openapi: 3.0.3 info: title: Sirion CLM API (Modeled) Contract Requests API description: 'IMPORTANT - MODELED DOCUMENT. This OpenAPI definition is a MODELED representation of the Sirion (SirionLabs) CLM "Business API & Integrations" surface. It is NOT copied from an official public reference. Sirion''s API reference is available only to authenticated Sirion users (via My Account -> Resources -> Help Guide in the tenant application, and at docs.sirion.ai behind login), and API access is provisioned per enterprise tenant. What is publicly CONFIRMED and reflected here: (1) SirionOne is RESTful and "any activity possible in the web application is possible via the APIs"; (2) authentication uses OAuth 2.0 client credentials for Sirion B2B APIs (an OAuth Client Id and OAuth Client Secret generated by a tenant admin under Admin 2.0 -> Business API & Integrations / OAuth Client Setup); (3) Sirion supports configurable outbound webhooks with field-based filtering and event-based, asynchronous processing; (4) core CLM entities include contracts, contract requests (CDRs), metadata and clauses, obligations, and suppliers / counterparties. What is MODELED and NOT publicly confirmable: all endpoint paths, the exact request/response schemas, the OAuth token URL, and the per-tenant host. The base server below uses a `tenant` variable on the confirmed product domain sirioncloud.com; substitute your organization''s actual Sirion host. Do not treat these paths as authoritative - obtain the real reference from your Sirion tenant.' version: 1.0-modeled contact: name: SirionLabs url: https://www.sirion.ai servers: - url: https://{tenant}.sirioncloud.com description: Per-tenant SirionOne instance (MODELED host pattern on the confirmed product domain sirioncloud.com). Replace {tenant} with your organization's Sirion subdomain. The exact API path prefix is provisioned per tenant. variables: tenant: default: your-org description: Your organization's Sirion tenant subdomain. security: - oauth2ClientCredentials: [] tags: - name: Contract Requests description: Contract Requests (CDRs) that drive intake and authoring (MODELED). paths: /contract-requests: get: operationId: listContractRequests tags: - Contract Requests summary: List contract requests (MODELED) description: Lists Contract Requests (CDRs). Confirmed conceptually by Sirion's SAP Ariba integration; path MODELED. responses: '200': description: A page of contract requests. content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/ContractRequest' '401': $ref: '#/components/responses/Unauthorized' post: operationId: createContractRequest tags: - Contract Requests summary: Create a contract request (MODELED) description: Creates a Contract Request that drives intake / authoring workflow. Sirion documents event-based, asynchronous replication of CDRs. MODELED. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ContractRequestInput' responses: '201': description: The created contract request. content: application/json: schema: $ref: '#/components/schemas/ContractRequest' '401': $ref: '#/components/responses/Unauthorized' components: schemas: ContractRequestInput: type: object description: MODELED contract request (CDR) payload. properties: title: type: string requestType: type: string counterparty: type: string requestedBy: type: string metadata: type: object additionalProperties: true ContractRequest: allOf: - $ref: '#/components/schemas/ContractRequestInput' - type: object properties: id: type: string stage: type: string description: Workflow stage of the request. createdAt: type: string format: date-time Error: type: object properties: code: type: string message: type: string responses: Unauthorized: description: Missing or invalid OAuth access token. content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: oauth2ClientCredentials: type: oauth2 description: 'OAuth 2.0 client credentials grant. CONFIRMED: a Sirion tenant admin generates an OAuth Client Id and OAuth Client Secret under Admin 2.0 -> Business API & Integrations (OAuth Client Setup), used to obtain an access token for the Sirion B2B APIs. The token URL below is MODELED / tenant-specific and must be replaced with your tenant''s actual token endpoint.' flows: clientCredentials: tokenUrl: https://your-org.sirioncloud.com/oauth/token scopes: {}