openapi: 3.0.1 info: title: Evisort Authentication API description: Partial, externally-reconstructed OpenAPI description of the Evisort REST API (Evisort is now Workday Contract Lifecycle Management, powered by Evisort). The full, authoritative reference lives behind Evisort's developer portals (developers.evisort.com, documents.developers.evisort.com, workflow.developers.evisort.com, admin.developers.evisort.com), which require an authenticated account and are not publicly crawlable. The base URL, the API-key to JWT authentication flow, and the endpoints described here were confirmed from publicly available integration and developer documentation. Endpoints whose exact request and response schemas are not publicly documented are described accurately rather than fabricated. version: '1.0' contact: name: Evisort Developer Support url: https://developers.evisort.com/ termsOfService: https://www.evisort.com/legal servers: - url: https://api.evisort.com/v1 description: Evisort production REST API security: - bearerAuth: [] tags: - name: Authentication description: Exchange an Evisort API key for a short-lived JWT bearer token. paths: /auth/token: post: operationId: createToken tags: - Authentication summary: Generate a JWT token from an Evisort API key description: 'Exchanges an Evisort API key (created in the Evisort UI under the admin console / API management) for a short-lived JWT bearer token. The returned token is supplied as `Authorization: Bearer {token}` on all subsequent requests.' parameters: - name: EVISORT-API-KEY in: header required: true description: The Evisort API key issued from the Evisort UI. schema: type: string responses: '200': description: A JWT bearer token. content: application/json: schema: $ref: '#/components/schemas/TokenResponse' '401': description: Invalid or missing API key. components: schemas: TokenResponse: type: object properties: token: type: string description: A JWT bearer token used on subsequent API calls. securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: JWT bearer token obtained from POST /auth/token by presenting an Evisort API key.