures). Markets an "agentic revenue operating system" built from named AI agents for > contracts, billing, collections, recovery, reconciliation and insight. This file is generated by API Evangelist from Agree.com's own public artifacts. Agree.com does not publish an llms.txt of its own (https://agree.com/llms.txt returns 404). Generated 2026-09-12. Not affiliated with or endorsed by Agree.com. ## Read this first: the documented base URL does not resolve Agree.com's documentation states "All API requests should be made to: https://api.agree.com/api/v1", and every curl example uses that host. **api.agree.com has no DNS record.** The working base URL is the one in the OpenAPI servers[] block: https://secure.agree.com/api/v1 Verified 2026-09-12: `dig api.agree.com` returns nothing; `GET https://secure.agree.com/api/v1/contacts` returns HTTP 401 as expected. Copy-pasting any documented example fails at name resolution. ## API - [OpenAPI 3.0 specification](https://secure.agree.com/documentation/openapi): The real machine-readable contract, served anonymously as JSON. 37 paths, 56 operations, 44 schemas, 6 tags. Every operation has a unique operationId, a summary and a description. - [API documentation](https://secure.agree.com/documentation): Redoc rendering of the same spec, with an extensive prose introduction and per-tag integration guides. - [Quick start](https://secure.agree.com/documentation#section/Introduction/Quick-Start): Send your first invoice in three calls. - [Developer portal](https://agree.com/developers): Marketing-level overview of the API, MCP, CLI and Embedded UI surfaces. ### Authentication Bearer API key, generated in the dashboard under Settings > API Keys. Authorization: Bearer YOUR_API_KEY The key is **organization-wide and unscoped** — the documentation states it "provides full access to your organization's data". There is no read-only key, no per-resource restriction, and no documented expiry. Rotation is manual, from the dashboard only. ### Resources - **Agreements** (8 operations) — create from a template, assign signature fields per recipient, send, fetch the executed PDF, soft delete. Exactly one recipient must hold the `owner` role. Agreements can carry an attached invoice. - **Invoices** (11 operations) — create, create-and-send in one call, recurring schedules, mark as sent or paid, invoice PDF and receipt PDF. The receipt PDF is only available once status is `paid`; any other status returns 422. - **Contacts** (5 operations) — the address book. Email is unique per organization. Created explicitly, or implicitly when you invoice a new email address. Deletion is soft. - **Customers** (5 operations) — a separate entity from Contacts; the distinction is not documented. - **Reports** (15 operations) — cash-flow stats, chart, forecast and outstanding invoices; revenue stats, chart, customers and customers-by-MRR; recovery aging (chart, invoices, trend) and leakage (stats, waterfall, stage durations, stalled invoices). - **Webhooks** (6 operations) — register endpoints, list, update, delete, send a test. ### Conventions - Success envelope: `{"data": {...}}`. Lists add `{"pagination": {"page", "page_size", "total_pages", "total_entries"}}`. - Pagination: `page` (default 1), `page_size` (default 10, max 100). Page-number, not cursor. - Errors: **not RFC 9457**. Two envelopes — `{"error": "message"}` for 400/401/403/404, and `{"errors": {"field": ["message"]}}` for 422 validation failures. No 5xx is documented. - Async PDFs: `GET /invoices/{id}/pdf` and `GET /agreements/{id}/pdf` return **202** with a `Retry-After` header (default 3s) while rendering. Repeat the same GET until 200 with `data.url`. - Tracing: responses carry `x-request-id` (undocumented, but emitted). ### What is NOT there — read before writing - **No idempotency.** There is no `Idempotency-Key` header and no request deduplication on any of the 25 mutating operations. A retried `POST /api/v1/invoices/create_and_send` after a timeout sends a second invoice and a second payment link to the customer, and nothing lets you detect it. The word "idempotency" appears once in the entire spec, as advice to *you* about handling duplicate webhooks. - **No refund operation.