# Ferguson > Ferguson Enterprises, LLC is a Fortune 500 distributor of plumbing supplies, HVAC > products, pipe/valves/fittings, waterworks and building supplies to professional > contractors, residential and commercial customers across the United States. Ferguson > operates an Enterprise API program for approved partners and software providers, > published through the Ferguson Developer Portal. This file was generated by API Evangelist (https://apievangelist.com) from the public profile at https://github.com/api-evangelist/ferguson. It is a third-party profile, not a Ferguson-published document, and it describes only what Ferguson makes publicly readable. ## What is public, and what is not Ferguson's API contract is NOT public. The developer portal at developer.ferguson.com is a Backstage application whose catalog and search APIs return HTTP 401 to anonymous requests, and the API catalog (documented "through Swagger", per Ferguson's FAQ) is visible only to organizations that have completed Ferguson's partner review and approval process. As of 2026-09-09 no OpenAPI, AsyncAPI, GraphQL SDL, Protobuf, WSDL, Postman collection, MCP server or A2A agent card could be found on any Ferguson host. No API base URL is published outside the gated portal. ## API program - [Ferguson Developer Portal](https://developer.ferguson.com/): partner-gated entry point to Ferguson's Enterprise APIs; documentation, code generation and collaboration tools. - [API catalog](https://developer.ferguson.com/apis): the list of Enterprise API products (requires approval and sign-in). - [Get Started](https://developer.ferguson.com/get-started): registration, Developer App creation, credentials, and the OAuth token call. - [FAQ](https://developer.ferguson.com/faq): who may access the APIs and how. - [Developer blog](https://developer.ferguson.com/blog): Ferguson's own writing on OAuth 2.0 grants, cURL, the Richardson Maturity Model and API strategy. - Access requests: api.team@ferguson.com ## Authentication OAuth 2.0. A partner registers, is approved, creates a Developer/Team App and receives a Key and Secret. The Key and Secret are base64-encoded into an HTTP Basic Authorization header on a token request with grant_type=client_credentials; the resulting access token is sent on API calls as `Authorization: Bearer ` per RFC 6750. Ferguson also documents the Authorization Code and Resource Owner Password Credentials (ROPC) grants. Responses are JSON. The gateway is Google Apigee. ## Profile artifacts (this repository) - [Authentication profile](authentication/ferguson-authentication.yml) - [Standards conformance](conformance/ferguson-conformance.yml) - [Plans and pricing](plans/ferguson-plans-pricing.yml): none published (plan_count 0) - [Rate limits](rate-limits/ferguson-rate-limits.yml): none published (limit_count 0) - [Packages](packages/ferguson-packages.yml): no first-party API client library - [Well-known probe](well-known/ferguson-well-known.yml): no discovery document on any host - [Domain security](security/ferguson-domain-security.yml): TLS/HSTS/SPF/DMARC posture ## Company - [Ferguson](https://www.ferguson.com) - [Customer support](https://www.ferguson.com/content/customer-support/) - [Terms of site use](https://www.ferguson.com/content/customer-support/website-information/terms-of-site-use/) - [Terms and conditions of sale](https://www.ferguson.com/content/customer-support/website-information/terms-of-sale/) - [LinkedIn](https://www.linkedin.com/company/ferguson-official) ## Notes for agents There is no callable public Ferguson endpoint. Do not construct one: api.ferguson.com is a legacy JBoss host that answers 403 at the root and is not the documented API gateway. An agent that needs Ferguson product availability, cost or purchase-order data must go through a partner integration approved by Ferguson (api.team@ferguson.com). Generated: 2026-09-09 | method: generated | source: apis.yml + repository artifacts