Hoppa till innehåll
Menu and API reference

Guide

Authentication

Use Bearer keys and scopes to control access to the API.

Protected resources require an API key in the Authorization HTTP header. The key belongs to a machine client. It creates no web session and sets no cookies.

bash
curl "https://firmainfo.se/api/v1/me" \
  -H "Authorization: Bearer fi_live_…"

Scopes and permissions

Each product area has its own scope. If the key lacks the scope a resource requires, you get 403 missing_scope.

ScopeData and features
companiesCompany registry, filtering, batch lookups and history
financialsAnnual accounts, key figures and structured notes
structureReported group relationships and share capital
governanceBoard, management and auditors
person_lookupExact lookup of a known personal identity number for a sole trader
marketInsider transactions and short positions
trademarksTrademarks, portfolios and events
workplacesWorkplaces and location data from Statistics Sweden
enrichmentVerified website, social links and logo
contactsContact fields from Statistics Sweden, including the marketing opt-out flag

Terms for personal data

The governance, person_lookup, contacts and market scopes contain data about natural persons. Your organisation must therefore accept the current version of our data terms before those scopes are enabled. As the recipient, you are responsible for how the data is used.

When the terms are updated to a new version, the affected resources respond with 403 terms_acceptance_required until you accept the update. The key remains valid for all other scopes.

Looking up sole traders

A sole trader may be registered under the owner's personal identity number. In ordinary flows the API therefore uses a public token and shows the identity masked as YYYYMMDD-XXXX.

A key holding the person_lookup scope, with current terms accepted, may submit an exact personal identity number that is already known in your own flow. The feature is deliberately narrow.

  • You can only make an exact lookup. There is no partial matching, searching or listing.
  • Exact person lookups have a separate limit of 10 calls per minute.
  • Ten-digit values are accepted only when the date, check digit and century can be determined without ambiguity.
  • A key without the right scope is rejected before the database is queried. The response never reveals whether the identity exists.

Rotating API keys

Create the new key first and deploy it to production. Once traffic is flowing through the new key, the old one can be revoked. A client may hold several active keys during the switch so the integration keeps working.