# API Report Card: Property Meld — Property Meld API (Version 2)

## Run metadata
- Methodology version: 1.1
- Evaluating model: Claude Fable 5.1 (claude-fable-5-1), Claude Code
- Date run: 2026-09-01 (evidence accessed 23:30–23:59 UTC)
- Provisional evidence-packet version or ID: PM-CLEANROOM-B-2026-09-01-prov1 (all sources below except those listed in the amendment log)
- Final evidence-packet version or ID: PM-CLEANROOM-B-2026-09-01-final2 — frozen copy at `evidence\meld-cleanroom-B-2026-09-01\` (`sha256-manifest.txt`; OpenAPI JSON sha256 `1c6f1140c5e2c87abec8a72f64d81256d5d6399359658a3a38062b02f35bd0bb`, YAML sha256 `55d68ca7ef793797bdaf03afaced854943219a6c7e5fe0389a12d55e3f1ea5e5`). final1 (read-only) was superseded by final2 after the operator authorized controlled live writes in the same session; no documentary source changed between them.
- Evidence-discovery mode: tool-enabled discovery (fresh session; no prior run material was read or reused)
- Evidence tier: fully verified — controlled live
- Live-write method and safety: controlled live — operator authorization recorded in chat (2026-09-01: "yes", then Tier 1 + Tier 2 approved, Tier 3 declined); fixtures = API-created `APITEST-DELETE` property, `APITEST-DELETE-UNIT` unit and `APITEST-DELETE-n` tags; every write stayed inside those fixtures; no meld, chat, invoice, estimate, assignment or notification-bearing call was made; cleanup verified by GET 404 and by list counts (properties 620, units 749, tags 9 — identical to pre-test). Plan: `live\01-controlled-live-write-plan.md`; results: `live\02-controlled-live-write-results.md`.
- Minimum live-test battery: steps 1–7 complete; step 8 N-A (no webhooks)
- Live tests performed: authenticate (token endpoint, `/check_token/`, `/ping/`); read and page `/meld/` plus 16 other list endpoints and one meld detail; page-size cap and ordering probes; incremental filters (`updated__gte`, `updated__lte`, `last_updated_gte`, `status`, `created__gte` in ISO and unix-ms); 12 deliberate error probes; header inspection on 419+ responses; two rate-limit bursts (120 requests at 31 req/s, 240 requests at 272 req/s); controlled writes — tag create/rename (PATCH and PUT)/delete, property create/update/deactivate, unit create/update/deactivate; idempotent double-send with both documented header spellings on tags and with `X-Idempotency-Key` on a property
- Live tests not possible: meld create/assign/complete (Tier 3 declined by the operator because a meld cannot be deleted or canceled via the API and may notify staff); vendor/technician assignment (would notify a real person)
- Documentation-graded checks (baseline verified): none — but within C1.2 and C1.3 the meld-specific items (create meld, assign, complete, cancel) remain graded from the OpenAPI schema and Permissions guide; property, unit and tag items were observed

## Final evidence packet manifest
Developer hub (ReadMe-hosted, public)
- https://docs.propertymeld.com/ — home; "API Version 1 Deprecation" notice; "If you need Version 2 API credentials, please contact Property Meld Support"
- https://docs.propertymeld.com/llms.txt — index of guides, 94 reference pages, recipes, changelog
- https://docs.propertymeld.com/v1.0/llms.txt — v1 (path `/api/v0.0.1/`) index
- https://docs.propertymeld.com/docs/getting-started.md
- https://docs.propertymeld.com/docs/making-your-first-api-request.md
- https://docs.propertymeld.com/docs/openapi-schema.md
- https://docs.propertymeld.com/docs/idempotent-requests.md
- https://docs.propertymeld.com/docs/rate-limitingthrottling.md
- https://docs.propertymeld.com/docs/permissions.md (updatedAt 2026-08-20)
- https://docs.propertymeld.com/reference/*.md — all 94 reference pages listed in llms.txt (each embeds the operation's OpenAPI definition)
- https://docs.propertymeld.com/recipes/*.md — 9 recipes (first request, paginate, filter, idempotency key, unit create/update/delete, vendor invites, media upload, deprecated media, custom report)
- https://docs.propertymeld.com/changelog — 2 entries ("Welcome", created 2021-06-01; "List and Detail Vendor Invite Endpoint", created 2024-04-26)
- https://api.propertymeld.com/api/v2/schema/ — OpenAPI 3.0.3, public and unauthenticated; YAML by default, JSON via `Accept: application/json` or `?format=json`; 60 paths, 94 operations, 140 schemas; single server `https://api.propertymeld.com/` "Property Meld Production Application"

