OpenMercantil User API

Authenticated Panel Pro endpoints — segments, lists, notes, tags, exports, audit. Requires session cookie (browser) and X-CSRF-Token header for mutations.

Operations 65

GET /api/v1/user/me Current authenticated user #
GET /api/v1/user/org Get the current organization, seats and visible members #
POST /api/v1/user/org Create an organization #
PUT /api/v1/user/org Rename the current organization #
POST /api/v1/user/org/invites Create or renew an organization invitation #
POST /api/v1/user/org/invites/{id}/resend Rotate and resend an organization invitation #
DELETE /api/v1/user/org/invites/{id} Cancel a pending organization invitation #
PUT /api/v1/user/org/members/{id} Change an organization member role #
DELETE /api/v1/user/org/members/{id} Remove a member from the organization #
POST /api/v1/user/org/leave Leave the current organization #
GET /api/v1/user/persona Current persona config + available list #
POST /api/v1/user/persona Set persona_primary #
GET /api/v1/user/segments List user segments #
POST /api/v1/user/segments Create segment #
GET /api/v1/user/segments/{id} Get segment #
PUT /api/v1/user/segments/{id} Replace mutable segment fields #
PATCH /api/v1/user/segments/{id} Patch mutable segment fields #
DELETE /api/v1/user/segments/{id} Delete segment #
POST /api/v1/user/segments/{id}/pin Toggle pin #
POST /api/v1/user/segments/{id}/run Execute segment filters → companies #
GET /api/v1/user/lists List user lists #
POST /api/v1/user/lists Create list #
GET /api/v1/user/lists/{id} Get list + items #
PUT /api/v1/user/lists/{id} Replace mutable list fields #
PATCH /api/v1/user/lists/{id} Patch mutable list fields #
DELETE /api/v1/user/lists/{id} Delete list and its items #
POST /api/v1/user/lists/{id}/items Add item to list #
DELETE /api/v1/user/lists/{id}/items/{item_id} Remove item from list #
GET /api/v1/user/notes Recent notes #
POST /api/v1/user/notes Create private note #
GET /api/v1/user/notes/{id} Get note #
PUT /api/v1/user/notes/{id} Replace mutable note fields #
PATCH /api/v1/user/notes/{id} Patch mutable note fields #
DELETE /api/v1/user/notes/{id} Delete note #
GET /api/v1/user/notes/for/{type}/{id} Notes for a target #
GET /api/v1/user/tags List user tags with counts #
POST /api/v1/user/tags Create tag #
DELETE /api/v1/user/tags/{id} Delete tag and assignments #
POST /api/v1/user/tags/{id}/assign Assign tag to target #
POST /api/v1/user/tags/{id}/unassign Unassign tag from target #
GET /api/v1/user/exports Export history + monthly usage #
GET /api/v1/user/exports/usage Monthly export quota usage only #
GET /api/v1/user/audit Audit log (MAX/Enterprise only) #
POST /api/v1/persons/lookup Run an authenticated KYC documentary lookup #
GET /api/v1/persons/lookup/usage Get the caller's KYC lookup allowance and usage #
GET /api/v1/persons/lookup/history Get the caller's redacted KYC lookup history #
GET /api/v1/user/api-credentials List API credential metadata #
POST /api/v1/user/api-credentials Create an API credential #
POST /api/v1/user/api-credentials/{id}/rotate Rotate one API credential #
DELETE /api/v1/user/api-credentials/{id} Revoke one API credential #
GET /api/v1/user/webhooks List outbound webhook metadata #
POST /api/v1/user/webhooks Create an outbound webhook #
PATCH /api/v1/user/webhooks/{id} Update an outbound webhook #
DELETE /api/v1/user/webhooks/{id} Delete an outbound webhook #
POST /api/v1/user/webhooks/{id}/rotate Rotate an outbound webhook signing secret #
POST /api/v1/support/ticket/{id}/reply Reply to a support ticket owned by the authenticated user #
GET /api/v1/csrf Get a live same-origin CSRF token #
POST /api/v1/resend-verification Resend the account email-verification link #
POST /api/v1/credits/checkout Create an idempotent credit-pack Checkout session #
POST /api/v1/empresa/{slug}/informe-legal Create the authenticated user's redacted corporate legal report #
POST /api/v1/checkout Create a subscription Checkout session #
GET /api/v1/billing/invoices List the authenticated user's invoices and subscription #
GET /api/v1/billing/portal Redirect to the authenticated user's Stripe portal #
POST /api/v1/billing/portal Create a Stripe portal session as JSON #
POST /api/v1/portal Create a Stripe Customer Portal session through the legacy alias #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/openmercantil-user-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

