Authentication
Every endpoint in the official Datapublica Business Register API requires a personal API token and a paid Datapublica plan. Free-plan accounts cannot create or use API tokens.
Token model
- A user can have one active personal API token.
- Create, view, or revoke the token in App settings.
- Requests made with the token resolve to its owner.
- The owner's account status, plan capabilities, and user-level usage limits apply.
- Revocation takes effect for subsequent requests.
The token is a credential. Store it in a secret manager or server-side environment variable. Do not embed it in client-side JavaScript, mobile application bundles, source control, URLs, screenshots, logs, or prompts sent to third parties.
Bearer header
Send the token in the HTTP Authorization header on every API request:
Authorization: Bearer <token>
Example:
curl --get 'https://query.datapublica.dk/api/companies/search' \
--header "Authorization: Bearer $DATAPUBLICA_API_TOKEN" \
--data-urlencode 'q=chr'
Use HTTPS and the canonical API host https://query.datapublica.dk.
Create and revoke a token
- Sign in at datapublica.dk.
- Open App settings.
- Create the token and copy it into secure server-side storage.
- Return to settings to view the active token or revoke it.
To rotate the credential, revoke the active token and then create a new one. Creating another token while one is active is not available because only one token can be active for a user.
Authentication failures
Missing, malformed, unknown, or revoked tokens return 401 with an error body:
{
"error": "Invalid bearer token"
}
A missing header returns the same response shape with a message indicating that the bearer token is missing. A suspended owner returns 403. A token whose owner is on the Free plan also returns 403 with code: "paid_plan_required".
Do not retry 401 responses without correcting or replacing the credential. See Errors for the complete error model.
Browser and cross-origin requests
The API accepts the Authorization header in cross-origin requests. A browser application would expose a personal token to the end user and to client-side code, so call the API from a trusted server unless the token owner explicitly controls that browser environment.
Support
Use the support page for token problems. Share the HTTP status and x-request-id, never the token itself.