# Cision > Cision is a PR and earned-media software company. Its platforms — CisionOne, the > Next Generation Cision Communications Cloud, PR Newswire and Brandwatch — cover > media monitoring, journalist and influencer outreach, press-release distribution > and earned-media analytics. Two REST APIs are published, both read-only reporting > surfaces over saved searches. API access is an enterprise contract entitlement: > there is no self-service signup, no free tier and no public sandbox. Generated by API Evangelist on 2026-08-13. Cision publishes no llms.txt of its own (/llms.txt returns 404 on www.cision.com, developers.cision.one, api.cision.one and the Confluence help host). ## What an agent can actually do here - Read the Mention Streams (saved boolean searches) configured in a CisionOne organisation. - Read the media mentions matching one stream over a date range, with sentiment, Advertising Value Equivalency, audience, domain authority, impact score and per-network social share counts. - Read a server-side statistics summary for a stream — advertising values and audiences by media type, plus a sentiment histogram. Nothing can be created, updated or deleted. Every published operation is a GET. Mention Streams are authored in the CisionOne user interface, so an agent cannot provision the object every other call depends on. ## APIs - [CisionOne API](https://www.cision.com/cisionone/): REST API connecting CisionOne monitoring data to internal tools and BI platforms. Base URL https://api.cision.one, path prefix /public/api/v2. Three operations: getStreams, getMentions, getStreamStats. - [Next Generation Cision Communications Cloud API](https://cision.atlassian.net/wiki/spaces/CSM/pages/25764989843/Settings+-+Cision+API): REST API over Communications Cloud searches. Base URL https://api.trendkite.com (the host Cision inherited with its 2019 TrendKite acquisition), path prefix /api/v2.2. Operations: POST /api/login, GET /api/v2.2/searches, GET /api/v2.2/totalmentions, GET /api/v2.2/stats. ## Specs - [OpenAPI 3.0.0 — CisionOne API](https://raw.githubusercontent.com/api-evangelist/cision/refs/heads/main/openapi/cision-cisionone-openapi.yml): harvested from the ReDoc reference Cision publishes at https://developers.cision.one/docs/api/v2. - [OpenAPI as published, verbatim](https://raw.githubusercontent.com/api-evangelist/cision/refs/heads/main/openapi/_original/cision-cisionone-openapi.json) ## Docs - [CisionOne API reference (ReDoc)](https://developers.cision.one/docs/api/v2) - [CisionOne - API (developer guide)](https://cision.atlassian.net/wiki/spaces/CSM/pages/26385776684/CisionOne+-+API) - [Settings - Cision API (Communications Cloud auth + endpoints)](https://cision.atlassian.net/wiki/spaces/CSM/pages/25764989843/Settings+-+Cision+API) - [CisionOne help site](https://cision.atlassian.net/wiki/spaces/CSM/overview) - [What's new in CisionOne (monthly product release notes)](https://cision.atlassian.net/wiki/spaces/CSM/pages/27828846642/Newsletter+February+2026) ## Authentication Both APIs use a token on the `X-Auth-Token` request header. There is no OAuth, no OpenID Connect and no scope surface. - CisionOne: an administrator mints a long-lived API token in CisionOne Settings. - Communications Cloud: POST `{"username": ..., "password": ...}` as JSON to https://api.trendkite.com/api/login and use the returned `access_token`. 401 means the token is missing or invalid. 403 means the token is valid but the account is not entitled to API access — a commercial gate, not a permissions one. ## Limits and conventions - Rate limit: 10 requests per minute, keyed on BOTH caller IP and API key. Exceeding it returns 429. No `RateLimit-*`, `X-RateLimit-*` or `Retry-After` headers are published, so a client must self-throttle to roughly one request every six seconds and cannot read remaining budget at runtime. - Date range is required on getMentions and getStreamStats and must not exceed 366 days. - `pagination[page]` x `pagination[page_size]` must not exceed 5000 mentions. - Response format is chosen by a required `format=json|csv` query parameter, not by the Accept header. - No error body schema is published anywhere. Branch on the status code alone: 400, 401, 403, 404, 429. - Readership for online content is deliberately zeroed in the response body under Cision's data-licensing terms. On the Communications Cloud API the real values arrive as a presigned CSV URL in the `x-additional-info` response header, which expires after five minutes. ## What Cision does not publish - No SDK or client library in any language, on any registry. Cision's own docs say the integration work "falls on you and your developers". - No MCP server, no A2A agent card, no GraphQL, no gRPC. - No webhooks, no events, no AsyncAPI — a search of Cision's help space for "webhook" returns zero results. - No sandbox, test mode, test credentials or CLI. - No security.txt, no responsible-disclosure page, no bug bounty, no trust center. - No API changelog, no deprecation policy, no Sunset header support, no public SLA. - No public status page — oneuptime.cision.com resolves but renders as "Cision Internal" and shows nothing to an anonymous visitor. - No Postman collection. ## Company - [Website](https://www.cision.com/) - [Pricing (contact sales; no published tiers)](https://www.cision.com/pricing/) - [Security Statement](https://www.cision.com/legal/security-statement/) - [Master Subscription Agreement](https://www.cision.com/legal/msa/) - [Privacy Policy](https://www.cision.com/legal/privacy-policy/) - [Blog](https://www.cision.com/us/blog/) - [GitHub](https://github.com/cision)