Guide
Authentication
Use Bearer keys and scopes to control access to the API.
Protected resources require an API key in the Authorization HTTP header. The key belongs to a machine client. It creates no web session and sets no cookies.
curl "https://firmainfo.se/api/v1/me" \
-H "Authorization: Bearer fi_live_…"
Scopes and permissions
Each product area has its own scope. If the key lacks the scope a resource requires, you get 403 missing_scope.
| Scope | Data and features |
|---|---|
companies | Company registry, filtering, batch lookups and history |
financials | Annual accounts, key figures and structured notes |
structure | Reported group relationships and share capital |
governance | Board, management and auditors |
person_lookup | Exact lookup of a known personal identity number for a sole trader |
market | Insider transactions and short positions |
trademarks | Trademarks, portfolios and events |
workplaces | Workplaces and location data from Statistics Sweden |
enrichment | Verified website, social links and logo |
contacts | Contact fields from Statistics Sweden, including the marketing opt-out flag |
Terms for personal data
The governance, person_lookup, contacts and market scopes contain data about natural persons. Your organisation must therefore accept the current version of our data terms before those scopes are enabled. As the recipient, you are responsible for how the data is used.
When the terms are updated to a new version, the affected resources respond with 403 terms_acceptance_required until you accept the update. The key remains valid for all other scopes.
Looking up sole traders
A sole trader may be registered under the owner's personal identity number. In ordinary flows the API therefore uses a public token and shows the identity masked as YYYYMMDD-XXXX.
A key holding the person_lookup scope, with current terms accepted, may submit an exact personal identity number that is already known in your own flow. The feature is deliberately narrow.
- You can only make an exact lookup. There is no partial matching, searching or listing.
- Exact person lookups have a separate limit of 10 calls per minute.
- Ten-digit values are accepted only when the date, check digit and century can be determined without ambiguity.
- A key without the right scope is rejected before the database is queried. The response never reveals whether the identity exists.
Rotating API keys
Create the new key first and deploy it to production. Once traffic is flowing through the new key, the old one can be revoked. A client may hold several active keys during the switch so the integration keeps working.