> ## Documentation Index
> Fetch the complete documentation index at: https://www.finta.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Retrieve company

> Returns the authenticated company's metadata including legal details and address.



## OpenAPI

````yaml /openapi.yaml get /company
openapi: 3.0.3
info:
  title: Finta API
  version: '1.0'
  description: >
    The Finta API provides programmatic access to your company's financial data,

    including transactions, journal entries, categories, and financial reports.


    ## Authentication


    Each API key is scoped to a single company. There is no company ID
    parameter.

    The key already knows which company it belongs to. If you have access to
    multiple

    companies, create a separate key for each.


    Authenticate by including your API key in the `Authorization` header:


    ```

    Authorization: Bearer finta_...

    ```


    ### Key prefix convention


    Every Finta credential is prefixed so it can be recognized at a glance in
    logs, error messages, and secret scanners. Today there is one credential
    type and its prefix is `finta_`. As additional credential or token types are
    introduced (for example restricted keys or webhook signing secrets), each
    will have its own distinct prefix that stacks on the brand prefix (e.g.
    `finta_<type>_...`). Treat the prefix as load-bearing: do not strip it
    before sending, and do not assume a missing or unknown prefix is still a
    Finta credential.


    ## Rate Limits


    The API enforces two independent limits. Both surface as `429 Too Many
    Requests`, but they are distinct error codes with different retry guidance.


    ### Per-minute burst limit


    Authenticated requests are limited to **6,000 requests per 60 seconds** (100
    per second) per API key. Unauthenticated requests (missing or invalid key)
    are limited to **120 requests per 60 seconds** per IP address.


    The window is **fixed**, not rolling. Each 60-second wall-clock interval is
    its own counter; all requests within that interval share it, and the counter
    resets to 0 in a single step at the next boundary. Available budget jumps
    from `0` back to the full bucket size (`6000` for authenticated API keys,
    `120` for unauthenticated IP buckets) instantaneously at the boundary,
    rather than aging out one slot at a time. Trust `X-RateLimit-Reset` for the
    exact reset timestamp.


    Every authenticated response (including 429s for this case) includes:


    | Header | Description |

    |--------|-------------|

    | `X-RateLimit-Limit` | Maximum requests per window (`6000` for
    authenticated requests, `120` for unauthenticated). |

    | `X-RateLimit-Remaining` | Requests remaining in the current window. |

    | `X-RateLimit-Reset` | Unix timestamp when the window resets. |


    On a 429 for this case, an additional header is included:


    | Header | Description |

    |--------|-------------|

    | `Retry-After` | Number of seconds until the next request is safe. |


    The error body is `type: rate_limit_error` / `code: rate_limit_exceeded`.


    **Retry guidance:** This case is retryable. Honor `Retry-After` as the
    minimum wait, then apply exponential backoff with jitter for any retries
    beyond the first (cap at a few minutes; abandon after a small number of
    attempts to avoid retry storms). Do not retry tighter than `Retry-After`.


    ### Monthly per-company limit


    Each company has a monthly cap on total API calls, independent of the
    per-minute burst:


    | Plan | Monthly cap |

    |------|-------------|

    | Formation | 10 |

    | Startup | 300 |

    | Growth | 30,000 |


    Counts reset at **midnight Pacific Time (US & Canada)** on the 1st of each
    month. This is the Finta application's configured time zone; the cap is
    computed in that zone, not in UTC. Consumers in other time zones should
    convert the local-midnight Pacific boundary to their own clock; note that
    the absolute UTC offset shifts by one hour twice a year for daylight saving
    (PST is UTC-8, PDT is UTC-7). Blocked requests are not counted toward the
    limit. The error body is `type: limit_error` / `code:
    monthly_limit_exceeded`, and the `message` field includes the reset date in
    human-readable form.


    **Retry guidance:** This case is **not retryable in the short term.** No
    `Retry-After` header is sent, deliberately, because the only meaningful
    remediation is to upgrade the plan (Settings -> Plans at app.finta.com) or
    wait until the 1st of the next month. Naive retry loops should branch on
    `error.code` and stop retrying when they see `monthly_limit_exceeded`. SDKs
    that auto-retry on 429 should look at `error.code` (or the absence of
    `Retry-After`) before re-issuing.