** Invoice status includes `refunded` and the webhook catalog includes `invoice.refunded`, but no refund, void, or reversal endpoint exists anywhere in the API. Money collected through this API cannot be returned through this API. - **No rate limits.** None documented, no `X-RateLimit-*` or `RateLimit-*` headers on live responses, and 429 does not appear in the spec. - **No dry-run.** Use the two-step `create` then `send` path — the provider recommends it — so the irreversible step is a separate, deliberate call. - **No SDKs.** No first-party client library in npm, PyPI, RubyGems, Packagist, NuGet, Maven, crates.io or pkg.go.dev, and no public GitHub organization. Generate a client from the spec. - **No status page, no changelog, no deprecation policy.** There is no mechanism to learn that the contract changed other than re-fetching and diffing it. - **No published compliance certifications.** No SOC 2, ISO 27001, or PCI DSS claim, and no trust center. The Terms of Service state the Services "are not tailored to comply with industry-specific regulations (HIPAA, FISMA, etc.)." ## MCP - MCP endpoint: `https://secure.agree.com/mcp` — a **live, hosted, remote** MCP server. It is not documented anywhere. agree.com/developers advertises "MCP — Connect Agree to AI agents through MCP" as a tile with no endpoint and no configuration snippet. The URL above was found by probing RFC 9728 protected-resource metadata, which is the only place Agree.com publishes it: - [/.well-known/oauth-protected-resource](https://secure.agree.com/.well-known/oauth-protected-resource) — `resource: https://secure.agree.com/mcp` - [/.well-known/oauth-authorization-server](https://secure.agree.com/.well-known/oauth-authorization-server) — OAuth 2.1, authorization_code + refresh_token, PKCE S256 required, dynamic client registration at `/oauth/register`, revocation at `/oauth/revoke`, one scope: `mcp`. The endpoint is OAuth-gated. An anonymous `tools/list` returns 401 with a correct RFC 9728 `WWW-Authenticate` challenge carrying `resource_metadata`. **The tool list and per-tool input schemas are not publicly knowable** and are not recorded here. The single `mcp` scope is undocumented — Agree.com publishes no statement of what it permits, so a consent screen backed by it tells a user nothing about whether the agent can send contracts or move money. ## Webhooks 12 event types, delivered at-least-once with HMAC-SHA256 signatures. Invoice: `invoice.created`, `invoice.sent`, `invoice.due`, `invoice.paid`, `invoice.failed`, `invoice.canceled`, `invoice.refunded`. Agreement: `agreement.created`, `agreement.sent`, `agreement.signed`, `agreement.executed`. Test: `webhook.test`. - Body: `{"event": "...", "payload": {full resource object}}` - Headers: `X-Webhook-Signature` (HMAC-SHA256 over the raw body, hex lowercase), `X-Webhook-Timestamp` - Secret: `whsec_`-prefixed, returned **once** at endpoint creation and never again. - Retries: 5 attempts — immediate, ~1 min, ~5 min, ~30 min, ~2 hours. Then `failure_count` increments. - Respond 200 within 5 seconds and process asynchronously. - Note: the prose documents these endpoints as `/api/v1/webhook_endpoints`; the OpenAPI declares `/api/v1/webhooks`. The OpenAPI paths are the ones that exist. ## Pricing - [Pricing](https://agree.com/pricing) - **Starter** — $0/mo, 1 seat, up to $1M annual volume. E-signatures, basic templates, basic reporting, email support. No payment processing. - **Growth** — $599/mo (20% off yearly), up to 10 users, up to $10M annual volume. Unlimited agreements, automated billing and invoicing, payment collection, automated recovery. Cards 3.5%, bank/ACH/wire 0.8%. - **Enterprise** — custom, unlimited users, up to $100M annual volume. Custom workflows, custom integrations and API access, dedicated AM, SLA, SSO. Interchange Plus on cards, free bank/ACH/wire. Plans are gated by annual payment volume, not seats or API calls. No metered API pricing. ## Integrations [HubSpot, QuickBooks, Salesforce, Slack, Xero, NetSuite, Sage](https://agree.com/integrations) ## Company - [Website](https://agree.com/) - [Terms of Service](https://agree.com/terms) - [Privacy Policy](https://agree.com/privacy) - [Sign up](https://secure.agree.com/signup) - Support: support@agree.com ## Optional - [API Evangelist profile](https://apis.io/provider/agree-com): independent third-party profile, Kin Score rating, and the derived artifacts this file summarizes.