# Federal Student Aid > Federal Student Aid (FSA) is the office of the U.S. Department of Education that > administers federal grants, loans and work-study for postsecondary students. It > operates StudentAid.gov, the consumer platform where borrowers complete the FAFSA, > manage federal loans and choose repayment plans. FSA publishes no public developer > API for those systems. The one publicly callable API carried on this record is the > College Scorecard API, operated by the Department of Education through the > api.data.gov gateway, which exposes institution- and program-level data including > federal aid participation, borrowing and repayment outcomes. Generated by the API Evangelist enrichment pipeline on 2026-09-09 from this provider's apis.yml and the artifacts in this repository. Method: generated. The provider does not publish an llms.txt on any host (probed studentaid.gov and collegescorecard.ed.gov, both 404 on 2026-09-09). ## What you can actually call There is exactly one. Read this before assuming otherwise: - The **College Scorecard API** is a read-only, single-endpoint JSON query API at `https://api.data.gov/ed/collegescorecard/v1/schools`. GET only. A free API key is required and is issued automatically at https://api.data.gov/signup/. A shared `DEMO_KEY` is published for immediate use at 30 requests per IP per hour. - **StudentAid.gov has no public API.** FAFSA submission, loan management and repayment changes happen only in the web application. - **FSA Partner Connect, COD, NSLDS and SAIG have no public API.** Schools, servicers and vendors exchange data through enrolled-organization gateways using batch XML; the technical references are PDF-only and the systems sit behind a partner login. ## College Scorecard API - [API Documentation](https://collegescorecard.ed.gov/data/api-documentation/): base URL, parameters, operators, pagination, rate limits, error codes. - [Data Documentation](https://collegescorecard.ed.gov/data/data-documentation/): what each dataset contains and how it was derived. - [Data Dictionary (.xlsx)](https://collegescorecard.ed.gov/files/CollegeScorecardDataDictionary.xlsx): every field, its dev-category and developer-friendly name, and the cohort map that says which years carry which variable. - [Change Log](https://collegescorecard.ed.gov/data/changelog/) and [tagged releases](https://github.com/RTICWDT/college-scorecard/releases). - [Glossary](https://collegescorecard.ed.gov/data/glossary/). - [Get an API key](https://api.data.gov/signup/) · [Gateway developer manual](https://api.data.gov/docs/developer-manual/). ### Calling it GET https://api.data.gov/ed/collegescorecard/v1/schools ?api_key=YOUR_KEY &school.state=CA &fields=id,school.name,latest.student.size &page=0&per_page=100 Key semantics an agent must get right: - **Time is part of the field path**, not a parameter: `2018.earnings.*` for a fixed year, `latest.earnings.*` for the newest. `latest` resolves **per metric**, so two fields under `latest` can come from different reference years. Check the cohort map before comparing across categories. - **Projection**: `fields=` takes dotted paths and accepts parent wildcards (`fields=id,school,latest`). Add `keys_nested=true` to get real nested objects instead of flat dotted-string keys — pin one shape, they are not interchangeable. - **Filtering**: `field=v1,v2` for value lists (no wildcards, no floats), `field__not=v` to exclude, `field__range=100..500` for inclusive numeric ranges (either side may be omitted). - **Geo**: `zip=12345&distance=10mi` (or `km`), measured from the ZIP centroid, U.S. only. - **Sorting**: `sort=field:desc`, only on fields flagged in the Data Dictionary index column. - **Field of study** records are a nested array; a filtered query returns only matching elements unless you pass `all_programs_nested=true`. - **Suppressed values are null**, not zero. ### Identifiers - `id` is the **IPEDS UNITID**. `ope6_id` / `ope8_id` are the **OPE ID** that Federal Student Aid issues for Title IV participation. Program codes are **CIP 4-digit**. All three are federal standards, so this data joins to IPEDS, to FSA program files and to accreditation data with no mapping table. ### Limits and failures - 1,000 requests per IP per hour on a registered key; 30/hour and 50/day on DEMO_KEY. - `X-RateLimit-Limit` and `X-RateLimit-Remaining` on every response. **No `Retry-After` and no reset header** — on a 429 you must choose your own backoff. - Gateway errors are string codes (`API_KEY_MISSING`, `OVER_RATE_LIMIT`, `HTTPS_REQUIRED`); application errors are numeric. Both arrive as `{"error":{"code":...,"message":...}}`. Not RFC 9457. ## Federal Student Aid, the programs - [StudentAid.gov](https://studentaid.gov) · [About FSA](https://studentaid.gov/about) - [Apply for aid — FAFSA](https://studentaid.gov/h/apply-for-aid/fafsa) - [Loan repayment](https://studentaid.gov/manage-loans/repayment) - [FSA Data Center](https://studentaid.gov/data-center) — published aid volume and portfolio data files (downloads, not an API). - [FSA Partner Connect](https://fsapartners.ed.gov/) — school, servicer and vendor systems, behind enrollment. ## Department of Education context - [Open Data Platform](https://data.ed.gov/) — the Department's CKAN data catalog. - [Vulnerability Disclosure Policy](https://www.ed.gov/about/ed-overview/required-notices/vulnerability-disclosure-policy) — covers all internet-accessible Department systems. Report via https://usdeptofed.responsibledisclosure.com/hc/en-us/requests/new. ## What this provider does not publish Recorded so an agent stops looking: no OpenAPI or other machine-readable contract, no GraphQL, no AsyncAPI or webhooks, no first-party SDK on any package registry, no first-party MCP server, no A2A agent card, no /.well-known documents on any of six hosts probed, no status page, no SLA, no deprecation policy, and no security.txt. Support for the College Scorecard API is scorecarddata@rti.org. ## Artifacts in this repository - apis.yml — the provider record - authentication/ — API key model and failure codes - changelog/ — dated release history - conformance/ — standards posture, including IPEDS / OPE ID / CIP identifier conformance - conventions/ — query grammar, pagination, error envelope, read-only semantics - data-model/ — entity graph, probed live from the API - errors/ — the twelve documented problem types - lifecycle/ — versioning, deprecation and support posture - mcp/ — the MCP search record (no first-party server) - packages/ — client library census (no first-party SDK) - plans/ · rate-limits/ — free service, published limits - sandbox/ — the published DEMO_KEY - security/ — domain security probe and the Department's vulnerability disclosure policy - well-known/ — 54 discovery probes, all misses