# eContract Developer Portal > eContract is an e-signature platform with a REST API, OAuth 2.1, webhooks and a remote MCP server. AI agents and integrations can create and send contracts (PDF/DOCX or templates), follow signing, hand each signer a personal signing link, and download the signed PDF and a hash-chained audit trail. Signing is always done by a person: API keys and OAuth tokens can never sign or decline. eContract is free for now (fair-use caps apply). - REST API base URL: https://api.econtract.online/api/v1 - MCP server (Streamable HTTP): https://api.econtract.online/mcp - OpenAPI document (JSON, served by the API): https://api.econtract.online/api/v1/openapi.json - OpenAPI document (YAML, used by this portal): https://developers.econtract.online/openapi/econtract-api.yaml - OAuth 2.1 discovery: https://api.econtract.online/.well-known/oauth-authorization-server - Auth: `Authorization: Bearer cl_live_…` (API key, for your own backend; created by a workspace owner or admin under Dashboard → API Keys) or `Authorization: Bearer eco_at_…` (OAuth 2.1 access token, authorization code + PKCE, for apps and AI clients acting for other people). Both are scoped to one workspace, carry scopes (`contracts:read`, `contracts:write`, …) and act with a role capped at `contract_manager`. - Each OpenAPI operation has `x-econtract-auth`: `machine` (API keys and OAuth tokens with the scope in `x-econtract-scope`), `user-session` (web app users only; machine credentials get 403) or `public`. - Human signing rule: sign, decline, saved signatures and certificates answer `403 HUMAN_ACTION_REQUIRED` to API keys and OAuth tokens. Agents send contracts and hand out signing links; people sign. - Rate limits per API key or OAuth grant: 60 requests/minute, 1,000/hour, 10,000/day (`X-RateLimit-*` headers, `429 RATE_LIMITED` with `Retry-After`). Fair-use caps answer `429 USAGE_LIMIT_REACHED`. - Typical flow: POST /contracts/send (JSON, base64 file, `delivery: "link"`) → poll GET /contracts/{id} until `processingStatus` is `ready` → POST /contracts/{id}/signing-links → people sign → GET /contracts/{id}/document?version=signed and GET /contracts/{id}/audit-trail - Send an `Idempotency-Key` header on every write and reuse it on retries. - No official SDKs: generate a client from the OpenAPI document. ## Guides - [Quickstart](https://developers.econtract.online/docs/quickstart): API key, send a PDF, signing links, signed PDF and audit trail, webhook (cURL, Node.js, Python) - [AI agents](https://developers.econtract.online/docs/ai-agents): end-to-end agent flow, the human-signs rule, API key vs OAuth, document and audit-trail formats - [MCP server](https://developers.econtract.online/docs/mcp): tools and scopes, connecting Claude, Claude Code, ChatGPT, Cursor and VS Code, troubleshooting - [Authentication](https://developers.econtract.online/docs/authentication): API keys, scope catalogue, path-to-scope table, machine role cap, rotation, rate limits - [OAuth 2.1](https://developers.econtract.online/docs/oauth): discovery, Client ID Metadata Documents, dynamic registration, PKCE, resource/audience, tokens, refresh rotation, revocation, connected apps - [Core concepts](https://developers.econtract.online/docs/concepts): workspaces, contract lifecycle, async processing, signers, templates - [Webhooks](https://developers.econtract.online/docs/webhooks): events, payload, headers, signature verification, retries, delivery log - [Idempotency](https://developers.econtract.online/docs/idempotency): Idempotency-Key semantics and replay rules - [Errors](https://developers.econtract.online/docs/errors): error envelope, error codes, X-Request-Id, what to retry - [Limits and pricing](https://developers.econtract.online/docs/limits): free mode, fair-use caps, rate and size limits - [Changelog](https://developers.econtract.online/docs/changelog): API versioning policy and changes ## API reference - [API reference](https://developers.econtract.online/docs/api): base URL, authentication, `x-econtract-auth`, errors, rate limits; one page per operation - [Send a contract](https://developers.econtract.online/docs/api/contracts/ContractsController_send): POST /api/v1/contracts/send - [Signing links](https://developers.econtract.online/docs/api/contracts/ContractsController_signingLinks): POST /api/v1/contracts/{id}/signing-links - [Verify a signed PDF](https://developers.econtract.online/docs/api/public-verify/PublicVerifyController_verifyPdf): POST https://api.econtract.online/verify-pdf (public, no credential) - [OpenAPI (JSON)](https://api.econtract.online/api/v1/openapi.json): public API, with the scope of each operation (`x-econtract-scope`) - [OpenAPI (YAML)](https://developers.econtract.online/openapi/econtract-api.yaml): document used by this portal ## Optional - [llms-full.txt](https://developers.econtract.online/llms-full.txt): all guides in one file - [eContract](https://econtract.online): the product - [Verify a signed PDF](https://verify.econtract.online): free web tool for checking PDF signatures