# BizAPI — NAICS Association Business Intelligence API > Real-time business-to-business data append API from the NAICS Association. Submit a partial > business record — a company name and address, a phone number, a website, or a DUNS number — > and BizAPI matches it against the Dun & Bradstreet business database of 220+ million US and > international business locations, returning NAICS and SIC classification codes, address and > contact data, employee and sales figures, and the full corporate family tree. One POST > operation plus a credit-free sandbox twin. HTTP Basic auth, prepaid match credits, 3 requests > per rolling second. Generated by API Evangelist on 2026-08-14 from the provider's published documentation. The provider does not serve an llms.txt of its own (https://www.naics.com/llms.txt returns 404). ## What it does - Input: any one of six match keys. DUNS number; company name + full address + phone (Standard); company name + state (Loose); website URL (US only); company name + country (Name); phone number. - Output: a three-block JSON envelope — `Search Terms` (echo of your input), `Matching Data` (match quality + remaining credits), `Appended Data` (the matched firmographic record). - Read-only. No writes, no collections, no pagination, no webhooks, no events. ## Endpoints - Live search (billable): POST https://www.naics.com/wp-json/naicsapi/v2/cosearch - Sandbox search (free): POST https://www.naics.com/wp-json/naicsapi/v2/cosearchtest - Legacy live search: POST https://www.naics.com/wp-json/naicsapi/v1/cosearch - Legacy sandbox: POST https://www.naics.com/wp-json/naicsapi/v1/cosearchtest - Route index (anonymous): https://www.naics.com/wp-json/naicsapi/v2 The provider labels v1 "Legacy API Solution" and recommends v2. Both are live and separately monitored. ## Things an agent must know before calling - **A miss is a 200, not a 404.** No match returns HTTP 200 with `"Appended Data": {"Message": "No match found"}`. Check that field, not the status code. - **Every successful match is billable and there is no idempotency key.** A retry is a duplicate charge against a prepaid credit balance. Use /cosearchtest for anything exploratory. - **DUNS, URL and Phone matches must be sent ALONE.** "If any other fields are submitted with DUNS, URL, or Phone Match, then these match methods will not trigger." - **Throughput is 3 requests per rolling second** and there is no `Retry-After` or `RateLimit-*` header. Pace client-side. Exceeding it returns 429 with "Too many requests. Please limit your requests to 3 per second". - **Credits are only visible in a 200 body**, at `Matching Data."Matches Remaining"`. At zero the API returns 403. There is no quota endpoint. - **Response fields depend on the account's Record Layout** (NA, TA, EA, SA, PA, PL), fixed at credential activation and echoed as `Matching Data.Layout`. The same call returns different fields for different accounts. - **Branch locations return blank size figures.** Year Started, Total Employees and Annual Sales are only reported at the headquarters. Check `Location Type` first. - **Low-confidence matches are withheld, not flagged.** Confidence 6 or lower returns nothing. - **The password contains significant spaces.** Do not trim it before base64 encoding. - **BEMFAB carries suppression semantics.** `D` means the record was de-listed at the customer's request — industry coding only, no marketing. ## Sandbox Same credentials as live, different path. The fixture company is Westrock Mwv, LLC — `{"duns": "10-223-5004"}`, `{"url": "www.westrock.com"}`, `{"phone": "8044441000"}`, or the full Standard body at 501 S 5TH St, Richmond, VA 23219, US. To force a failure, put the string "bad" in any input field. Browser console (credentials required): https://www.naics.com/naics-api-test-V2/ ## Authentication HTTP Basic. `Authorization: Basic base64(username:password)`. Credentials are issued manually by NAICS Association at account activation — there is no self-serve key console, no OAuth, no scopes, no rotation or revocation endpoint. Request access at https://www.naics.com/bizapi-details/. ## Errors - 400 — "No valid search terms submitted. Must have at least one of companyName, duns, url, or phone." - 400 — "Missing field: layout" (account misconfiguration; contact the provider) - 401 — "Credentials are Missing or Invalid." - 403 — "Request not submitted due to lack of searches." (credits exhausted) - 429 — "Too many requests. Please limit your requests to 3 per second" - 500 — Internal Server Error Not RFC 9457. Bespoke JSON, no machine-readable error code field. ## Pricing No published plans, no free tier, no self-serve checkout. Quote-based, charged per successfully matched listing, with each Record Layout its own unpublished price tier. The public data-append pricing page publishes two worked examples: 5,000 records at $500 setup + $200/thousand = $1,350; 25,000 records at $1,000 setup + $160/thousand = $4,400. ## Provider docs - Product page: https://www.naics.com/business-intelligence-api/ - Documentation hub: https://www.naics.com/business-intelligence-api/bizapi-documents/ - V2 manual (PDF, v2.0.0.1, 2021-09-01): https://www.naics.com/wp-content/uploads/2021/09/BizAPI-V2-Documentation.pdf - V1 manual (PDF, v3.0.1.1, 2020-08-12): https://www.naics.com/wp-content/uploads/2018/05/BizAPI-Documentation.pdf - Data dictionary (xlsx): https://www.naics.com/wp-content/uploads/2020/07/BizAPI-Data-Dictionary.xlsx - Postman collection (zip): https://www.naics.com/wp-content/uploads/2021/09/NAICS-BizAPI-V2-Examples.postman_collection.json_.zip - Test console: https://www.naics.com/naics-api-test-V2/ - Request access: https://www.naics.com/bizapi-details/ - Pricing: https://www.naics.com/data-layouts-pricing/ - Status: https://status.naics.com/ - Blog: https://www.naics.com/the-business-data-blog/ - Support: APICloudSolutions@NAICS.com · 973-625-5626 ## API Evangelist artifacts - OpenAPI: openapi/bizapi-company-search-api-openapi.yml (authored by API Evangelist; see the overlay for known divergences from the provider's published contract) - Overlay: overlays/bizapi-company-search-api-overlay.yaml - Conventions: conventions/bizapi-conventions.yml - Errors: errors/bizapi-problem-types.yml - Sandbox: sandbox/bizapi-sandbox.yml - Authentication: authentication/bizapi-authentication.yml - Rate limits: rate-limits/bizapi-rate-limits.yml - Plans: plans/bizapi-plans-pricing.yml - Lifecycle: lifecycle/bizapi-lifecycle.yml - Changelog: changelog/bizapi-changelog.yml - Data model: data-model/bizapi-data-model.yml - Conformance: conformance/bizapi-conformance.yml - Well-known probe: well-known/bizapi-well-known.yml - Packages: packages/bizapi-packages.yml - MCP (candidate, no server exists): mcp/bizapi-mcp.yml - Agent skills: skills/_index.yml ## Not available No OpenAPI published by the provider. No GraphQL. No MCP server. No A2A agent card. No /.well-known/ surface of any kind. No SDKs in any package registry. No CLI. No webhooks or events. No dated changelog. No terms of service page. No published SLA. No security.txt, bug bounty or trust center.