# General Services Administration (GSA) > GSA is the U.S. federal government's acquisition, real estate and shared-services > agency, and one of the largest single publishers of public APIs in the federal > government. Its developer surface is a directory — https://open.gsa.gov/api/ — > covering roughly thirty APIs run by separate GSA programs: SAM.gov (the > Integrated Award Environment), api.data.gov, Data.gov, Search.gov, Site Scanning, > the Digital Analytics Program, Regulations.gov, Touchpoints, Per Diem and the IT > Dashboard. There is no single GSA API; there is a federation behind one gateway > and one API key. Generated by API Evangelist on 2026-09-12 from GSA's own published material. GSA does not publish an llms.txt (https://open.gsa.gov/llms.txt returned 404 on 2026-09-12), so this file is generated, not harvested. ## How access works - Most GSA APIs sit behind **api.data.gov** (API Umbrella), operated by GSA Technology Transformation Services. One free 40-character key works across every participating federal API. Sign up: https://api.data.gov/signup/ - Pass the key as the `X-Api-Key` header, the `api_key` query parameter, or the HTTP basic-auth username. - `DEMO_KEY` works anonymously for exploration: 30 requests/hour and 50/day per IP. - Default allowance with a real key: **1,000 requests/hour**, rolling. - **SAM.gov is the exception.** Its keys come from the SAM.gov Account Details page, it meters **daily** rather than hourly, and the allowance depends on who you are: 10/day for a non-federal user with no SAM.gov role, 1,000/day for a federal or role-holding user, 10,000/day for a federal system account. Sensitive and FOUO endpoints additionally require a System Account over HTTP Basic. - No OAuth, no OpenID Connect, no mutual TLS anywhere in the estate. ## Machine-readable contracts 22 real OpenAPI documents were harvested from GSA's own hosts and are in this repository under `openapi/`, covering 203 operations: - Per Diem — https://open.gsa.gov/api/perdiem/v2/openapi.yaml (base https://api.gsa.gov/travel/perdiem) - Regulations.gov — https://open.gsa.gov/api/regulationsgov/v4/openapi.yaml (base https://api.regulations.gov/v4, a JSON:API surface) - SAM.gov Entity Management — https://open.gsa.gov/api/entity-api/v1/openapi.yaml (base https://api.sam.gov/entity-information/v4) - SAM.gov Exclusions — https://open.gsa.gov/api/exclusions-api/v1/openapi.yaml - SAM.gov Contract Awards — https://open.gsa.gov/api/contract-awards/v1/openapi.yaml - SAM.gov Opportunity Management — https://open.gsa.gov/api/opportunities-api/v1/openapi.json - SAM.gov Subaward Reporting / Bulk Upload — https://open.gsa.gov/api/subawards-bulkupload-api/v1/subawardapi.yml - SAM.gov Subcontracting Plan Reports — https://open.gsa.gov/api/spr-api/v1/openapi.yaml - SAM.gov Assistance Listings — https://open.gsa.gov/api/assistance-listings-api/v1/assistance-listings-api.openapi.yaml - SAM.gov Entity Extracts — https://open.gsa.gov/api/sam-entity-extracts-api/v1/openapi.yaml - Data.gov CKAN catalog — https://open.gsa.gov/api/datadotgov/v1/openapi.json (base https://catalog.data.gov/api/3) - Site Scanning — https://api.gsa.gov/technology/site-scanning/v1/api-json?api_key=DEMO_KEY (served live from the API host) - IT Collect — https://gsa.github.io/ITDB-schema/public-by-2026/api/data/gov/docs/itcollect_openapi.json (51 operations) - Digital Analytics Program — https://open.gsa.gov/api/dap/v2/openapi.yaml - Search.gov results and clicks — https://open.gsa.gov/api/searchgov-results/v2/openapi.yml - api.data.gov Admin (API Umbrella) and Metrics — https://open.gsa.gov/api/apidatagov/v1/openapi.yaml - Touchpoints — https://touchpoints.app.cloud.gov/api/v1/openapi.yml - Acquisition Gateway Listings v4 — https://open.gsa.gov/api/ag-api/v4/openapi.yaml ## What is NOT there, so you do not go looking - **No /.well-known/api-catalog** on any GSA host. The only well-known document GSA serves is https://gsa.gov/.well-known/security.txt (RFC 9116, HackerOne VDP). - **No A2A agent card** at `/.well-known/agent-card.json` or `/.well-known/agent.json` on any host. - **No status page.** https://gsa.statuspage.io/ exists but is an unconfigured Statuspage tenant whose only components are named "API (example)" and "Management Portal (example)". - **No SLA, no deprecation policy, no Sunset/Deprecation headers.** - **No idempotency mechanism** on any write surface, including Regulations.gov comment submission and SAM.gov opportunity publication. - **No first-party SDK** in any package registry, in any language. - **No event, webhook, streaming or AsyncAPI surface anywhere.** - **No GraphQL, gRPC or SOAP.** - **No pricing.** Every API is free; there is no paid tier to buy. ## MCP GSA Technology Transformation Services publishes real MCP servers, two of which wrap GSA's own APIs: - https://github.com/GSA-TTS/mcp-server-gsa-perdiem — six tools over the Per Diem API, stdio transport, `PERDIEM_API_KEY`. - https://github.com/GSA-TTS/mcp-server-regulations-gov — six tools over Regulations.gov, container image `ghcr.io/gsa-tts/mcp-server-regulations-gov:0.2.0`. Neither publishes a public remote endpoint. GSA also runs an MCP Server Hub catalog (https://github.com/GSA-TTS/mcp-server-hub-catalog, 29 pilot servers, mostly over other agencies' APIs) and a federal open-data MCP registry (https://github.com/GSA-TTS/fed-data-mcp-registry). The hub README states these are pilots and not intended for production use. ## Conventions you must not assume Pagination is spelled four incompatible ways inside one provider: `page`+`size` (SAM.gov entity, exclusions, contract awards), `page`+`limit` (Site Scanning), `page[number]`+`page[size]` (Regulations.gov), `limit`+`offset` (Data.gov CKAN, Get Opportunities). Errors are a vendor envelope, `{"error":{"code":"...","message":"..."}}`; branch on `error.code`. Rate-limit signal is `X-RateLimit-Limit` and `X-RateLimit-Remaining` with no `Retry-After` and no reset header. Exhaustion is `429 OVER_RATE_LIMIT`. ## Retired surfaces (probed 2026-09-12) - Search.gov Type-Ahead Suggestions API — page and spec both 404, no retirement notice. - Sustainable Facilities Tool (SFTool) developer API — sftool.gov now serves one catch-all page for every path. - AG Document Library API — GSA's own v1 spec is titled "(decommissioned)". ## Links - API directory: https://open.gsa.gov/api/ - Open Technology: https://open.gsa.gov/ - API key signup: https://api.data.gov/signup/ - Developer manual (keys, limits, errors): https://api.data.gov/docs/developer-manual/ - Code: https://github.com/GSA and https://github.com/GSA-TTS - Contact: https://open.gsa.gov/contact - Vulnerability disclosure: https://gsa.gov/vulnerability-disclosure-policy