Verify a domain or licence number
GET /v1/check
Public endpoint. Pass ?domain= or ?license_number=, not both.
Rate limit: 10 requests / IP / hour (unauthenticated). Authenticated callers skip the IP gate and use their plan quota.
Response: { query, verdict, verdict_detail, match, alternatives, confidence, _meta }.
Read verdict first: one of licensed, licensed_provisional, domain_not_listed,
licence_not_active, related_host_listed, name_match_only, not_found, generic_term
(see the CheckVerdict schema), with verdict_detail as quotable text. A host and its
www-counterpart are one site; another host on the same registrable domain is reported as
such (related_host_listed, related_hosts[]), never as the queried host. match carries the regulator name,
the licence UUID and the status’s own provenance (status_source_url, status_observed_at);
_meta.register says how fresh the matched register is, and _meta.stale_jurisdictions which
registers are past their SLA on a miss. See the confidence-scoring guide at
https://igregulator.io/docs/confidence/ for match-type semantics.
Headers on every response: X-RateLimit-Limit, X-RateLimit-Remaining,
X-RateLimit-Reset, X-Upgrade-URL.
Parameters
Section titled “ Parameters ”Query Parameters
Section titled “Query Parameters ”A bare hostname. Case is ignored, one trailing dot is dropped, and an internationalised name is converted to punycode (query.domain is what we looked up; query.input echoes what you sent when it differs). A scheme, path, port or underscore is a 400.
Example
bet365.comA licence number as the register prints it — case, spaces and separators are ignored (055149-r-331499-004 finds 055149-R-331499-004). An earlier version of a UKGC number (055148-R-331498-001) resolves to the version the register lists now, said in superseded_number and first in verdict_detail. For KH, TGC and IOM, whose registers publish none, pass the iGregulator reference returned as license_number (e.g. IOM/OGRA/bm-solutions-iom-limited). match.match_type is license_number.
Example
039028-R-319297-014Retrospective lookup. Reconstructs the matched licence’s status as it stood at that moment from transition history, within our observation window only — e.g. “was this operator licensed at the time of a transaction three months ago”. Exactly two formats: YYYY-MM-DD, a real calendar date (the end of that day, UTC; today’s date means now), or an ISO-8601 datetime with a UTC offset (2026-03-01T12:00:00Z, 2026-03-01T14:00+02:00). Anything else — 2026/03/01, 2026-02-30, a datetime without an offset — and any future instant is a 400 with details.field: "as_of". match.status and verdict stay current; the historical answer is the top-level as_of object (which names the licence it is about), and verdict_detail leads with it.
Example
2026-03-01Responses
Section titled “ Responses ”Lookup result (may indicate confidence: "none").
object
object
The hostname looked up: lower-cased, one trailing dot dropped, an internationalised name in punycode (bücher.de → xn--bcher-kva.de).
What you sent, when it differs from domain.
The answer in one field, derived from match by the rules below — read it before the individual fields. It describes match (the link the regulator lists now); a dual-licensed domain’s other links are in jurisdictions[]. It is about the licence as it stands NOW — with ?as_of=, verdict_detail leads with the answer for that date and as_of carries it.
The first that applies, in this order:
licence_not_active— the matched licence status is notactive(surrendered,expired,revoked,suspended,pending,not_in_register,unknown—verdict_detailnames it), whether or not the regulator still lists the domain on it; when it no longer does,verdict_detailsays that too. Also alicense_numberquery whose licence is notactive, and a domain the regulator lists under an operator that holds no licence that can cover a website (match.statusandmatch.license_numbernull — a UKGC licensee with non-remote licences only, an MGA one with no B2C licence). Onlyrevoked/suspendedare enforcement decisions.domain_not_listed— the licence isactive, but the regulator no longer lists this domain on it (domain_status: delisted): it does not cover this site.related_host_listed— the queried host is NOT listed; another host on the same registrable domain is. One operator:matchdescribes that host (match_type: related_host,matched_domain). Several operators:matchis null,match_absence_reasonisshared_registrable. Either way the hosts are inrelated_hosts[]. A listing covers the host the regulator names — a made-up subdomain of a licensed brand is not licensed. (A host’s www-counterpart is the same site, not a related host:www.x.comis answered fromx.comaslicensed.)licensed_provisional— aslicensed, with astatus_qualifier(todayprovisional_under_assessment: a Curaçao licence the CGA keeps in force pending its final assessment).licensed—match.statusisactive, the regulator lists this domain (or its www-counterpart) on that licence (domain_status: active), nostatus_qualifier. For alicense_numberquery: the licence isactive.name_match_only—confidencemedium/low: a name resembled the operator’s; no licence we hold lists this domain. The status belongs to that operator, not to this domain.not_found— in none of the registers we cover (checked_jurisdictions). Not a finding that it is unlicensed.generic_term— a generic gambling label we will not map to one operator. The exact domain is on no licence we hold (it would have matcheddomain_exactotherwise).
