Skip to main content
Pathway’s application and built-in agent use the same product API described here. A Personal Access Token is scoped to its user and organization. Read-only tokens can inspect the workspace. Read-write tokens can use the mutations allowed by that user’s role. This page is the wide map. The rest of the guide goes deeper on the underwriting paths most integrations need. Use the live OpenAPI explorer for every operation and generated schema within a family.

Deals and documents

Underwriting data

Transaction tags, debt positions, exclusions, screening, and web research are also managed through Book routes. Those mutations feed the next analytics request, which always calculates from the Book’s current stored state and organization settings.

Underwriting configuration

Intake and organization data

CRM and connected systems

Some connection setup routes require an interactive user session because they complete OAuth or an administrator action. PAT access is enforced per route, token mode, organization membership, and user role. A 403 means the credential is valid and lacks permission for that operation.