# VaultRE > VaultRE — marketed since the MRI Software acquisition as MRI Vault CRM — is an Australian > cloud real estate CRM and transaction platform used by residential, commercial, rural, land, > business and property-management agencies across Australia and New Zealand. It is the agency > system of record: contacts, appraisals, listings, offers, open homes, feedback, tenancies, > maintenance, trust/invoicing and AML records, feeding listings outward to the Australian portal > duopoly. It publishes a genuinely open, versioned, machine-readable contract — four OpenAPI > 3.0.1 documents downloadable anonymously — behind an approval-gated key. Generated by API Evangelist on 2026-07-26. VaultRE does not publish an llms.txt of its own (/llms.txt returns no document on any VaultRE host), so this file was generated from the apis.yml catalog entry and the artifacts in this repository. Every URL below was verified live. ## What an agent needs to know first - **Two credentials on every request.** `X-Api-Key: ` AND `Authorization: Bearer `. A missing API key returns 403; a missing/expired bearer token returns 401. - **Access is not self-serve.** The API key is issued only after a reviewed integrator registration (VaultRE says new integrations are generally created within two business days). Then each agency must separately mint a scoped, revocable access token for that integrator from inside its own VaultRE account. There is no sandbox, demo tenant or public test dataset. - **Scopes are chosen by the customer, not requested by the client.** Call `GET /scopes` (operationId `getTokenScopes`) at session start to learn what this token can actually do. The scope vocabulary is not published anywhere. - **Rate limits are tight: 10 requests/second and 10,000 requests/day per API key**, resetting at 00:00 UTC, HTTP 429 on exceed. VaultRE explicitly tells integrators NOT to call the API live on each page load — synchronise periodically and cache locally. `GET /integrator/usage` reports remaining daily quota. - **There is no idempotency contract.** No `Idempotency-Key` header or parameter exists in any specification. Retrying a failed write may duplicate it. - **Errors are not RFC 9457.** Every error is `application/json` shaped `{ "success": false, "msg": "...", "code": "..." }`. The `code` vocabulary is readable only at runtime from `GET /responseCodes`. - **Property "lives" are the central abstraction.** A Property is the physical asset; a *life* is one marketing episode on one side of the market. Most listing-level operations address `/properties/{propertyid}/{salelease}/{lifeid}/…` where `{salelease}` is the literal string `sale` or `lease`. Feedback, open homes, offers, files, owners, landlords and tenancies hang off the LIFE, not the Property. - **Property images must be downloaded and self-hosted.** Hotlinking is prohibited and results in the feed being disabled. ## APIs - [VaultRE API](https://docs.api.vaultre.com.au/swagger/index.html): the core REST API — 324 paths and 453 operations in v1.3 across contacts, properties (residential, commercial, rural, land, business, holiday rental, livestock, clearing sales), listings and photos, enquiries, offers, open homes, feedback, appraisals, calendar and tasks, inspections, maintenance and suppliers, tenancies, invoices, deals, campaigns and advertising, templates and merge fields, SMS and email, AML checks, keys, suburbs and precincts, an event-stream poll endpoint, CoreLogic property and AVM lookups, and REINZ sales reporting for New Zealand. Base URL `https://ap-southeast-2.api.vaultre.com.au/api/v1.3`. - [VaultRE Integrator API](https://docs.api.vaultre.com.au/integrator.html): integrator-level endpoints — enumerate the accounts that granted a token, list users, validate a user, read granted and possible scopes, list tokens, read merge fields and API usage. Replaces the customer bearer token with a self-signed HS512 JWT (`{"apiKey", "timestamp"}`, valid 300 seconds). - [VaultRE Aggregator API](https://docs.api.vaultre.com.au/swagger/aggregator/index.html): a separate write-only ingestion API letting other CRM systems feed property data into VaultRE for a franchise-group agency. Six operations — staff, appraisal, listing, unconditional, settlement, withdrawn. Queued, not live: HTTP 202 on receipt, errors delivered to a nominated webhook. Base URL `https://aggregator.api.vaultre.com.au/api/v1.0`. Authenticated with