    ## Pagination


    List endpoints use cursor-based pagination. Pass `limit` to control page
    size

    (default 100, max 500). To fetch the next page, pass `starting_after` with
    the

    `next_cursor` value from the previous response. Responses include `object:
    "list"`,

    `url` (the canonical path of the collection, relative to the API host),
    `has_more`

    (whether more results exist), `next_cursor` (the ID to pass as
    `starting_after`),

    and `data` (the page of items).


    ## Amounts


    Every monetary field in the API follows two non-negotiable rules:


    1. **Integer cents.** Monetary values are integers, never floats and never
    formatted strings. `$499.00` is `49900`. `$1,500.00` is `150000`. Divide by
    100 to get dollars. This avoids floating-point precision errors in financial
    calculations.

    2. **`_cents` suffix.** The field name always ends in `_cents` (e.g.
    `amount_cents`, `balance_cents`, `total_cents`, `net_income_cents`,
    `change_in_cash_cents`, `cash_cents`). If a field name does not end in
    `_cents`, it is not a monetary value.


    These rules apply to every monetary field across every endpoint
    (transactions, journal entries, income statement, balance sheet, cash flow).
    There are no exceptions and there is no "summary" or "display" sibling field
    that returns the same amount in dollars or as a string. If you encounter a
    field that appears to hold a monetary value but does not end in `_cents`, or
    whose value is not an integer, treat it as a bug and report it.


    Sign conventions:


    - **Income statement**: revenue/income amounts are positive, expense amounts
    are negative. Summing every section's `total_cents` yields net income
    without sign-flipping.

    - **Balance sheet**: `balance_cents` carries the natural-sign cumulative
    balance for that account at the report date.

    - **Cash flow**: `amount_cents` is positive for cash inflows and negative
    for cash outflows.


    ## Errors


    Errors return a consistent JSON structure:


    ```json

    {
      "error": {
        "type": "invalid_request_error",
        "code": "resource_missing",
        "message": "The requested resource was not found.",
        "doc_url": "https://www.finta.com/docs/api-reference/errors#resource_missing"
      }
    }

    ```


    ### Status codes


    | Status | Meaning |

    |--------|---------|

    | `200 OK` | Request succeeded. |

    | `400 Bad Request` | Request was malformed or had invalid parameters. |

    | `401 Unauthorized` | The bearer credential is missing, malformed, or
    unrecognized. The fix is to obtain a valid API key. |

    | `403 Forbidden` | The API key is valid, but the caller does not have
    permission to access the resource. The fix is to regain access (reactivate
    the user, restore company access, restore an active subscription), not to
    get a new key. See the `Forbidden` response component for the four specific
    codes. |

    | `404 Not Found` | The requested resource, or the endpoint itself, does not
    exist. Unknown or renamed paths (for example an old hyphenated report path
    like `/reports/income-statement` instead of `/reports/income_statement`)
    return this same envelope with `type: invalid_request_error` and `code:
    resource_missing`, as JSON, regardless of the `Accept` header. |

    | `429 Too Many Requests` | Either the per-minute burst rate limit
    (retryable, with `Retry-After`) or the monthly per-company API call limit
    (not retryable in the short term, no `Retry-After`). Branch on `error.code`
    to distinguish the two and avoid retry storms on monthly exhaustion. See the
    Rate Limits section for the full retry guidance. |

    | `5xx` | An unexpected error on Finta's side. Retry with exponential
    backoff. |


    The `error.type` and `error.code` fields are stable identifiers safe to
    switch on programmatically. The `error.message` is human-readable and may
    change without notice.
servers:
  - url: https://app.finta.com/api/v1
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Company
    description: Retrieve company metadata
  - name: Categories
    description: List your chart of accounts categories
  - name: Transactions
    description: >
      Transactions are what your bank shows you: a single line like "AWS charged
      you $499."

      Most API consumers want transactions. For accounting-level detail, see
      Journal Entries.


      Amounts are in cents (e.g. `amount_cents: 49900` = $499.00).
  - name: Journal Entries
    description: >
      Journal entries are the accounting records that transactions create. A
      single $499 AWS

      charge becomes two journal entries: debit Software $499, credit Cash $499
      (double-entry

      bookkeeping). Use journal entries when you need accounting-level detail.


      Amounts are in cents (e.g. `amount_cents: 49900` = $499.00).
