Clio API Guide: How It Works and Where Legal Data Fits

Title card for the Vaquill AI guide: Clio API Guide: How It Works and Where Legal Data Fits

Short answer: the Clio API lets your software read and write the records a law firm keeps in Clio, such as matters, contacts and documents. It uses OAuth 2.0, so each firm user approves your app before it can touch their data, and you register the app in Clio's developer portal. To reach other firms, you apply to be listed in the Clio App Directory. Clio's published API documentation has no research service, so the text of a statute or a regulation has to come from a separate legal data source that you connect yourself.

TL;DR

  • Clio is practice management software. That is the system a law firm uses to run its work, from client matters to billing.
  • There are two developer systems. The Clio Manage API is the main one. The Clio Platform covers Clio Grow today and is meant to cover more later.
  • Sign-in is OAuth 2.0. Each user approves your app and you choose the permissions it asks for.
  • Limits are published. Clio Manage allows 50 requests a minute per token at peak hours.
  • Clio's documentation we read has no research API. Legal research data comes from a different provider. The last half of this guide shows where it can fit.

What Clio is, and what its API is for

Clio makes software that law firms use to manage their practice. The core product is Clio Manage. A "matter" in Clio is one client engagement or case, and most other records hang off it, such as the people involved, the documents and the invoices.

An API, short for application programming interface, is a set of web addresses that software can call to read or change data. Clio's developer hub says its APIs let you "power workflows, build integrations, and drive innovation." Legal software companies use it so their customers do not retype data. Firms use it to build private tools for themselves.

A short history of Clio's platform

It helps to know how Clio ended up with an app ecosystem at all. Clio's own history page says the company was founded in 2008 by Jack Newton and Rian Gauvreau, and that in 2013 it marked its fifth birthday by launching the Clio Cloud Conference, its annual user event, and opening offices in Toronto and Dublin.

Outside integrations became a big deal a few years later. In October 2017, LawSites, the legal technology blog by journalist Bob Ambrogi, reported that Clio had added 12 more integration partners, "bringing the total to more than 70," and called the App Directory "new." A year later, on October 4, 2018, Newton announced at the conference in New Orleans that Clio had bought Lexicata, a client intake tool, and was launching Clio Grow. The ABA Journal noted it was Clio's first acquisition. Clio's history page now lists Clio Grow as the former Lexicata.

By October 22, 2019, LawSites reported another 35 integration partners, "bringing the total to almost 200." Newton described the idea like this: "Much like you can customize your smartphone with a number of products and services that work together, Clio provides a platform to integrate all of the legal technologies that help law firms improve their client services and firm productivity."

Go from about 70 listed integrations to almost 200 in two years and you get a sense of how normal this route is. If you are about to build a Clio integration, you are joining a crowd. The directory also shows what that crowd builds. The 2019 list runs from document assembly and mail to time tracking and hiring appearance attorneys.

The two developer systems

Clio's handbook says that, as of January 2026, there are two ways in. The table sets out the differences we read in the documentation.

Clio Manage APIClio Platform API
Products reachedClio ManageClio Grow today, more planned by Clio
Developer portaldevelopers.clio.comdevelopers.api.clio.com
Base address (US)app.clio.com/api/v4api.clio.com
Default rate limit50 requests per minute per access token at peak hours3 requests per second per app
Access token lifetime30 days24 hours
Refresh tokenDoes not expireReplaced each time you use it
Test account7-day trial, then a free developer account if approvedFree developer team, plus a trial of the product

If your app needs both products, Clio says you must currently create one app in each system, and your users approve each one separately. The rest of this guide focuses on Clio Manage.

What an integration can do

Clio publishes a reference listing every resource the Manage API exposes. The main groups are:

  • Matters and contacts, including practice areas and matter stages.
  • Documents, with folders, versions, uploads and downloads.
  • Notes, tasks and calendar entries.
  • Time and expense entries, and bills.
  • Custom fields, which let a firm add its own data points to a record.

Three features matter if you add outside data to an app. Webhooks let Clio notify your app when a record is created, updated or deleted, so you do not have to keep asking. Custom actions add a menu item inside Clio Manage on a matter, contact, document or activity. When a user clicks it, a new browser tab opens at your address with the record's identity attached. Add to Clio lets a user begin the connection from inside Clio instead of from your site.

