# SEC EDGAR APIs > Free JSON APIs from the U.S. Securities and Exchange Commission on data.sec.gov for EDGAR. They return each filer's submission history and the XBRL financial data extracted from company reports, with no key or account. - Canonical: https://www.anchorterminal.com/tools/sec-edgar - Markdown: https://www.anchorterminal.com/tools/sec-edgar.md (~7,100 tokens) - Slim: https://www.anchorterminal.com/tools/sec-edgar.min.md (~1,580 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/sec-edgar.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-10 ## Overview **Grade E · 40.8/100 · rank #909 of 950 · #9 in Data providers · not agent-ready · confidence medium** ## Assessment The official source for US company filings and reported financial figures, free, keyless and, per the SEC, updated in real time as filings are disseminated. Documentation is one page with no OpenAPI file, error reference or changelog, responses cannot be filtered or sized, and there is no status page, SLA or support for scripted access. ## Facts | Field | Value | | --- | --- | | Vendor | U.S. Securities and Exchange Commission (https://www.sec.gov) | | Kind | HTTP API | | Category | Data providers (https://www.anchorterminal.com/categories/data-providers) | | Transport | HTTP | | Endpoint | `https://data.sec.gov` | | Auth | None · No key, account or sign-up. The SEC asks automated callers to declare themselves in the User-Agent header with an organisation name and a contact email address, and says requests from undeclared tools will be managed. The APIs are read-only. A separate set of token-protected APIs for EDGAR filers (submitting filings, managing users) is not part of this listing. | | Pricing | Free (Free) · Free, with nothing to buy and no account. The limit is 10 requests a second for each user, whatever the number of machines, and the SEC may block IP addresses that exceed it (https://www.sec.gov/about/privacy-information, checked 2026-10-09). | | x402 | No · No x402, MPP or L402 in the API documentation or the privacy and security policy (checked 2026-10-09). | | Licence | Public information. The SEC says information on sec.gov may be copied or further distributed without its permission, and asks for citation. EDGAR names and logos are registered trademarks | | Docs | https://www.sec.gov/search-filings/edgar-application-programming-interfaces | | llms.txt | not found | | API | Four GET routes on `https://data.sec.gov` returning JSON. `submissions/CIK##########.json`, `api/xbrl/companyconcept/CIK##########/{taxonomy}/{tag}.json`, `api/xbrl/companyfacts/CIK##########.json` and `api/xbrl/frames/{taxonomy}/{tag}/{unit}/{period}.json`. No query parameters | | Coverage | Filing history for every EDGAR filer, with name, former names, tickers, exchanges, SIC code and addresses. XBRL facts from forms 10-Q, 10-K, 8-K, 20-F, 40-F and 6-K in standard taxonomies such as us-gaap, ifrs-full, dei and srt | | Rate limits | 10 requests a second for each user across all machines. Over it, further requests from the IP address may be limited until the rate has stayed below the threshold for 10 minutes | | Credentials | None. A User-Agent header with an organisation name and contact email address is requested of automated callers | | Response size | No limit, paging or field selection. Submissions hold at least a year or 1,000 of the most recent filings in column arrays, with older filings in extra files listed under `filings.files`. On 9 October 2026 Apple's submissions file was 164 KB (28 KB gzipped) and one company concept 19 KB | | Frames | One fact for each reporting entity for a period written `CY2019` (annual), `CY2019Q1` (quarterly) or `CY2019Q1I` (instantaneous). Units with a denominator are written with `-per-`, such as `USD-per-shares` | | Errors | Not documented. A request for a path that does not exist on data.sec.gov answered 404 with an XML body carrying the code `NoSuchKey` | | Bulk data | `companyfacts.zip` and `submissions.zip`, rebuilt nightly at about 3:00 a.m. ET. EDGAR index files and daily archives sit under `https://www.sec.gov/Archives/edgar/` | | Terms | Content is public information that may be copied or redistributed without permission. Automated access must follow the SEC Web Site Privacy and Security Policy. CORS is not supported, per the docs | | Capabilities | data.company | | Tags | official, government, hosted, free, no-key, open-data, us | | JSON | https://www.anchorterminal.com/api/v1/tools/sec-edgar.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 38 | 7.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 23 | 3.7 | | Agent ergonomics | 13% | 16.2 | 41 | 6.7 | | Security & auth | 14% | 17.5 | 52 | 9.1 | | Payments & pricing | 10% | 12.5 | 60 | 7.