Vendor site and help center
- https://propertymeld.com/ — product positioning ("Property Maintenance Software"; Communication, Scheduling, Oversight & Data, MAX Intelligence, TrueCost)
- https://propertymeld.com/pricing/ — Core $1.60/unit/mo, Ops $2.00/unit/mo; "Miscellaneous — API access for customer-built agent interactions — Ops only"
- https://propertymeld.com/property-meld-integration-partners/ — accounting and inspection integrations, Partner Nexus
- https://propertymeld.com/terms-of-use/ — "provided by Property Meld, Inc."; API mentioned in warranty disclaimer
- https://propertymeld.com/privacy-policy/
- https://propertymeld.com/sitemap_index.xml and child sitemaps (523 URLs; no developer/API pages beyond integrations and pricing)
- https://help.propertymeld.com/hc/en-us — categories (Coordinators/Property Managers, Residents, Maintenance Techs, Vendors, Admin/Executives, Accounting, Property Owners/Investors, Nexus, Help and Support)
- https://help.propertymeld.com/hc/en-us/search?query=… — searches: API (13), webhook (0), API key (48), Nexus API (21), sandbox (0), release notes (239), client credentials (7), API credentials (16), Create API Key (19), Nexus partner API (9), integration credentials (105), developer (2), custom integration (159) — every API-related hit concerns Propertyware/Rentvine/Yardi/Rent Manager PMS integrations, none the Property Meld API
- https://help.propertymeld.com/hc/en-us/sections/45583077692563-Integrations-Partner-Nexus, …/categories/44512819122067-Admin-Executives
- https://help.propertymeld.com/hc/en-us/articles/46505599019923-Property-Meld-101-Let-s-Get-Set-Up

Status
- https://status.propertymeld.com/ — Atlassian Statuspage; 11 components (System, Search, Email and Text Notifications, File Upload and Download, Meld Chat, Propertyware/AppFolio/Buildium/Rent Manager Integration, Workflows, MAX on Call) with per-component uptime percentages (99.98 %, 100.0 %)
- https://status.propertymeld.com/history, https://status.propertymeld.com/uptime, https://status.propertymeld.com/history.atom — 25 incident entries, latest updated 2026-09-01

Live observations (operator-supplied production credential)
- `evidence\meld-cleanroom-B-2026-09-01\live\live-log-2026-09-01.jsonl` (all calls, Authorization redacted), `00-live-battery-summary.md`, `list-endpoint-summary.json`, `01-controlled-live-write-plan.md`, `02-controlled-live-write-results.md`, `tier1-tags-notes.txt`, `tier1b-tags-recheck-notes.txt`, `tier2-property-unit-notes.txt`

## Evidence-amendment log
Controlled verification pass (one targeted first-party search per no/partial/unverified finding; same procedure for every finding):
- C1.4, C2.8 — site-restricted search "webhooks / event notifications / callback URL" (propertymeld.com, docs, help): no first-party source found; marks unchanged.
- C3.5 — site-restricted search "sandbox / test environment / staging": none found; N-A unchanged.
- C4.2 — search for SDK / client library / MCP: added https://github.com/Property-Meld (14 public repositories: Heroku buildpacks and forks of django/graphene/zeep; no API SDK); mark unchanged.
- C2.10, C2.11, C2.12 — search "breaking changes / deprecation policy / request id / SLA": added https://propertymeld.com/frequently-asked-questions/, https://propertymeld.com/nexus/, https://propertymeld.com/property-meld-customer-support/ (no API, SLA or uptime content); marks unchanged.
- C4.4 — extracted entry dates from the changelog HTML (2021-06-01, 2024-04-26); supports partial.
- C3.1–C3.4, C5.1 — login-gated product interface: added **https://app.propertymeld.com/317/n/317/nexus/api-keys/** ("Nexus API Keys"), read in the operator's own logged-in Chrome session (read-only; nothing clicked, created or revoked; page text saved as `app-ui\nexus-api-keys-page-text-2026-09-01.txt`). Effect: C3.3 unverified → yes; C3.4 unverified → yes; C5.1 provisional partial → yes; C3.1 and C3.2 stay no (no scope, role or read-only control on the key list).
- C5.1 — added help-center sections Account Settings, User Management, Account Management (no article on API keys); no further change.
- C1.2, C1.3, C2.3, C2.4 — controlled live writes (same session, after operator authorization): added `02-controlled-live-write-results.md`. Effect: C2.4 yes (documentation-graded) → **partial** (observed: the guide's `X-IdempotencyKey` header is not honored, retry returned 500; the recipe's `X-Idempotency-Key` replays correctly); C2.3 partial confirmed with an additional unhandled 500 on a duplicate tag name; C1.2 and C1.3 marks unchanged, now observation-backed for property/unit/tag operations.

