Contractor portal

signatures.accept

Accept and sign an agreement in your own portal session, after reviewing the exact version. Only you can, interactively; agents can't sign for you.

POST/api/v1/contractor/signatures.accept

INTERACTIVE_SIGNATURE_REQUIRED. The contractor signs or declines in their own portal session. API and MCP calls are refused with a portalUrl to the agreement.

Permissions

contractor:readcontractor:write

Who can call it

contractor

Retries

Idempotency key required, with expectedRevision

MCP

Not offered over MCP: The named contractor signs or declines in person, after verifying again.

Fields

  • idstring (ID)Required

    The record's ID.

  • expectedRevisionintegerRequired

    The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.

    at most 9007199254740991 · greater than 0

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–150 characters

  • challengeIdstring (ID)Required

    The ID of the related record.

  • challengestringRequired

    40–200 characters

  • documentSha256stringRequired

    SHA-256 hash as 64 lowercase hex characters

  • versionintegerRequired

    at most 9007199254740991 · greater than 0

  • legalNamestringRequired

    1–300 characters

Example

curl https://app.getoatmilk.com/api/v1/contractor/signatures.accept \
  -H "Authorization: Bearer $OATMILK_OAUTH_TOKEN" \
  -H "X-Accounting-Organization: $OATMILK_ORGANIZATION_ID" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
  "expectedRevision": 3,
  "challengeId": "1a2b3c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d",
  "challenge": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c",
  "documentSha256": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c",
  "version": 1,
  "consent": true,
  "legalName": "Synthetic Ventures Inc."
}'
Response
{
  "data": { … }
}

Try it

Try it

Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.

POST/api/v1/contractor/signatures.accept
curl https://app.getoatmilk.com/api/v1/contractor/signatures.accept \
  -H "Authorization: Bearer $OATMILK_OAUTH_TOKEN" \
  -H "X-Accounting-Organization: $OATMILK_ORGANIZATION_ID" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
  "expectedRevision": 3,
  "challengeId": "1a2b3c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d",
  "challenge": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c",
  "documentSha256": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c",
  "version": 1,
  "consent": true,
  "legalName": "Synthetic Ventures Inc."
}'

More in Contractor portal.