a CRM Key + Secret Key and a self-signed HS512 JWT valid 120 seconds. ## Specs - [OpenAPI 3.0.1 — core API v1.3](https://docs.api.vaultre.com.au/swagger/vaultre.yaml) (current; 324 paths, 453 operations, 356 schemas) - [OpenAPI 3.0.1 — core API v1.2](https://docs.api.vaultre.com.au/swagger/vaultre_v1_2.yaml) (229 paths, 326 operations) - [OpenAPI 3.0.1 — core API v1.1](https://docs.api.vaultre.com.au/swagger/vaultre_v1_1.yaml) (121 paths, 189 operations) - [OpenAPI 3.0.1 — Aggregator API v1.0](https://docs.api.vaultre.com.au/swagger/aggregator/aggregator_v1_0.yaml) (6 paths, 6 operations) ## Docs - [Developer documentation](https://docs.api.vaultre.com.au/) — public MkDocs site, no login wall, nine pages - [Getting started](https://docs.api.vaultre.com.au/basics.html) — the two-step access reality - [Technical guide](https://docs.api.vaultre.com.au/guide.html) — auth headers, rate limits, versioning, date formats, image hotlinking rule - [API reference / Swagger UI](https://docs.api.vaultre.com.au/swagger/index.html) - [oAuth guide](https://docs.api.vaultre.com.au/oauth.html) — OAuth2-style authorisation-code flow for minting customer tokens - [Integrator endpoints](https://docs.api.vaultre.com.au/integrator.html) - [Aggregator API](https://docs.api.vaultre.com.au/aggregator.html) - [Webhooks](https://docs.api.vaultre.com.au/webhooks.html) — HMAC-SHA512 `X-VaultRE-Signature` - [Code samples](https://docs.api.vaultre.com.au/samples.html) - [Changelog](https://docs.api.vaultre.com.au/changelog.html) — dated, by version, current through 2026-05-29 - [Request integration access](https://www.mrisoftware.com/au/products/vault/api-integrations/) — the approval gate - [Product site](https://www.mrisoftware.com/au/products/vault/) - [Status page](https://status.mrisoftware.com/) — MRI Software group status page, "Vault CRM" component - [Sample code](https://github.com/VaultGroup/api-samples) — curl, PHP, Perl and Python samples (no packaged SDK exists in any registry) ## Events - **Webhooks**: HTTP POST JSON to a URL registered out of band with api@vaultre.com.au. Signed with `X-VaultRE-Signature: t=,sha512=` — HMAC-SHA512 over `.` keyed with your API key, modelled on Stripe. Hash the RAW body: any reserialisation breaks the match. Webhook requests carry no other authentication. Only three event names are published anywhere: `user.update`, `property.update`, `contact.merge`. - **Polling alternative**: `GET /eventStream` (operationId `getEventStream`) with `eventsSince` and `cursor`. Events expire after 30 days. ## Artifacts in this repository - openapi/ — four harvested OpenAPI 3.0.1 documents - authentication/vaultre-authentication.yml — the full two-credential model, per surface - scopes/vaultre-scopes.yml — the OAuth flow, and why the scope vocabulary is not published - conventions/vaultre-conventions.yml — pagination, versioning, dates, rate limits, error envelope - errors/vaultre-problem-types.yml — the error catalogue and permission-denial reasons - lifecycle/vaultre-lifecycle.yml — versioning, deprecation posture, status page - changelog/vaultre-changelog.yml — structured recent changelog - conformance/vaultre-conformance.yml — what standards this API does and does not meet - data-model/vaultre-data-model.yml — the entity graph, including the Property/life abstraction - asyncapi/vaultre-webhooks.yml — the event surface - agentic-access/vaultre-agentic-access.yml — per-operation agent execution contracts - mcp/vaultre-mcp.yml — a CANDIDATE MCP tool surface derived from the OpenAPI (VaultRE publishes no MCP server) - mcp/vaultre-tool-crosswalk.yml — every candidate tool bound to its backing operationId - skills/ — packaged agent skills for the marquee integration flows - security/vaultre-domain-security.yml — TLS/HSTS/DNS posture - well-known/vaultre-well-known.yml — a recorded negative result; no /.well-known/ surface exists ## What VaultRE does not have No RESO or OData surface (correct for Australia — there is no MLS and no RESO mandate; the local listing seam is REAXML and portal feeds). No OpenID Connect discovery. No `/.well-known/` documents of any kind. No security.txt, no published vulnerability-disclosure policy, no trust centre, no named compliance certification. No sandbox. No official SDK in any package registry. No Postman collection. No AsyncAPI. No MCP server for the product API. No published API pricing. One region only (`ap-southeast-2`).