Document extraction API

Document extraction API to build into your product

Your users upload documents in your app. Docsumo reads them and sends back JSON with a confidence score on every field. The few fields that need a person open in our review screen, inside your app and under your brand.

  • 99% field-level accuracy
  • 250+ document types, and any other
  • SOC 2 Type 2, ISO 27001 and HIPAA
Payables · Northwind Supply Co. · INV-4471
POST/api/v1/eevee/apikey/upload/INV-4471.pdf200
Review · InvoiceDocsumo · white-label
Vendor
Northwind Supply Co.0.99
Invoice number
INV-44710.99
Invoice date
2026-09-300.98
PO number
PO-20918Fixed
Subtotal
3,000.000.99
Tax
240.000.98
Total due
3,240.000.99
WebhookStatus changed to approved · data sent to your API
Docsumo's review screen inside your app, under your brand. Your user never logs in to Docsumo.

Trusted by 10,000+ mid-sized and enterprise teams, including

  • Grid Finance
  • Hitachi
  • PayU

Who uses it

  • Lending and loan origination software

    Bank statements, pay stubs and tax forms read as borrowers upload them.

  • Insurance and risk software

    ACORD forms, certificates of insurance and loss runs read into your users' records.

  • AP, procurement and payroll software

    Invoices, receipts and payroll forms turned into line items your product can post.

  • Property and real estate software

    Leases, rent rolls and utility bills read for your users' portfolios.

What your product gets

Extraction, review and checks behind one API.

  • Extraction for 250+ document types

    Invoices, bank statements, pay stubs, tax forms, ACORD forms, bills of lading and more, printed or handwritten, in files of up to 500 pages. It isn't limited to pre-built models, so any other document you set up works too.

  • JSON with a confidence score per field

    Every field comes back with its value, a confidence score, whether it needs review and where it sits on the page. Tables come back as rows, even when they run across pages.

  • A white-label review screen

    Fields below the threshold you set open in Docsumo's review screen, in an iframe with a temporary token. It can run without Docsumo branding, and your users never need a Docsumo login.

  • An account for each customer

    Your product can create a Docsumo account for each of your customers through the signup API, so every customer's documents stay in their own account.

  • Classification and splitting

    A combined upload is split into the documents inside it, and each one is sorted into a type you name. On the Business plan.

  • Webhooks

    Your backend hears about every document status change, with separate test and production URLs and a static IP on request.

  • Cross-document checks

    Match an invoice to its PO and receipt, or a pay stub to a bank statement, before the data reaches your product. On the Enterprise plan.

  • A test environment

    Try a new document type or field in test before your customers see it. On the Business plan.

Three ways to use it

How software companies put Docsumo to work.

Most start with one and add the others.

  • New feature

    Ship a document feature

    Your users upload invoices, statements or forms and get checked data back. You don't train or host a model.

    • JSON with a confidence score per field
    • A review screen under your brand
    • An account for each of your customers
  • Replacement

    Replace the OCR you maintain

    No more fixing templates when a supplier, bank or carrier changes its layout. You get one structure per document type.

    • No template per layout
    • Handwriting and scans
    • Test it beside your current engine first
  • Compliance

    Pass customer security reviews

    Enterprise customers will ask where their documents go. The answers are ready before they ask.

    • SOC 2 Type 2, ISO 27001, HIPAA, GDPR
    • BAA and DPA available
    • A published subprocessor list
How it fits

Five steps from a new customer to approved data.

  1. 01

    Create your customer's account

    Your product calls the signup API when a customer signs up. Pick document types from 250+ or set up your own fields.

    Signup API
  2. 02

    Send files from your backend

    Files of up to 500 pages, by upload, public URL or Base64, tagged with your own IDs and metadata.

    POST /upload
  3. 03

    Get JSON back

    By webhook when the status changes, or on request. Every field has a confidence score.

    Webhook
  4. 04

    Route the unsure fields

    Show them in your own screen and save corrections by API, or open our white-label screen in an iframe.

    Review
  5. 05

    Use the approved data

    Post it to your product's records. Your user never left your app.

    Your product
For your engineers

A REST API, webhooks and an iframe. Nothing to host.

Send a file, get JSON back, and give your users the review screen when a field needs a person. Every call here is from the API reference.

