# Access & end users

> How FCRA Partner Access is enabled, which permissible purposes an agreement covers, and how to register the employers and landlords your orders are for.

- **HTML:** https://offendersearch.app/docs/fcra/access
- **Base URL:** https://api.offendersearch.app
- **Authentication:** `X-API-Key` request header, on an account with FCRA Partner Access
- **FCRA API reference as markdown:** https://offendersearch.app/docs/fcra.md

## FCRA Partner Access

The FCRA API is not self-serve. There is no dashboard switch, plan or key setting that turns it on. Our team enables it per account after a written FCRA agreement is signed; the agreement names the permissible purposes your account may use. Trial accounts cannot place orders. Every call is authenticated with the same `X-API-Key` header as the other APIs.

Without access, every `/v1/fcra/*` call returns `403 fcra_not_enabled`. Request access at `/contact?topic=fcra`.

## Permissible purposes

| Purpose | Meaning |
| --- | --- |
| `employment` | Employment purposes, with your end user’s § 1681b(b) certifications in place. |
| `tenant_screening` | A rental application the consumer initiated. |
| `consumer_written_instructions` | The consumer’s written instructions (§ 1681b(a)(2)). |
| `legitimate_business_need` | Another business transaction the consumer initiated. |

An end user may hold only purposes your agreement allows, and an order may state only a purpose its end user holds.

## End users

An end user is the employer, landlord or other business the report is for. Register each one once, with your certification that it holds the stated purposes, and reference it by id on every order.

POST /v1/fcra/end-users

```bash
curl -X POST https://api.offendersearch.app/v1/fcra/end-users \
  -H "X-API-Key: $OFFENDERSEARCH_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Northwind Staffing LLC",
    "externalId": "EU-4821",
    "permissiblePurposes": ["employment"],
    "certification": {
      "text": "End user certifies it will use reports only for employment purposes …",
      "version": "v3",
      "certifiedAt": "2026-10-02T14:00:00Z",
      "certifiedBy": "compliance@your-cra.example"
    }
  }'
```

| Field | Required | Description |
| --- | --- | --- |
| `name` | yes | The end user’s legal name. |
| `externalId` | no | Your own id for the end user. |
| `address` | no | The end user’s business address: `line1`, `city`, `state`, `postalCode`. |
| `permissiblePurposes` | yes | One or more of the purposes above, all within your agreement. |
| `certification.text` | yes | The certification the end user gave you, as you hold it (at least 10 characters). |
| `certification.version` | yes | Your version label for that certification. |
| `certification.certifiedAt` | yes | When it was given (ISO 8601). |
| `certification.certifiedBy` | no | Who at your company recorded it. |

`GET /v1/fcra/end-users` lists them; `GET /v1/fcra/end-users/{id}` returns one; `PATCH /v1/fcra/end-users/{id}` changes its purposes or sets `status` to `suspended`. A suspended end user cannot be used on a new order (`422`).

## What stays with you

- Disclosure, authorization and consent from the consumer — you attest to it on each order.
- Vetting your end users and holding their certifications.
- Adjudication, pre-adverse and adverse-action notices, and the consumer’s copy of the report.

---

## Related

- Next: [Orders](https://offendersearch.app/docs/fcra/orders.md)
- Index: [FCRA API reference](https://offendersearch.app/docs/fcra.md)
