# Trisotech > Trisotech (Montreal, Canada; founded 1996) builds the Digital Enterprise Suite — a > standards-anchored low-code platform for modelling and automating business processes, cases > and decisions using the OMG BPMN 2.0, CMMN 1.1 and DMN standards with FEEL. Models published > to the Service Library become callable services with their own generated OpenAPI, container > image, HTML form, CDS Hooks discovery endpoint, SMART on FHIR launch, and Model Context > Protocol server. Sold into healthcare, finance and the public sector. GENERATED BY API EVANGELIST. Trisotech does not publish an llms.txt; /llms.txt returns 404 on both www.trisotech.com and cloud.trisotech.com (probed 2026-09-02). Every URL below was fetched and returned HTTP 200 on that date. ## APIs - [Public API reference](https://cloud.trisotech.com/help/des/system-integration/rest-api-documentation.html): 129 operations across 30 resource groups — places, content, promotion change requests, execution environments, deployments, data stores, event emitters, issues, identities, groups, users, user-task search, test data, AI agents. Base URL https://{instance}.trisotech.com/publicapi. Unversioned path. - [Public API access and auth](https://cloud.trisotech.com/help/des/system-integration/rest-api.html): OAuth 2, bearer token in Authorization. Always send Accept: application/json — the default is deprecated XML. - [Service (Automation) API](https://cloud.trisotech.com/help/service-library/service-rest-api-endpoint.html): per-service endpoints to execute a decision, start a workflow or case, list and inspect running instances, read and write instance data, navigate the case file, manage resume points, and trigger by message. - [Service Execution endpoint](https://cloud.trisotech.com/help/service-library/service-execution-rest-api-endpoint.html): POST to execute; GET returns an input template in JSON, XML or HTML form instead of executing. - [Generated OpenAPI per service](https://cloud.trisotech.com/help/service-library/openapi-endpoint.html): every published service emits its own OpenAPI in JSON or YAML, for gateway import or client generation. - [SPARQL API](https://cloud.trisotech.com/help/digital-modeling-suite/sparql.html): read-only SPARQL 1.1 over the Digital Enterprise Graph at {instance}/ds/query. One graph per modeling place. Requires the graph_r and repo_r grants. - [Asynchronous events](https://cloud.trisotech.com/help/des/system-integration/asynchronous-events.html): CloudEvents 1.0.1 JSON messages over configurable event emitters, filtered with FEEL, subscribed by hierarchical topic. - [Event catalog (machine-readable, anonymous)](https://cloud.trisotech.com/docs/messages-documentation.json): 23 topics, 104 message types, each with typed fields and a per-topic security constraint. - [Events documentation (human)](https://cloud.trisotech.com/publicapi/doc-events) ## Authentication and authorization - [Client Apps and the full grant list](https://cloud.trisotech.com/help/admin/client-apps.html): 20 published OAuth grants — repo_r, repo_w, group_r, group_w, graph_r, users_r, users_w, mvn_r, mvn_w, mvn_d, emitter_r, emitter_w, bpmn_x, cmmn_x, dmn_x, docker_r, asset_w, openid, admin, and the deprecated service_x. - Authorization URL: https://{instance}.trisotech.com/oauth2/auth - Token URL: https://{instance}.trisotech.com/oauth2/token - [SCIM provisioning](https://cloud.trisotech.com/help/admin/scim-aad.html) ## AI agents - [MCP endpoint](https://cloud.trisotech.com/help/service-library/mcp.html): expose a single service or a whole environment to an AI agent over Streamable HTTP or SSE. The client URL is generated per service on the customer's own instance — there is no vendor-wide MCP endpoint. Marked incubating. - [Model Context Protocol overview](https://www.trisotech.com/model-context-protocol-mcp/) - Agent activity is auditable through the `aiagent` event topic: AIAgentToolInvoke and AIAgentChat. ## Healthcare - [CDS Hooks endpoint](https://cloud.trisotech.com/help/service-library/cds-hooks.html): standard CDS Hooks discovery endpoint with FHIR prefetch queries declared per service input. Requires the Healthcare Feature Set subscription. Incubating. - [SMART on FHIR applications](https://cloud.trisotech.com/help/service-library/smart-on-fhir.html): launch context for patient, user and encounter; service tasks carry authorization to the FHIR server. Incubating. - [FHIR](https://www.trisotech.com/fhir/) - [CQL in the Workflow Modeler](https://cloud.trisotech.com/help/workflow-modeler/cql.html) ## Testing - [Test endpoint](https://cloud.trisotech.com/help/service-library/test-endpoint.html): runs DMN TCK test cases against a published service; returns a testResult XML document with a pass/fail per case. - [Trials](https://www.trisotech.com/trials/) ## Operations - [Documentation home](https://cloud.trisotech.com/help/) - [System integration](https://cloud.trisotech.com/help/des/system-integration/system-integration.html) - [Release notes](https://www.trisotech.com/release-notes/): dated, versioned, two trains — current 13.0.x and 12.14.x LTS. - [Status](https://www.trisotech.com/status/) - [Security and compliance](https://www.trisotech.com/security/): SOC 2 Type II; data centre ISO 27001:2013 and SOC 3; hosted in Quebec, Canada on Google Cloud. - [Contact / report a security incident](https://www.trisotech.com/contact-us/) - [GitHub organization](https://github.com/Trisotech) ## Commercial - [Pricing (request only)](https://www.trisotech.com/pricing/): no published tiers or prices; contact sales. - [Terms of service](https://www.trisotech.com/terms-of-service/) - [Privacy statement](https://www.trisotech.com/privacy-statement/) - [Company](https://www.trisotech.com/company/) - [Blog](https://www.trisotech.com/blog/) ## Known gaps (probed 2026-09-02, recorded so an agent does not waste calls) - No public OpenAPI file. https://cloud.trisotech.com/publicapi/doc returns 200 but redirects to the instance login; /openapi.json, /swagger.json, /v3/api-docs all 404. - No /llms.txt, no /.well-known/security.txt, no /.well-known/openid-configuration, no /.well-known/agent-card.json, no /.well-known/api-catalog on any host — all 404. - No published rate limits and no rate-limit response headers. - No idempotency key and no request-deduplication window. - Errors are not RFC 9457. The envelope is {"error":[{"code","systemMessage","userMessage"}]} and a missing bearer token returns HTTP 500 with code RequiresLogin, not 401. - No first-party SDK on any public package registry.