Approve automatically only on licensed (and licensed_provisional if your policy accepts provisional licences); route everything else to a human.
Plain English stating the verdict, safe to quote as it stands: it names the regulator, operator and licence (never our KH/TGC/IOM reference as a licence number), says when we read the listing and — separately — whether that register’s last read is past its SLA, scopes every miss to the registers we cover, and never calls anything “unlicensed”. With ?as_of= it LEADS with the answer for that date (“On 2026-03-01 we were not yet tracking … so its status then is unknown. Today: …”); for a superseded licence number it leads with that note. The wording may improve over time — branch on verdict, quote verdict_detail.
object
How sure we are WHICH OPERATOR this is — a statement about the match, not about the licence. high = the domain (or its www-counterpart, or — match_type: related_host — another host on the same registrable domain), or the licence number, is listed under this operator in a register we cover. medium = no register we cover ties this domain to one operator; its root closely matches one of the operator’s trading or legal names, so we can name the operator but not prove the domain is theirs (it may be a lookalike). low = a weak name resemblance; operator is a guess. (A generic gambling label such as bestcasino is not a low match: match is null and match_absence_reason is generic_term.) Whether the site is licensed is status together with domain_status, never confidence.
domain_exact — a register lists the queried host, or its www-counterpart (www.x.com and x.com are one site; matched_domain says which spelling is stored). related_host — the queried host is NOT listed; another host on its registrable domain is, under this one operator, and the match describes that host (matched_domain; verdict related_host_listed) — a listing covers the host the regulator names, so this is never licensed. license_number — a ?license_number= query. trading_name_fuzzy / name_similarity — a name resembled the operator’s (confidence medium/low).
Jurisdiction code — UKGC, MGA, CW (Curaçao), KH (Kahnawake), AN (Anjouan), TGC (Tobique) or IOM (Isle of Man). GET /v1/jurisdictions lists them with names and licence types.
The regulator’s name, as GET /v1/jurisdictions gives it (e.g. Curaçao Gaming Authority, UK Gambling Commission) — no second call needed to say who licenses it. null when jurisdiction is.
The licence’s iGregulator UUID — the input to GET /v1/licenses/{license_id} (full record, not_listed_since, last_listed_at) and /v1/licenses/{license_id}/history. null when no licence is attached (name_similarity matches).
The licence number as the regulator’s register prints it — except for KH (Kahnawake), TGC (Tobique) and IOM (Isle of Man), whose registers publish none. For those three it is an iGregulator reference we assign: KH/IG/<slug> or KH/CSPA/<slug>, TGC/B2C/<slug> or TGC/B2B/<slug>, IOM/OGRA/<company key>. The reference is stable and /v1/check?license_number= accepts it, but no regulator issued it: do not present it to a user as the licence number.
true for KH, TGC and IOM: those registers publish no licence number, so license_number is an iGregulator reference — never present it as the regulator’s number. false everywhere else (and when there is no licence).
Where THIS status was published — provenance is per status, not per licence (the same field as on /v1/licenses/{id}). Often not the register the licence is listed in: a Curaçao or Anjouan revocation comes from the enforcement / revoked-licences page, a Kahnawake termination from its advisory notice. Cite it when you report the status. null for a status set before we tracked provenance.