## API eligibility
- Qualifying API: yes
- API operator: Property Meld, Inc. [terms-of-use: "provided by Property Meld, Inc."; OpenAPI `info.title` "Property Meld API", `contact.email` support@propertymeld.com]
- Access or credential issuer: Property Meld — OAuth2 client-credentials pairs created on the "Nexus API Keys" screen of the operator's account (`Create API Key`, per-key `Revoke`) [app.propertymeld.com Nexus API Keys page, observed 2026-09-01]; docs also state "If you need Version 2 API credentials, please contact Property Meld Support" [docs home]
- Eligibility basis: first-party REST API at `https://api.propertymeld.com/api/v2/` exposing melds (work orders), properties, units, residents, vendors, owners, invoices, estimates and more, with a public OpenAPI 3.0.3 schema and developer hub [OpenAPI `paths`; docs home "The Property Meld API is a REST-based set of services…"]. Live: token issued, `GET /meld/` returned 25,716 records for the operator's tenant, and a property, unit and tags were created, updated and deleted under the controlled protocol.

## Context
- Software category: maintenance or operations tool
- What the API is for and its core objects and workflows: The API gives programmatic access to a management company's Property Meld account — its maintenance requests ("melds"), the properties, units, residents, owners and vendors attached to them, work logs, invoices, expenditures and estimates. Core workflows are creating melds, moving them through status (assignment, scheduling, completion), and exchanging chat, files and financial documents on them. It is designed for "bespoke system integrations, maintenance analytics, automated custom workflows" [docs home].

## Provider and property-management fit
- What this product is: Property Meld is maintenance-operations software for residential property managers that tracks work orders from resident intake through vendor or technician completion. [propertymeld.com home: "Property Maintenance Software"; help-center categories]
- Bank status, when relevant: N-A (not a financial product)
- Who provides any bank account or regulated banking service: none [no banking content on any first-party page]
- What the customer actually receives: a per-unit subscription to hosted maintenance software (resident portal, coordinator dashboard, vendor/technician apps, MAX AI intake) plus this API on the Ops plan [pricing page]
- Property-management fit: PM-specialized [home page; help-center audiences: Coordinators / Property Managers, Residents, Maintenance Techs, Vendors, Property Owners / Investors; integration pages for AppFolio, Buildium, Propertyware, Rent Manager, Rentvine, Yardi]
- Documented PM-specific workflows: resident maintenance request intake and triage (MAX), coordinator assignment and scheduling, vendor acceptance and invoicing, owner approval of repairs, turns and renovation projects, expenditure export to the accounting PMS [pricing feature table; help-center "Accounting" and "Property Owners / Investors" categories; Permissions guide]
- Trust or fiduciary workflow support, when relevant: N-A (no funds are held or moved; invoices/expenditures are documents exported to the PMS)
- Operational role and dependencies: Property Meld runs the maintenance workflow and hands invoices and expenditures to a separate property-management/accounting system (AppFolio, Buildium, Propertyware, Rent Manager, Rentvine or Yardi) for ledgers, owner statements and payments.

## Coverage classification (fixed before inspection)
Default maintenance/operations classification, applied without deviation. "Present" states below were filled in after inspection and are scored against the **Property Manager** access level (the operator's own level; Permissions guide) because that is the access a PM operator receives.

