# Financial Conduct Authority (FCA) > The UK's conduct regulator for around 42,000 financial services firms and the > prudential regulator for most non-bank firms. The FCA is a regulator, not a > market participant: it publishes two genuine public APIs — the Financial > Services Register API (firm, individual and fund authorisation records) and the > data publication query API behind FIRDS and FITRS (UK instrument reference data > and transparency calculation file artefacts). Everything else it publishes is > documents and spreadsheets. No OpenAPI, GraphQL, AsyncAPI, gRPC, webhook, SDK, > CLI, sandbox or MCP server exists on any FCA property. Generated by API Evangelist on 2026-07-25. No /llms.txt is published by the FCA (www.fca.org.uk/llms.txt returns 404, register.fca.org.uk/llms.txt returns 401), so this file is generated from the catalog entry and the artifacts in this repo. ## APIs - [FCA Financial Services Register API](https://register.fca.org.uk/Developer/s/): Read-only REST over the public record of authorised firms, individuals, funds and appointed representatives. Base URL https://register.fca.org.uk/services/V0.1. Resources are addressed by Firm Reference Number (FRN), Individual Reference Number (IRN) or Product Reference Number (PRN), with sub-resources for names, individuals, permissions, requirements, passports, regulators, appointed representatives, addresses, waivers, exclusions and disciplinary history. - [FCA Data Publication API (FIRDS / FITRS)](https://data.fca.org.uk/#/download): Anonymous OpenSearch-style query interface over published file artefacts. Base URL https://api.data.fca.org.uk. Two public indices: fca_data_firds_files (UK instrument reference data, 11,583 records) and fca_data_fitrs_files (UK transparency calculation results, 2,603 records). ## Authentication - FS Register API: API key in two request headers, `X-Auth-Email` and `X-Auth-Key`. Obtained free by self-serve registration at the developer portal. There is no OAuth, no scopes and no permission model. - Data Publication API: none. Anonymous GET. - The OIDC discovery document at register.fca.org.uk/.well-known/openid-configuration belongs to the Salesforce Experience Cloud platform hosting the developer portal login. It is not an FCA API identity surface. - Detail: [authentication profile](authentication/fca-uk-authentication.yml) ## Conventions - Versioning: URI path, `V0.1`, on the Register API only. The data publication API has no version segment. - Pagination: `from` + `size` offset paging on the data publication API; nothing documented publicly for the Register API. - Query: the data publication API accepts a documented subset of the Elasticsearch query_string DSL — `q`, `from`, `size`, `sort`, `pretty`, `df`, `default_operator`. - Idempotency: not applicable — both surfaces are read-only GET. - Errors: proprietary JSON, not RFC 9457. `{"Success":"false", "..."}` on the Register API; `{"message":"Missing Authentication Token"}` on the data publication API. - Rate limits: 50 requests per 10 seconds on the Register API; documented but unquantified throttling on the data publication API, with file downloads exempt. - Detail: [conventions](conventions/fca-uk-conventions.yml), [error catalog](errors/fca-uk-problem-types.yml), [rate limits](rate-limits/fca-uk-rate-limits.yml) ## Docs - [Financial Services Register](https://www.fca.org.uk/firms/financial-services-register): the public page describing the API, the free developer portal, and the explicit absence of any SLA. - [FS Register API Developer Portal](https://register.fca.org.uk/Developer/s/): Salesforce login wall with free self-serve registration. All reference documentation is behind it. - [FCA FIRDS technical specification (PDF)](https://www.fca.org.uk/publication/systems-information/fca-firds-tech-spec.pdf): documents the machine-to-machine file query interface, its parameters and its response shape. - [FCA FITRS technical specification (PDF)](https://www.fca.org.uk/publication/systems-information/fca-fitrs-tech-spec.pdf): the transparency-system equivalent. - [FCA Data](https://www.fca.org.uk/data): the data index. Insurance data (General Insurance Value Measures) is published as XLSX, not as an API. - [Register Extract Service](https://www.fca.org.uk/firms/financial-services-register/data-extract): paid bulk file delivery, the FCA's answer to the Register API's one-entity-per-lookup design. - [FCA Handbook](https://handbook.fca.org.uk/): the rulebook, HTML only. ## Artifacts in this repo - [Authentication](authentication/fca-uk-authentication.yml) - [Conventions](conventions/fca-uk-conventions.yml) - [Data model](data-model/fca-uk-data-model.yml) - [Error catalog](errors/fca-uk-problem-types.yml) - [Rate limits](rate-limits/fca-uk-rate-limits.yml) - [Lifecycle](lifecycle/fca-uk-lifecycle.yml) - [Conformance](conformance/fca-uk-conformance.yml) - [Packages (community, none official)](packages/fca-uk-packages.yml) - [Well-known surface](well-known/fca-uk-well-known.yml) - [Domain security probe](security/fca-uk-domain-security.yml) ## Not present - No OpenAPI or Swagger document (probed on every host). - No GraphQL, gRPC, AsyncAPI, webhooks or event surface of any kind. - No first-party SDK, CLI, sandbox, Postman collection, MCP server or agent skill. - No status page, no SLA, no deprecation policy, no API changelog. - No security.txt, no vulnerability disclosure programme, no trust centre. - No ACORD reference anywhere on fca.org.uk; the FCA does not sponsor insurance data-interchange standards. - No UK open-insurance mandate. The FCA's Open Finance vision (14 April 2026) names insurance as in scope but the first discussion paper is not due until Q4 2026.