Skip to content

Contracts

List contracts

contracts:read
ParameterInTypeRequiredDescription
statusquerystringNodraft | sent | signed | cancelled | expired
limitqueryintegerNoPage size, 1-200 (default 50)
cursorquerystringNoOpaque cursor from meta.nextCursor
Request exampleNo request body
curl https://api.rieckflow.com/v1/contracts \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Newest first. Each row carries signerCount/signedCount, so you can see how far a contract has got without fetching it.application/json
Possible errors 5
HTTPCodeMeaning
400invalid_cursorThe cursor is malformed, expired or belongs to another list shape.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Create a draft

contracts:write

{ title, content, parties[], expiresOn?, templateKey? }. Each party needs a name and email; role is signer (default) or copy, signatureMethod is mitid (legal weight), simpel or klik, and order controls who is asked when — a party is not asked until every lower number has signed. Nothing is sent: the draft stays editable until you call /send.

Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/contracts \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
201 The contract with its parties. Location points at it.application/json
Possible errors 7
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
429rate_limitedThe organisation’s rate budget is exhausted.

Get contract

contracts:read
ParameterInTypeRequiredDescription
contractIdpathstringYes
Request exampleNo request body
curl https://api.rieckflow.com/v1/contracts/9b2f1c1e-… \
-H "Authorization: Bearer $RIECK_API_KEY"
200 The contract, its content, its contentHash once frozen, and every party with its signing status. ⚠️ The signature evidence (CPR, MitID serial, IP, the drawn signature) is never serialised — it is evidence, not a message.application/json
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Delete a draft

contracts:write

Drafts only. A sent contract is cancelled, never deleted — the database enforces that independently.

ParameterInTypeRequiredDescription
contractIdpathstringYes
Request exampleNo request body
curl -X DELETE https://api.rieckflow.com/v1/contracts/9b2f1c1e-… \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
204 No contentNo response body
Possible errors 7
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
429rate_limitedThe organisation’s rate budget is exhausted.

Send for signature

contracts:write

This is the point of no return: the content is frozen and hashed, and the contract can no longer be edited. Options: requireCode (a 6-character access code per signer), email, sms, reminders, expiresOn, message (your covering text in the e-mail — it never touches the contract itself). Sending an already-sent contract returns it unchanged rather than failing, and never mints new links.

ParameterInTypeRequiredDescription
contractIdpathstringYes
Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/contracts/9b2f1c1e-…/send \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
200 The contract plus meta.links — each signer’s own URL and code. ⚠️ Those are CAPABILITIES: the path IS the permission to sign. They exist only in this response (we store only their hash), so deliver each one to its own party and do not log them.application/json
Possible errors 8
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
422customer_email_missingThe invoice cannot be sent because the customer has no e-mail.
429rate_limitedThe organisation’s rate budget is exhausted.

Cancel a contract

contracts:write

Withdraws a draft or a sent contract; the parties’ links stop working. A SIGNED contract cannot be cancelled — that is not an API limit, it is signed.

ParameterInTypeRequiredDescription
contractIdpathstringYes
Request exampleNo request body
curl -X POST https://api.rieckflow.com/v1/contracts/9b2f1c1e-…/cancel \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041"
200 The contract in its new state.application/json
Possible errors 7
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
429rate_limitedThe organisation’s rate budget is exhausted.

The sealed PDF

contracts:read
ParameterInTypeRequiredDescription
contractIdpathstringYes
Request exampleNo request body
curl https://api.rieckflow.com/v1/contracts/9b2f1c1e-…/pdf \
-H "Authorization: Bearer $RIECK_API_KEY"
200 The PAdES-sealed document the database stored when the last party signed — the thing to archive. 422 contract_not_signed until then; we do not hand you a report that looks like a contract.application/pdf
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Contract audit log

contracts:read
ParameterInTypeRequiredDescription
contractIdpathstringYes
Request exampleNo request body
curl https://api.rieckflow.com/v1/contracts/9b2f1c1e-…/timeline \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Newest first. kind: created, sent, signed, cancelled, expired, party_signed, party_declined, party_reminded, party_consented. The same append-only trail the portal renders — written only by the database’s own triggers, so there is no second version of it.application/json
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Your contract templates

contracts:read
ParameterInTypeRequiredDescription
limitqueryintegerNoPage size, 1-200 (default 50)
cursorquerystringNoOpaque cursor from meta.nextCursor
Request exampleNo request body
curl https://api.rieckflow.com/v1/contract-templates \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Your organisation’s own template library — latest version of each, archived ones excluded, newest first. templateId is stable across versions; id IS the version. Editing a template creates a new version rather than changing this one. ⚠️ Paged because each row carries the full content (up to 200,000 characters), not because the library is long.application/json
Possible errors 5
HTTPCodeMeaning
400invalid_cursorThe cursor is malformed, expired or belongs to another list shape.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.