Too Good To Go

Too Good To Go is a Danish certified B Corporation, founded in Copenhagen in 2015, that operates the world's largest marketplace for surplus food. Consumers use its mobile app to buy discounted "Surprise Bags" of unsold food from bakeries, restaurants, supermarkets and hotels near closing time, and partner businesses list that surplus through the MyStore partner portal at store.toogoodtogo.com. Alongside the consumer marketplace the company sells Too Good To Go Platform, a modular AI-assisted surplus-management product for grocery retailers that tracks near-expiry inventory, sets automated markdowns, routes unsold stock to charity and pushes the remainder onto the marketplace. It also runs the Look-Smell-Taste date-label campaign and Too Good To Go Parcels. Too Good To Go publishes no public API, developer portal, or machine-readable contract: its developer subdomain answers 401 behind a JumpCloud SSO login, and the live backends at api.toogoodtogo.com and apptoogoodtogo.com serve only the mobile app and the partner portal.

Too Good To Go is profiled on the APIs.io network. Tagged areas include Company, Food Waste, Surplus Food, Marketplace, and Sustainability.

17.2/100 emerging ▬ flat Agent 5/100 agent aware Full breakdown ↓
scored 2026-09-02 · rubric v0.18.0
0 APIs
CompanyFood WasteSurplus FoodMarketplaceSustainabilityGrocery RetailConsumer AppClimate TechB CorporationDenmark

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-02 · rubric v0.18.0
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/too-good-to-go: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Too Good To Go Rate Limits

0 limits

RATE LIMITS

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Too Good To Go Domain Security

TLSv1.3 · DMARC

SECURITY

Too Good To Go Vulnerability Disclosure

Hackerone · contact published

SECURITY

Too Good To Go Trust Center

SOC 2 Type 2, PCI DSS v4.0.1

SECURITY

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 4

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 6

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: too-good-to-go
name: Too Good To Go
description: 'Too Good To Go is a Danish certified B Corporation, founded in Copenhagen in 2015, that operates the world''s
  largest marketplace for surplus food. Consumers use its mobile app to buy discounted "Surprise Bags" of unsold food from
  bakeries, restaurants, supermarkets and hotels near closing time, and partner businesses list that surplus through the MyStore
  partner portal at store.toogoodtogo.com. Alongside the consumer marketplace the company sells Too Good To Go Platform, a
  modular AI-assisted surplus-management product for grocery retailers that tracks near-expiry inventory, sets automated markdowns,
  routes unsold stock to charity and pushes the remainder onto the marketplace. It also runs the Look-Smell-Taste date-label
  campaign and Too Good To Go Parcels. Too Good To Go publishes no public API, developer portal, or machine-readable contract:
  its developer subdomain answers 401 behind a JumpCloud SSO login, and the live backends at api.toogoodtogo.com and apptoogoodtogo.com
  serve only the mobile app and the partner portal.'
url: https://raw.githubusercontent.com/api-evangelist/too-good-to-go/refs/heads/main/apis.yml
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source:
  - rate-limits
  - security
  generated: '2026-09-02'
  method: derived
image: https://store.toogoodtogo.com/apple-touch-icon.png
x-type: company
x-source: harvest:secondary-market
x-secondary-market-listing: https://www.hiive.com/securities/too-good-to-go-stock
x-tier: profiled
x-tier-reason: enrichment
specificationVersion: '0.20'
created: '2026-08-30'
modified: '2026-08-30'
tags:
- Company
- Food Waste
- Surplus Food
- Marketplace
- Sustainability
- Grocery Retail
- Consumer App
- Climate Tech
- B Corporation
- Denmark
apis: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://www.toogoodtogo.com/en-us
  name: Too Good To Go
- type: Login
  url: https://store.toogoodtogo.com/
  name: MyStore partner portal login
- type: StatusPage
  url: https://status.toogoodtogo.com/
  name: Too Good To Go status page
- type: TrustCenter
  url: security/too-good-to-go-trust-center.yml
  name: Trust center — SOC 2 Type 2, PCI DSS v4.0.1
- type: Compliance
  url: security/too-good-to-go-trust-center.yml
  name: Published certifications (SOC 2 Type 2, PCI DSS v4.0.1)
- type: Security
  url: security/too-good-to-go-vulnerability-disclosure.yml
  name: Security vulnerability disclosure
- type: VulnerabilityDisclosure
  url: security/too-good-to-go-vulnerability-disclosure.yml
  name: Vulnerability disclosure profile
- type: DomainSecurity
  url: security/too-good-to-go-domain-security.yml
  name: Domain security posture
- type: TermsOfService
  url: https://www.toogoodtogo.com/en-gb/terms-and-conditions-using-the-app
  name: Terms and conditions for using the app
- type: PrivacyPolicy
  url: https://www.toogoodtogo.com/en-us/privacy-policy
  name: Privacy policy
- type: WellKnown
  url: well-known/too-good-to-go-well-known.yml
  name: Well-known document probe
- type: SecurityTxt
  url: well-known/too-good-to-go-security.txt
  name: security.txt (RFC 9116)
- type: Lifecycle
  url: lifecycle/too-good-to-go-lifecycle.yml
  name: Lifecycle and operational posture
- type: Conformance
  url: conformance/too-good-to-go-conformance.yml
  name: Standards conformance
- type: ErrorCatalog
  url: errors/too-good-to-go-problem-types.yml
  name: Observed error envelopes
- type: Conventions
  url: conventions/too-good-to-go-conventions.yml
  name: API conventions and reversibility
- type: Packages
  url: packages/too-good-to-go-packages.yml
  name: Client packages (no first-party SDK)
- type: Plans
  url: plans/too-good-to-go-plans-pricing.yml
  name: Plans and pricing
- type: RateLimits
  url: rate-limits/too-good-to-go-rate-limits.yml
  name: Rate limits
- type: LLMsTxt
  url: llms/too-good-to-go-llms.txt
  name: llms.txt
x-enrichment:
  date: '2026-08-30'
  status: minimal
  artifacts_added: 14
  pass: local-v1
x-coverage:
  state: gated
  reason: partner-login
  detail: Too Good To Go runs a developer subdomain at developers.toogoodtogo.com, but it answers 401 with a "Login with JumpCloud"
    SSO interstitial, and its two live backends (api.toogoodtogo.com and apptoogoodtogo.com) return RFC 9457 404s on all 13
    OpenAPI, Swagger and GraphQL discovery paths — the only machine surface is the private mobile-app and MyStore partner
    backend, fronted by DataDome.
  evidence:
  - url: https://developers.toogoodtogo.com/
    status: 401
  - url: https://api.toogoodtogo.com/openapi.json
    status: 404
  - url: https://apptoogoodtogo.com/api/auth/v5/authByEmail
    status: 403
  - url: https://www.toogoodtogo.com/en-us
    status: 429
  - url: https://www.toogoodtogo.com/.well-known/security.txt
    status: 200
  checked: '2026-08-30'

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/too-good-to-go"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/too-good-to-go/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/too-good-to-go/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.