| Object or workflow | Class | Weight | Present / read-only / absent |
|---|---|---|---|
| Work orders (melds) | critical | 3 | present — GET list/detail, POST, PUT, PATCH |
| Status transitions | critical | 3 | present, materially limited — complete only; no cancel path; accept/reject are vendor-level |
| Vendor/technician assignment | critical | 3 | present, limited — only an undocumented write-only `maintenance` array on create/update; assignment requests read-only |
| Vendors | important | 2 | present — GET, PUT, PATCH, DELETE; create via POST /vendor_invite/ |
| Scheduling/appointments | important | 2 | present, read-only for PM level — schedule/reschedule/cancel endpoints are vendor-level writes |
| Residents | important | 2 | present — full CRUD |
| Units/properties | important | 2 | present — full CRUD (create, update, deactivate observed live) |
| Estimates | optional | 1 | read-only for PM level (create/accept/reject exist for vendor level) |
| Invoices | optional | 1 | present — list/detail; create/update via POST/PATCH /meld/{id}/invoice/ |
| Owner approval | optional | 1 | present — `owner_approval_status` writable on meld; owners full CRUD |
| Tags | optional | 1 | present — full CRUD (create, rename, delete observed live) |
| Workflow: create a work order | critical | 3 | present — POST /meld/ |
| Workflow: assign it | critical | 3 | partial — write-only `maintenance` array, no item schema or description |
| Workflow: transition to completion | critical | 3 | present — PATCH /meld/{id}/complete/ |

## Functional coverage map
- Core objects: melds (critical, 3, present); status transitions (critical, 3, present-limited); assignment (critical, 3, present-limited); vendors (important, 2, present); scheduling (important, 2, read-only at PM level); residents (important, 2, present); units/properties (important, 2, present); estimates (optional, 1, read-only); invoices (optional, 1, present); owner approval (optional, 1, present); tags (optional, 1, present). Also exposed: owners, projects (read), property groups (read), work logs (read), expenditures (read), files (read), meld chat (read/write), management agents (read), vendor invites.
- Primary operational workflows: create meld → assign (write-only `maintenance` field) → complete (`/complete/`); create/update units, properties, residents, owners, tags; invite and update vendors; attach media via signed S3 upload; post meld chat; create meld invoice.
- Principal lifecycle changes: complete meld (PM); cancel meld (absent — no endpoint, `status` read-only on all write schemas, `MANAGER_CANCELED` exists only as an enum value); reassign (write-only `maintenance` field, partial); vendor accept/reject assignment and appointment schedule/reschedule/cancel (vendor level only); deactivate vendor/resident/unit/property/owner/tag (DELETE, present — unit, property and tag deletes observed live); estimate accept/reject and invoice approve/decline (vendor level / not writable at PM level); owner-approval status change (present).