The latest read of status_source_url that still said this status. When the status CHANGED is in /v1/licenses/{license_id}/history.
See the LicenseStatus schema. Approve only on active. not_in_register (the register no longer lists the licence; upstream_status is then null) and surrendered (the operator gave it up) are not revocations, and unknown means we could not read the regulator’s wording — read upstream_status and decide for yourself. We do not guess. This is the LICENCE’s status: for the domain read domain_status too, and on a medium/low match it is the named operator’s licence, not a statement about this domain. null on a domain match (with license_number and license_id) when the regulator lists the domain under an operator that holds no licence that can cover a website — a UKGC licensee with non-remote licences only, an MGA one with no B2C licence; jurisdiction names the regulator that lists it and verdict is licence_not_active.
Populated for domain matches (domain_exact, related_host) only. direct = licensee runs the domain; white_label = licensee authorises a third-party brand on the domain. null for licence-number and fuzzy matches.
The regulator’s own words for the licence status, verbatim, before our enum mapping (e.g. Surrendered → surrendered, Revoked - Non Payment of Fee → revoked, N/A Indefinite → active). Always informative; essential when status is unknown. null when status is not_in_register — there is no current upstream word, and repeating the last one we read as if it were current is how a page came to say ‘revoked · upstream: valid’. Also null when the register’s word says the licence is in force (valid, Active, Licensed, Assessment in progress…) and status is revoked, suspended, surrendered or expired: that status was read from another publication (an enforcement register, an advisory notice), and the register row it would sit next to had not caught up. The reverse is never suppressed — a negative word next to active is always shown.
Set when status is right but not the whole truth; null otherwise. provisional_under_assessment: a Curaçao licence the CGA register lists as ”status is active (the operator may trade), and expires_at may be in the past; a decision is outstanding. Treat as licensed, and re-check: the licence can become final or end. Derived from upstream_status.
The status of matched_domain under this operator, which is not the status of the licence. delisted = the domain is no longer listed on this licence — this site is not covered by it; the licence’s own status is in status, whatever that is. On a related_host match it is the RELATED host’s status, not the queried host’s (which is not listed at all). Simplest: branch on verdict. Field by field, the site is licensed only when match_type is domain_exact, status is active AND domain_status is active. null for licence-number queries and for fuzzy matches (no register ties the domain to this operator).
The hostname the register lists, which this match describes. Usually the query itself; its www-counterpart when only that spelling is stored (www.virginbet.com for virginbet.com — one site, verdict as for the query); or, on a related_host match, another host of the same registrable domain (fi.unibet.com for zz.unibet.com — NOT the queried host, verdict related_host_listed). null for licence-number queries and name matches.
When a regulator source last listed matched_domain on this licence — the latest register, certificate or seal read that wrote this link as listed. Present only while domain_status is active. null when the domain is delisted: we do not keep the time it was last listed before the de-listing, nor since when it has been de-listed, and we will not approximate either. Also null for licence-number queries and name matches.
The regulator’s OWN per-domain verification page for this match, when the regulator publishes one — a Curaçao certificate (cert.cga.cw) or a Tobique validation seal (validate.thetgc.ca). Fetch or link it to confirm the verdict against the primary source directly. We re-read these pages to keep domain_status current: every Tobique seal nightly, each Curaçao certificate every few days (a rolling nightly batch, oldest first) — so the page itself can be newer than our domain_status. null where the regulator has no such page (UKGC, MGA, KH, AN) or for non-domain matches. A legacy cert.gcb.cw link is served on cert.cga.cw, which it redirects to.
On a match from a register row: the licence status that page printed at our latest read of it, verbatim (Active, Revoked…). null when we hold no such reading. When it is not in-force wording, the page is not confirmation — say what it reads and when (verification_page_read_at). It moves no status by itself: a revocation comes only from a regulator publication (status_source_url).
When we read verification_page_status off the page.
object
Mirror of match.confidence — about the match, not the licence. Also low with match: null when the label is generic (match_absence_reason: generic_term). Omitted when nothing matched (match_absence_reason: no_record_found).
