# Lawmatics > Lawmatics is a legal CRM, client-intake and marketing-automation platform for law firms. Its public > surface is one REST API - the Lawmatics OAuth API v1.22.0, 177 operations over 95 paths at > https://api.lawmatics.com - plus outbound webhooks. Lawmatics does not publish an OpenAPI, an > AsyncAPI, an MCP server, an agent card, a client SDK, a CLI or a sandbox; its machine-readable > contract is a Postman collection published at https://docs.lawmatics.com/. Generated by API Evangelist on 2026-08-13. Lawmatics does not serve an llms.txt of its own (https://www.lawmatics.com/llms.txt and https://docs.lawmatics.com/llms.txt both return 404), so this file is generated from the artifacts in this repository. ## Start here - [API documentation](https://docs.lawmatics.com/): the official Postman-hosted reference, including the Getting Started With Auth guide, the Param Guide and the dated changelog. - [Open API and webhooks overview](https://help.lawmatics.com/en/articles/10699983-lawmatics-open-api): what the API is for, how to get access, and the rate limit. - [Outbound webhooks developer guide](https://help.lawmatics.com/en/articles/15438485-outbound-webhooks): event types, envelope, signature verification, retry schedule. ## How access works - OAuth 2.0 authorization code grant. Authorize at `https://app.lawmatics.com/oauth/authorize`, exchange at `https://api.lawmatics.com/oauth/token`. - Developer settings must be switched on for a Lawmatics account by a support representative before a developer app can be created at `https://app.lawmatics.com/settings/developers`. - Access tokens do not expire. There are no refresh tokens, no scopes, and no deauthorization endpoint - an authorized app holds full CRUD over the firm's account until the firm intervenes. - Requests carry `Authorization: Bearer `. - Rate limit is per firm per minute. The API docs say 50/min, the help centre says 150/min; both are current. Exhaustion returns `429` with `Retry-After: 60` and there are no pre-exhaustion headers. ## Query grammar (applies to every list endpoint) - `fields` - comma-separated field selection, one level deep; `fields=all` expands everything. - `page` - 1-based page number; page size is not settable. - `sort_by` / `sort_order` - defaults to `id desc`. - `filter_by` / `filter_on` / `filter_with` - one filter per request; operators `=`, `!=`, `<=`, `<`, `>=`, `>`, `like`, `ilike`, `null`, `not_null`. Responses use a JSON:API-shaped `data` / `id` / `type` / `attributes` / `relationships` envelope. Errors are `{"errors":[{"status","title","detail"}]}` in `application/json` - not RFC 9457. ## Vocabulary warning The product says **Matter**; the API says **prospect**. `/v1/prospects` is the matter endpoint and every matter identifier is `prospect_id`. There is no `/v1/matters`. ## APIs - [Lawmatics OAuth API](https://docs.lawmatics.com/) - base `https://api.lawmatics.com`, 177 operations across matters, contacts, companies, custom forms, custom fields, collections, events, tasks, notes, files, folders, tags, users, interactions, relationships, pipelines, stages, practice areas, sources, campaigns, time entries, expenses, invoices and transactions. ## Specs and artifacts in this repository - OpenAPI (derived from the provider's Postman collection): `openapi/lawmatics-openapi.yml` - Postman collection (provider-published, verbatim): `postman/lawmatics-oauth-api.postman_collection.json` - Authentication profile: `authentication/lawmatics-authentication.yml` - API conventions: `conventions/lawmatics-conventions.yml` - Error catalogue: `errors/lawmatics-problem-types.yml` - Rate limits: `rate-limits/lawmatics-rate-limits.yml` - Data model (43 entities, derived from published response payloads): `data-model/lawmatics-data-model.yml` - Webhook catalogue: `asyncapi/lawmatics-webhooks.yml` - Lifecycle and versioning: `lifecycle/lawmatics-lifecycle.yml` - Changelog: `changelog/lawmatics-changelog.yml` - Conformance and compliance: `conformance/lawmatics-conformance.yml` - Agentic access classification: `agentic-access/lawmatics-agentic-access.yml` - Agent skills: `skills/_index.yml` - Candidate MCP tool list (no server ships): `mcp/lawmatics-mcp.yml` - Plans and pricing: `plans/lawmatics-plans-pricing.yml` ## What Lawmatics does not publish - No OpenAPI, no AsyncAPI, no GraphQL, no gRPC. - No MCP server - hosted or stdio. Third-party community servers exist; none is endorsed. - No A2A agent card at `/.well-known/agent-card.json` or `/.well-known/agent.json` on any host. - No `/.well-known/` documents at all: no `security.txt`, no OAuth authorization server metadata. - No first-party SDK in any language, and no CLI. - No sandbox, test mode or test credentials. - No deprecation policy, no Sunset header support, no SLA. - No error-code reference; only two of 177 operations carry a published error example. ## Company - [Website](https://www.lawmatics.com/) - [Pricing](https://www.lawmatics.com/pricing) - [Security and compliance](https://www.lawmatics.com/security) - SOC 2 Type 2 and HIPAA, verified by AssuranceLab - [Status](https://status.lawmatics.com/) - [Help centre](https://help.lawmatics.com/) - [Blog](https://www.lawmatics.com/blog) - [GitHub](https://github.com/boost-legal) - API contact: api@lawmatics.com