Portfolio API: Estate and Document Access
Two optional scopes that let your own tools read more than your investment portfolio.
Your estate plan (estate:read)
A key with estate:read can read the details of your estate plan under /api/v1/portfolio/ext/estate/:
- wills, other assets, relationships, guardians, gifts and trusts
- powers of attorney, funeral wishes and organ donation choices
- residency stays, journeys and accommodation
- appointments, engagement letters and to-dos
- the list of documents in your vault (titles and categories, not the files)
These lists are read only and support the same cursor pagination and updated_since syncing as the rest of the Portfolio API. To-dos are the exception: they are worked out fresh each time, so that list comes back whole and updated_since does not apply. Some of this is sensitive personal information, including health choices, so give the scope only to tools you trust.
The files themselves (documents:read)
documents:read lets a key download the files in your vault and your will documents. Because that is the most sensitive thing a key can do, it has extra safeguards:
- You confirm who you are again before creating a key with this scope, adding the scope, changing the key’s expiry or rotating it.
- The key must have an expiry date no more than 90 days away.
- A download request returns a signed link that expires after a few minutes. Fetch the file straight away.
- The first time a key downloads a file, we email you. That email cannot be switched off.
- Downloads have their own hourly limit, separate from your plan’s request limit, and every download is recorded.
Request GET /api/v1/portfolio/ext/documents/<id>/download/ for a vault file or GET /api/v1/portfolio/ext/wills/<id>/document/ for a will. A vault file that is still being security-checked answers 202 Accepted; try again shortly.
Tell your keys apart
Orchard72 API keys start with twai_, which makes them easy to search for in code and logs. If one is ever exposed, revoke it from your developer hub straight away.
Estate webhooks
Three webhook events let your tools react without polling. They carry ids and status only, never names, titles or file contents:
will.status_changed: a will moved to a new stagedocument.uploaded: a document was added to your vaulttask.due: a to-do has reached its due date
Fetch the detail with an estate:read key. Signing and retries are explained in the webhook reference.
Choosing scopes
Scopes never include one another. A key with documents:read but not estate:read cannot list your documents, and a key with estate:read cannot download them. Give each tool only the scopes it needs.
Related
- Portfolio API: Getting Started: creating a key and your first request.
- The full reference for each endpoint is in the interactive API documentation at
/api/v1/portfolio/ext/docs/.
Can’t find what you’re looking for?
Our support team is here to help. Contact us and we’ll get back to you as soon as possible.
Contact Support
