openapi: 3.0.3 info: title: Concord Agreements Users API description: 'The Concord REST API provides programmatic, read-oriented access to a Concord contract lifecycle management (CLM) account. It exposes the authenticated user, the organizations that user belongs to, the agreements (contracts) within an organization, an agreement''s attachments and members, and organization-level reports, groups, and tags. All requests are authenticated with an API key passed in the `X-API-KEY` header; API key generation is available on paid plans only. Confirmed endpoints below were validated against the live production host (https://api.concordnow.com/api/rest/1), which returns HTTP 401 `{"statusCode":401,"restCode":"unauthorized"}` when called without a valid key. Concord''s public developer reference is a rendered documentation portal (https://api.doc.concordnow.com/) and does not expose a machine-readable OpenAPI file; response schemas here are modeled from documented behavior and connector mappings, not copied from an official spec. The template document-generation operation is documented to exist but its exact path and request body are not published, so it is included and explicitly flagged as modeled/unconfirmed.' version: '1.0' contact: name: Concord url: https://www.concord.app servers: - url: https://api.concordnow.com/api/rest/1 description: Production - url: https://uat.concordnow.com/api/rest/1 description: UAT / Sandbox security: - apiKeyAuth: [] tags: - name: Users description: The authenticated user and their organization memberships. paths: /user/me: get: operationId: getCurrentUser tags: - Users summary: Get the authenticated user description: Returns the profile of the user that owns the API key. Confirmed live (returns 401 without a valid key). responses: '200': description: The authenticated user. content: application/json: schema: $ref: '#/components/schemas/User' '401': $ref: '#/components/responses/Unauthorized' /user/me/organizations: get: operationId: listUserOrganizations tags: - Users summary: List the user's organizations description: Lists the organizations the authenticated user belongs to. The response payload nests the list under an `organizations` selector. responses: '200': description: A list of organizations. content: application/json: schema: type: object properties: organizations: type: array items: $ref: '#/components/schemas/Organization' '401': $ref: '#/components/responses/Unauthorized' components: schemas: Organization: type: object description: Modeled representation of a Concord organization. properties: id: type: string name: type: string User: type: object description: Modeled representation of the authenticated user. properties: id: type: string email: type: string format: email firstName: type: string lastName: type: string Error: type: object description: Modeled from the live 401 response body. properties: statusCode: type: integer restCode: type: string responses: Unauthorized: description: Missing or invalid API key. The live API returns `{"statusCode":401,"restCode":"unauthorized"}`. content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: apiKeyAuth: type: apiKey in: header name: X-API-KEY description: API key generated in the Concord account (paid plans only) and sent in the `X-API-KEY` request header. Confirmed against the live production host, which returns 401 unauthorized without a valid key.