Present only when match is null. generic_term: the label is an ultra-generic gambling word (e.g. bestcasino.example) we cannot map to one operator. shared_registrable: the queried host is not stored, and the hosts of its registrable domain are linked to more than one operator — related_hosts[] lists them, none is the answer (verdict related_host_listed when one of them is listed now, else not_found). no_record_found: a specific query we checked against every covered register and did not find. Lets a caller phrase the answer precisely instead of treating every miss as “unlicensed”.
Present when the queried host is on no licence we hold — match is null, a name match, or related_host_listed — the jurisdiction codes actually checked. Report a miss as “not found in the registers of these N jurisdictions”, never as “unlicensed”: we cover these regulators, not every regulator. Example: [“AN”,“CW”,“IOM”,“KH”,“MGA”,“TGC”,“UKGC”].
Present when the related-host stage answered (verdict related_host_listed, or not_found with shared_registrable): the other stored hosts on the queried host’s registrable domain, listed first, at most 10. Not evidence about the queried host.
Another stored host on the queried host’s registrable domain (Public Suffix List, private section included: a hosting platform’s customers are not each other’s related hosts). Its listing is about IT, not about the queried host.
object
The operator’s licence jurisdiction; null when it holds none.
That host’s link status under that operator.
A license_number query for an earlier version of a UKGC number (055148-R-331498-001), resolved to the version the register lists now (-002): the last part of a UKGC number goes up when the Commission varies a licence. A later version than ours is not resolved.
object
The number as sent.
match.license_number.
The sentence verdict_detail leads with.
Present only when a matched domain is licensed by MORE THAN ONE (operator, jurisdiction) pair — dual-licensed brands; the links of a host and of its www-counterpart count together, one entry per operator. Best-first: jurisdictions[0] is the pair match reports. Read this before phrasing a single-jurisdiction verdict about a multi-licensed brand; a domain can be active under one register and delisted under another at the same time, and each entry carries its own register freshness.
One (operator, jurisdiction) pair that licenses the matched domain. A brand can be licensed by different legal entities in different jurisdictions at once; status/domain_status are per-link — active in one register and delisted in another are both true simultaneously.
object
Jurisdiction code — UKGC, MGA, CW (Curaçao), KH (Kahnawake), AN (Anjouan), TGC (Tobique) or IOM (Isle of Man). GET /v1/jurisdictions lists them with names and licence types.
The licence number as the regulator’s register prints it — except for KH (Kahnawake), TGC (Tobique) and IOM (Isle of Man), whose registers publish none. For those three it is an iGregulator reference we assign: KH/IG/<slug> or KH/CSPA/<slug>, TGC/B2C/<slug> or TGC/B2B/<slug>, IOM/OGRA/<company key>. The reference is stable and /v1/check?license_number= accepts it, but no regulator issued it: do not present it to a user as the licence number.
Same as match.license_reference_is_ours, for this entity’s licence: true (KH, TGC, IOM) means license_number is an iGregulator reference — never present it as the regulator’s number.
The stored spelling this link is on — the query or its www-counterpart (one site; each operator appears once, with its better link).
When we last read the matched jurisdiction’s register, and whether that read is inside its freshness SLA — the same rule and numbers as /v1/health/coverage (24 h for UKGC, AN, TGC, IOM; 48 h for MGA, CW, KH). A stale register means a change the regulator published since last_read_at is not in this answer.
object
Jurisdiction code — UKGC, MGA, CW (Curaçao), KH (Kahnawake), AN (Anjouan), TGC (Tobique) or IOM (Isle of Man). GET /v1/jurisdictions lists them with names and licence types.
The newest last_verified_at among the jurisdiction’s licences — when a load last confirmed its register. Cached up to 10 minutes.
last_read_at is less than sla_hours old. null if never read.
{ "jurisdiction": "UKGC", "last_read_at": "2026-09-30T03:00:26.364Z", "fresh": true, "sla_hours": 24}This entity’s licence status (see LicenseStatus).
The domain’s status under THIS entity — same meaning as match.domain_status. Licensed through this entity only when status and domain_status are both active.
Same as match.verification_page_status, for this link.
