# signatures.accept

Accept and sign an agreement in your own portal session, after reviewing the exact version. Only you can, interactively; agents can't sign for you.

`POST /api/v1/contractor/signatures.accept`

Permissions: `contractor:read`, `contractor:write` · Roles: contractor · Idempotency key required · Send `expectedRevision`

**INTERACTIVE_SIGNATURE_REQUIRED.** The contractor signs or declines in their own portal session. API and MCP calls are refused with a portalUrl to the agreement.

Not available over MCP: The named contractor signs or declines in person, after verifying again.

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `id` | string (ID) | Yes | The record's ID. |
| `expectedRevision` | integer | Yes | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. at most 9007199254740991; greater than 0. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–150 characters. |
| `challengeId` | string (ID) | Yes | The ID of the related record. |
| `challenge` | string | Yes | 40–200 characters. |
| `documentSha256` | string | Yes | SHA-256 hash as 64 lowercase hex characters. |
| `version` | integer | Yes | at most 9007199254740991; greater than 0. |
| `consent` | true | Yes |  |
| `legalName` | string | Yes | 1–300 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/contractor/signatures.accept \
  -H "Authorization: Bearer $OATMILK_OAUTH_TOKEN" \
  -H "X-Accounting-Organization: $OATMILK_ORGANIZATION_ID" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
  "expectedRevision": 3,
  "challengeId": "1a2b3c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d",
  "challenge": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c",
  "documentSha256": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c",
  "version": 1,
  "consent": true,
  "legalName": "Synthetic Ventures Inc."
}'
```

Reference page: https://app.getoatmilk.com/docs/api/contractor/signatures.accept
