# TransUnion > A global information and insights company providing credit reporting, risk, fraud and > identity solutions, and one of the three largest consumer credit bureaus in the United > States. Almost all of TransUnion's API surface is contract-gated: access requires a > business agreement and credentials issued by an account manager. One product line is a > genuine exception and is the only TransUnion API with a public machine-readable > contract — TruContact Trusted Call Solutions, the STIR/SHAKEN call authentication and > verification service that came to TransUnion with the Neustar acquisition in December > 2021, whose OpenAPI is published openly on GitHub under an MIT licence. Generated by API Evangelist on 2026-08-13 from apis.yml and the artifacts in this repo. No provider-published llms.txt exists: https://neustar.github.io/tcs-apis/llms.txt returns 404. ## APIs - [TruContact Trusted Call Solutions — STI-AS / STI-VS](https://neustar.github.io/tcs-apis/): Nine POST operations that sign SIP Identity headers (PASSporTs) and verify them, including Call Validation Treatment with CNAM and robocall analytics. Deployed inside the carrier's own network, so the spec's servers[] block is templated by design. - [TransUnion Global Developer Portal](https://www.transunion.com/business): Credit, identity verification, fraud prevention and consumer risk decisioning APIs. Contract-gated. NOTE: the historical portal host developer.transunion.com no longer resolves (NXDOMAIN, checked 2026-08-13). - [TruValidate Device Risk](https://github.com/iovation/deviceprint-SDK-iOS): Device fingerprinting ("blackbox") collected by mobile SDKs and submitted to a risk check. The API host api.iovation.com requires a client certificate — mutual TLS, no anonymous surface. ## Specs - [TruContact TCS STIR/SHAKEN OpenAPI 3.1.0](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/openapi/transunion-trucontact-tcs-shaken-openapi.yml): 9 operations, 8 schemas. Source: github.com/neustar/tcs-apis, gh-pages branch. - [TruContact 3GPP-based Call Authentication OpenAPI 3.0.3](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/openapi/transunion-trucontact-3gpp-call-authentication-openapi.yml): 2 operations, aligned to 3GPP TS 24.229 Release 17.10.0. ## Artifacts - [Authentication](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/authentication/transunion-authentication.yml): apiKey in a QUERY parameter with client-IP allowlist fallback; the spec declares no securitySchemes at all. - [Error catalog](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/errors/transunion-problem-types.yml): 179 error_ids extracted from the spec's response examples, each with its HTTP status and the SIP response code it maps to. - [Conventions](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/conventions/transunion-conventions.yml): media types encoded in the operation name (j-j, s-j, s-s, mps, mpj); no idempotency; no pagination; URI-path v2. - [Conformance](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/conformance/transunion-conformance.yml): RFC 8224, ATIS-1000074/78/80/84/85/92/93/94/98, 3GPP TS 24.229. - [Data model](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/data-model/transunion-data-model.yml): the message graph — signing request, Identity/PASSporT, verification response, and the external STI certificate that dominates the failure surface. - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/lifecycle/transunion-lifecycle.yml): URI-path v2, public GitHub proposal process, one tagged release, no deprecation policy, no status page. - [Packages](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/packages/transunion-packages.yml): TruValidate Device Risk SDKs for iOS (v5.9.0, 2026-08-07) and Android (v5.4.0, 2026-07-24); legacy Trustev .NET and PHP clients. - [Rate limits](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/rate-limits/transunion-rate-limits.yml): none published — no 429, no rate-limit headers. - [Plans](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/plans/transunion-plans-pricing.yml): none published — contract-first, sales-gated. - [Vulnerability disclosure](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/security/transunion-vulnerability-disclosure.yml): public HackerOne VDP at hackerone.com/transunion, submissions open, no bounties. - [Agent skills](https://raw.githubusercontent.com/api-evangelist/transunion/refs/heads/main/skills/_index.yml): two skills grounded in real operationIds. ## Docs - [TruContact TCS API reference](https://neustar.github.io/tcs-apis/) - [TruContact TCS API repository](https://github.com/neustar/tcs-apis) - [Trusted Call Solutions](https://www.transunion.com/solution/trucontact/branded-communications/trusted-call-solutions) - [TruContact](https://www.transunion.com/solution/trucontact) - [Client Technical Services](https://techservices.transunion.com/) - [TransUnion for business](https://www.transunion.com/business) - [Vulnerability disclosure program](https://hackerone.com/transunion) ## Notes for agents - There is no TransUnion MCP server and no A2A agent card. Do not assume one. - There is no self-serve signup and no published pricing anywhere in TransUnion's estate. - www.transunion.com and techservices.transunion.com sit behind Cloudflare bot management and answer HTTP 403 to non-browser clients, including /robots.txt.