Disputes are an endpoint
Unlike most screening data APIs, a dispute here is a call, not an email. Open a reinvestigation on any record we furnished, follow it on the 30-day clock, and receive the outcome by webhook — with the correction sent to every partner that received the record.
Part of the FCRA Orders API, for approved consumer reporting agencies and screening platforms under a written FCRA agreement.
curl -X POST https://api.offendersearch.app/v1/fcra/orders/fo_7c1e9b2a4d3f/disputes \
-H "X-API-Key: $OFFENDERSEARCH_FCRA_KEY" \
-H "Content-Type: application/json" \
-d '{
"recordIds": ["crim:IL-SANGAMON:2021CR004417"],
"reason": "not_me",
"consumerStatement": "I have never lived in Sangamon County.",
"receivedAt": "2026-10-03T09:12:00Z"
}'Reinvestigation is where accuracy is proven
The costly FCRA cases in screening turn on the wrong record on the wrong person. A dispute is the moment that question is asked directly — and the moment a slow, manual handoff with a data supplier costs you the most.
The clock is yours, not your vendor’s
Your 30 days start when the consumer’s dispute reaches you. A dispute you can open the same minute — with receivedAt recorded — is time you keep, instead of days lost to an email thread with a data supplier.
Corrections reach everyone, not just you
When a dispute changes or removes a record, every partner that received it gets a record.corrected event. The consumer is not left disputing the same error with each screening company that bought it.
Two front doors, one dispute
You can open a dispute through the API, or the consumer can open it themselves in the portal with the access code on your order. Both create the same object, on the same clock, visible to you by webhook.
The dispute, field by field
One dispute object, whoever opened it. It is what you read, what the consumer sees in the portal, and what the webhooks point to.
| Field | Meaning |
|---|---|
id | The dispute’s identifier |
orderId | The order whose furnished records are disputed |
recordIds | The furnished records in dispute — one dispute can cover several |
origin | partner (opened by you), consumer_portal (opened by the consumer with the access code) or consumer_request (filed through our public intake) |
reason | not_me, inaccurate, incomplete, outdated or other |
consumerStatement | The consumer’s own words, when given |
receivedAt / dueAt | When the dispute was received, and 30 days after |
extendedAt | Set when new information extends the period by 15 days |
status | received, investigating, then verified, modified, deleted or unable_to_verify |
overdue | True if the due date has passed without an outcome |
changes | For modified records, exactly what changed |
A “not me” dispute, call by call
| When | What happens | What your platform receives |
|---|---|---|
| Day 0 | The candidate disputes a registry record as not theirs in the consumer portal. | dispute.created to you, origin consumer_portal |
| Day 1 | Status moves to investigating; the registry that holds the record is checked again. | dispute.updated |
| Day 9 | The candidate adds a photo ID statement through you; you post it as new information. | dueAt extended by 15 days |
| Day 12 | The registry entry’s date of birth does not match the candidate’s. Outcome: deleted. | dispute.updated with outcome |
| Day 12 | The record is suppressed from future orders about the candidate. | record.corrected to every partner that received it |
Twelve days, not thirty — because the match evidence and the source are already on the order, the reinvestigation starts from what was furnished rather than from scratch.
Extending the period when new information arrives
When the consumer sends relevant information during the 30 days, the statute allows up to 15 more. Post it with POST /v1/fcra/disputes/{id}/information and the dispute’s dueAt moves out by 15 days, with extendedAt recording when. The extension can be used once; a second call, a call after the outcome, or one after the due date returns 409 dispute_not_extendable.
How the API maps to your own dispute duties
As the consumer reporting agency, you own the dispute with the consumer: the 30-day reinvestigation, the written result within five business days of finishing, and notice to past recipients when the consumer asks for it (15 U.S.C. § 1681i). When a disputed item came from a supplier, the supplier has to be told promptly so it can reinvestigate its part.
Opening the dispute in the API is that notice, and its outcome is the supplier’s answer. The outcome, the changes and the list of partners that received the record give you what you need for the result letter and any notices to past recipients. Disputes the consumer files with us directly reach you as dispute.created, so nothing is filed where you cannot see it. The general process is explained in FCRA disputes for public records.
Where dispute handling usually breaks
- Disputes that live in an inbox. Without a due date on an object, the 30 days run out unnoticed.
- Re-checking a stored copy. The reinvestigation has to go back to the court or registry that holds the record.
- Fixing one report and nothing else. Every partner that received the record needs the correction, and later orders must not reinsert it.
- Consumer disputes you never hear about. If the consumer contacts the supplier directly, the screening company still needs to know.
- No record of what was furnished. A dispute is decided against what the report said on the day; keep the evidence.
What the consumer sees while you work
In the consumer portal, the person sees the same dispute in plain language: the records they disputed, the reason they gave, the date it was received, the date it is due, and the outcome once there is one — including what changed. They never see your internal notes, other orders, or anything that was withheld.
That shared view is the point. When the consumer and the screening company look at the same status and the same due date, there is far less back-and-forth, and far fewer disputes escalate into complaints because someone did not know where things stood.
A dispute, start to finish
Every dispute follows the same four steps, on the same 30-day clock.
