# CB Insights > Private-market intelligence on 12M+ private and public companies, investors, funding deals, cap > tables, exits, business relationships, management teams and proprietary predictive scores. > Operated by CB Information Services, Inc. (New York). Programmatic access is credit-metered and > credential-gated — clientId/clientSecret are issued by CB Insights, exchanged for a 24-hour bearer > token, and every data call debits an account credit ledger. Generated by API Evangelist from the CB Insights public developer surface on 2026-08-09. CB Insights does not publish an llms.txt of its own (404 on www.cbinsights.com/llms.txt and api-docs.cbinsights.com/llms.txt; 403 on docs.cbinsights.com/llms.txt). ## Start here - [Developer Portal](https://api-docs.cbinsights.com/portal): entry point for the current v2 API. - [Quick Start](https://api-docs.cbinsights.com/portal/docs/quick-start): register, authenticate, first call. - [API Reference (v2, Redoc)](https://api-docs.cbinsights.com/portal/docs/api/): the rendered contract. - [OpenAPI/Swagger 2.0 contract](https://api-docs.cbinsights.com/v2/cbinsights_api_v2.json): the machine-readable spec — 28 operations, 115 definitions. - [Sign up for trial API access](https://api-docs.cbinsights.com/portal/signup): 25 companies, 5 scouting reports, 5 ChatCBI messages. - [API Terms of Use](https://api-docs.cbinsights.com/portal/api-terms-of-use). ## Authentication - [Authentication](https://api-docs.cbinsights.com/portal/docs/CBI-API/cbi-authentication): POST clientId/clientSecret to `https://api.cbinsights.com/v2/authorize`, receive `{"token": "..."}`, send it as `Authorization: Bearer ` on every call. Valid 24 hours. No refresh token — re-authorize on expiry. - Credentials are not self-issued: trial credentials come from the portal sign-up, production credentials from a CB Insights representative. - Enterprise identity: SAML 2.0 SSO (SP-initiated only) and SCIM user provisioning — https://docs.cbinsights.com/docs/sso/index.html and https://docs.cbinsights.com/docs/scim/index.html ## The v2 API (current) Base URL `https://api.cbinsights.com`. Every operation is a POST whose JSON body carries the filter set; results are cursor-paginated with `nextPageToken` / `totalHits` / `totalHitsRelation`. The contract declares no operationIds — operations are addressable only by method and path. Resolve first, then fan out. `POST /v2/organizations` never charges credits and exists so you can match your own records to CB Insights `orgId`s before spending anything. - Organizations: `POST /v2/organizations` (lookup by name/url/profileUrl, free) - Firmographics: `POST /v2/firmographics` (full company profiles: taxonomy, identifiers, financials, headcount, competitors, business models, expert collections, parents/subsidiaries) - Financial transactions: `POST /v2/financialtransactions/fundings|investments|portfolioexits` and the per-organization variants under `/v2/organizations/{orgId}/financialtransactions/...` - Business relationships: `POST /v2/businessrelationships`, `POST /v2/organizations/{orgId}/businessrelationships` - Management and board: `POST /v2/managementandboard`, `POST /v2/organizations/{orgId}/managementandboard` - Outlook (Mosaic Score, Commercial Maturity, Exit Probability): `POST /v2/outlook`, `POST /v2/organizations/{orgId}/outlook`, plus `/mosaichistory`, `/commercialmaturityhistory`, `/exitprobabilityhistory`, `/fundingwindow` - Revenue: `POST /v2/revenuebyyear`, `POST /v2/organizations/{orgId}/revenuebyyear` - Scouting reports (AI-generated): `POST /v2/organizations/{orgId}/scoutingreport` and `/scoutingreportstream` - Strategy map: `POST /v2/organizations/{orgId}/strategymap` - ChatCBI research LLM: `POST /v2/chatcbi`, `POST /v2/chatcbichunked`, `POST /v2/cbirag` ## The v1 API (older, still documented) Base URL `https://api.cbinsights.com`, all GET, JWT from `GET /v1/authorize?clientId=&clientSecret=`. Last release v1.9.0 on 2024-07-26; no OpenAPI is published for it. - [v1 reference](https://api-docs.cbinsights.com/docs/endpoints/): organizations, deals, people, business