# Arthur Online > Arthur Online is a London-headquartered UK property management platform (founded 2008, acquired by Aareon in January 2021) used by letting agents, self-managing landlords, block and social housing managers, and student accommodation operators. The Arthur API v2 is a JSON REST API over 317 documented operations across 16 resource areas, secured with OAuth 2.0 Authorization Code and scoped to an account by the mandatory X-EntityID header. Arthur publishes the complete API reference anonymously as a public Postman collection, but issues credentials only to paying accounts that ask support for access. There is no RESO posture: the UK has no MLS, no NAR and no RESO certification regime. Generated by the API Evangelist enrichment pipeline on 2026-07-26. Method: generated from apis.yml plus the artifacts in this repository. Source of truth for the contract: https://developer.arthuronline.co.uk/ ## Access at a glance - Base URL: https://api.arthuronline.co.uk/v2 (401 to every anonymous request - there is no public read surface) - Auth: OAuth 2.0 Authorization Code. Authorize https://auth.arthuronline.co.uk/oauth/authorize, token https://auth.arthuronline.co.uk/oauth/token - Token lifetimes: authorization code 15 minutes, access token 14 days, refresh token 21 days - Required on every call: `Authorization: Bearer ` and `X-EntityID: `; add `Content-Type: application/json` on POST/PUT - Rate limit: 5,000 requests per hour, platform-wide; raise via Arthur technical support - Getting credentials: be inside a paying Arthur account, ask Arthur support for API access, then register an application under Settings > OAuth Applications - No scopes, no idempotency key, no sandbox, no SDKs, no CLI, no status page, no change log ## APIs - [Arthur Properties API](https://developer.arthuronline.co.uk/): Properties and everything hung off them - assets, certificates, conversations, general information, notes, units, tenancies, tasks, work orders, utilities, transactions, tags - [Arthur Units API](https://developer.arthuronline.co.uk/): Lettable units beneath a property, plus unit-level viewings, tenancies and compliance - [Arthur Tenancies API](https://developer.arthuronline.co.uk/): Tenancy agreements, tenants on a tenancy, deposit registration, recurring charges - [Arthur Tenants API](https://developer.arthuronline.co.uk/): Tenant people records and tenant-portal invitations - [Arthur Applicants API](https://developer.arthuronline.co.uk/): The lettings funnel - applicant status, credit checks, assigned managers - [Arthur Viewings API](https://developer.arthuronline.co.uk/): Viewing appointments, attached applicants, offers - [Arthur Maintenance API](https://developer.arthuronline.co.uk/): The largest surface - tasks, subtasks, work orders, quotes, contractor workflow - [Arthur Financials API](https://developer.arthuronline.co.uk/): Invoices, transactions, transaction payoff, recurring charges - [Arthur Assets API](https://developer.arthuronline.co.uk/): Files and documents shared with owners, tenants and contractors - [Arthur Utilities API](https://developer.arthuronline.co.uk/): Utility accounts and meter readings - [Arthur Certificates API](https://developer.arthuronline.co.uk/): Compliance certificates with expiry tracking - [Arthur Entities API](https://developer.arthuronline.co.uk/): The account boundary named in X-EntityID - [Arthur Conversations API](https://developer.arthuronline.co.uk/): Threaded messaging between managers, tenants, owners and contractors - [Arthur Tags API](https://developer.arthuronline.co.uk/): Cross-cutting tagging on every major record - [Arthur Notes API](https://developer.arthuronline.co.uk/): Free-text notes on any record - [Arthur Types API](https://developer.arthuronline.co.uk/): 39 read-only reference vocabularies backing every enumerated field ## Specs - [OpenAPI 3.1 (16 documents, 317 operations)](openapi/): derived operation-for-operation from the provider's public Postman collection - [AsyncAPI 3.0 webhooks](asyncapi/arthur-online-webhooks-asyncapi.yml): 125 subscribable triggers across 30 models - [Webhook catalogue](asyncapi/arthur-online-webhooks.yml): triggers, delivery contract, envelope, official payload templates - [Postman collection](collections/arthur-online.postman_collection.json): the provider's own published reference, 324 requests - [OpenAPI overlays](overlays/): API Evangelist enhancements over each derived spec ## Runtime semantics - [Conventions](conventions/arthur-online-conventions.yml): entity header, response envelope, pagination, filters, Simple types and `strict`, custom fields, data types, throttling - [Authentication](authentication/arthur-online-authentication.yml): the OAuth 2.0 profile - [Errors](errors/arthur-online-problem-types.yml): the proprietary {status, error, message} envelope and the documented 200/400/401/404 statuses - [Rate limits](rate-limits/arthur-online-rate-limits.yml): 5,000 requests per hour - [Lifecycle](lifecycle/arthur-online-lifecycle.yml): v2 URI versioning, no deprecation policy, no status page, commercial support terms - [Data model](data-model/arthur-online-data-model.yml): the entity graph read from the nested path shapes - [Vocabulary](vocabulary/arthur-online-vocabulary.yml): the 39 Types endpoints plus the core lettings terms - [Conformance](conformance/arthur-online-conformance.yml): what Arthur does and does not conform to, including the absent RESO posture - [Domain security](security/arthur-online-domain-security.yml): TLS, HSTS, SPF, DMARC probe results ## Agent surfaces - [Candidate MCP tool surface](mcp/arthur-online-mcp.yml): 317 candidate tools derived from the operations - Arthur ships no hosted MCP server - [Tool crosswalk](mcp/arthur-online-tool-crosswalk.yml): each candidate tool bound to its backing operation, plus the UI-only capabilities - [Agent skills](skills/_index.yml): packaged operating instructions for the marquee flows - [Agentic access](agentic-access/arthur-online-agentic-access.yml): recommended execution contracts per operation - [Arazzo workflows](arazzo/_index.yml): multi-step flows stitched from real operationIds ## Agent cautions - Writes are not idempotent and carry no request key. Never auto-retry a POST or PUT - it creates a duplicate record. - Send `strict=true` on POST/PUT. Without it, an unrecognised Simple type value is silently created as new reference data in the customer's account. - Resolve every enumerated value against the Types API before writing; do not guess enum members. - Records are only visible inside the entity named in X-EntityID. A wrong entity id returns 404, not 403. - Webhook deliveries are unsigned. Do not trust a payload without an out-of-band check against the API. - The API host answers 401 to everything anonymous - there is nothing to explore without customer credentials. ## Docs - [Developer portal / API reference](https://developer.arthuronline.co.uk/) - [Postman Documenter](https://documenter.getpostman.com/view/22554870/2s93sZ5YeM) - [Arthur API overview](https://www.arthuronline.co.uk/connect/arthur-api) - [Integrations directory](https://www.arthuronline.co.uk/connect/) - [Support portal / knowledge base](https://support.arthuronline.co.uk/) - [API support and bespoke endpoint terms](https://support.arthuronline.co.uk/support/solutions/articles/202000052217-api-work-providing-support) - [Pricing](https://www.arthuronline.co.uk/pricing) - [Data security FAQs](https://www.arthuronline.co.uk/legal/data-security) - [Fair usage policy](https://www.arthuronline.co.uk/legal/fair-usage-policy) - [Privacy policy](https://www.arthuronline.co.uk/legal/privacy-policy) - [Terms and conditions](https://www.arthuronline.co.uk/legal/terms-and-conditions) - [GitHub organisation](https://github.com/arthur-crm) - [Webhook payload templates](https://github.com/arthur-crm/webhookPayloadTemplates)