# OSHA — Occupational Safety and Health Administration > The U.S. federal agency that sets and enforces workplace safety and health standards. > OSHA operates two distinct API surfaces: the Injury Tracking Application (ITA) API, a > write-only regulatory filing channel employers use to submit OSHA Forms 300A, 300 and 301 > under 29 CFR 1904.41; and the OSHA enforcement datasets (inspections, violations, accidents) > published as read-only data through the U.S. Department of Labor's data API. Neither surface > publishes an OpenAPI, an MCP server, an agent card or any /.well-known/ document — the ITA > contract is distributed as a PDF. Generated by API Evangelist from apis.yml and the artifacts in this repository, 2026-08-27. OSHA does not publish an llms.txt; https://www.osha.gov/llms.txt returns HTTP 403. ## APIs - [OSHA Injury Tracking Application (ITA) API](https://www.osha.gov/injuryreporting/ita): Submit and correct establishment records, Form 300A summaries and Form 300/301 case data. Base URL https://www.osha.gov/oshaApi/v1. Bearer-token auth; token issued from a logged-in ITA account. Account-scoped — a caller sees only its own establishments. - [OSHA Enforcement Data API](https://data.dol.gov/): Read OSHA inspection, violation, accident and related enforcement records. Base URL https://data.dol.gov/get/. X-API-KEY header auth. Note: new DOL API token creation is currently disabled, and the documented /get/ paths presently return the DOL Open Data Portal web app rather than data. ## Documentation - [ITA API documentation (PDF)](https://www.osha.gov/sites/default/files/ita/documentation/osha_injury-tracking-application-api-documentation-v1.pdf): The full contract — auth, all nine establishment/300A/submission operations, field data dictionaries and cross-field validation rules. - [ITA case data API specifications (PDF)](https://www.osha.gov/sites/default/files/ita_case_data_api_specifications.pdf): Forms 300/301 case-data endpoints. - [Injury Tracking Application](https://www.osha.gov/injuryreporting): Who must file, when, and how. - [OSHA data](https://www.osha.gov/data): Every OSHA data surface — enforcement search, ITA data, severe injury reports, fatalities, chemical exposure data. - [DOL Developer Portal](https://usdepartmentoflabor.github.io/Developer/): The DOL-wide API portal that documents the OSHA Enforcement dataset tables. - [DOL OSHA Enforcement dataset](https://usdepartmentoflabor.github.io/Developer/health-and-safety/dol-osha-enforcement/): The ten enforcement tables and their key fields. ## Getting started - [Testing / sandbox environment](https://preview.osha.gov/injuryreporting/ita): A separate host running the same validation rules. Swap preview.osha.gov for www.osha.gov on every call. Data is purged periodically and does not satisfy a filing obligation. - [ITA help request form](https://www.osha.gov/injuryreporting/ita/help-request-form): The support channel for API problems; include the request URL, body and response. ## Artifacts - authentication/osha-authentication.yml — the three credential models across the two surfaces. - conventions/osha-conventions.yml — versioning, pagination, error envelope, hypermedia links, bulk arrays, and the reversibility analysis of every write. - errors/osha-problem-types.yml — the response envelope and the nine published Form 300A validation rules. - data-model/osha-data-model.yml — Establishment / Form300A / CaseData / Submission and the ten enforcement tables, with their declared join keys. - lifecycle/osha-lifecycle.yml — versioning, the enforcedata.dol.gov retirement, and the suspended token issuance. - changelog/osha-changelog.yml — the ITA API's own dated change history, 2017-03-01 through 2018-07-16. - sandbox/osha-sandbox.yml — the preview.osha.gov testing environment. - conformance/osha-conformance.yml — cross-cutting standards plus the OSHA Form 300A / 300 / 301 and 29 CFR 1904 domain standards the contract declares. - packages/osha-packages.yml — the eight DOL data SDKs, all archived, none on any package registry. - rate-limits/osha-rate-limits.yml — no published rate limit; the only quantitative cap is a 200-record page. - plans/osha-plans-pricing.yml — no plans; free public-sector data. - well-known/osha-well-known.yml — every /.well-known/ probe and its status. No document is served. - mcp/osha-mcp.yml — no MCP server exists; a candidate tool surface derived from the published endpoints. - security/osha-domain-security.yml — TLS, HSTS, DNSSEC, SPF and DMARC posture. ## Not published OSHA publishes none of the following, verified by probe on 2026-08-27: OpenAPI or Swagger, GraphQL, AsyncAPI or any event/webhook surface, gRPC or WSDL, an MCP server, an A2A agent card, /.well-known/security.txt, an API status page, a deprecation policy, a vulnerability disclosure policy, a trust center, a CLI, or a Postman collection.