relationships, collections, credits. - [v1 change log](https://api-docs.cbinsights.com/docs/change_log/): ten dated releases from 2020-12-30. - [Error codes](https://api-docs.cbinsights.com/docs/reference/error_codes/) - [Rate limiting](https://api-docs.cbinsights.com/docs/reference/rate_limiting/) - [Credit model](https://api-docs.cbinsights.com/docs/reference/credit_model/) ## Agent surfaces - [MCP Server](https://api-docs.cbinsights.com/portal/docs/Integrations/cbi-mcp-server): hosted at `https://mcp.cbinsights.com/`, OAuth 2.1 with dynamic client registration and PKCE. Connect from Claude, ChatGPT, Perplexity and Microsoft Copilot (Chat, Researcher, Excel) via each client's connector directory. `tools/list` requires a token, so the tool set is not publicly enumerable. - [Snowflake Marketplace](https://api-docs.cbinsights.com/portal/docs/Integrations/snowflake): structured data with Semantic Views (SQL or Cortex Analyst); research reports as a Cortex Knowledge Extension. - Microsoft 365 Copilot connector and Salesforce CRM integration: https://www.cbinsights.com/mcp-gallery ## Limits and metering - Rate limit: 100 requests per rolling one-second window across all endpoints. Headers `ratelimit-limit`, `ratelimit-remaining`, `ratelimit-reset`. Exceeding returns 429. - Credits: every data call debits the account ledger; the per-call cost is returned in `x-cbinsights-credits-call-consumed`. Exhaustion returns **424 Failed Dependency** — do not retry, top up. - Deep paging: `totalHitsRelation` becomes `gte` past 10,000 results. - No idempotency key is documented, and retries are billable. De-duplicate client-side. ## Reference vocabularies Almost every filter is an integer id resolved against a published list. HTML tables only — no CSV/JSON. - [Taxonomy: sector / industry / sub-industry](https://api-docs.cbinsights.com/portal/docs/References/Taxonomy/industries) - [Markets](https://api-docs.cbinsights.com/portal/docs/References/Taxonomy/markets) · [Technologies](https://api-docs.cbinsights.com/portal/docs/References/Taxonomy/technologies) · [Business models](https://api-docs.cbinsights.com/portal/docs/References/Taxonomy/business-models) · [Awards and spotlights](https://api-docs.cbinsights.com/portal/docs/References/Taxonomy/awards-and-spotlights) - [Funding types](https://api-docs.cbinsights.com/docs/reference/funding_types/) · [Investor types](https://api-docs.cbinsights.com/docs/reference/investor_type/) · [Organization status](https://api-docs.cbinsights.com/docs/reference/org_status/) · [People titles](https://api-docs.cbinsights.com/docs/reference/person_titles/) · [Stock exchanges](https://api-docs.cbinsights.com/docs/reference/stock_exchanges/) · [Address/geography](https://api-docs.cbinsights.com/docs/reference/address/) - [Mosaic Score](https://api-docs.cbinsights.com/docs/reference/mosaic/) (only v2.1 is served) ## Company and policy - [Website](https://www.cbinsights.com/) · [Pricing](https://www.cbinsights.com/pricing) · [Research/blog](https://www.cbinsights.com/research/) · [Support](https://www.cbinsights.com/company/support) · [Login](https://www.cbinsights.com/login) - [Security and privacy](https://www.cbinsights.com/security-and-privacy/): SOC 2 Type II, GDPR; CCPA and EU AI Act stated as in progress. "Your data is never used to train the AI models we use." - [Trust center](https://trust.cbinsights.com/) (Vanta-hosted) · [Privacy policy](https://www.cbinsights.com/privacy-policy/) · [GitHub](https://github.com/cbinsights) ## Known gaps (observed 2026-08-09, not published by CB Insights) - No OpenAPI for v1; the v2 contract is Swagger 2.0 with no operationIds. - No change log for v2 — the published history stops at v1.9.0 (2024-07-26). - No status page, no SLA, no deprecation or sunset policy. - No `/.well-known/security.txt`, no `/.well-known/api-catalog`, no A2A agent card on any host. - No maintained client SDK in any language; the only first-party package (npm `cbinsights`) was last published in 2016 and its repository is gone. - No webhooks or event surface; change detection is polling via the v1 `lastUpdateTime` filter.