# DecisionLink / Xfactor.io > DecisionLink pioneered enterprise Customer Value Management (CVM) and now trades as Xfactor.io, a > revenue-operations AI platform. Its platform runs on four FastAPI services behind > `https://api.xfactor.io` — Value Proposition, Value Facts, Value Chat and Collaboration Manager — > which together publish 156 operations across four OpenAPI 3.1 documents. The documents and their > Swagger UI pages are reachable anonymously; every operation requires an Auth0-issued bearer JWT > or a customer-issued API key. Generated by API Evangelist on 2026-08-13 from the provider's own published OpenAPI documents and live probes. Xfactor.io does not serve an llms.txt of its own (`/llms.txt` returns 404) and has no developer portal, so this file is API Evangelist's rendering of a public surface, not the provider's. ## What you should know before integrating - **There is no developer program.** No portal, no pricing page, no self-service signup, no SDK, no CLI, no MCP server, no Postman collection, and no public GitHub repositories. Credentials are issued to contracted customers; the commercial motion is "Get a Demo". - **The specs are FastAPI defaults, and they are good.** All 156 operations carry a summary and a tag, 153 carry a description, and 154 operationIds are unique — but none of that was authored as documentation. It is what FastAPI emits from typed route handlers. - **No idempotency, no pagination, no rate-limit signal.** These are the three things an agent needs most and none of them exist. Retrying a POST duplicates. List endpoints are unbounded. No `RateLimit-*` or `Retry-After` header is ever returned and no `429` is declared. - **Errors are FastAPI-shaped, not RFC 9457.** `{"detail": ...}` — an array of `{loc, msg, type}` on 422, a string on 401/403/409/500. There is no error code to branch on. - **Versioning is inconsistent.** Value Proposition and Value Facts answer on both `/v1/` and `/api/v1/`; Value Chat and Collaboration Manager only on `/api/v1/`; credentials and insights are `/v2/` and require auth even for their OpenAPI document. ## APIs - [Value Proposition API](https://api.xfactor.io/v1/value-proposition/docs): 88 paths, 109 operations, 131 schemas. Value propositions, companies, benefits, costs, factors, situations, solutions, products, workflows, discovery, shares, collaborations, users and privileges. [OpenAPI](https://api.xfactor.io/v1/value-proposition/openapi.json) - [Value Facts API](https://api.xfactor.io/api/v1/value-facts/docs): 17 paths, 17 operations. Reference vocabulary for the value model — accrual, area, cost-category, expense, format, impact and case-study improvement types — plus translations and localization components. [OpenAPI](https://api.xfactor.io/v1/value-facts/openapi.json) - [Value Chat API](https://api.xfactor.io/api/v1/value-chat/docs): 17 paths, 20 operations. Growth AI chat sessions, prompts, file upload, feedback, and submit-then-poll generation jobs for value propositions and value models. A Socket.IO transport is also mounted but undocumented. [OpenAPI](https://api.xfactor.io/api/v1/value-chat/openapi.json) - [Collaboration Manager API](https://api.xfactor.io/api/v1/collaboration/docs): 8 paths, 10 operations. The buyer-facing side of a shared value proposition — its own login, plus discovery, benefits, factors and assets. [OpenAPI](https://api.xfactor.io/api/v1/collaboration/openapi.json) ## Authentication - Auth0 OIDC: issuer `https://xf-prd.us.auth0.com/`, token audience `https://api.xfactor.io/`. [Discovery document](https://xf-prd.us.auth0.com/.well-known/openid-configuration) - API keys for API-based access, stored as SHA-256 one-way hashes. [Data Processing Addendum](https://www.xfactor.io/data-processing-addendum/) - Web application: passwordless authentication and SSO/SAML. ## Operations and trust - [SLA and support services](https://www.xfactor.io/service-levels-support-services/): 99% monthly availability target, service credits from 25% to 50% of monthly fees, support 8:00 AM–6:00 PM ET weekdays, P1 response in 4 business hours. - [Trust center (SecureFrame)](https://app.secureframe.com/ext/trust-center/xfactor-io/): SOC 2 Type II, annual external penetration testing by InGuardians, AWS sub-processor. - No status page. `status.xfactor.io` does not resolve. - No changelog, no deprecation policy, no Sunset or Deprecation headers. - No `/.well-known/` document of any kind on any host the company controls. ## Company - [Website](https://www.xfactor.io/) - [Blog](https://www.xfactor.io/blog/) - [Contact and support](https://www.xfactor.io/contact-us/) - [Get a demo](https://www.xfactor.io/get-a-demo/) - [Terms of use](https://www.xfactor.io/terms-of-use/) - [Privacy notice](https://www.xfactor.io/privacy-notice/) - [Subscription and services agreement](https://www.xfactor.io/subscription-and-services-agreement/) - [GitHub organization](https://github.com/XFactor-IO) (no public repositories) ## Optional - [API Evangelist profile](https://apis.io/provider/decisionlink/) - Derived artifacts in this repository: `authentication/`, `conventions/`, `errors/`, `data-model/`, `lifecycle/`, `conformance/`, `skills/`, `mcp/` (candidate only), `overlays/`.