1. Received
You open the dispute through the API, or the consumer opens it in the portal. The 30-day clock starts from when the dispute reached you.
2. Investigating
The record is checked again with the authority that holds it — the registry or the court — not against our own copy.
3. Outcome
Verified, modified, deleted, or unable to verify — and a record that cannot be verified in time is treated as deleted.
4. Correction fan-out
A changed or removed record is corrected or suppressed in every later order, and every partner that received it gets a record.corrected event.
Four outcomes, each with a consequence
verified
The record was confirmed with the authority that holds it, as furnished. Nothing changes, and you have the confirmation on the dispute.
modified
The record was corrected. changes lists exactly what changed, and the correction applies to every later order about the consumer.
deleted
The record was removed, or found not to be the consumer’s. It is suppressed from every later order about them.
unable_to_verify
It could not be verified in time. Under the statute an unverifiable item is deleted, and it is suppressed the same way.
Timing and the treatment of unverifiable items follow 15 U.S.C. § 1681i. This is background, not legal advice.
Three events keep your platform in step
dispute.created
A dispute was opened on one of your orders — by you, or by the consumer in the portal. Start your own consumer timeline from it.
dispute.updated
The status changed — investigating, then an outcome. Fetch the dispute to read what changed.
record.corrected
A record you received was modified or removed by any partner’s dispute. Update your copy of the report.
Every event is signed and carries identifiers only. Webhooks & events
The consumer can dispute without calling you
Every order carries an access code. Put it in your pre-adverse notice and the consumer can see exactly what we furnished and dispute any item themselves — the dispute lands on your order, on the same clock. How the consumer portal works.
From agreement to your first order
Regulated access is a separate grant on your account, not a setting you can turn on yourself.
1. Agree the scope
We review your business and the permissible purposes you serve, and sign a written FCRA agreement that fixes those purposes, your end-user certifications and the controls applied to every answer.
2. We enable your key
Regulated access is switched on for your account only after the agreement is signed, and only for the purposes it names. Standard self-serve access stays exactly as it was, and never carries regulated use.
3. Register end users, then place orders
Register each employer or landlord once, with its permissible purposes and your certification. Each order then names the end user, the purpose and your consent attestation, carries the consumer’s full name and date of birth, and runs a sex-offender search, a criminal search, or both.
4. Get an answer you can stand behind
Orders run in the background and report back by signed webhook. Each search runs live in the states that matter and comes with a source-by-source coverage table. Only records that pass every control are furnished, each with its match evidence and the time it was verified; everything else is a count by reason, and the whole order is kept as evidence.
FCRA dispute API questions
How long does an FCRA dispute take?
The statute gives the agency 30 days from receipt, extendable by 15 days if the consumer sends relevant information during that time. Every dispute object carries its dueAt, and extendedAt when the extension is used, so your platform always knows the deadline.
Can I test disputes in the sandbox?
Yes. A sandbox subject with the last name Dispute returns a record whose dispute resolves as deleted shortly after you open it, so you can exercise the whole flow — events, suppression and the correction notice — without a real consumer.
What does opening a dispute through the API replace?
The email chains and portal tickets most data providers use. You get an object with a clock, a status, an outcome and events, and the consumer gets the same view in the portal.
Can one dispute cover more than one record?
Yes. recordIds takes every furnished record the consumer disputes on that order, and the dispute resolves with one outcome for all of them. When the records need different answers — a registry entry and an unrelated court case, say — open one dispute per record so each gets its own outcome and clock.
Who reinvestigates — you or us?
We reinvestigate what we furnished, with the registry or court that holds the record, and report the outcome back to you. You keep your own obligations to the consumer as the agency that issued their report — your notices and your timeline.
When does the 30-day clock start?
From receivedAt — when the dispute reached you, or when the consumer filed it in the portal. dueAt is 30 days later. If the consumer provides new information during the period, it can extend by up to 15 days, and extendedAt records when (15 U.S.C. § 1681i(a)(1)).
What happens if a record cannot be verified in time?
It is treated as deleted: removed from your report’s furnished set for later orders and suppressed for that consumer. The statute treats an item that cannot be verified the same way as an inaccurate one.
Will a deleted record come back in a later order?
No. A deleted or unverifiable record is suppressed — withheld under disputed_suppressed from every later order about the same consumer, for every partner.
How do I learn about disputes the consumer files directly?
A portal dispute on one of your orders arrives as dispute.created, with origin consumer_portal, and every change after that as dispute.updated. GET /v1/fcra/disputes lists every dispute on your orders.
Does the reinvestigation start from what was furnished?
Yes. The order’s evidence record holds the coverage for each search and the hash-pinned captures from every live check — so the reinvestigation starts from exactly what was reported and when, and is then checked again with the authority that holds the record.
Which records can be disputed?
Any record furnished in the order, by its recordId. Withheld records were never furnished, so there is nothing about them in your report to dispute.
Hand reinvestigation to an API
Tell us about your dispute volume and the purposes you serve. We will set up the agreement and walk your team through the dispute flow in the sandbox.
Request FCRA Partner Access How the program works
FCRA pricing is quoted per partner — contact us for pricing. Standard self-serve access is separate and is not a consumer report.