Same as match.status_qualifier, for this entity’s licence.
as_of on /v1/check: the AsOf reconstruction, plus WHICH licence it reconstructs. It is the status of that one licence on that date — match’s licence, picked by today’s links — not a record of who ran the domain then: domain_operators keeps no history of when a domain was linked to a licence.
object
The resolved instant (UTC). A bare YYYY-MM-DD resolves to the end of that day; today’s date resolves to now.
observed: the date is within our window, status is known. corrected: the event in effect on that date is one we later WITHDREW (see correction) — status is null. We do not report the withdrawn status, and we do not fall back to the one before it either: neither is something we observed for that date. before_tracking: the date predates when we started watching — status is null, NOT a guess. no_such_license: we have no history for this licence. no_license_resolved: a fuzzy /v1/check match with no specific licence to time-travel.
Licence status as of the date, or null when not observed.
The history transition in effect at the date — when this status was last confirmed relative to the query.
object
Present only when knowledge is corrected. The event that was in effect at the date and that we later withdrew. withdrawn_status is what we USED to say — never quote it as the status.
object
Lower bound of our knowledge — when we first observed this licence.
What was time-travelled: a licence status, never a domain link.
match.license_id; null when no licence was resolved.
The licence number as the regulator’s register prints it — except for KH (Kahnawake), TGC (Tobique) and IOM (Isle of Man), whose registers publish none. For those three it is an iGregulator reference we assign: KH/IG/<slug> or KH/CSPA/<slug>, TGC/B2C/<slug> or TGC/B2B/<slug>, IOM/OGRA/<company key>. The reference is stable and /v1/check?license_number= accepts it, but no regulator issued it: do not present it to a user as the licence number.
The operator holding that licence (match.operator).
On a domain query that resolved a licence: “We do not record when this domain was linked to this licence; this is the licence’s status on that date.” Null otherwise.
/v1/check provenance: the SingleMeta envelope plus when the answer was computed and how fresh the registers behind it are.
object
ISO-8601 timestamp when iGregulator’s scraper last fetched this record.
Reserved: when the regulator last modified the record on its register, as opposed to when we fetched it. Always null today, for every jurisdiction — we do not store an upstream modification time. Kept in the shape so clients need not branch if it is ever populated. For freshness use scraped_at; for when a licence’s status was last read from its source, status_observed_at on the licence.
The regulator page this answer rests on. For a licence — including a /v1/check match — it is the page that published the licence’s current STATUS (status_source_url: an enforcement register, a revoked-licences list, an advisory notice), falling back to the register the licence is listed in when they are the same page. Null when not attributable to a single URL.
authoritative — UKGC: the Commission’s own machine-readable register export (a ZIP). scraped — every other jurisdiction (MGA, CW, KH, AN, TGC, IOM): parsed from the regulator’s HTML/PDF pages; also every operator-search row. derived — a computed answer, not a direct lookup: a fuzzy or no-match /v1/check, with no source row behind it.
Kept for compatibility. On a domain_exact match it is the matched licence’s last_verified_at. On a name match or a miss there is no record behind the answer, and it is just the request time — the same value as checked_at, not a register read. For register freshness read register / stale_jurisdictions.
When this answer was computed (the request time). Always present.
On a match from a register row: the page that published the matched licence’s current status (match.status_source_url, else the register it is listed in). null on a name match or a miss — no record is behind the answer.
Reserved; always null — we store no upstream modification time. Use register.last_read_at and match.status_observed_at for freshness.
How the answer was obtained, not how sure the match is (that is confidence): authoritative — a UKGC licence, read from the Commission’s own register export; scraped — a licence read from another regulator’s pages; derived — a name match or a miss, computed with no source row behind it.
Present when match.jurisdiction is set: that register’s last read and whether it is inside its SLA.
object
Jurisdiction code — UKGC, MGA, CW (Curaçao), KH (Kahnawake), AN (Anjouan), TGC (Tobique) or IOM (Isle of Man). GET /v1/jurisdictions lists them with names and licence types.
The newest last_verified_at among the jurisdiction’s licences — when a load last confirmed its register. Cached up to 10 minutes.
last_read_at is less than sla_hours old. null if never read.
