# Deals and proof of cash

A deal is one party's private workspace for one transaction: a buyer's, a seller's or a broker's. It holds documents, figures read from them, figures typed in, and saved runs. Everything in a deal is encrypted under that deal's own key, and its documents serve that deal only. They're never shared with another deal or used to train AI.

## Granting a deal

Deals are created on acquestor.com. To work on one through the API or an AI host, its owner turns on outside AI access for that deal and picks the API key or AI client. The grant names one deal; any other `deal_id` returns 403 `deal_access_off`. See [Authentication](/concepts/authentication#one-deal-per-grant).

Through a grant you can:

| Operation | MCP tool | Does |
| --- | --- | --- |
| `GET /deals` | `list_deals` | Lists the granted deal, with its business and listing named beside their IDs; pages with `limit` and `cursor` |
| `GET /deals/{deal_id}` | `get_deal` | Saved runs, summary figures, and each document's type and status; never document contents |
| `POST /deals/{deal_id}/figures` | | Adds figures you type: bank deposits, P&L revenue, tax-return receipts or taxable income, SDE, by period |
| `POST /deals/{deal_id}/documents` | | Uploads a bank statement, P&L or tax return; it's read for figures at 3 credits a page |
| `GET /deals/{deal_id}/documents/{document_id}` | | Document status and the figures read from it, each with its page |
| `POST /deals/{deal_id}/runs` | `save_to_deal` | Runs a computed tool on the deal and saves the result; charged at that tool's price |
| `POST /diligence/proof-of-cash` | `proof_of_cash` | Reconciles the deal's figures (below) |

Through the REST API, passing `deal_id` to a computed tool reads inputs from the deal and saves the run. Through the MCP server, computed tools read the deal but don't save; `save_to_deal` is the one tool that saves.

## Figures in a deal

```json
POST /deals/{deal_id}/figures
{"figures": [
  {"label": "bank_deposits", "period": "2025-01", "value": 61200},
  {"label": "pl_revenue", "period": "2025", "value": 742000},
  {"label": "return_gross_receipts", "period": "2025", "value": 735500}
]}
```

`period` is `YYYY` for a year or `YYYY-MM` for a month; bank deposits are monthly. Typed figures are dated the day you add them. Figures read from a document carry its `document_id` and `page`.

A file that looks like a printout of a BizBuySell, BizQuest or LoopNet page is refused before it is stored.

## Proof of cash

`POST /diligence/proof-of-cash` · MCP `proof_of_cash` · 50 credits

Reconciles bank deposits to P&L revenue and to tax-return receipts, period by period, and flags each period whose variance passes the threshold you set.

```json
{"deal_id": "…", "variance_threshold": 0.05,
 "confirmed_exclusions": [{"period": "2025-03", "amount": 25000, "reason": "loan_proceeds"}]}
```

`variance_threshold` is required: you set the share of variance at which a period is flagged. Deposits that aren't revenue, such as transfers, loan proceeds, owner contributions and refunds, are excluded only when you confirm them in `confirmed_exclusions`, each with its `period`, `amount` and `reason`. Each period returns deposits, exclusions, net deposits, P&L revenue, return receipts, both variances and whether it's flagged. A missing source for a period comes back as a gap.

Proof of cash checks the records you give it. It isn't a quality-of-earnings review, which comes from a CPA firm; the SBA ceiling flags the price at which SBA's rules call for one.