## Category 1: Functional Coverage and Usefulness: 5.6/15
- C1.1 Object coverage: **partial** — weighted coverage = 79 % (16.5/21; no critical object absent). Melds 3×1.0 [OpenAPI `/api/v2/meld/` GET/POST, `/api/v2/meld/{id}/` GET/PUT/PATCH; Permissions guide "Melds — read, write"]; status transitions 3×0.5 [`/meld/{id}/complete/` PATCH; `WriteMeld.status` and `PatchedWriteMeld.status` are `readOnly`; no cancel operation among the 60 paths; `/meld/canceled/` is a vendor read list and returned 400 "…or have access to this url" live]; assignment 3×0.5 [`WriteMeld.maintenance` `{"type":"array","items":{},"writeOnly":true}` with no description; `in_house_servicer_ids`, `assigned_technicians`, `vendor_assignment_requests` all `readOnly`]; vendors 2×1.0 [`/vendor/{id}/` PUT/PATCH/DELETE, `/vendor_invite/` POST]; scheduling 2×0.5 [Permissions guide: PM "Meld actions — write (complete, invoice, media, upload URL)"; Vendor "…schedule/reschedule/cancel"]; residents 2×1.0 [`/resident/` GET/POST and `{id}` GET/PUT/PATCH/DELETE]; units/properties 2×1.0 [observed live: `POST /property/` 201 id 1761925, `POST /unit/` 201 id 1978373, PATCH 200 on both, DELETE 204 on both]; estimates 1×0.5 [Permissions: PM "Invoices, expenditures, estimates — read"]; invoices 1×1.0 [`/meld/{id}/invoice/` POST/PATCH; PM "Meld actions — write (… invoice …)"]; owner approval 1×1.0 [`WriteMeld.owner_approval_status` writable; `/owner/` CRUD]; tags 1×1.0 [observed live: POST 201, PATCH/PUT 200, DELETE 204].
- C1.2 Core operational actions: **partial** (controlled live for property, unit, tag; documentation for meld items) — weighted coverage = 79 % (16.5/21; no critical write workflow absent). Create meld 3×1.0 [POST `/meld/`, `WriteMeld`]; assign 3×0.5 [write-only untyped `maintenance` array, above]; complete 3×1.0 [PATCH `/meld/{id}/complete/`, `PatchedMeldComplete{is_complete, completion_notes, …}`]; vendors 2×1.0; scheduling 2×0.0 [PM level cannot write schedules, Permissions guide]; residents 2×1.0; units/properties 2×1.0 [live: create 201, PATCH `maintenance_notes` 200 and persisted on GET]; estimates 1×0.0 [PM read]; invoices 1×1.0; owner approval 1×1.0; tags 1×1.0 [live: create 201, PATCH and PUT rename 200 and persisted].
- C1.3 Delete or lifecycle actions: **no** (controlled live for deactivations; documentation for meld items) — weighted coverage = 55 % (10.5/19), but a critical lifecycle action (cancel a work order) is absent. Complete 3×1.0 [`/complete/`]; cancel 3×0.0 [no endpoint; `status` read-only in `WriteMeld`/`PatchedWriteMeld`/`PatchedMeldComplete`; `Status5c6Enum` lists `MANAGER_CANCELED` but no operation sets it]; reassign 3×0.5 [`maintenance` write-only field]; appointment schedule/cancel/reschedule 2×0.0 [vendor-level only, Permissions guide]; vendor deactivate 2×1.0 [DELETE `/vendor/{id}/`]; resident/unit/property/owner deactivate 2×1.0 [live: `DELETE /unit/1978373/` 204 → GET 404; `DELETE /property/1761925/` 204 → GET 404]; estimate accept/reject 1×0.0 [Vendor: "accept/reject — write"; PM: read]; invoice approve/decline 1×0.0 [PM: read]; owner-approval status change 1×1.0; tag delete 1×1.0 [live: DELETE 204 → GET 404, list back to baseline].
- C1.4 Change notification: **partial** — no webhooks or events exist [OpenAPI: 0 occurrences of "webhook"; llms.txt index has none; help-center search "webhook" = 0 results; verification search none]. Efficient incremental polling exists and was verified live: `GET /meld/?updated__gte=2026-08-25T00:00:00Z` → 516 records, 0 violations, plus `status`, `completed__gte`, `marked_complete__gte`, `scheduled__gte`, `vendor_scheduled__gte` filters [OpenAPI `meld_list` parameters]; `updated__gte` on `/unit/`, `/property/`; `last_updated_gte` on `/vendor/`, `/resident/`, `/invoice/`, `/estimates/` [live step 3]. Not available on work logs, expenditures, projects, owners, tags, files.
Score math: earned 1.5 of 4 applicable checks; unrounded fraction = 0.375; category points = 5.625 → 5.6/15; verification coverage = 100 % (4 of 4).
What this means for you: You can read everything about your maintenance operation and you can create work orders, complete them, and manage units, properties, residents, owners, vendors and tags. Creating, updating and deactivating a property and a unit worked exactly as documented in the live test. You cannot cancel a work order through the API. Assigning a vendor or technician is possible only through an undocumented field. Scheduling, estimate approval and invoice approval are vendor-side actions in this API. There are no webhooks, so your automations must poll with the `updated__gte` filter.

