# Federal Aviation Administration (FAA) > The FAA is the United States civil aviation authority, an operating administration of the U.S. Department of Transportation. It regulates and certificates aircraft, airmen, airports and air carriers, operates the National Airspace System, and publishes the aeronautical information the entire US aviation chain depends on — NOTAMs, TFRs, charts, the 28-day NASR subscription, aircraft registration and airport data. Its API posture is genuinely mixed: two APIs are open, unauthenticated and Creative Commons Zero; the rest are gated by credential, by regulation, or by an executed agreement. Generated by API Evangelist on 2026-07-28. The FAA publishes no llms.txt of its own — https://www.faa.gov/llms.txt returns 404 and https://api.faa.gov/llms.txt returns the Gravitee developer-portal HTML shell, not a document. This file is generated from the API Evangelist catalog entry at https://apis.io/providers/federal-aviation-administration/ and the artifacts in https://github.com/api-evangelist/faa. ## Open APIs — no credential required - [Airport Status Web Service (ASWS)](https://external-api.faa.gov/asws/api): Airport delay summaries and per-airport status for ~40 major US airports, keyed on IATA code. JSON or XML. Creative Commons Zero. 2 operations. - [Aeronautic Product Release API (APRA)](https://external-api.faa.gov/apra): Chart publication metadata and downloads — VFR sectionals, terminal area charts, IFR enroute and oceanic, terminal procedures (dTPP), digital obstacle files, chart supplements, CIFP and the NASR 28-day subscription. 34 operations across 17 product families, each an /info edition lookup plus a /chart download. Creative Commons Zero. - [Temporary Flight Restriction (TFR) list](https://tfr.faa.gov/tfrapi/exportTfrList): Active TFRs as JSON with NOTAM id, TFR type, ARTCC facility, state. - [NAS Status airport status information feed](https://nasstatus.faa.gov/api/airport-status-information): XML feed of ground stops, ground delay programs, closures and arrival/departure delays. - [NMS North Atlantic Track NOTAM feed](https://nms.aim.faa.gov/datanat/nat.json): Live NAT track NOTAMs as JSON from the NOTAM Management Service, with ICAO id, condition message and start/end datetimes. - [NMS system metrics feed](https://nms.aim.faa.gov/data/content.json): Operational metrics for the NMS API — onboarded users, API calls per day, data volume, active NOTAMs. - [FAA Data Catalog (CKAN 2.11.4)](https://catalog.data.faa.gov/api/3/action): Standard CKAN Action API over the FAA data clearinghouse, plus a DCAT-US 1.1 feed at https://catalog.data.faa.gov/data.json. - [Aeronautical Information Services Open Data](https://ais-faa.opendata.arcgis.com/): 73 datasets — class airspace, frequencies, runways, navaids, obstacles, chart tile services — as ArcGIS GeoServices REST plus bulk CSV/GeoJSON/KML/shapefile. - [UAS Data Delivery System Open Data](https://udds-faa.opendata.arcgis.com/): 28 datasets — UAS Facility Maps (the LAANC altitude grid), national security UAS flight restrictions, FRIAs, SAMS. ## Gated APIs - [NOTAM API](https://external-api.faa.gov/notamapi/v1): Notices to Air Missions. Requires client_id and client_secret headers; an unauthenticated GET returns HTTP 401. No public OpenAPI. - [NOTAM Management Service (NMS) API](https://nms.aim.faa.gov/): The replacement for the legacy USNS and FNS NOTAM systems. Access is requested by email to notams@faa.gov. No public spec. - [Air Carrier PRD API](https://external.apic4e.faa.gov): Submits and searches pilot records in the Pilot Records Database under 14 CFR Part 111. Requires client_id and client_secret headers, and access is restricted to operators under Part 121, 135, 125, 91K, Air Tour, Public Aircraft or 91 Corporate — other public or private entities will not be authorized. Rate limited to 1 request per 10 seconds. - [Safety Assurance System (SAS) API](https://external.apic4e.faa.gov/axh-sasp-api/sas): Submits passenger discrepancy reports. Requires X-API-KEY and X-APP-ID headers. - [DMS Lookup API](https://api.faa.gov/): Designee lookup by Designee Number or ODA Key ID. Only an internal entrypoint is published. - [SWIM / SWIM Cloud Distribution Service](https://www.faa.gov/air_traffic/technology/swim): Near real-time flight, terminal and NOTAM data over Solace JMS. Requires an executed SWIM agreement via the SWIFT Portal. - LAANC