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 14 | 1.2 | | Transparency & trust (editorial 43, provenance 70) | 7% | 8.8 | 57 | 5.0 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **40.8 → E** | ### Why each score - Reliability 38: Graded as a hosted API. No status page was found for data.sec.gov in the API docs, the developer pages or the FAQ (0), so there is no incident history to read (5). The limit is published, 10 requests a second for each user (15). The policy says an IP address over the limit may be limited until its rate has stayed below the threshold for 10 minutes, with no status code, Retry-After header or backoff guidance documented. Every request is a read (8 of 15). No SLA, and the SEC says it gives no technical support for scripted access (0). The APIs carry no beta label (10). 0 + 5 + 15 + 8 + 0 + 10 = 38. - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 23: No OpenAPI file or other machine-readable contract is linked from the docs (0). www.sec.gov/llms.txt returns 404 (0). One page describes the four routes in prose, says what each returns and points large pulls to the bulk files, with nothing on response fields (10 of 20). Path patterns state the 10-digit CIK, the taxonomy, the unit form and the three period formats, with no list of allowed values and no response schema (7 of 15). Example URLs are given, with no example response and no error reference (4 of 15). Paths carry no version and no API changelog was found. The page shows a last update of 8 April 2025 (2 of 15). Total 23. - Agent ergonomics 41: No limit, paging or field selection. `companyconcept` and `frames` narrow a request to one concept, and submissions use compact column arrays, but Apple's submissions file was 164 KB on the day (8 of 25). No query parameters. Older filings are split into extra files listed with their date ranges, and nothing filters by form or date (6 of 20). Errors are not documented, and a missing path answered 404 with an XML `NoSuchKey` body (5 of 20). Every route is a GET on a JSON document and safe to retry (15 of 20). A call needs one CIK and no key, but the CIK comes from a separate file, the User-Agent must be set, and no official SDK was found (7 of 15). Total 41. - Security & auth 52: No credential, so there is no secret to leak. The declared User-Agent carries a contact address, not a key (20 of 30). The APIs are read-only (15 of 20). Responses are mostly numbers and filing metadata, with names and descriptions as filers wrote them and no guidance on treating them as untrusted (7 of 15). No account, so no request log or usage view (0 of 15). A Vulnerability Disclosure Policy updated on 21 September 2026 authorises good-faith research, takes reports through a Bugcrowd form and asks for 90 days before disclosure. security.txt returns 404, there is no paid bounty, and no certification was found (10 of 20). Total 52. - Payments & pricing 60: No x402, MPP or L402 (0). Free, stated publicly, with nothing to buy (20). No account or card (20). An agent can call with no sign-up, sending only a declared User-Agent (20). Total 60. - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. (data quality 100, half of this category once the task suite runs) - Maintenance & community 14: No dated change to the data APIs was found. The docs page shows a last update of 8 April 2025, 549 days before the check (0 of 30). EDGAR News and Announcements carries three posts in the last 90 days (14 August, 14 September and 7 October 2026), all about the filing system and its taxonomies and none about these APIs, so half credit (10 of 20). The SEC publishes webmaster@sec.gov and opendata@sec.gov for feedback and says it gives no technical support for scripted access. No forum or issue tracker was found (4 of 15). No official SDK (0 of 15). No package to judge (0 of 10). Total 14. - Transparency & trust 57: Closed government service. The policy says information on sec.gov is public and may be copied or redistributed without permission, and sets the automated access rules (15 of 30). The privacy policy lists what is logged on each visit, says partial IP addresses are published in response to FOIA requests, and links Privacy Impact Assessments and system of records notices. No retention period for access logs is stated (18 of 30). No deprecation policy for the APIs. The policy says its limits may change (2 of 20). Google Analytics, Foresee, Akamai and GovDelivery are named. The Amazon hosting seen in response headers is not, and no data locations are given (8 of 20). Total 43. Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/sec-edgar.md (JSON https://www.anchorterminal.com/fixes/sec-edgar.json) ### What we couldn't check - unchecked: the `companyfacts` and `frames` routes. To keep to a few requests, only `submissions` and `companyconcept` were called, so the size of a company facts response was not seen - unchecked: behaviour over the rate limit. No attempt was made to reach it, so the status code and any Retry-After header are unknown - unchecked: a request with no declared User-Agent. Every request carried one, so the response to an undeclared tool was not seen - unchecked: the Privacy Impact Assessments and system of records notices, which may state how long access logs are kept - unchecked: the token-protected EDGAR filer APIs on api.edgarfiling.sec.gov. They are a separate surface for filers and were not read or graded - No status page for data.sec.gov was found by reading the docs, developer pages and FAQ. Web search was not available to look further - `provenance.terms` and `provenance.privacy` are the same page, the SEC Web Site Privacy and Security Policy, because the API docs name it as the document automated access must comply with and no separate API terms were found - The docs say data.sec.gov does not support CORS. The submissions response on the day carried `access-control-allow-origin: *` and the company concept response did not - `lastRelease` is null because no dated change to the data APIs was found. The date the APIs launched was not found either - The Accessing EDGAR Data page says the SEC does not allow automated tools to crawl the site, while the FAQ says scripted access with a declared User-Agent is allowed. Read together they permit declared, rate-limited access. Recorded as a fact, with no deduction ### Sources - EDGAR Application Programming Interfaces documentation: (seen 2026-10-09) - Accessing EDGAR Data, fair access and index files: (seen 2026-10-09) - SEC Web Site Privacy and Security Policy: (seen 2026-10-09) - Webmaster FAQ, developer section: (seen 2026-10-09) - Developer Resources: (seen 2026-10-09) - Vulnerability Disclosure Policy: (seen 2026-10-09) - EDGAR News and Announcements: (seen 2026-10-09) - EDGAR Release 26.3 note, 14 September 2026: (seen 2026-10-09) - Submit Filings page, with the three latest announcements: (seen 2026-10-09) - submissions call for Apple (200, JSON, 164 KB): (seen 2026-10-09) - company concept call for Apple (200, JSON, 19 KB): (seen 2026-10-09) - data.sec.gov robots.txt (404, XML NoSuchKey body): (seen 2026-10-09) - www.sec.gov robots.txt, no Content-Signal line: (seen 2026-10-09) - security.txt (404): (seen 2026-10-09) - llms.txt (404): (seen 2026-10-09) - RDAP record for sec.gov: (seen 2026-10-09) ## Who's behind it (provenance 70/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | U.S. Securities and Exchange Commission | 20/20 | | Domain age | sec.gov, registered 1997-10-02 (29 years) | 15/15 | | Endpoint on the vendor's domain | data.sec.gov | 15/15 | | Terms of service | read, states 2 of the 7 things a reader expects, and has 1 clause that costs points | 3.7/10 | | Privacy policy | read, states 3 of the 8 things a reader expects | 6.3/10 | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The SEC is an independent agency of the United States federal government. The API documentation page says data.sec.gov was created to host its JSON APIs. No separate API terms were found. The API documentation says automated access must comply with the SEC Web Site Privacy and Security Policy, so the terms link and the privacy link are the same page. Its Internet Security Policy section sets the request limit and its Website Dissemination section covers reuse. The page was last updated on 29 November 2023. The API answers at data.sec.gov, on the SEC's domain. Response headers on 9 October 2026 carried Amazon API Gateway request identifiers. www.sec.gov/.well-known/security.txt returns 404. A Vulnerability Disclosure Policy, last updated on 21 September 2026, takes reports through a form hosted by Bugcrowd. No status page was found for data.sec.gov in the API docs, the developer pages or the FAQ. The EDGAR News and Announcements page says it carries system status for the filing system. The changelog link is EDGAR News and Announcements, which carries release notes for the EDGAR filing system. No changelog for the data APIs was found. RDAP for sec.gov gives a registration date of 1997-10-02 through get.gov. data.sec.gov has no robots.txt (404). www.sec.gov/robots.txt allows `/Archives/edgar/data` and carries no Content-Signal line. