# Malt > Malt is a European freelance marketplace and Freelance Management System (FMS), founded in Paris > in 2013, connecting over a million independent consultants in tech, data, AI, design, marketing > and management with enterprise buyers. Malt publishes a small, credential-gated public API at > api.malt.com: a freelancer billing surface (invoices, service charge invoices, payments, invoice > PDFs) and a SCIM 2.0 user-provisioning endpoint for enterprise identity lifecycle management. This file was GENERATED by API Evangelist from Malt's published apis.yml profile and the artifacts in this repository. Malt does not publish an llms.txt of its own — https://api.malt.com/llms.txt returns 404, and www.malt.com answers 403 to non-browser clients on every path. ## What an agent can and cannot do here - The API is fully credential-gated. Every operation returns HTTP 401 with an empty body without a token. There is no anonymous, sandbox or read-only public surface. - Freelancer tokens are self-served at https://www.malt.com/account/tokens (My Account > API Keys) with selectable permission scopes. Client team and organization tokens are obtained through a Malt representative — the SCIM half of the API is effectively sales-gated. - Authentication is a bare opaque token in the `Authorization` header. The API guidelines show `Authorization: your-api-token-here` with NO `Bearer ` prefix, even though the OpenAPI also declares an unused http/bearer scheme. - There is no MCP server, no A2A agent card, no GraphQL endpoint, no AsyncAPI document and no documented webhook catalog. - There is no idempotency key. `POST /scim/v2/Users` is not safe to retry blindly. - There are no published rate limits and no rate-limit response headers — an agent has no way to pace itself except by observing failures. - Errors carry no machine-readable code. Discriminate by HTTP status only. - What the platform is famous for — talent search, profiles, availability, rates, project offers, missions — is NOT in the API. The contract covers billing and provisioning only. ## APIs - [Malt Exposed APIs](https://api.malt.com/): Stoplight Elements documentation portal rendering a single unified OpenAPI 3.0.3 document. Base URL https://api.malt.com. 13 operations across two disjoint capability groups. ## Specs - [OpenAPI (verbatim, as published)](openapi/_original/malt-unified-exposed-apis-openapi.json): fetched from https://api.malt.com/unified-exposed-apis.json - [OpenAPI (YAML)](openapi/malt-exposed-apis-openapi.yml) - [Spec list, as served by the docs portal](openapi/_original/malt-spec-summary.json): fetched from https://api.malt.com/specSummary.json - [API Evangelist Overlay](overlays/malt-exposed-apis-overlay.yaml) ## Operations Freelancer billing (7 operations, all read-only, tag Invoices / Payments / Fee Invoices): - `GET /freelancer/invoices` — findInvoices — list invoices in a date range (`since` required, `until` optional). Unpaged. - `GET /freelancer/invoices/{id}` — getInvoice - `GET /freelancer/invoices/{id}/pdf` — getInvoicePdf — base64 PDF inside a JSON body - `GET /freelancer/payments` — findPayments — list payments with the invoices each settles - `GET /freelancer/fee-invoices` — findFeeInvoices — Malt's own service charges to the freelancer - `GET /freelancer/fee-invoices/{id}` — getFeeInvoice - `GET /freelancer/fee-invoices/{id}/pdf` — getFeeInvoicePdf Enterprise user provisioning (6 operations, SCIM 2.0, tag SCIM): - `GET /scim/v2/Users` — findUsers — SCIM `filter`, 1-based `startIndex`, `count` - `POST /scim/v2/Users` — createUser — no idempotency key - `GET /scim/v2/Users/{userId}` — getUserById - `PUT /scim/v2/Users/{userId}` — replaceUser - `PATCH /scim/v2/Users/{userId}` — modifyUser — accepts only setting `active` to `false` - `DELETE /scim/v2/Users/{userId}` — deleteUser — 403 when the user has platform activity ## Artifacts - [Authentication profile](authentication/malt-authentication.yml) - [API conventions](conventions/malt-conventions.yml) - [Error catalog](errors/malt-problem-types.yml) - [Data model](data-model/malt-data-model.yml) - [Conformance](conformance/malt-conformance.yml) — SCIM 2.0 conformant; no OAuth, no RFC 9457 - [Lifecycle](lifecycle/malt-lifecycle.yml) — status page only; no versioning or deprecation policy - [Rate limits](rate-limits/malt-rate-limits.yml) — none published - [Plans and pricing](plans/malt-plans-pricing.yml) — three named tiers, no published prices - [Packages](packages/malt-packages.yml) — no API client library in any language - [Components](components/malt-components.yml) — the @maltjoy design system (Stencil web components) - [MCP candidate manifest](mcp/malt-mcp.yml) — derived; Malt ships no MCP server - [Tool crosswalk](mcp/malt-tool-crosswalk.yml) - [Agent skills](skills/_index.yml) - [Agentic access contracts](agentic-access/malt-agentic-access.yml) - [Well-known probe](well-known/malt-well-known.yml) - [security.txt (verbatim)](well-known/malt-security.txt) - [Vulnerability disclosure](security/malt-vulnerability-disclosure.yml) — Yogosha CVD program - [Domain security](security/malt-domain-security.yml) ## Docs - [API documentation and reference](https://api.malt.com/) - [Help center](https://help.malt.com/kb/en/) - [Status page](https://status.malt.com/) — StatusCake public uptime report - [Engineering blog](https://blog.malt.engineering/) — [RSS](https://blog.malt.engineering/feed) - [Newsroom](https://newsroom.malt.com/fr) - [GitHub organization](https://github.com/Maltcommunity) - [Pricing](https://www.malt.com/c/pricing) - [Terms (CGU / CGV)](https://www.malt.com/legal) - [Privacy center](https://www.malt.com/about/privacy) - [Vulnerability disclosure (Yogosha)](https://app.yogosha.com/cvd/malt/rqtSc4eIMUj7CKFhA87hI) ## Optional - [Company website](https://www.malt.com/) - [Careers](https://careers.malt.com/) - [Malt for companies](https://www.malt.com/c/companies) - [Malt for freelancers](https://www.malt.com/c/freelancers)