Offendersearch
FCRA API Reference

Access & end users

How access is switched on, the permissible purposes, and registering your end users.

Base URL https://api.offendersearch.app

FCRA Partner Access

The FCRA API is not self-serve. There is no dashboard switch, plan or key setting that turns it on. Our team enables it per account after a written FCRA agreement is signed; the agreement names the permissible purposes your account may use. Trial accounts cannot place orders. Every call is authenticated with the same X-API-Key header as the other APIs.

Without access, every /v1/fcra/* call returns 403 fcra_not_enabled. Request access at /contact?topic=fcra.

Permissible purposes

PurposeMeaning
employmentEmployment purposes, with your end user’s § 1681b(b) certifications in place.
tenant_screeningA rental application the consumer initiated.
consumer_written_instructionsThe consumer’s written instructions (§ 1681b(a)(2)).
legitimate_business_needAnother business transaction the consumer initiated.

An end user may hold only purposes your agreement allows, and an order may state only a purpose its end user holds.

End users

An end user is the employer, landlord or other business the report is for. Register each one once, with your certification that it holds the stated purposes, and reference it by id on every order.

POST /v1/fcra/end-users
curl -X POST https://api.offendersearch.app/v1/fcra/end-users \
  -H "X-API-Key: $OFFENDERSEARCH_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Northwind Staffing LLC",
    "externalId": "EU-4821",
    "permissiblePurposes": ["employment"],
    "certification": {
      "text": "End user certifies it will use reports only for employment purposes …",
      "version": "v3",
      "certifiedAt": "2026-10-02T14:00:00Z",
      "certifiedBy": "compliance@your-cra.example"
    }
  }'
FieldRequiredDescription
nameyesThe end user’s legal name.
externalIdnoYour own id for the end user.
addressnoThe end user’s business address: line1, city, state, postalCode.
permissiblePurposesyesOne or more of the purposes above, all within your agreement.
certification.textyesThe certification the end user gave you, as you hold it (at least 10 characters).
certification.versionyesYour version label for that certification.
certification.certifiedAtyesWhen it was given (ISO 8601).
certification.certifiedBynoWho at your company recorded it.

GET /v1/fcra/end-users lists them; GET /v1/fcra/end-users/{id} returns one; PATCH /v1/fcra/end-users/{id} changes its purposes or sets status to suspended. A suspended end user cannot be used on a new order (422).

What stays with you

  • Disclosure, authorization and consent from the consumer — you attest to it on each order.
  • Vetting your end users and holding their certifications.
  • Adjudication, pre-adverse and adverse-action notices, and the consumer’s copy of the report.