# Decisiv > Decisiv operates the Service Relationship Management (SRM) platform for the commercial vehicle > industry — the network where fleets, asset owners, OEMs, dealers, independent service providers and > component suppliers work a single service event together. Its APIs cover asset registration and VIN > identification, service requests, cases, estimates, line items with VMRS coding, parts, labour, > sublet work between shops, and telematics-driven faults and diagnostic readings. Documentation is > public; credentials are provisioned by Decisiv per OAuth Application per module. This file was generated by API Evangelist from Decisiv's publicly published specifications and documentation on 2026-08-12. Decisiv does not publish an llms.txt of its own. ## APIs - [SRM Gateway — Account Management](https://srm-api.decisivapps.com/api-docs/v1?urls.primaryName=Account%20Management): accounts, users, roles, and the webhook subscription surface. OpenAPI 3.1.0, 14 paths / 21 operations. - [SRM Gateway — Asset Management](https://srm-api.decisivapps.com/api-docs/v1?urls.primaryName=Asset%20Management): the fleet view — registered assets, depots, contacts, service requests, cases, estimates, VMRS. OpenAPI 3.1.0, 64 paths / 85 operations. - [SRM Gateway — Service Management](https://srm-api.decisivapps.com/api-docs/v1?urls.primaryName=Service%20Management): the service-provider view — cases, customers, customer assets, line items, parts, charges, time tasks, sublet work. OpenAPI 3.1.0, 104 paths / 139 operations. - [SRM Gateway — Telematics](https://srm-api.decisivapps.com/api-docs/v1?urls.primaryName=Telematics): diagnostic readings and fault codes. OpenAPI 3.1.0, 4 paths / 6 operations. - [Global Assets API](https://global-assets.decisivapps.com/api-docs/): asset lookup by id or VIN plus campaigns, recalls, warranties, service history and OEM build information. Swagger 2.0 v2.1.5. - [Service Provider API](https://service-provider.decisivapps.com/api-docs/): dealer access to customers, group customers, assets and group assets. Swagger 2.0 v2.0.4. - [Platform API](https://api-docs.decisiv.net/docs/api/1): the original XML API — cases, estimates and line items, parts, VMRS, notes, attachments, estimate approval, service locations, push notifications. Versioned by Accept-Version / Accept headers, XSD schemas published. Base URLs: `https://srm-api.decisivapps.com` (SRM Gateway), `https://global-assets.decisivapps.com/api/v1/`, `https://service-provider.decisivapps.com/api/v1/`, `https://api.decisiv.net/platform_api`. Staging mirrors exist at `https://srm-api.staging.decisivapps.com` and `https://login.staging.decisivapps.com`. ## Authentication - [OAuth guide](https://api-docs.decisiv.net/docs/api/oauth/) - [OAuth 2.0 / OIDC discovery](https://login.decisiv.net/.well-known/openid-configuration): issuer `decisiv.net`, authorize `/oauth/authorize`, token `/oauth/token`, revoke, introspect, userinfo, JWKS at `/oauth/discovery/keys` (ES256). Scopes: `public`, `read`, `write`, `update`, `openid`. PKCE `S256` supported. - The authorization code flow is required for new integrations. The password grant is declared **deprecated** in the specs and will be removed. - The older Global Assets / Service Provider / Platform APIs additionally require the `X-Decisiv-Transition-Token` header during the migration to OAuth. - Module access is provisioned per OAuth Application. An unprovisioned module returns 428 with `decisiv:access:003`. ## Conventions - Media type `application/vnd.api+json`; bodies are JSON:API. - Pagination `page[number]` / `page[size]`; filtering `filter[attr]` with `:like`, `:lt`, `:lte`, `:gt`, `:gte`, `:include` operators; `include` for related resources; `sort` for ordering. - Errors are a JSON:API `errors[]` array (`title`, `detail`, `code`, `status`, `source`) — **not** RFC 9457 problem+json. Codes are namespaced `decisiv::`; 112 are published. - Idempotency exists on exactly one operation: `POST /service_management/{srm_account_id}/v1/customer_assets/{id}/create_case`, via `X-DECISIV-IDEMPOTENCY-KEY` (max 128 chars) with `X-Decisiv-Idempotent-Replay` on the replay. - `X-DECISIV-SILENCE-EVENTS` mutes the webhook events a write would otherwise emit, for that transaction. - No rate limits are published: 429 is declared on 37 operations but there is no number, no window and no `RateLimit-*` or `Retry-After` header. ## Webhooks Managed through Account Management: `GET/POST /account_management/v1/accounts/{account_id}/webhooks`, `PATCH`/`DELETE` on `{id}`, `POST .../refresh_signing_key`, and `GET .../webhook_events` for the account's subscribable catalog. Endpoints must be `https://`, may carry up to 10 custom headers, and each carries a rotatable signing key. Eighteen event names are published, covering asset registration/transfer/meter updates, case created/closed/reopened/note/attachment/repair status, estimate approval requested/approved/declined, service request accepted/declined, and maintenance service events and scheduled operations. No AsyncAPI document is published. ## Docs - [API documentation index](https://api-docs.decisiv.net/) - [SRM Connect / Gateway reference](https://srm-api.decisivapps.com/api-docs/v1) - [Platform API changelog](https://api-docs.decisiv.net/docs/api/1/changelog/) — dated, but last updated 2021-09-30 - [Platform API versioning](https://api-docs.decisiv.net/docs/api/1/architecture/versioning/) - [Platform API push notifications](https://api-docs.decisiv.net/docs/api/1/architecture/notifications/) - [Solutions Center](https://www.decisivmarketplace.com/solutions-center/) - [Trust Center](https://www.decisiv.com/trust-center/) — ISO/IEC 27001 certified since February 2024 (certificate issued by Prescient Security, accredited by IAS/IAF) ## Access There is no self-serve signup, no published pricing and no free tier. The API documentation site says "Contact us to enable your access to these APIs" and names sales@decisiv.com / 804-762-4153 x1. The three SRM Gateway listings on the Decisiv Marketplace end in a demo-request form. ## Not published No MCP server. No A2A agent card at `/.well-known/agent-card.json` or `/.well-known/agent.json` on any Decisiv host. No GraphQL. No AsyncAPI. No security.txt. No API client SDK in any language — the only first-party packages are the `@decisiv/*` Key Design System React components on npm, last released in August 2020. No status page. No deprecation policy, no Sunset headers. No changelog for the current SRM Gateway product.