# Aclid > Aclid is a biosecurity and biosafety compliance automation platform for the synthetic biology supply chain. Gene synthesis providers, biofoundries and research institutions use it to screen DNA/RNA orders for pathogenic, toxic and export-controlled sequence elements, verify the customers placing those orders against sanctions and watchlists, and document the compliance review the US Framework for Nucleic Acid Synthesis Screening expects. Delivered as a hosted dashboard plus a public REST API at api.aclid.bio. This file was GENERATED by API Evangelist from Aclid's own published API contract and public site. Aclid does not publish an llms.txt of its own (https://www.aclid.bio/llms.txt returned 404 on 2026-09-06). ## APIs - [Aclid API](https://api.aclid.bio/docs): REST API, base https://api.aclid.bio, 18 operations under /v2/. Initiate a sequence screen from FASTA, FASTQ, CSV or inline JSON; retrieve screen summaries, full findings and a pre-signed stream URL for large results; create and retrieve customers (which also runs a sanctions and watchlist screen); attach notes with a decision status; mint hosted or embedded customer verification URLs. - [OpenAPI 3.1.0](https://api.aclid.bio/openapi.json): The live machine-readable contract, info.version 2.2.1. ## Authentication - Method: API key sent as the RAW value of the HTTP `Authorization` header — no `Bearer` prefix. - Keys are issued from your profile in the [Aclid Dashboard](https://dash.aclid.bio). - The key itself selects live mode or test mode. Aclid publishes no key prefix, so keys are not distinguishable by inspection. - HTTPS only. Unauthenticated calls return HTTP 403. - CAVEAT for code generators: the published OpenAPI declares no `securitySchemes` and no `security[]` requirement, so a client generated from the spec alone will send unauthenticated requests. ## Conventions - Idempotency: PARTIAL. `idempotence_key` is a request-BODY field (max 60 chars, UUID example) on the five screen-initiation operations only. Within 24 hours a repeat key is not re-assessed and the request is redirected with HTTP 303 to the original screen summary. Creating a customer, creating/updating a note and minting a verification URL have NO replay protection. - Pagination: cursor-based. `cursor` plus `limit` (10..100) on List Screens and List Customers; List Customers also takes `page_index`. The response field carrying the next cursor is not documented. - Async: screens accept an `asynchronous` flag; poll `ScreenStatus` (pending_upload, queued, running, succeeded, failed, deleted, archived). There are no webhooks and no event stream. - Errors: not RFC 9457. Validation failures return a FastAPI `HTTPValidationError` (`detail[]` of loc/msg/type). The edge returns a JSON body with `request_id` on 403. - Rate limits: none documented. No 429, no `RateLimit-*` headers, no `Retry-After`. - Size limits: max 1,000,000,000 total base pairs per screen; FASTA sequences at least 30 bp. - Reversibility: GET and POST only. No delete, cancel or archive operation exists on the public API. The one reversal path is re-posting a note with the same `note_id` to change its `decision_status`; Aclid states no window for it. ## Compliance frameworks screened Findings come back as a map keyed by framework id, each carrying a reason code: - `us_ccl_export_control` — US Commerce Control List (BIS) - `eu_dual_use_export_control` — EU Regulation (EU) 2021/821 - `us_select_agent` — US Federal Select Agent Program - `us_screening_framework` — US Framework for Nucleic Acid Synthesis Screening - `nih_recombinant_dna_guidelines` — NIH Guidelines, Risk Groups 1-4 - `eu_directive_2000_54_ec` — EU Directive 2000/54/EC, Risk Groups 1-4 - `zkbs_oncogenes` — ZKBS oncogene evaluations - `usda_vs` — USDA APHIS Veterinary Services regulated pathogens 36 reason codes in total, plus three common exemption codes (`housekeeping`, `unspecific`, `match_window_below_threshold`). ## Embedded components - [verify.aclid.bio/widget.js](https://verify.aclid.bio/widget.js): drop-in customer verification widget. `Aclid.showEmbeddedVerification({ verificationUrl, onSuccess })`. Requires your site to be allow-listed by the Aclid team. - Hosted verification flow at https://verify.aclid.bio with optional `redirect_url`. - ORCID linking is offered inside the verification flow to expedite researcher review. ## Docs - [API reference (ReDoc)](https://api.aclid.bio/docs) - [Aclid Dashboard](https://dash.aclid.bio) - [Status page](https://status.aclid.bio) — per-component: Dashboard, API, Compliance Verification, Marketing Site - [Guide to the screening certification process](https://www.aclid.bio/resources/guide-to-the-screening-certification-process) - [Resources](https://www.aclid.bio/resources) - [Contact / sales](https://www.aclid.bio/contact) - [Terms of Service](https://www.aclid.bio/terms-of-service) - [Privacy Policy](https://www.aclid.bio/privacy-policy) ## Not published by Aclid Recorded so an agent does not go looking: no SDKs or client libraries in any registry, no CLI, no pricing page (sales-gated), no changelog, no SLA, no MCP server, no A2A agent card, no AsyncAPI, no webhooks, no trust centre and no published security certifications. The `/.well-known/security.txt` served on dash.aclid.bio and verify.aclid.bio is expired (Expires 2026-04-07). ## API Evangelist profile - [apis.yml](https://raw.githubusercontent.com/api-evangelist/aclid/refs/heads/main/apis.yml) - [OpenAPI (harvested)](https://raw.githubusercontent.com/api-evangelist/aclid/refs/heads/main/openapi/aclid-openapi.yml) - [Compliance reason codes](https://raw.githubusercontent.com/api-evangelist/aclid/refs/heads/main/errors/aclid-compliance-reason-codes.yml) - [Conventions](https://raw.githubusercontent.com/api-evangelist/aclid/refs/heads/main/conventions/aclid-conventions.yml)