  • PDF, JPG, PNG and TIFF up to 500 pages, as a file, a public URL or Base64
  • An account for each of your customers, created by the signup API
  • Several API keys, each with its own permissions
  • Webhooks on every status change; a static IP on request
  • A white-label review screen in an iframe, signed for one document
  • Docsumo MCP for AI agents, on the same API key
“We love Docsumo for its ease of integration and the flexibility it provides with API and webhook callbacks.”
Howard LeinerCTO, Arbor
POST · /api/v1/eevee/apikey/upload/
# Send a file from your backend, tagged with your own IDs
curl -X POST https://app.docsumo.com/api/v1/eevee/apikey/upload/ \
  -H "apikey: $DOCSUMO_API_KEY" \
  -F "file=@INV-4471.pdf" \
  -F "type=invoice" \
  -F "user_doc_id=acme-inv-4471" \
  -F 'doc_meta_data={"customer_id": "acme"}' \
  -F "review_token=true"

# Response (trimmed)
{ "data": { "document": [{
  "doc_id": "9f2c41e07b8d4c6a",
  "status": "new",
  "review_url": "https://app.docsumo.com/review-document/9f2c41e07b8d4c6a?token=…"
}] } }
`type` is one of your document types. `review_token=true` adds a signed review link to the response.
Build or embed

What you'd build yourself on a raw OCR or LLM API.

Reading the page is the bottom layer. Your product needs the rest before a customer trusts the data.

  • Included
  • Partly included
  • You build and run it
Layers of an embedded document extraction feature: what a raw OCR or LLM API leaves to you, and what Docsumo includes.
Your own buildOCR or LLM API + your codeDocsumoIDP platform
PartlyThe API's audits cover only its partSecurity reviewsIncludedSOC 2 Type 2, ISO 27001, HIPAA
You build itYou build and run tenant isolationAn account per customerIncludedCreated by API at signup
You build itYou queue, sign and retry themWebhooksIncludedEvery status change; static IP on request
You build itCross-document checksIncludedEnterpriseInvoice to PO, pay stub to statement
You build itYou design, host and maintain itReview screenIncludedInside your app, under your brand
PartlyVaries by API; you decide what to trustConfidence and thresholdsIncludedA score per field, thresholds per field
You build itClassification and splittingIncludedBusinessName the types, no training set
PartlyPrompts or templates you maintainFields and tables as JSONIncludedOne schema per document type
IncludedWhat the API you call doesReading the pageIncludedPrinted and handwritten text
Sources and the date we checked them

“Your own build” means calling an OCR or LLM API and writing the rest yourself; what a given API includes varies, so check its own docs. Docsumo layers: API reference, pricing, security.

In production

What your users get when documents stop waiting on people.

99%
field-level accuracy in production
95%+
of documents processed straight through, no manual review
250+
document types, and any other you set up
$15
saved per processed document
Choosing an API

What to check before you embed an extraction API.

Your customers will judge the feature by its worst document, not its average one. These are the questions that decide whether it holds up.

Accuracy on your users' documents

Benchmarks use clean samples. Your users send phone photos, scans with stamps, and layouts nobody has seen before. Run a few hundred of their real files through the trial and count the fields you'd have to fix. Docsumo reports 99% field-level accuracy across 250+ document types in production, and 95%+ of documents go straight through with no manual review.

What happens to the fields it isn't sure about

This is where most in-house builds stall. A value with no confidence score gets trusted when it shouldn't be, or every document gets checked by hand. Docsumo scores every field, lets you set the threshold per field, and sends the rest to review: in our screen inside your app, or in yours through the API. Each correction improves the model.

Whose brand your users see

Your customers bought your product, so the feature should look like it. Docsumo's API runs behind your product, and the embedded review screen can run without Docsumo branding, so your users see your product, not ours.

One schema, every layout

Your product's code expects the same keys every time. Docsumo returns one structure per document type, whatever the supplier, bank or carrier, so a new layout doesn't break your integration. Field names and the output schema are yours to configure.

Keeping customers apart

Give each customer its own Docsumo account. Your product can create one through the signup API when the customer signs up, so one customer's documents never sit in another's account. Inside each account, tag uploads with your own IDs and metadata, group documents in folders by API, and give each part of your system its own API key with only the permissions it needs.

The security review your customers will run

Your enterprise customers will ask where their documents go. Docsumo is SOC 2 Type 2 audited, ISO 27001 certified, and HIPAA and GDPR compliant, with a BAA and DPA available. Data can stay in the US, the EU, the UK, India, Australia or Singapore, and documents are not used to train shared or third-party models. It runs only in the cloud; there is no on-premise version.

“Docsumo's self-learning capabilities and the accuracy of the invoice line-item data capture made it stand out for us.”
Jussi Karjalainen, Founder & Managing Partner, Valtatech
Read the case study →
Security and data

The answers your customers' security review will ask for.

Docsumo becomes a subprocessor in your product. This is what your customers will want to know about it.

  • SOC 2 Type 2Independently audited controls
  • ISO 27001Certified security management
  • HIPAAFor protected health data
  • GDPRFor EU personal data

Encrypted with TLS in transit and AES-256 at rest. Your documents are not used to train shared or third-party models.