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.sec.gov/about/privacy-information), read 2026-10-09, dated 2023-11-29, states 2 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "The SEC does not allow "unclassified" bots or automated tools to crawl the site." - Gives the date it was last updated. Last updated 2023-11-29. - Not found in the text. Names the governing law or courts. - Not found in the text. States a limit on its liability. - Not found in the text. Says how the agreement or account can be ended. - Not found in the text. Says how changes to the terms are announced. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Current guidelines limit each user to 10 requests a second in total, however many machines send them. "Current guidelines limit users to a total of no more than 10 requests per second, regardless of the number of machines used to submit requests." - Also in the text (2026-10-08). Information on sec.gov is treated as public information and may be copied or redistributed without the SEC's permission. "Information presented on sec.gov is considered public information and may be copied or further distributed by users of the web site without the SEC’s permission." **Privacy policy** (https://www.sec.gov/about/privacy-information), read 2026-10-09, dated 2023-11-29, states 3 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2023-11-29. - Not found in the text. Says how long data is kept. - Not found in the text. Says whether personal data is sold or shared for advertising. - Not found in the text. Says what rights people have over their data. - Not found in the text. Gives a privacy contact. - Not found in the text. Says where data is transferred or stored. - Also in the text (2026-10-08). Parts of the automatically collected visit data, including partial IP addresses, are posted publicly on the website in response to Freedom of Information Act requests. "Additionally, portions of this data, to include partial IP addresses, are posted publicly on our website in response to frequent Freedom of Information Act (FOIA) requests." ## Data quality (100/100) Data quality becomes half of Task success for data providers when Task success is scored. Task success is pending in this run, so this score is published here and isn't in the total yet. | Check | Finding | Points | | --- | --- | --- | | Coverage | Every EDGAR filer's submission history, and XBRL financial facts from forms 10-Q, 10-K, 8-K, 20-F, 40-F and 6-K. Facts in a company's own custom taxonomy are left out (5 of 5) | 25/25 | | Freshness | Updated as filings are disseminated. The docs state a typical delay under a second for submissions and under a minute for XBRL, longer at peak filing times | 15/15 | | History | EDGAR started in 1994 and 1995, per the SEC. Apple's filing history on the day ran from 26 January 1994. XBRL was first required in 2009 | 15/15 | | Methodology published | www.sec.gov/search-filings/edgar-application-programming-interfaces | 15/15 | | Sources disclosed | named | 10/10 | | Licence | Public information. May be copied or further distributed without the SEC's permission, with citation requested | 10/10 | | Official standing | The SEC's own electronic filing system, through which companies must file under US federal securities law | 10/10 | Caching and reuse: Caching, storing and redistribution are permitted. The SEC seal, logos and EDGAR trademarks may not be used in a way that suggests affiliation. ## Live (updated 2026-10-10 05:39 UTC) - Right now: up, HTTP 200, 209 ms, checked 2026-10-10 05:39 UTC (get on `https://data.sec.gov`) - Uptime 24h 100.0% (143 probes) · 30 days 100.0% (143 probes) · p50 205 ms · p95 441 ms - Watching changelog - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/sec-edgar.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - No key, account or card. A request needs only a User-Agent header that declares who is calling - The SEC is the primary source. Filings reach the submissions API with a typical delay under a second and the XBRL APIs under a minute, per the docs - Content on sec.gov is public information that may be copied or redistributed without the SEC's permission, per its dissemination statement - The rate limit is published, 10 requests a second for each user across all machines - Nightly bulk ZIP files carry every submissions and company facts record, so large pulls need no API calls ## Weaknesses - No OpenAPI file, llms.txt, response schema, error reference or official SDK was found. The documentation is one page of prose with example URLs - No query parameters. A filing history cannot be filtered by form or date, and the submissions response for Apple