## Category 2: API Design, Reliability, and Operability: 5.0/10
- C2.1 Modern API conventions: **yes** — resource-oriented REST over HTTPS with GET/POST/PUT/PATCH/DELETE, JSON bodies, path version `/api/v2/`, action sub-resources (`/complete/`, `/accept/`) [OpenAPI paths; live 200/201/204 semantics on reads and writes].
- C2.2 Consistent typing: **no** — types vary between the published schema and live responses on core fields, and between schemas for the same field. Live meld detail: `assigned_technicians` returned an array, schema says `string`; `merged_meld` returned an object, schema says `string` [`MeldSerializerDetail`; live `GET /meld/13755005/`]. Estimates: `total` declared `string` but returned as a JSON number, while `total_w_markup` is declared `number` and `pm_fee` is a decimal string in the same record [`EstimateSerializerList`; live `GET /estimates/?limit=1`]. `maintenance_limit` is `string` in `ReadProperty` but `number/double` in `WriteProperty` [OpenAPI components]. Six `Project` fields (`created`, `updated`, `coordinators`, `unit`, `prop`, `melds`) and `Vendor.allow_assignments` are returned live but absent from the schema. Several non-nullable declared fields return `null` (`integration_partner`, `integration_partner_id`, `Owner.user`, `MeldInvoice.payment`). Query params use `true/false` strings on some filters but `integer` on others (`exp`, `has_estimates`, `recurring`) [OpenAPI `meld_list` parameters].
- C2.3 Structured errors: **partial** — correct HTTP statuses (401, 404, 405, 400) and JSON bodies with a usable message, but no machine-readable error code and three different shapes: `{"detail": "Not found."}`, `{"error": "X-Multitenant-Id is missing"}`, `{"status": ["Select a valid choice…"]}` [live step 4]. Invalid `limit`, `offset` and unknown parameters are silently ignored with 200. Posting a tag whose name already exists returns an unhandled **500** `{"status_code":500,"detail":"An internal server error occurred."}` instead of a 400/409 [controlled live T1b]. The OpenAPI documents only 200/201/204 responses (no 4xx schemas).
- C2.4 Duplicate prevention: **partial** (controlled live) — the mechanism exists and works: a repeated `POST /tag/` and a repeated `POST /property/` with the same `X-Idempotency-Key` returned the stored 201 with the same id and no duplicate [controlled live T3, P1; recipe "How to use idempotency key"]. Limitation: the canonical Idempotent-requests guide documents the header as `X-IdempotencyKey`, and that spelling is **not honored** — the repeated POST with it hit the duplicate-name constraint and returned 500 on two separate attempts [controlled live T2, T1b]. A developer following the guide gets no protection; the header is also absent from the OpenAPI parameters. State-transition PATCH actions (`/complete/`, `/accept/`) cannot create duplicates.
- C2.5 Graceful handling under load: **partial** — limits documented (50 read req/s, 30 write req/s) and "you may receive a 429 Too Many Requests… we recommend implementing exponential backoff or retry logic", but no `Retry-After` header and no numeric backoff guidance [Rate Limiting/Throttling guide]. Live: no rate-limit headers on any response; 272 req/s on `/ping/` and 31 req/s on `/meld/` produced no 429 [live step 5].
- C2.6 Pagination for large collections: **partial** — `limit`/`offset` with `count`, `next` and `previous` URLs on every list endpoint [OpenAPI `Paginated*List` schemas; recipe "How to paginate results"; live step 2], `ordering`/`order_by` parameters. Limitations: undocumented hard cap of 500 rows per page (`limit=1000` silently returns 500) and no documented default or stable ordering guarantee (`ordering=bogusfield` silently ignored) [live page-size and ordering probes; `limit` description "Number of results to return per page." only].
- C2.7 Bulk or incremental export: **partial** — no bulk or async export path; incremental sync is possible on the main list endpoints via `updated__gte` (melds, units, properties) and `last_updated_gte` (vendors, residents, invoices, estimates) plus pagination [OpenAPI parameters; live step 3], but not on work logs, expenditures, projects, owners, tags, files or management agents [OpenAPI: those list operations expose only `limit`, `offset`, `ordering`].
- C2.8 Webhook security and delivery reliability: **N-A** — no webhooks or events (already penalized in C1.4).
- C2.9 Concurrency and conflict control: **no** — no ETag, `If-Match`, version field or 409 semantics documented or observed [OpenAPI: 0 occurrences of "ETag"/"If-Match"/"409"; no `ETag` header on any live response, including write responses; docs guides silent]. Observed but not scored here: a sub-second read-after-write lag (a GET immediately after PATCH showed the old name; a GET immediately after DELETE returned 200; both were correct seconds later) [controlled live T4, T5, T1b].
- C2.10 Versioning and backward compatibility: **partial** — explicit path versioning (`/api/v2/`, prior `/api/v0.0.1/`) and a dated deprecation notice for v1 ("May 31, 2026: Version 1 entered its deprecation period. December 31, 2026: Support for Version 1 ends") [docs home; v1.0 llms.txt], but no published policy defining breaking vs non-breaking changes or a standing deprecation window [docs guides; verification search].
- C2.11 Request traceability: **partial** — every response carries a unique Cloudflare `CF-RAY` identifier (e.g. `a34816bd6adf7619-ORD`) but no vendor request-id header, and the identifier is not documented or referenced for support anywhere in the docs [live step 5; docs grep for "request id/correlation": none].
- C2.12 Service availability and status transparency: **yes** — public Atlassian Statuspage with 11 components, per-component uptime percentages (99.98 %, 100.0 %), an incident history page with 25 entries (latest 2026-09-01) and Atom/RSS feeds [status.propertymeld.com, /history, /history.atom]. Limitation noted: no API-specific component.
Score math: earned 5.5 of 11 applicable checks (C2.8 N-A); unrounded fraction = 0.5; category points = 5.0/10; verification coverage = 100 % (11 of 11).
What this means for you: The API is a clean, predictable REST design and it has a real status page. But your code must defend itself. Field types do not always match the schema, error bodies come in three shapes with no error code, a duplicate name crashes with a 500, page size is capped at 500 without warning, and there is no way to detect a concurrent edit. Idempotency keys work, but only with the header name in the recipe (`X-Idempotency-Key`), not the one in the guide.

