# Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) > ATF is a law enforcement agency in the United States Department of Justice. It publishes three > machine-readable surfaces: a read-only JSON API over Title 27 CFR regulation text, two public > ArcGIS feature services (Federal Firearms Licensee premises and ATF office locations), and a > DCAT-US 1.1 open-data catalog. All of it is anonymous, free and read-only. ATF publishes no > OpenAPI, no SDK, no MCP server and no developer portal. Generated by API Evangelist on 2026-09-05 from live probes. ATF does not publish an llms.txt (https://www.atf.gov/llms.txt returns 404). This file is ours, not theirs. ## Start here - [ATF eRegulations API — version index](https://regulations.atf.gov/api/regulation): the entry point. Returns every CFR part and effective version the platform holds. No key required. - [Modeled OpenAPI 3.1 description](https://github.com/api-evangelist/bureau-of-alcohol-tobacco-firearms-and-explosives-atf-/blob/main/openapi/bureau-of-alcohol-tobacco-firearms-and-explosives-atf--eregulations-openapi.yml): seven operations, modeled by API Evangelist from live probes. ATF authored no contract. - [ATF open-data catalog (DCAT-US 1.1)](https://opendata-atf-geoplatform.hub.arcgis.com/data.json): the one machine-readable discovery document ATF actually serves. ## Regulation text and rulemaking (regulations.atf.gov) - [GET /api/regulation](https://regulations.atf.gov/api/regulation): all parts and versions. - [GET /api/regulation/{part}](https://regulations.atf.gov/api/regulation/478): versions of one part. - [GET /api/regulation/{part}/{version}](https://regulations.atf.gov/api/regulation/478/2026-01141): the full nested text tree for that effective version. - [GET /api/search?q=](https://regulations.atf.gov/api/search?q=firearm): full-text search. `q` is required; `regulation`, `version` and `page` narrow it. - [GET /api/notice](https://regulations.atf.gov/api/notice): Federal Register notices amending the parts. - [GET /api/notice/{documentNumber}](https://regulations.atf.gov/api/notice/2026-01141): one notice with its verbatim amendment instructions and authority citation. - [GET /api/diff/{part}/{older}/{newer}](https://regulations.atf.gov/api/diff/478/2025-04872/2026-01141): structural diff between two versions. Parts carried: 447 (Importation of Arms, Ammunition and Implements of War), 478 (Commerce in Firearms and Ammunition), 479 (Machine Guns, Destructive Devices, and Certain Other Firearms), 555 (Commerce in Explosives), 646 (Contraband Cigarettes), 771 (Rules of Practice in Explosive License and Permit Proceedings). ## Geospatial data (ArcGIS, ATF org PrP5ZtrES07DmVmv) - [Federal Firearm Licensees locations](https://services6.arcgis.com/PrP5ZtrES07DmVmv/arcgis/rest/services/Federal_Firearm_Licensees_locations/FeatureServer/0): 77,514 geocoded FFL premises, 90 attribute fields, query-only, maxRecordCount 2000. - [ATF Office Locations](https://services6.arcgis.com/PrP5ZtrES07DmVmv/arcgis/rest/services/ATF_Office_Locations/FeatureServer/0): 537 offices and field divisions, 9 fields, query and extract. - [ATF open data site](https://opendata-atf-geoplatform.hub.arcgis.com/): CSV, GeoJSON, KML, Shapefile, GeoPackage and Excel downloads of the same layers. ## Human documentation - [ATF website](https://www.atf.gov/) - [Data and statistics](https://www.atf.gov/resource-center/data-statistics) - [Firearms trace data reports](https://www.atf.gov/resource-center/data-statistics/firearms-trace-data-reports) - [Listing of Federal Firearms Licensees](https://www.atf.gov/firearms/listing-federal-firearms-licensees) - [eRegulations](https://regulations.atf.gov/) - [Publications](https://www.atf.gov/resource-center/publications) - [Privacy policy](https://www.atf.gov/privacy-policy) - [ATF on GitHub](https://github.com/atfweb) — Drupal theme and eRegulations server components only, no SDK. ## Things an agent must know before calling - **Check Content-Type, not the status code.** An unknown CFR part or notice id returns HTTP 200 with an HTML web page, not a 404. `/api/regulation/999` and `/api/notice/does-not-exist` both do this. Parse a response only when Content-Type is `application/json`. - **ArcGIS returns errors inside 200 responses** as `{"error":{"code":...}}`. Inspect the body. - **No authentication, no signup, no key.** There is nothing to obtain and nothing to rotate. - **Read-only.** No write operation exists on any surface, so idempotency, dry-run and reversibility are all not applicable rather than missing. - **No rate limits are published and no rate-limit headers are returned.** The one real ceiling is the ArcGIS `maxRecordCount` of 2000 per query — 39 pages to walk the FFL layer. - **No status page, no SLA, no deprecation policy, no changelog.** Outages and breaking changes are unannounced. `/api/notice` tells you when the REGULATION changed, never when the API changed. - **Freshness is uneven.** 27 CFR 478 is current to 2026-01-22; 27 CFR 646 has not been reloaded since 2014-08-11. Do not assume every part is equally current. - **FFL records are business and, for home-based licensees, residential addresses.** Lawfully published by ATF, but treat bulk export as a disclosure decision, not a technical one. ## Surfaces that are NOT public APIs - [eForms](https://eforms.atf.gov/): licensee filing behind a Login.gov account. Web app, no API. - eTrace / National Tracing Center: restricted to credentialed law-enforcement agencies. - [FFL eZ Check](https://fflezcheck.atf.gov/): interactive licence verification, no documented API. - Firearms trace data reports: published as PDF and spreadsheet documents only. No API. ## Machine-readable artifacts in this repository - openapi/ — modeled OpenAPI 3.1 for the eRegulations API (method: generated). - geoservices/ — the two ArcGIS service and layer descriptors, saved verbatim. - data-portal/ — the DCAT-US 1.1 catalog, saved verbatim. - json-schema/ — attribute schemas derived from the ArcGIS field definitions. - data-model/, conventions/, errors/, lifecycle/, authentication/, conformance/, rate-limits/, plans/, packages/, mcp/, well-known/, security/ — the derived and probed profile.