DEVELOPERS
Build on Alethia.
A REST API with API keys, webhooks and an OpenAPI spec, available on the Enterprise plan.
curl "https://app.alethiahq.com/api/v1/entities" \
-H "Authorization: Bearer tk_{workspaceId}_{secret}"THE API
- 9
- resources, from entities and people to fund commitments and cap-table records.
- 39
- endpoints, each with its parameters, response fields and a curl example.
- 19
- webhook events, signed with HMAC and retried on failure.
- 1,000
- requests per key per 15 minutes.
Counted from the API catalogue the reference pages are generated from.
QUICK START
From zero to your first request.
One. As a workspace admin on the Enterprise plan, open Settings, then Integrations, and choose New key. Give it a label and at least one scope, and add the restricted-records or webhook-management capabilities only if the integration needs them. The plaintext key is shown once.
Two. Send that key as a bearer token in the Authorization header on every call. The workspace is resolved from the key itself, so there is no workspace parameter to pass.
REFERENCE
Everything you need to integrate.
Authentication
How to mint a workspace API key, the Authorization header format, scopes, capabilities and the plan the API is available on.
Resources
Every resource and all 39 endpoints: parameters, request and response fields, and a curl example for each.
Webhooks
The 19 subscribable events, their payload shapes, HMAC signature verification, delivery and retries, and the test endpoint.
Errors
The error envelope and every status code the API returns, with the condition that produces each one.
Rate limits and paging
1,000 requests per key per 15 minutes, the headers that report your budget, and cursor pagination.
OpenAPI specification
The whole API as an OpenAPI 3.0 document: paths, schemas, security and the webhook event catalogue.
AI CONNECTOR
Connect an AI app to a workspace.
Alethia also runs an MCP server. A person can connect Claude, ChatGPT, Cursor or another MCP client to their workspace, sign in as themselves and ask it questions. It is on every plan and reads only what that person may see.
QUESTIONS
Building on the API, answered.
Do I need a paid plan to use the API?
The public API is an Enterprise capability: the workspace subscription must be active on Enterprise (verifyApiKey returns 403 otherwise), and workspace/company access must not be suspended. Scopes and any high-trust capabilities are set when the key is minted, in-app.
Where do I create an API key?
In the app, as a workspace admin: Settings → Integrations → New key. Choose a label and at least one scope; the plaintext key is shown once and cannot be retrieved again.
What's the rate limit?
1000 requests per 15 minutes, per key. Exceeding it returns 429 with Retry-After, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset headers.
Is there a machine-readable spec?
Yes — the full OpenAPI 3.0 document is served at /api/openapi.json, unauthenticated, ready to import into Postman, Swagger UI or a codegen tool.
Which resources are read-only over the API?
Properties and fund commitments are list/read (GET) only — there is no create, update or delete route for either.
Talk to us about your integration.
Tell us what you are building, and we will walk through the resources and events that fit.