## Category 3: Access Control and Safe Automation: 2.5/5
- C3.1 Read-only credentials: **no** — every token is issued with `scope: "read write"` [live token response]; the API-key screen has no scope, permission or read-only control (columns Name, Date Created, Client ID, Actions) [Nexus API Keys page, observed 2026-09-01]; access levels are assigned per company by Property Meld, not per key ("To find out which access level your company has, contact support@propertymeld.com") [Permissions guide].
- C3.2 Scoped credentials: **no** — a credential cannot be restricted to resources, actions or a role by the operator; the only differentiation is the company-wide access level (Property Manager / Vendor / Inspection Partner) set by the vendor [Permissions guide; API-key screen shows no per-key options].
- C3.3 Multiple keys: **yes** — five distinct client-credential pairs coexist on the operator's account, each with its own Client ID and creation date (3/10/2026 … 9/1/2026) [Nexus API Keys page].
- C3.4 Rotation and revocation: **yes** — self-serve: `Create API Key` button plus a `Revoke` action on every key row [Nexus API Keys page]; access tokens expire after 36,000 s [live token response].
- C3.5 Test and production isolation: **N-A** — no sandbox or test environment exists [OpenAPI `servers`: only "Property Meld Production Application"; docs, help-center search and verification search: none].
Score math: earned 2 of 4 applicable checks (C3.5 N-A); unrounded fraction = 0.5; category points = 2.5/5; verification coverage = 100 % (4 of 4).
What this means for you: You can make separate keys for separate tools and you can revoke any of them yourself. But every key has full read-and-write power over your whole account. You cannot hand an AI agent a read-only or limited key, and there is no sandbox to test against — this run had to use labeled fixtures inside the live account.

## Category 4: Documentation and AI-Agent Readiness: 3.8/5
- C4.1 Complete self-serve reference: **partial** — public developer hub with authentication guide (curl walk-through), all 94 operations in the reference, an OpenAPI schema, and nine recipes with worked curl examples (first request, paginate, filter, idempotency, unit CRUD, vendor invites, media upload, custom report) [docs.propertymeld.com guides, reference, recipes]. Limitations: reference pages are auto-generated schema dumps — 93 of 94 operations have no worked request/response example and most have no description [OpenAPI: 1 operation with an inline example; `/complete/`, `/accept/`, `/schedule/`, `PUT/PATCH /meld/{id}/` have empty descriptions]; the assignment field `maintenance` is undescribed and untyped; no 4xx responses are documented; the filter recipe's "Response Example" is a placeholder `{"success":true}`; the idempotency guide names a header that does not work [controlled live].
- C4.2 Reliable machine-consumable integration path: **yes** — a complete, server-generated OpenAPI 3.0.3 specification is public in JSON and YAML (60 paths, 94 operations, 140 schemas, security schemes) and suitable for code or tool generation [api.propertymeld.com/api/v2/schema/; "OpenAPI Schema" guide]; the unit and property create payloads generated from it were accepted live. No official SDK and no MCP server exist [GitHub org Property-Meld: buildpacks and forks only; docs grep "SDK/MCP": none]. Schema defects noted in C2.2 require some manual correction but do not remove the path.
- C4.3 AI-readable documentation: **yes** — `llms.txt` indexes every guide, reference page, recipe and changelog entry with descriptions; every page has a `.md` version ("Append .md to any documentation page URL"); reference `.md` pages embed the endpoint's OpenAPI definition [docs.propertymeld.com/llms.txt; docs home banner "For AI agents…"]. No `llms-full.txt` (404).
- C4.4 Kept current: **partial** — the OpenAPI schema is generated live from the server, guide pages carry `updatedAt` stamps (Permissions 2026-08-20, first-request 2026-04-13, reference pages 2026-08-04), and the v1 deprecation is dated [docs]. But the changelog has only two entries in five years (2021-06-01 and 2024-04-26) and does not record the v2 endpoints, the deprecated `/media/` endpoint or the 2026 v1 deprecation [docs.propertymeld.com/changelog]; help-center release notes cover the product UI, not the API.
Score math: earned 3 of 4 applicable checks; unrounded fraction = 0.75; category points = 3.75 → 3.8/5; verification coverage = 100 % (4 of 4).
What this means for you: A coding assistant can load this API well. There is a public OpenAPI file and an llms.txt index with Markdown for every page. What is missing is human explanation. Most endpoints have no description or example, one guide documents a header that does not work, and the changelog will not tell you when something changes.

