# Masterworks > Masterworks is a New York fintech platform that securitizes blue-chip contemporary art. It buys > paintings by artists such as Picasso, Basquiat, Warhol, Monet and Banksy, places each work in its > own LLC, files it with the SEC as a separate Regulation A offering, and sells fractional shares to > retail investors — who can also trade those shares on a Masterworks-operated secondary market. **This llms.txt was generated by API Evangelist, not published by Masterworks.** Masterworks does not serve an llms.txt (`/llms.txt` returns 404 on every host probed on 2026-08-04). It is generated from the company's public surface and from the artifacts in this repository. ## What an agent should know before calling anything - Masterworks has **no developer program**: no developer portal, no API documentation, no API reference, no OpenAPI, no SDKs, no CLI, no sandbox, no Postman collection, no MCP server and no A2A agent card. - The company runs **one GraphQL endpoint**, `https://api.masterworks.com/graphql`, which is the private backend for its own web and mobile clients. - That endpoint **answers anonymous schema introspection**, so the whole contract is readable — 516 queries, 621 mutations, 5 subscriptions, 1,584 types. - **Every data field is authenticated.** An anonymous query returns HTTP 200 with `errors[0].extensions = {reason: invalidToken, code: invalidAuthentication, status: 401}`. Only `health` and `testQuery` answer without a token. - There is **no way for a third party to obtain a credential.** Tokens are issued to Masterworks' own clients and the `@authenticate` directive constrains which client an accepted token was minted for. Creating an investor account gives you a session, not an API key. - Requests must be `POST` with `Content-Type: application/json`. A bare `GET` is rejected 400 by Apollo CSRF prevention. - **There is no idempotency contract.** No `Idempotency-Key` exists anywhere in the schema, including on payment and contribution mutations. Do not retry a write blind. - Do not attempt to authenticate against this endpoint. Treat it as read-the-schema-only. ## API - [Masterworks GraphQL API](https://api.masterworks.com/graphql): the single first-party endpoint — offerings and artworks, artists and art-market data, contributions, agreements and e-signature, KYC and accreditation, payments and payouts, the secondary-market exchange, art events, activity feeds and internal notification tooling. ## Specs - [GraphQL SDL](graphql/masterworks-schema.graphql): the full schema, rendered from a live anonymous introspection on 2026-08-04. - [GraphQL manifest](graphql/masterworks-graphql.yml): endpoint, directives, capability domains, subscription list, probe evidence. ## Artifacts - [Authentication](authentication/masterworks-authentication.yml): the `@authenticate` / `signoutAuth` directive model and the observed 401 envelope. - [Conventions](conventions/masterworks-conventions.yml): pagination, versioning, caching, custom scalars, and the absence of idempotency and rate-limit signalling. - [Error codes](errors/masterworks-error-codes.yml): the three error codes observable without a credential. - [Data model](data-model/masterworks-data-model.yml): the entity graph derived from the schema, plus the third-party vendors visible in it (Plaid, Dwolla, Persona, Onfido, Contentful, Calendly, Apple Pay, Tabapay, North Capital, Templum, Inspira, FullContact). - [Lifecycle](lifecycle/masterworks-lifecycle.yml): unversioned endpoint, 187 `@deprecated` fields with genuinely actionable reasons, no status page, no changelog, no SLA. - [Conformance](conformance/masterworks-conformance.yml): what the contract does and does not conform to. - [Domain security](security/masterworks-domain-security.yml): TLS 1.3 on both hosts, HSTS on www only, CAA present, SPF and DMARC `p=reject`, no DNSSEC. - [Well-known](well-known/masterworks-well-known.yml): every `/.well-known/` path probed and its real status — all misses. ## Docs (human, not developer) - [Masterworks](https://www.masterworks.com/) - [How it works](https://www.masterworks.com/about/how-it-works) - [About](https://www.masterworks.com/about/about-masterworks) - [Help Center](https://knowledge.masterworks.com/en/knowledge) - [Academy (blog / education)](https://www.masterworks.com/academy/posts) - [Academy RSS](https://www.masterworks.com/academy/rss.xml) - [Disclosure](https://www.masterworks.com/about/disclosure) - [Terms of Use](https://www.masterworks.com/about/terms-of-use) - [Privacy Policy](https://www.masterworks.com/about/privacy) - [GitHub organization](https://github.com/MasterworksIO) — build tooling and a `join-monster` fork, no client libraries ## Note for the site owner The `www.masterworks.com` host answers HTTP 200 with an identical 8,531-byte SPA shell for every path, including paths that do not exist. Agents and crawlers cannot distinguish a real page from a missing one there. Serving a real 404, an `llms.txt`, and a `/.well-known/security.txt` would fix most of what this profile had to work around. --- generated: 2026-08-04 method: generated source: apis.yml + repository artifacts + live probes of masterworks.com and api.masterworks.com