
Short answer: Harvey has an API, and its documentation is open to read, but only customers can use it and the main assistant API costs extra. Legora publishes no API documentation that I could find, and its contract terms offer APIs "if specifically agreed in the Order Form". Legora does document an MCP connection (a way for another AI tool to ask it a question), which it turns on for each customer. Everything below comes from each company's own pages, read in early October 2026.
TL;DR
- Harvey: yes, documented. A public developer site lists endpoints, rate limits and sign-in steps for customers.
- Harvey access is by contract. Tokens are created inside a customer workspace, and features depend on your order form.
- Legora: no public API documentation found. Its terms allow APIs by agreement, and its help centre documents an MCP server.
- Both support single sign-on and connect to document systems. Those are integrations, which differ from an API a developer can build on.
- No page describes fetching law as stored text. Neither company's pages mention an endpoint that returns a statute by citation.
Terms used here
An API is a way for software to request something from another service and get a structured reply. An MCP server is a newer kind of connection. It lets an AI assistant such as Claude or ChatGPT call a service as a tool. Single sign-on (SSO) lets staff log in with their company identity instead of a separate password. An order form is the contract page that lists what a customer bought.
A short history of both
Both companies are young, and their developer stories are still taking shape.
Harvey. The first big public moment came on February 15, 2023. The law firm Allen & Overy, now A&O Shearman, put out a news release about adding Harvey to its work worldwide. It says Harvey "will empower more than 3,500 of A&O's lawyers across 43 offices," and that the firm had tested it in beta since November 2022.
Legora. The company was called Leya until February 19, 2025. Its own post that day tells the origin story. The first version appeared in May 2023. Mannheimer Swartling, which Legora calls Sweden's largest law firm, gave the team a room in its Stockholm office. The post says: "While many startups begin in garages, our journey began in a dedicated conference room at Mannheimer Swartling". It adds that the room was a product lab for nine months, until the paid launch.
Harvey
Harvey's help centre links to a Developer Portal. The portal opens without a login. Its introduction says the APIs let a firm bring its own data into Harvey and put Harvey inside its own tools.
The portal documents these areas:
- Assistant. A completion endpoint that sends a question, with optional files or storage projects, to Harvey and returns an answer.
- Vault. Upload, list, update and delete documents in Harvey's document storage. Search inside a project. Read or add rows in review tables.
- History export. Usage and query records for your organisation.
- Audit logs. Workspace activity records.
- Client matters. Create and update the clients and matters that usage is billed against.
The portal also lists six downloadable OpenAPI files. These are machine-readable descriptions of the endpoints. A separate page sets rate limits, counted for each organisation every minute. The limits are 20 for the assistant, 10 for Vault, 60 for audit logs, 2 for history export and 150 for client matters. Sending too many requests returns an error code, 429.
Who can use it. The authentication page says you create tokens in an "API Tokens" section of your workspace settings. If you cannot see it, contact your Customer Success Manager. The introduction says to check your order form or email Harvey support for which features your organisation can use. The assistant endpoint's own page is more direct. It needs an "Assistant access via API" permission, which is "only available in your workspace with an additional purchase".
MCP. Harvey also documents an MCP server with five tools. They answer legal questions, list research sources, list Vault projects and ask about Vault documents. It works with Claude, Google Gemini Enterprise and Microsoft 365 Copilot, and each person signs in with their own Harvey account. The guide's troubleshooting section says to check with your Harvey admin that you are enrolled in the feature.
Integrations and SSO. Harvey's site lists SAML single sign-on, audit logs and IP allow-listing among its security controls. Its help centre has an Integrations section. It covers Word and Outlook add-ins and connectors, including MCP connectors. It also covers document systems such as iManage, NetDocuments, SharePoint and Google Drive. Other tools named there are Ironclad, Aderant iTimekeep, PacerPro, Gmail search and Microsoft 365 Copilot. I read that section's index only. The two articles I tried did not load for me.