drone airspace authorization: obtainable only through FAA-Approved UAS Service Suppliers, never directly from the FAA. ## Specs - [Airport Status Web Service OpenAPI 3.0.1](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/openapi/faa-airport-status-web-service-openapi.yml) - [Aeronautic Product Release API OpenAPI 3.0.1](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/openapi/faa-aeronautic-product-release-api-openapi.yml) - [Air Carrier PRD API OpenAPI 3.0.0](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/openapi/faa-air-carrier-prd-api-openapi.yml) - [Safety Assurance System API OpenAPI 3.0.0](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/openapi/faa-safety-assurance-system-api-openapi.yml) - No AsyncAPI, no GraphQL, no gRPC/protobuf and no MCP server are published by the FAA. ## Discovery - [Developer portal](https://api.faa.gov/) — Gravitee APIM; redirects to https://portal.apic4e.faa.gov/. Self-serve account and application creation. - [Portal catalog API](https://apim-api.apic4e.faa.gov/portal/environments/DEFAULT/apis) — unauthenticated machine-readable list of every published API with id, version, entrypoints and owner. The closest thing the FAA has to an api-catalog. - [FAA Data Portal](https://www.faa.gov/data) - No /.well-known/ document is published on any FAA host. ## Conventions and operations - Authentication: none for ASWS/APRA/TFR/NAS status/CKAN/ArcGIS; client_id + client_secret headers for NOTAM and PRD; X-API-KEY + X-APP-ID for SAS; X-Gravitee-Api-Key at the gateway. No OAuth 2.0 or OpenID Connect anywhere, so no scopes. - Rate limits: one published limit in the whole estate — 1 request per 10 seconds on the Air Carrier PRD API. No RateLimit headers, no 429 declared. - Errors: no RFC 9457 problem+json. Error responses are bare status codes with prose. The gateway returns {"message":"Unauthorized","http_status_code":401}. - Idempotency: none. The three write surfaces have no idempotency key. - Versioning: no policy. The real clock is the 28-day airspace (AIRAC) cycle — call /info before /chart. - Deprecation: no policy or Sunset header, but two APRA operations (getDERSRelease, getDERSEdition) are marked deprecated, one PRD production host is labelled deprecated, and the USNS and FNS NOTAM systems are being retired in favour of NMS. - Vulnerability disclosure: https://www.faa.gov/web_policies/vulnerability_disclosure_policy — vulnerabilitydisclosure@faa.gov, 90-day window, safe harbour, no bug bounty. - SDKs: no client library for the HTTP APIs. The FAA's only first-party libraries are Java clients for SWIM at https://github.com/faa-swim. ## Artifacts - [apis.yml (APIs.json)](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/apis.yml) - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/authentication/faa-authentication.yml) - [API conventions](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/conventions/faa-conventions.yml) - [Error catalog](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/errors/faa-problem-types.yml) - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/lifecycle/faa-lifecycle.yml) - [Plans](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/plans/faa-plans.yml) - [Rate limits](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/rate-limits/faa-rate-limits.yml) - [Conformance](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/conformance/faa-conformance.yml) - [Data model](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/data-model/faa-data-model.yml) - [Packages](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/packages/faa-packages.yml) - [Well-known probe index](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/well-known/faa-well-known.yml) - [SWIM event surface](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/asyncapi/faa-swim-event-surface.yml) - [Candidate MCP tool manifest](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/mcp/faa-mcp.yml) - [Agent skills](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/skills/_index.yml) - [Domain security probe](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/security/faa-domain-security.yml) - [Vulnerability disclosure](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/security/faa-vulnerability-disclosure.yml) - [Agentic access contracts](https://raw.githubusercontent.com/api-evangelist/faa/refs/heads/main/agentic-access/faa-agentic-access.yml)