How Docsumo protects your data →
  • Hosting regions

    US, EU (Frankfurt), UK (London), India, Australia or Singapore, on Amazon Web Services and Google Cloud.

  • A published subprocessor list

    Docsumo's own subprocessors are listed on its website, ready for your vendor records.

  • BAA and DPA

    A business associate agreement for healthcare data and a data processing agreement for GDPR.

  • API keys you control

    Several keys, each with its own permissions; regenerate or revoke any of them.

  • Webhooks from a static IP

    On request, so your firewall can allow only Docsumo's address.

  • SSO and MFA

    Single sign-on and multi-factor authentication for your own team in the app.

Questions

Questions about the document extraction API

Which document extraction or parsing API should we embed in our product?

Docsumo is an intelligent document processing (IDP) platform, and its API suits software companies that need more than text: fields as JSON with a confidence score each, a white-label review screen their users work in without a Docsumo login, an account for each of their customers, and checks across documents. If you only need text and layout from clean documents and have engineers to build the review and checking layers yourself, a raw OCR or LLM API can be enough. Either way, test it on your own users' files before you decide.

Can our users review documents without a Docsumo login?

Yes. Upload with `review_token=true` and the response includes a signed review URL. Add `&client=true` and open it in an iframe in your app. Your user sees the document, edits any field and approves it, and the token opens that one document only. You can also get a fresh signed link for any document later. See the iframe guide.

Can we white-label Docsumo?

Yes. The API runs behind your product, and the embedded review screen can run without Docsumo branding, so your customers see your product, not ours.

Can we build our own review screen instead?

Yes. Every field comes back with its value, a confidence score, a flag for whether it needs review and its position on the page, so you can highlight it on your own document viewer. When your user corrects a value, save it with the Update Field call and the data stays in step.

Why not call an LLM or OCR API directly?

Reading the text is the easy part. Your product also needs the same schema for every layout, a confidence score it can trust, a place for people to fix the unsure fields, and checks across documents. Docsumo reads the page with OCR, uses LLMs to structure the text, then adds those layers, so your engineers don't build and maintain them. A direct LLM or OCR call can be enough for clean documents in a prototype.

How do we keep each of our customers' documents separate?

Give each of your customers its own Docsumo account. Your product can create one through the signup API when a customer signs up, so each customer's documents stay in its own account. Inside an account, tag uploads with your own `user_doc_id` and `doc_meta_data`, group documents in folders by API, and issue several API keys, each with its own permissions.

Do we have to train a model for each document type?

No. Docsumo reads 250+ document types, and it isn't limited to pre-built models, so you can set up any other document with the fields you need. For classification on the Business plan, you name the document types you want, with no training set. When reviewers correct a field, the model improves.

Can Docsumo replace the OCR engine already in our product?

Yes, if cloud processing works for you: Docsumo is cloud only, so it replaces an engine you call, not one you install. It returns one structure per document type, whatever the layout, so there are no templates to maintain. Run it beside your current engine on the same files, compare the fields, then switch.

Which files can we send, and how fast can we send them?

PDF, JPG, PNG and TIFF files of up to 500 pages each, by file upload or as a public URL or Base64. Excel files work for profit and loss statements, rent rolls and balance sheets. Each API call carries one document, and the rate limit is 10 requests a second per account. Docsumo reads most printed languages, and handwriting support varies by language.

Is there an SDK?

The API is plain REST with JSON responses and an API key in a header, so any language with an HTTP client works. The API reference comes with a Postman collection. For AI agents, Docsumo MCP connects Claude, Cursor and apps built on the OpenAI API without any client code.

How is pricing handled when Docsumo is part of our product?

Start with the free trial: 14 days, up to 1,000 pages, with the API and webhooks included. Plans are on pricing. For usage inside your own product, we agree terms with you before you launch, so book a call and bring your expected volumes.

What support do we get while we build?

Software companies that join the partner program as technology partners get dedicated support from the first demo to go-live, and a direct line when one of their clients needs help. Every account on the Business plan also has an account manager.

Can Docsumo run on our servers or in our cloud?

No. Docsumo is cloud only, with nothing to install. It runs on Amazon Web Services and Google Cloud, and your data can be hosted in the US, the EU (Frankfurt), the UK (London), India, Australia or Singapore. See security at Docsumo.

Are our customers' documents used to train models?

No. Documents are encrypted with TLS in transit and AES-256 at rest, and they are not used to train shared or third-party models. Docsumo is SOC 2 Type 2 audited, ISO 27001 certified, and HIPAA and GDPR compliant, and a BAA and DPA are available.

Send us your users' hardest documents.

We'll run them through the API on a call, show you the JSON and the review screen, and talk through how it fits your product.