Legora
Legora is harder to pin down, so here is what I checked. I read Legora's main site, its sitemap, and its newsroom, product, engineering and legal pages. I also read its help centre, with the sitemap and machine-readable index. Then I tried the obvious developer addresses: developers, docs, api and help, each as a name on legora.com. None of those addresses answered, and the sitemap lists no developer or API page.
What I did find:
- Contract wording. Legora's US general terms, last updated May 2026, describe the service as a web, mobile and desktop product "or, if specifically agreed in the Order Form, APIs offered by Legora". Its security measures page uses the same words, and its security policy also lists "our application programming interface" among its services. So API access exists as something a customer can negotiate. No documentation for it is public.
- An MCP server. One help-centre page, How to connect an MCP client to Ask Legora, documents a remote MCP server with one tool, Ask Legora. You send a task. You can name a project and pick one or two jurisdictions for research. The tool waits up to 20 seconds for an answer and returns it with a link to the Legora chat. The page says: "Legora enables this connection for each organization. If you can't connect, contact Legora support to request access." The English sitemap does not list this page. I found it through the Korean section.
- Partner use of MCP. A September 17, 2026 press release says the ChatGPT Enterprise plugin "runs through Legora's MCP server" and is available to shared customers. An August 25, 2026 release describes a beta MCP connection for approved mutual customers of Google Cloud's Gemini Enterprise for Legal.
Integrations and SSO. Legora's product page says its platform brings in "DMS integrations, document ingestion, content sources, third-party legal services, and MCP connectors". Its help centre has setup guides for SAML 2.0 and Entra ID single sign-on. It also has guides for the Word and Outlook add-ins. A newsroom release says Legora links to iManage "through iManage APIs". That means Legora calls iManage's API. It does not describe an API of its own.
One limit on my check. The help centre's home page shows article cards, such as one on the Legora Agent, that I could not open. Some content may sit behind a login or outside its sitemap. "Not published" here means not published where I could look.
The comparison in one table
| Product | API publicly documented? | Who can use it | Source |
|---|---|---|---|
| Harvey API (assistant, Vault, history, audit logs, client matters) | Yes: endpoint pages, rate limits and OpenAPI files | Customers with the right permissions; the assistant endpoint needs an additional purchase | Harvey developer portal |
| Harvey MCP server | Yes: setup guide and tool list | Enrolled Harvey users, signing in with their Harvey account | Harvey developer portal, MCP guide |
| Legora API | No documentation found | Only where "specifically agreed in the Order Form" | Legora US general terms |
| Legora MCP server | Yes: one help-centre page | Organisations that Legora enables; others contact Legora support | Legora help centre |
Where the law inside each assistant comes from
An assistant that answers legal questions needs a body of law behind it. Each company has said how it got one. These are announcements, so they cover what each company chose to share.
On June 18, 2025, Harvey posted news of a strategic alliance with LexisNexis "to integrate LexisNexis generative AI technology, primary law content, and Shepard's Citations within the Harvey platform". Harvey's CEO, Winston Weinberg, says in the post that the two are "delivering seamless access to reliable, citation-backed answers and custom workflows". The post said the integration would arrive "later this year", so ask what is live for your account.
On August 5, 2026, Legora announced new US case law, statutes, regulations and agency guidance in its research tool. It says every document was "sourced directly from the courts, official reporters, agencies themselves, and trusted partners," and it names Wolters Kluwer as the source of its statutes and regulations.
So one company gets US primary law through an alliance. The other describes building its own collection. Neither announcement mentions an API, and that matters for question 6 below. Law inside an assistant's answers is not always text your own software can fetch.
What to ask
Use these with either company, or any vendor that says "we have an API". Two of them lean on shared standards. OpenAPI is a neutral format for describing an API. The OpenAPI Initiative says it grew from the Swagger Specification, which SmartBear Software donated. MCP lets AI assistants call a service. Anthropic released it as open source on November 25, 2024 as "a new standard for connecting AI assistants to the systems where data lives". So a vendor that publishes an OpenAPI file or an MCP guide gives you something you can check.