{ "jurisdiction": "UKGC", "last_read_at": "2026-09-30T03:00:26.364Z", "fresh": true, "sla_hours": 24}Present when no licence we hold lists the query — match is null, or a medium/low name match: the covered registers currently past their SLA (often []). Each one weakens a “not found”; say so when you report the miss.
A covered jurisdiction whose latest register read is past its freshness SLA. A domain its regulator listed after last_read_at would not be in our data yet, so each entry weakens a “not found”.
object
Jurisdiction code — UKGC, MGA, CW (Curaçao), KH (Kahnawake), AN (Anjouan), TGC (Tobique) or IOM (Isle of Man). GET /v1/jurisdictions lists them with names and licence types.
{ "query": { "domain": "spinlu.com" }, "verdict": "domain_not_listed", "verdict_detail": "The Anjouan Gaming Authority no longer lists spinlu.com on the licence held by 3-102-947207 SRL (licence ALSI-202602010-FI1), which is itself active — that licence does not cover this site.", "match": { "confidence": "high", "match_type": "domain_exact", "operator": "3-102-947207 SRL", "operator_slug": "3-102-947207-srl", "jurisdiction": "AN", "regulator_name": "Anjouan Gaming Authority", "license_id": "d9832e56-10bb-458b-82af-ac7762f7a502", "license_number": "ALSI-202602010-FI1", "license_reference_is_ours": false, "status": "active", "status_source_url": "https://anjouangaming.com/license-register/", "status_observed_at": "2026-09-30T04:00:10.125Z", "expires_at": "2027-02-15", "domain_association": "direct", "domain_status": "delisted", "matched_domain": "spinlu.com", "domain_last_listed_at": null, "upstream_status": "valid", "status_qualifier": null, "verification_url": null }, "alternatives": [], "confidence": "high", "_meta": { "scraped_at": "2026-09-30T04:00:10.125Z", "source_modified_at": null, "source_url": "https://anjouangaming.com/license-register/", "confidence_hint": "scraped", "checked_at": "2026-09-30T18:38:49.425Z", "register": { "jurisdiction": "AN", "last_read_at": "2026-09-30T04:00:16.351Z", "fresh": true, "sla_hours": 24 } }}Invalid query / parameters.
object
Human-readable error summary.
HTTP-status-level class. Stable enum; branch on details.reason for finer control. Current values: invalid_query, invalid_slug, invalid_license_id, invalid_jurisdiction_code, invalid_pagination, not_found, auth_required, auth_invalid, auth_revoked, payment_required, quota_exceeded, rate_limited, server_error.
object
Machine-readable refinement of the top-level code. Stable vocabulary; branch on this in clients. Examples: invalid_input, missing_required_parameter, conflicting_parameters, operator_not_found, license_not_found, jurisdiction_not_found, route_not_found, api_key_missing, malformed_header, api_key_invalid, api_key_revoked, quota_exceeded, export_requires_pro, export_daily_limit_reached, as_of_not_supported, dataset_not_found, internal_error.
Present only when the error maps to a specific request input field (query param, path param, body key). Omitted for errors that aren’t field-scoped (e.g. rate_limited, auth_revoked).
Optional human-readable / agent-actionable hint describing how to resolve the error.
{ "reason": "api_key_revoked", "suggestion": "Generate a new API key at https://app.igregulator.io/api-keys. Revoked keys cannot be restored."}{ "error": "API key has been revoked", "code": "auth_revoked", "details": { "reason": "api_key_revoked", "suggestion": "Generate a new API key at https://app.igregulator.io/api-keys. Revoked keys cannot be restored." }}Missing / malformed / revoked API key.
object
Human-readable error summary.