was 164 KB uncompressed on 9 October 2026 - No status page or SLA was found for data.sec.gov, and the SEC says it gives no technical support for scripted access - No API changelog or deprecation policy was found. The docs page was last updated on 8 April 2025 and the policy says limits may change - Lookups need a 10-digit CIK. Mapping a ticker or name to a CIK uses separate files on www.sec.gov that the SEC does not guarantee ## Before you call it (notes for agents) 1. Send a User-Agent naming the operator's organisation and a contact email address on every request. The SEC limits or blocks undeclared automated tools 2. Stay under 10 requests a second in total across all machines. Over the limit, the IP address may be limited until the rate has stayed below the threshold for 10 minutes 3. Pad the CIK to 10 digits with leading zeros in `submissions/CIK##########.json` and the XBRL paths. Find a CIK in `https://www.sec.gov/files/company_tickers.json` 4. Prefer `api/xbrl/companyconcept/` for one figure. `companyfacts` returns every concept a company has reported, and `submissions` returns at least 1,000 filings in column arrays 5. Read older filings from the extra files named in `filings.files`, and check a frame fact's own start and end dates, since frames align company periods to calendar quarters ## Connect First request: ```bash curl -H "User-Agent: $ORG_NAME $CONTACT_EMAIL" https://data.sec.gov/submissions/CIK0000320193.json ``` Through letme (picks today, calling later): https://letme.dev/sec-edgar. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | ZoomInfo API + MCP | BB | 72.2 | 110 | data.company | no | https://www.anchorterminal.com/tools/zoominfo.md | | People Data Labs | B | 64.2 | 362 | data.company | no | https://www.anchorterminal.com/tools/people-data-labs.md | | Apollo API + MCP | B | 63.3 | 398 | data.company | no | https://www.anchorterminal.com/tools/apollo.md | | Coresignal API + MCP | B | 62.9 | 413 | data.company | no | https://www.anchorterminal.com/tools/coresignal.md | | Lusha API + MCP | B | 62.3 | 435 | data.company | no | https://www.anchorterminal.com/tools/lusha.md | | LeadMagic API + MCP | C | 60.2 | 524 | data.company | no | https://www.anchorterminal.com/tools/leadmagic.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Four JSON routes on data.sec.gov. `submissions/CIK##########.json` for a filer's history, and `api/xbrl/companyconcept/`, `api/xbrl/companyfacts/` and `api/xbrl/frames/` for XBRL facts (source: ) - XBRL data comes from forms 10-Q, 10-K, 8-K, 20-F, 40-F and 6-K and their variants, limited to facts in standard taxonomies that apply to the whole filing entity (source: ) - The docs state a typical processing delay of less than a second for submissions and under a minute for XBRL, longer at peak filing times (source: ) - Two bulk files, `companyfacts.zip` and `submissions.zip` under `https://www.sec.gov/Archives/edgar/daily-index/`, are rebuilt nightly at about 3:00 a.m. ET (source: ) - The limit is 10 requests a second for each user. Over it, the IP address may be limited until the rate has stayed under the threshold for 10 minutes (source: ) - The SEC says it does not allow unclassified bots or automated tools to crawl the site, permits scripted access with a declared User-Agent, and gives no technical support for it (source: ) - On 9 October 2026 the submissions file for Apple (CIK 320193) listed a filing accepted that morning and 1,001 recent filings, with 1,264 older ones from 1994 in a second file (source: ) - #9 of 9 in Best data provider APIs for AI agents: https://www.anchorterminal.com/best/data-providers/index.md - All 31 data comparisons: https://www.anchorterminal.com/compare/data-providers/index.md ## Compare - [Alpha Vantage vs SEC EDGAR APIs](https://www.anchorterminal.com/compare/alpha-vantage-vs-sec-edgar.md): E 41.3 vs E 40.8 - [Companies House API vs SEC EDGAR APIs](https://www.anchorterminal.com/compare/companies-house-vs-sec-edgar.md): D 49.3 vs E 40.8 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on sec.gov or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "sec-edgar", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html SEC EDGAR APIs on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![SEC EDGAR APIs on Anchor Terminal](https://www.anchorterminal.com/badges/sec-edgar.svg)](https://www.anchorterminal.com/tools/sec-edgar) ``` Plain link: ```html SEC EDGAR APIs on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say SEC EDGAR APIs is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/sec-edgar-dark.png - Light: https://www.anchorterminal.com/assets/share/sec-edgar-light.png