How sign-in works

Clio follows the OAuth 2.0 "authorization code" pattern. OAuth is the standard way for a user to let one app use another service without sharing a password. The steps, as the docs describe them:

  1. You create a developer application in the portal. You name it, give it a website address and redirect addresses, and accept Clio's developer terms.
  2. You choose access permissions, which are the same thing as OAuth scopes. Each is read-only or read and write, per resource. Clio advises asking for the smallest set that works.
  3. Your app sends the user to Clio's authorize address. The user sees the permissions you asked for and approves them.
  4. Clio sends the user back to your redirect address with a code that is valid for 10 minutes. Your app trades the code for an access token and a refresh token.
  5. Your app sends the access token on every call. When it expires, your app uses the refresh token to get a new one.

Two details trip up newcomers. If you add a permission later, existing users must approve again. And the user's own role in their Clio account also limits what they can reach, so a call can fail with a 403 error even when your app has the right permission.

Why the design looks like this. Before OAuth, an app that wanted your data often asked for your password. The IETF, the body that publishes internet standards, says in RFC 5849 (April 2010) that OAuth 1.0 "was originally created by a small community of web developers" who wanted to solve delegated access, meaning one program acting for a user at another service. OAuth 2.0 arrived as RFC 6749 in October 2012 and replaced it. Its introduction lists what goes wrong when you hand a third party your password. The app has to store that password, often in clear text. It gets far more access than it needs. And "Resource owners cannot revoke access to an individual third party without revoking access to all third parties, and must do so by changing the third party's password."

Clio's approval screen is the fix for each of those. Your app never sees a firm user's password, the user sees which permissions you asked for, and the firm can cut off your app without disturbing anything else.

Regions

Clio runs separate instances for the US, Canada, EMEA (Europe, the Middle East and Africa) and Australia. A token from one region does not work in another, and an app built for US customers does not automatically work for Canadian ones. The base address changes with the region, for example eu.app.clio.com for Europe. If you serve several regions you need a developer account and an app in each, and you must record which region each user belongs to.

Rate limits

Clio Manage counts requests per access token over a 60-second window. The default is 50 requests per minute during peak hours, and higher off-peak. Peak hours for the US and Canada are 04:00 to 19:00 Pacific Time, Monday to Friday. Clio says limits can change without notice, so your code should read the rate-limit headers on each response. Clio says it does not offer custom limit increases at this time. If you go over, the API returns a 429 error with a header saying how long to wait. Some third-party guides quote different numbers. The figures here come from Clio's own documentation.

Building and listing your app

Clio has no separate sandbox. Its handbook says to use the 7-day trial, then apply for a free developer account. Private apps, which serve one firm, are not reviewed and cannot appear in the App Directory. The docs also say apps are not available on Clio's EasyStart pricing tier, which limits who can use yours.

To appear in the App Directory, Clio's launch page lists four steps: a security review, a recorded demo for Clio's partnerships team, a listing you fill in, and launch. Clio's documentation hub is the place to start. You will reread its authorization guide and rate limit page often, and the regions page lists every address.

Clio Manage holds the firm's own records, and the law itself sits in a research library. A lawyer working a matter still needs to know which statutes and regulations apply, and whether the citations in a draft are real. That is a research job, and there are three ways it can meet a Clio app.

Clio's own research products. Clio now owns the vLex research library and the Vincent assistant. Clio's help center says Vincent can read a matter's context from Clio Manage. That is a feature inside Clio's products. The developer documentation we read has API references for Manage, Grow and Accounting, and none for research. Our guide to the Fastcase, vLex and Clio family covers what each company says about API access.

A research tool that pushes into Clio. Fastcase's own page describes an integration that saves research to a matter in Clio and logs research time with the Clio timer. That pattern starts in the research tool and writes into Clio. It is not new. LawSites' October 2019 list of new Clio integration partners already included Fastcase BK, a bankruptcy forms tool that saves documents to the right matter in Clio.

Your app, pulling law in from a data API. It fits two simple jobs.

  • Link a matter to the law that governs it. A custom action on the matter opens your app. Your app reads the matter through the API, finds the statutes or regulations the firm has listed, fetches their text from a legal data source, and shows it beside the matter. You can save the result back as a note or a document.
  • Check the citations in a document. Your app downloads a draft through the Documents API, pulls out the statute and regulation citations, and asks the data source whether each one points to a real section. A citation that does not match should be treated as unverified until a person looks at it.

