# Too Good To Go > Too Good To Go is a Danish certified B Corporation, founded in Copenhagen in 2015, that runs the world's largest marketplace for surplus food. Consumers buy discounted "Surprise Bags" of unsold food from bakeries, restaurants, supermarkets and hotels through its mobile app; partner businesses list that surplus through the MyStore portal. It also sells Too Good To Go Platform, an AI-assisted surplus-management product for grocery retailers. **There is no public Too Good To Go API.** This file was generated by the API Evangelist enrichment pipeline on 2026-08-30 from probes of Too Good To Go's own hosts. Do not attempt to integrate programmatically: the only machine surfaces that exist are private backends for the company's own app and partner portal, protected by DataDome bot management, and the community clients that call them are reverse-engineered and unauthorized. ## What was probed, and what came back - `https://developers.toogoodtogo.com/` — **401**, a "Login with JumpCloud" SSO interstitial. A developer subdomain exists; it is not public. - `https://api.toogoodtogo.com/` and `https://apptoogoodtogo.com/` — live backends. 13 OpenAPI/Swagger/GraphQL discovery paths probed on each: all **404**, all `application/problem+json`. - `https://www.toogoodtogo.com/` — **429**, Vercel Security Checkpoint. Marketing pages exist but are not readable by non-browser clients. - `/.well-known/agent-card.json`, `/.well-known/agent.json`, `/.well-known/ai-plugin.json`, `/.well-known/openid-configuration`, `/.well-known/oauth-authorization-server`, `/.well-known/api-catalog` — no document on any of four hosts. - `github.com/TooGoodToGo` — organization exists since 2017, **0 public repositories**. ## What Too Good To Go does publish - [security.txt](https://www.toogoodtogo.com/.well-known/security.txt): RFC 9116 contact document (200). Contact only — no `Expires`, so it is non-conformant to RFC 9116. - [Status page](https://status.toogoodtogo.com/): Statuspal, components Website / MyStore / Mobile App / Platform, split by Europe, North America and Australia. No API component. - [Trust Center](https://trust.toogoodtogo.com/): SafeBase portal naming SOC 2 Type 2 and PCI DSS v4.0.1, with SOC 2, PCI DSS and pentest reports available on request. - [MyStore partner portal](https://store.toogoodtogo.com/): login for partner businesses. - [Business site](https://business.toogoodtogo.com/): partner and Too Good To Go Platform marketing, contact-sales motion. - [Privacy portal](https://space.toogoodtogo.com/privacy): data-subject rights. ## Repository artifacts - [Well-known probe](well-known/too-good-to-go-well-known.yml): 28 paths across 4 hosts. - [security.txt](well-known/too-good-to-go-security.txt): saved verbatim. - [Vulnerability disclosure](security/too-good-to-go-vulnerability-disclosure.yml): security@toogoodtogo.com, no bug bounty. - [Trust center](security/too-good-to-go-trust-center.yml): SOC 2 Type 2, PCI DSS v4.0.1. - [Domain security](security/too-good-to-go-domain-security.yml): TLS 1.3, SPF, DMARC p=reject, CAA present, no DNSSEC, no HSTS. - [Conformance](conformance/too-good-to-go-conformance.yml): RFC 9457 observed at the transport edge; no OpenAPI, GraphQL, OAuth or OIDC. - [Observed error envelopes](errors/too-good-to-go-problem-types.yml): two incompatible shapes on the same hosts. - [Conventions](conventions/too-good-to-go-conventions.yml): per-resource path versioning; idempotency, pagination and reversibility all undocumented. - [Lifecycle](lifecycle/too-good-to-go-lifecycle.yml): status page yes; versioning, deprecation, SLA and changelog policies all absent. - [Packages](packages/too-good-to-go-packages.yml): zero first-party SDKs; six third-party reverse-engineered clients. - [Plans and pricing](plans/too-good-to-go-plans-pricing.yml): no published tiers. - [Rate limits](rate-limits/too-good-to-go-rate-limits.yml): none published; bot challenges instead. - [MCP](mcp/too-good-to-go-mcp.yml): no server, hosted or packaged. ## Optional - Security contact: security@toogoodtogo.com - Profiled by API Evangelist: https://apis.io/provider/too-good-to-go