## Category 5: Accessibility and Cost: 7.5/15
- C5.1 Self-serve API key: **yes** — an entitled account creates credentials itself with the `Create API Key` button on the Nexus API Keys screen; five keys were created this way between 3/10/2026 and 9/1/2026 [Nexus API Keys page, observed 2026-09-01]. Noted: the docs home also says "If you need Version 2 API credentials, please contact Property Meld Support", which applies to obtaining entitlement, scored under C5.3.
- C5.3 Not commercially gated: **no** — "API access for customer-built agent interactions" is listed under Miscellaneous as "Ops only"; Ops is the top tier at $2.00/unit/month versus Core at $1.60/unit/month [propertymeld.com/pricing feature comparison table].
Score math: earned 1 of 2 applicable checks; unrounded fraction = 0.5; category points = 7.5/15; verification coverage = 100 % (2 of 2).
What this means for you: If you are on the Ops plan, you can make a key in seconds without talking to anyone. If you are on Core, the API is not included, and you must upgrade every unit to Ops to get it.

## Total
- Raw: 24.38 / 50 (5.625 + 5.0 + 2.5 + 3.75 + 7.5)
- Normalized before rounding: 48.75 / 100
- Published numeric score: 49 / 100
- Letter grade: F
- Evidence tier: fully verified — controlled live (fixtures: API-created `APITEST-DELETE` property, unit and tags; operator authorization recorded; cleanup verified)
- Overall verification coverage: 100 % (25 verified of 25 applicable checks; gate: no category Unable to verify; overall ≥ 80 %) — passed
- Partial-result flag: no. Remaining documentation-graded items sit inside C1.2/C1.3 (meld create, assign, complete, cancel) because the operator declined a test meld — it cannot be deleted or canceled via the API and may notify staff. Observing them would not change either mark: the cancel gap and the undocumented assignment field are structural.
- Unresolved evaluator disagreements: none within this run; judgment calls that a second run could mark differently, with score effect: (1) C1.3 no → partial if "cancel a work order" is not treated as a critical lifecycle action: +1.9 raw, score 52, still F. (2) C1.2 partial → yes if the write-only `maintenance` array is accepted as full assignment support: +1.9 raw. (3) C2.2 no → partial: +0.5 raw. (4) C3.2 no → partial (vendor-assigned company role counted as role scoping): +0.6 raw. (5) C2.4 partial → yes if the working recipe header is deemed sufficient documentation: +0.5 raw. (6) C2.11 partial → no (CF-RAY not vendor-supplied): −0.5 raw. All five favorable changes together give 59, still F; the unfavorable change gives 48, F.

## Bottom line for a property manager
Property Meld is a maintenance-only tool, and its API reflects that: you can build reporting, reminders, dashboards and intake automations on top of your work orders, units, residents and vendors today. You can also create work orders and mark them complete, and the live test confirmed that creating, updating and deactivating properties, units and tags works cleanly. You cannot cancel a work order, you cannot reliably assign a vendor (the only field for it is undocumented), and scheduling, estimate and invoice approvals belong to the vendor's side of the API. The biggest strengths are a public OpenAPI file, an llms.txt index that AI tools can read, working idempotency keys, and self-serve keys you can revoke. The biggest limitations are the missing webhooks, full-access-only keys with no sandbox, loose typing, a guide that documents the wrong idempotency header, and the fact that the API is sold only with the Ops plan. Property Meld is not a bank and holds no funds. You still need your property-management system for ledgers, owner statements and payments; Property Meld feeds invoices and expenditures into it.