HTTP-status-level class. Stable enum; branch on details.reason for finer control. Current values: invalid_query, invalid_slug, invalid_license_id, invalid_jurisdiction_code, invalid_pagination, not_found, auth_required, auth_invalid, auth_revoked, payment_required, quota_exceeded, rate_limited, server_error.
object
Machine-readable refinement of the top-level code. Stable vocabulary; branch on this in clients. Examples: invalid_input, missing_required_parameter, conflicting_parameters, operator_not_found, license_not_found, jurisdiction_not_found, route_not_found, api_key_missing, malformed_header, api_key_invalid, api_key_revoked, quota_exceeded, export_requires_pro, export_daily_limit_reached, as_of_not_supported, dataset_not_found, internal_error.
Present only when the error maps to a specific request input field (query param, path param, body key). Omitted for errors that aren’t field-scoped (e.g. rate_limited, auth_revoked).
Optional human-readable / agent-actionable hint describing how to resolve the error.
{ "reason": "api_key_revoked", "suggestion": "Generate a new API key at https://app.igregulator.io/api-keys. Revoked keys cannot be restored."}{ "error": "API key has been revoked", "code": "auth_revoked", "details": { "reason": "api_key_revoked", "suggestion": "Generate a new API key at https://app.igregulator.io/api-keys. Revoked keys cannot be restored." }}Rate limit reached. Public endpoints: 10 req / IP / hour — a free API key (no card, 10,000 requests / month) from https://app.igregulator.io/signup lifts it. Authenticated: per plan tier; paid tiers are not open yet, so email founder@igregulator.io for a higher limit. Retry after the window surfaced in X-RateLimit-Reset.
object
Human-readable error summary.
HTTP-status-level class. Stable enum; branch on details.reason for finer control. Current values: invalid_query, invalid_slug, invalid_license_id, invalid_jurisdiction_code, invalid_pagination, not_found, auth_required, auth_invalid, auth_revoked, payment_required, quota_exceeded, rate_limited, server_error.
object
Machine-readable refinement of the top-level code. Stable vocabulary; branch on this in clients. Examples: invalid_input, missing_required_parameter, conflicting_parameters, operator_not_found, license_not_found, jurisdiction_not_found, route_not_found, api_key_missing, malformed_header, api_key_invalid, api_key_revoked, quota_exceeded, export_requires_pro, export_daily_limit_reached, as_of_not_supported, dataset_not_found, internal_error.
Present only when the error maps to a specific request input field (query param, path param, body key). Omitted for errors that aren’t field-scoped (e.g. rate_limited, auth_revoked).
Optional human-readable / agent-actionable hint describing how to resolve the error.
{ "reason": "api_key_revoked", "suggestion": "Generate a new API key at https://app.igregulator.io/api-keys. Revoked keys cannot be restored."}{ "error": "API key has been revoked", "code": "auth_revoked", "details": { "reason": "api_key_revoked", "suggestion": "Generate a new API key at https://app.igregulator.io/api-keys. Revoked keys cannot be restored." }}Headers
Section titled “Headers ”Unix epoch seconds.
Unexpected server error.
object
Human-readable error summary.
HTTP-status-level class. Stable enum; branch on details.reason for finer control. Current values: invalid_query, invalid_slug, invalid_license_id, invalid_jurisdiction_code, invalid_pagination, not_found, auth_required, auth_invalid, auth_revoked, payment_required, quota_exceeded, rate_limited, server_error.
object
Machine-readable refinement of the top-level code. Stable vocabulary; branch on this in clients. Examples: invalid_input, missing_required_parameter, conflicting_parameters, operator_not_found, license_not_found, jurisdiction_not_found, route_not_found, api_key_missing, malformed_header, api_key_invalid, api_key_revoked, quota_exceeded, export_requires_pro, export_daily_limit_reached, as_of_not_supported, dataset_not_found, internal_error.
Present only when the error maps to a specific request input field (query param, path param, body key). Omitted for errors that aren’t field-scoped (e.g. rate_limited, auth_revoked).
Optional human-readable / agent-actionable hint describing how to resolve the error.
{ "reason": "api_key_revoked", "suggestion": "Generate a new API key at https://app.igregulator.io/api-keys. Revoked keys cannot be restored."}{ "error": "API key has been revoked", "code": "auth_revoked", "details": { "reason": "api_key_revoked", "suggestion": "Generate a new API key at https://app.igregulator.io/api-keys. Revoked keys cannot be restored." }}