# Specright > Specright is a specification data management (SDM) platform. It centralizes the > specifications behind a physical product — raw materials, ingredients, formulas, > packaging components, finished goods and the bills of materials connecting them — and > shares them with suppliers, co-manufacturers and internal teams. Founded 2015, > headquartered in Tustin, California. The platform is built on Salesforce, which is > visible throughout the API. Specright publishes a REST API at https://api.specright.com/v1 with 46 operations, and an OAuth-protected Model Context Protocol endpoint on its marketing site. It does NOT publish an OpenAPI document, an SDK, a GraphQL schema, or an event/webhook surface. ## Generated This file was generated by API Evangelist from Specright's public surface on 2026-08-28. Specright serves no llms.txt of its own (https://www.specright.com/llms.txt returns 404). Every URL below was fetched and its status recorded. ## The API in one paragraph Four resource families — /specs (specifications), /specfamilies (BOM / finished good), /suppliers, and a generic /objects/{api-name} reaching any object configured in the tenant — each supporting the identical operation set: list, create, read, update, delete, list files, get file, get definition, and an asynchronous CSV bulk job. Records are returned as an array of untyped field/label/value triples rather than a keyed object, and the field vocabulary is per-tenant configuration read at runtime from the /definition endpoints. The contract declares no business fields at all. ## Start here - Developer portal: https://developer.specright.com/ (200; a React SPA — the reference is rendered client-side and is not visible to a crawler) - API reference: https://developer.specright.com/api-reference (200) - Production base URL: https://api.specright.com/v1 (401 with WWW-Authenticate: Bearer) - Sandbox base URL: https://test.specright.com/v1 (401; live but undocumented) - Liveness: https://api.specright.com/health (200, "HEALTHY"; undocumented) - Status page: https://status.specright.com/ (200, Atlassian Statuspage, with a public JSON API at /api/v2/summary.json; not linked from any Specright property) ## Authentication Send BOTH headers on every business operation — they are two different things: - `x-api-key` — the key Specright issues to the integration. - `x-user-id` — the Specright user the call acts as. Required on all 45 non-token operations. Record permissions are evaluated against this principal, so a 403 on a well-formed request usually means this user lacks access, not that the key is wrong. A bearer token from `POST /v1/token` (Basic-authenticated, `expires_in` 3600) may replace the API key. The real authorization server is Keycloak: https://login.specright.com/realms/Specright/.well-known/openid-configuration (200), which advertises 19 scopes including the Specright-defined `specright-api`, `specright-network`, `supplier-network` and `service_account`. None of those scopes is documented anywhere. Credentials are not self-service. Specright issues developer accounts to customers and partners; the documented contact is api@specright.com. ## Operations (46) Token - POST /token Specifications — Endpoints for Specification/Packaging Object - GET /specs · POST /specs · GET /specs/{id} · PATCH /specs/{id} · DELETE /specs/{id} - GET /specs/{id}/files · GET /specs/{id}/files/{file-id} · GET /specs/definition Spec Families — Endpoints for Spec Family/BOM/Finished Good Object - GET /specfamilies · POST /specfamilies · GET /specfamilies/{id} · PATCH /specfamilies/{id} · DELETE /specfamilies/{id} - GET /specfamilies/{id}/files · GET /specfamilies/{id}/files/{file-id} · GET /specfamilies/definition Suppliers - GET /suppliers · POST /suppliers · GET /suppliers/{id} · PATCH /suppliers/{id} · DELETE /suppliers/{id} - GET /suppliers/{id}/files · GET /suppliers/{id}/files/{file-id} · GET /suppliers/definition Other Objects — any object configured in the tenant - GET /objects/{api-name} · POST /objects/{api-name} · GET /objects/{api-name}/{id} · PATCH /objects/{api-name}/{id} · DELETE /objects/{api-name}/{id} - GET /objects/{api-name}/{id}/files · GET /objects/{api-name}/{id}/files/{file-id} - GET /objects/{api-name}/definition · GET objects/definition Bulk Operations — asynchronous, CSV - POST /specs/bulkjob · GET /specs/bulkjob/{job-id}/status · GET /specs/bulkjob/{job-id}/details - POST /specfamilies/bulkjob · GET /specfamilies/bulkjob/{job-id}/status · GET /specfamilies/bulkjob/{job-id}/details - POST /suppliers/bulkjob · GET /suppliers/bulkjob/{job-id}/status · GET /suppliers/bulkjob/{job-id}/details - POST /objects/{api-name}/bulkjob · GET /objects/{api-name}/bulkjob/{job-id}/status · GET /objects/{api-name}/bulkjob/{job-id}/details ## Conventions - Response envelope: `{"data": [...], "success": true}`. Records are `{"fields": [{"field","label","value"}]}` — positional, untyped, no field guaranteed. - Read `/definition` FIRST. It returns object-info, fields-list, connections-list and recordtypes-list. Without it you cannot name a field. - Sparse fieldsets: `fields`. Filtering: `filter` (a JSON string — the grammar is NOT published). Sorting: `sort=field[:asc|:desc]`. Pagination: `skip` / `limit`, offset only, with no total, no next link, and no published default or maximum. - Upsert: `PATCH /{resource}/{id}?externalid=&operation=update|upsert`. **If `operation` is omitted, upsert is assumed** — the default creates records. - Identifiers are Salesforce: 18-character record IDs, `750`-prefixed bulk job IDs, and `specright__*__c` custom-field API names. ## What is NOT there — read before integrating - No OpenAPI, Swagger or GraphQL. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs, /redoc and more on every host: 404 or SPA shell. The 2020 launch post promised "GraphQL support is coming soon"; /graphql returns 404 six years later. - No SDKs. Zero packages on npm, PyPI, RubyGems, crates.io, Packagist and NuGet. The GitHub organization https://github.com/Specright has 0 public repositories. - No rate limits. No published numbers, no X-RateLimit-*/RateLimit-* headers, no Retry-After, no 429 on any operation. - No idempotency key and no dry-run. External-ID PATCH is the only retry-safe write; POST and bulk-job submission both duplicate on retry. - No reversal for any write. No undo, restore, rollback or cancel among the 46 operations, and no stated retention for a deleted record. Bulk delete cannot be cancelled once accepted. - No webhooks or events. Polling is the only change-detection mechanism. - No error catalog. Failure statuses are 400/401/403/406/422 with no named codes, no problem+json, and no published error envelope. - No deprecation policy, no Sunset/Deprecation headers, no API changelog, no SLA. - No security.txt on any host, and no published SOC 2 / ISO 27001 claim or trust center. ## MCP Specright serves an MCP endpoint at https://www.specright.com/wp-json/mcp/mcp-oauth-server — remote, OAuth-gated, discoverable through https://www.specright.com/.well-known/oauth-protected-resource (RFC 9728, 200) and https://www.specright.com/.well-known/oauth-authorization-server (RFC 8414, 200), single scope `mcp`. It sits on the WordPress marketing site, NOT on the product API, and there is no evidence it exposes the specification operations above. `tools/list` returns 401, so the tool set is not publicly readable. Note that the site's robots.txt disallows /wp-json/, which covers the endpoint its own discovery document advertises. ## Company - Website: https://www.specright.com/ (200) - Pricing: https://www.specright.com/plans-pricing/ (200) — three tiers (Foundations, Plus, Enterprise), all quote-only; no prices, no quotas, no stated API entitlement - Blog: https://www.specright.com/blog/ (200) · RSS https://www.specright.com/feed/ (200) - Integrations: https://www.specright.com/integrations/ (200) - Support: https://www.specright.com/customer-support/ (200) - Terms: https://www.specright.com/terms-of-use/ (200) - Privacy: https://www.specright.com/privacy-notice/ (200) - Demo: https://www.specright.com/request-a-demo/ (200) - API contact: api@specright.com Product releases are announced as dated blog posts — numbered 18.0 to 24.0 through 2023, then seasonal (Release 34 shipped as the Summer 2026 release, 2026-07-28). None of them documents an API change. ## API Evangelist artifacts in this repo - authentication/specright-authentication.yml - scopes/specright-scopes.yml - conventions/specright-conventions.yml (includes the reversibility assessment) - errors/specright-error-codes.yml - data-model/specright-data-model.yml - lifecycle/specright-lifecycle.yml - changelog/specright-changelog.yml - conformance/specright-conformance.yml - mcp/specright-mcp.yml - well-known/specright-well-known.yml - plans/specright-plans-pricing.yml - rate-limits/specright-rate-limits.yml - sandbox/specright-sandbox.yml - packages/specright-packages.yml - security/specright-domain-security.yml - skills/_index.yml (four Agent Skills)