SIRF Developer API
Connect your server to published SIRF metadata using the versioned, read-only API. Developer keys do not grant access to private accounts, claim evidence, moderation tools or full lyrics.
Developer access is not activated yet. Issuance, revocation and security checks must pass before keys are enabled.
Authentication and keys
Create keys from your verified account when access is enabled. Each key is shown once, expires after 90 days and can be revoked. At most five active keys are allowed per account. Store the secret in your server environment; never put it in public browser code, query strings, screenshots or support messages.
Send the key in the Authorization header. Keys are scoped to selected datasets; possession of a key does not override profile privacy or source restrictions. Revoked keys and disabled, unverified or suspended accounts cannot use the API.
curl 'https://sirf.one/api/v1/music?limit=25' -H 'Authorization: Bearer YOUR_API_KEY'
Endpoints and returned data
/api/v1/companies— published company name, CIN, state, status, incorporation date and canonical link. Scope: companies.read./api/v1/music— published recording title, credited artist, language, stored release date and canonical link. Scope: music.metadata.read. This is not a full-lyrics or audio distribution API./api/v1/directories— approved source-backed directory records and public provenance. Supply category, such as post-offices or railway-stations. Scope: directories.read./api/v1/ifsc— approved bank-branch lookup data, excluding contact numbers. Scope: ifsc.read. Confirm banking details with the bank before a transfer.
Directory and IFSC exports are denied until the operator explicitly approves the relevant source for API redistribution. Website visibility alone is not a redistribution licence. Preserve source attribution and dated provenance; do not imply government, bank or artist endorsement.
Search and pagination
Use q for a search query of up to 80 characters, limit for a page size from 1 to 50, and id for an exact record identifier. Responses contain api_version, data and pagination. When pagination.next_cursor is non-null, send it unchanged as cursor on the next request, keeping the same query and category. Do not assume cursors are interchangeable between endpoints. Data may change between requests.
Company id is the CIN. Music id can be the recording identifier or slug. Directory id is paired with category, and IFSC id is the branch code. Optional dates can be null; an import date is not a verified release date.
Limits, errors and responsible use
Each key allows up to 1,000 authenticated requests per UTC day and 30 per minute, enforced through shared server-side counters. Authenticated requests consume quota even when a query is invalid or a record is absent. Read X-RateLimit-Remaining and respect Retry-After. Do not create multiple keys to circumvent limits.
Expect 400 for invalid queries, 401 for invalid or expired keys, 403 for denied scopes or unapproved exports, 404 for unsupported routes or missing company records, 429 for quota exhaustion and 503 when access or a source is unavailable. Lists can be empty; no uptime or coverage guarantee is made. Treat errors as errors rather than empty datasets, and use bounded retry backoff for temporary failures.
No payment or investment API is included in this release. Report suspected privacy or authorization issues privately through our security reporting page. For expanded access, contact business@sirf.one without sending your key.