openmercantil-user-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: OpenMercantil User API
  version: 1.9.3
  summary: Versioned public-read, browser-account, billing, support and provider-callback contracts.
  description: Public JSON API for Spanish company information derived from BORME and other public sources.
  termsOfService: https://openmercantil.es/terminos-de-uso
  contact:
    name: OpenMercantil
    url: https://openmercantil.es/soporte
    email: social@openmercantil.es
  license:
    name: Source-specific upstream terms; see response catalog metadata
    url: https://openmercantil.es/terminos-de-uso
  x-publisher:
    name: OpenMercantil
    url: https://openmercantil.es/
    email: social@openmercantil.es
  x-spatial: http://publications.europa.eu/resource/authority/country/ESP
  x-temporal: 2009-01-01/..
  x-language: es
  x-dcat-catalog: https://openmercantil.es/catalog.rdf
  x-rate-limit:
    free:
      per_min: 60
      per_day: 200
      kind: anonymous-ip
    profesional:
      per_min: 120
      per_day: 5000
      kind: api-key
    max:
      per_min: 600
      per_day: 50000
      kind: api-key
    enterprise:
      per_min: 1200
      per_day: 500000
      kind: contract
  x-methodology: https://openmercantil.es/metodologia
  x-sources: https://openmercantil.es/fuentes
  x-corrections: https://openmercantil.es/correcciones
  x-contract-status: Public read, browser-account and provider-callback surfaces are explicitly separated in this contract. Operator/admin routes are excluded. The public MCP consumes only the allowlisted GET read plane.
  x-account-segment-contract:
    projection: company_public_v2 immutable corporate sidecar
    synchronous_row_cap: 500
    bounded_count_cap: 50001
    count_semantics: The segment run response count is the number of rows returned, never a global total. Dataset preview uses total_is_lower_bound=true and total_lower_bound when the bounded count reaches 50001.
    related_web_dataset_surface:
      preview_path: /mi-cuenta/datasets/preview
      export_path: /mi-cuenta/datasets/export.csv
      synchronous_export_max_rows: 500
      overflow_status: 503
      overflow_error: async_export_required
  x-company-identity-contract:
    version: '1.0'
    projection: company_public_v2 immutable generation-bound corporate sidecar
    applies_to: Every /api/v1/company/{slug}*, /api/v1/empresa/{slug}* and /api/v1/grafo/{slug} read before any report, cache, graph or dataset lookup. /api/v1/companies/compare resolves both requested subjects in one bounded company_public_v2 batch before either row is exposed; MCP company tools inherit these preflights through REST.
    resolution:
      published: canonical corporate slug admitted
      safe_alias: internally canonicalized and Content-Location emitted
      withheld: neutral 404; includes absent, personal and ambiguous/quarantined identities
      unavailable: 503 with no-store; clients must not infer absence
    search: Exact corporate CIF, exact canonical/safe-alias slug, or bounded name_prefix2 pool scored in application code. DNI/NIE and ambiguous CIFs return zero items.
    public_company_count: company_public_projection_state.row_count
servers:
- url: https://openmercantil.es
  description: Production
tags:


# --- truncated at 32 KB (129 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/openmercantil/refs/heads/main/openapi/openmercantil-user-api-openapi.yml