- Is there written documentation I can read before signing, and can you send the OpenAPI file?
- Which endpoints does my order form include, and which cost extra?
- What are the rate limits, per organisation or per user, and how do I ask for more?
- Do API calls count towards my seat price or a separate meter?
- Can I create and revoke tokens myself, or does support do it?
- What does the API return: my own documents and answers, or also the underlying law as text I can store?
- Do API and MCP calls log to the same audit trail as app use?
- What happens to my integration when a version changes?
Question 6 matters most for engineers. Harvey's endpoint list is built around its assistant, document storage and admin records, and research content is reached by asking questions. If you need statutes and regulations delivered as data, with a citation in and the text out, check that before you buy. Vaquill AI is built for that kind of retrieval over US primary law.
For the wider checklist, see the ten questions to ask a legal data vendor.
Where to read next
Our full reviews cover Harvey and Legora as products, and Harvey vs Legora compares them directly. For API-first sources of US law, see the legal data API roundup and the complete guide to US law data.
A sales rep says "yes, we have an API," but you cannot find documentation anywhere. What is the most useful next request?
FAQ
Does Harvey have an API?
Yes. Its developer portal documents an API for its assistant, its document storage (Vault), usage history, audit logs and client matters. Only Harvey customers can use it. The assistant endpoint needs an extra purchase.
Is the Harvey API public?
The documentation is public and needs no login. Using the API is not public, because tokens are created inside a customer's workspace and the features depend on the order form. Harvey sends you to your Customer Success Manager or its support address.
What are the Harvey API rate limits?
Harvey publishes them for each organisation, per minute. The limits are 20 requests for the assistant, 10 for Vault, 60 for audit logs, 2 for history export and 150 for client matters. Exceeding a limit returns a 429 error.
Does Legora have an API?
I found no public API documentation from Legora. Its terms say APIs are offered "if specifically agreed in the Order Form", so a customer can ask to negotiate access. Ask Legora for written documents before you rely on it.
Does Legora have an MCP server?
Yes. A help-centre page documents a remote MCP server with one tool, Ask Legora. Legora says it enables the connection for each organisation. Its press releases describe MCP-based connections for a ChatGPT Enterprise plugin and a beta Gemini Enterprise integration.
Can I get legal research data from the Harvey or Legora API?
Harvey's published endpoints cover its assistant, documents and administration, and its MCP tools can query research sources by asking questions. Legora's MCP tool takes a question and optional jurisdictions and returns an answer with a link. Neither page describes fetching the text of a statute by citation. If that is the need, ask each vendor directly.
Do Harvey and Legora support single sign-on?
Both do. Harvey lists SAML single sign-on among its security controls. Legora has setup guides for SAML 2.0 and Entra ID. Single sign-on controls how your staff log in. It says nothing about whether a developer API exists.
Where do I start if I need legal data in my own product?
Start with the checklist above, then look at sources built to deliver law as data. The US primary law API is one such starting point.
New legal AI guides, weekly.
Further Reading
Westlaw API: What Exists, Who Can Use It and What It Covers
Read postLexisNexis API: What the Developer Portal Offers and How Access Works
Read postLexis+ AI, CoCounsel and Westlaw AI: Is There an API?
Read postFastcase, vLex and Clio: One Family, Which APIs Exist?
Read postMidpage API: What It Offers and Who It Fits
Read postThe Legal AI Funding Arms Race: What $11B Harvey Means for In-House Buyers
Read post
Co-Founder & CTO
Priyansh leads engineering and AI at Vaquill AI: the pipelines that pull statutes, regulations and court rules from every US jurisdiction's official publisher, and the REST API, MCP server and open dataset that serve them.