We are not saying a ready-made connector between Clio and any research API exists. This is a design you could build with the two APIs. Clio's security guidelines tell developers to request and store only what they need and to track every outside service that touches user data. Sending an outside service only a citation or a search phrase, and never the document, keeps that exposure small.

A primary-law API such as Vaquill AI's can serve these jobs for US statutes, regulations, court rules and agency guidance. Its published spec lets you resolve a citation to its exact section, fetch a section's text by identifier, and search across the corpora it covers. The citation check described above covers statute, regulation and rule citations.

Before you build

  1. Which Clio product are your users on? Manage and Grow use different systems today.
  2. Which regions will you serve? Plan an account and an app for each.
  3. What is the smallest set of permissions you need? Fewer permissions mean fewer approval screens.
  4. Can your app live within 50 requests a minute per token? Batch where you can and cache what you fetch.
  5. Where will legal data come from, and under what terms? Read the licence for display, storage and use inside your product. Our ten questions for a legal data vendor and build or buy guide help here.
  6. Who checks the result? A match against a database tells you a citation exists. A lawyer still decides whether it supports the argument. See our guide to verifying citations before filing.

For the wider picture of US legal data sources, start at the US law data guide.

Try it

This call checks one federal statute citation against the Vaquill AI API. Replace the key with your own.

curl -G "https://api.vaquill.ai/api/v1/us/statutes/resolve" \
  --data-urlencode "cite=29 U.S.C. 206" \
  -H "Authorization: Bearer vq_key_YOUR_KEY"

The reply has resolved: true and a section with the section's title ("Minimum wage"), its identifier and a link to the official source. A citation that does not resolve comes back with resolved: false. A batch form takes up to 50 citations in one request, which suits a whole document.

What would you do?
Question 1 of 4

You are choosing between asking firm staff to type their practice-management password into your app and sending them to a sign-in screen where they approve your app. Why is the second design the safer one?

FAQ

What is the Clio API?

It is a set of web addresses that let other software read and change data in Clio, such as matters and contacts. The main one is the Clio Manage API. Clio also runs a Clio Platform API, which reaches Clio Grow today.

How do I get access to the Clio API?

Sign up for a 7-day Clio Manage trial, then apply for a free developer account. In the developer portal you create an app and receive a client ID and secret. Clio Platform developers use a separate portal and a free developer team.

How does Clio API authentication work?

Clio uses OAuth 2.0 with the authorization code flow. A user approves your app on a Clio screen, and your app receives an access token to send with each call. Manage access tokens last 30 days, and refresh tokens do not expire.

What are the Clio API rate limits?

For Clio Manage the default is 50 requests per minute per access token at peak hours, with higher limits off-peak. The Clio Platform default is 3 requests per second per app. Clio says custom increases are unavailable at this time and that limits can change, so read the response headers.

How do I list my app in the Clio App Directory?

You pass a security review, send Clio's partnerships team a demo, fill in a listing, and Clio launches it. Private apps for a single firm skip this and cannot be listed. Clio's launch page has the contact details.

The documentation we read lists API references for Clio Manage, Clio Grow and Clio Accounting, and none for legal research. Clio owns vLex and Vincent, but we found no public API documentation for them. Ask Clio directly if you need that access.

We have not verified one. The design in this guide uses the Clio API and a legal data API that you connect yourself. Check Clio's App Directory for current listings before you build.

Can I add statute text to a Clio matter?

Yes, as a design you build. Your app can read the matter, fetch the statute text from a legal data source and write it back as a note or document. The Clio documentation lists notes, custom fields and documents as resources your app can create with the right permissions.

For readers who want the US primary law behind such an app, see /legal-api.

Connect our US primary law database.
Every US statute, regulation, constitution, and executive order via REST, MCP or SQL. 5M+ sections, section-level citations, and links to the official source. Plus a free open dataset.
Updated October 5, 202617 min read

New legal AI guides, weekly.

Priyansh Khodiyar

Priyansh Khodiyar

Co-Founder & CTO

Priyansh leads engineering and AI at Vaquill AI: the pipelines that pull statutes, regulations and court rules from every US jurisdiction's official publisher, and the REST API, MCP server and open dataset that serve them.