# Bloomberg Data > Bloomberg's enterprise market-data surface: the Data License / Hypermedia (HAPI) REST API on > api.bloomberg.com, and B-PIPE real-time streaming market data over the BLPAPI protocol. Both are > contracted enterprise products — there is no self-service signup, no public API key, and no public > machine-readable contract. This file is generated by API Evangelist from the public artifacts in > this repository; it is not published by Bloomberg. ## What an agent can and cannot do here - There is **no public OpenAPI, GraphQL schema, AsyncAPI document, MCP server or A2A agent card** for this surface. Every discovery path was probed on 2026-08-27 and missed. - The API host **is** an RFC 9728 OAuth protected resource and its authorization server is published, so an agent holding contracted client credentials can discover exactly where to get a token. - Data-plane authority is **contractual, not scoped**: the OAuth scopes Bloomberg publishes are identity scopes only. An agent cannot read its own data entitlements from its token. ## APIs - [Bloomberg Data License API](https://www.bloomberg.com/professional/support/api-library/): Reference, pricing, regulatory, ESG, fundamentals, estimates and historical content, delivered request/response and by subscription. Base: https://api.bloomberg.com/eap/ (JWT bearer required; unauthenticated calls return HTTP 401 "No definition of jwt found in header or query string"). - [Bloomberg B-PIPE API](https://www.bloomberg.com/professional/products/data/enterprise-catalog/real-time-data-feed/): Real-time streaming quotes, trades and market depth. **Not HTTP** — consumed through the BLPAPI SDK over a TCP session (default port 8194) against a customer-provisioned B-PIPE appliance or Server API host. ## Authentication - Protected resource metadata: https://api.bloomberg.com/.well-known/oauth-protected-resource - Authorization server: https://bsso.blpprofessional.com - Authorization server metadata: https://bsso.blpprofessional.com/.well-known/oauth-authorization-server - Token endpoint: https://bsso.blpprofessional.com/as/token.oauth2 - Client registration: https://bsso.blpprofessional.com/as/clients.oauth2 - Supported client auth: client_secret_basic, client_secret_post, client_secret_jwt, private_key_jwt, tls_client_auth - PKCE (S256), Pushed Authorization Requests, Token Exchange, Device Code and CIBA are all advertised. ## Client libraries - Python `blpapi` 3.26.7.1 (2026-08-12) — Bloomberg's own index only, **not on PyPI**: `python -m pip install --index-url=https://blpapi.bloomberg.com/repository/releases/python/simple/ blpapi` - C++ / Java / .NET BLPAPI SDK 3.26.7 — vendor download from https://www.bloomberg.com/professional/support/api-library/ - Node.js `blpapi` 1.2.0 (2015-03-19) — https://github.com/bloomberg/blpapi-node (unmaintained relative to the 3.26.x line) - SDK reference documentation: https://bloomberg.github.io/blpapi-docs/ ## Product and commercial - Data License product page: https://professional.bloomberg.com/products/data/data-license/ - Data catalog portal (login required): https://data.bloomberg.com/ - Enterprise Console (customer only): https://console.blpprofessional.com/ - Pricing: not published. Enterprise contract only; access begins with a sales conversation. - Terms of service: https://www.bloomberg.com/notices/tos/ - Privacy policy: https://www.bloomberg.com/privacy/ ## Security - security.txt: https://www.bloomberg.com/.well-known/security.txt - Vulnerability reports: mailto:reportvuln@bloomberg.net - Disclosure policy: https://www.bloomberg.com/responsible-disclosure ## Machine-readable artifacts in this profile - well-known/bloomberg-data-well-known.yml — every /.well-known probe and its status - authentication/bloomberg-data-authentication.yml — the OAuth/JWT profile - scopes/bloomberg-data-scopes.yml — published scopes (identity only) - conformance/bloomberg-data-conformance.yml — standards evidenced from discovery documents - packages/bloomberg-data-packages.yml — first-party SDKs with versions and dates - lifecycle/bloomberg-data-lifecycle.yml — versioning, deprecation, status posture - conventions/bloomberg-data-conventions.yml — error envelope, tracing, reversibility - plans/bloomberg-data-plans-pricing.yml — records that no plans are published - rate-limits/bloomberg-data-rate-limits.yml — records that no limits are published