  - name: Reports
    description: >
      Financial statements: income statement, balance sheet, and cash flow. Each
      report

      returns the complete statement for a single period. You cannot filter to
      one category

      or request multiple periods in one call.
paths:
  /company:
    get:
      tags:
        - Company
      summary: Retrieve company
      description: >-
        Returns the authenticated company's metadata including legal details and
        address.
      operationId: getCompany
      responses:
        '200':
          description: The company object
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Company'
              example:
                id: comp_a1b2c3d4e5f6g7
                object: company
                name: Acme Corp
                legal_name: Acme Corp Inc.
                entity_type: c_corp
                federal_ein_last4: '6789'
                delaware_file_number: '1234567'
                incorporation:
                  date: '2022-10-21'
                  state: DE
                legal_address:
                  line_1: 548 Market Street
                  line_2: PMB 39381
                  city: San Francisco
                  state: CA
                  postal_code: '94104'
                  country: US
                created: 1688053841
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '429':
          $ref: '#/components/responses/RateLimited'
components:
  schemas:
    Company:
      type: object
      required:
        - id
        - object
        - name
        - created
      properties:
        id:
          type: string
          description: Unique identifier with `comp_` prefix.
          example: comp_a1b2c3d4e5f6g7
        object:
          type: string
          enum:
            - company
        name:
          type: string
          description: The company's preferred display name.
          example: Acme Corp
        legal_name:
          type: string
          nullable: true
          description: The company's legal name.
          example: Acme Corp Inc.
        entity_type:
          type: string
          nullable: true
          enum:
            - c_corp
            - pbc
            - llc
            - s_corp
            - other
          description: >-
            Legal entity type. Closed enum: `c_corp` (C corporation), `pbc`
            (public benefit corporation), `llc` (limited liability company),
            `s_corp` (S corporation), `other` (any other legal structure the
            company self-identified). Returns `null` when the company has not
            yet completed the onboarding step that captures legal structure. New
            values may be added over time as the onboarding questionnaire grows;
            consumers should treat unrecognized values defensively.
          example: c_corp
        federal_ein_last4:
          type: string
          nullable: true
          description: >-
            Last 4 digits of the company's Federal Employer Identification
            Number. The full EIN is not exposed via the API.
          example: '6789'
        delaware_file_number:
          type: string
          nullable: true
          description: Delaware file number, if applicable.
        incorporation:
          type: object
          nullable: true
          properties:
            date:
              type: string
              nullable: true
              format: date
              description: Date of incorporation (YYYY-MM-DD).
            state:
              type: string
              nullable: true
              description: State of incorporation (USPS 2-letter code, uppercase).
              example: DE
        legal_address:
          type: object
          nullable: true
          properties:
            line_1:
              type: string
              nullable: true
              example: 123 Main St
            line_2:
              type: string
              nullable: true
              example: Suite 100
            city:
              type: string
              nullable: true
              example: San Francisco
            state:
              type: string
              nullable: true
              description: State (USPS 2-letter code, uppercase).
              example: CA
            postal_code:
              type: string
              nullable: true
              example: '94105'
            country:
              type: string
              nullable: true
              description: Country (ISO 3166-1 alpha-2 code).
              example: US
        created:
          type: integer
          description: Unix timestamp of when the company was created.
          example: 1737000000
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - type
            - code
            - message
            - doc_url
          properties:
            type:
              type: string
              enum:
                - authentication_error
                - permission_error
                - invalid_request_error
                - rate_limit_error
                - limit_error
              description: >-
                The error category. `authentication_error` (401) means the
                bearer credential was missing, malformed, or unrecognized.
                `permission_error` (403) means the credential was valid but the
                caller is not allowed to access the resource. `rate_limit_error`
                is for per-minute burst limits (retry shortly). `limit_error` is
                for monthly API call limits per company (upgrade or wait for
                reset).
            code:
              type: string
              enum:
                - invalid_api_key
                - user_inactive
                - user_removed_from_company
                - company_closed
                - subscription_required
                - resource_missing
                - parameter_missing
                - category_update_failed
                - rate_limit_exceeded
                - monthly_limit_exceeded
                - invalid_date_range
                - invalid_date
              description: A specific error code.
            message:
              type: string
              description: A human-readable description of the error.
            doc_url:
              type: string
              format: uri
              description: A link to documentation about this error.
              example: https://www.finta.com/docs/api-reference/errors#invalid_api_key
            param:
              type: string
              nullable: true
              description: The parameter that caused the error, if applicable.
  responses:
    Unauthorized:
      description: >-
        Authentication failed. Returned when the bearer credential itself is
        missing, malformed, or unrecognized. The consumer should obtain a valid
        API key and retry. This is distinct from `403 Forbidden`, which is
        returned when the credential is valid but the caller is not allowed to
        access the resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              type: authentication_error
              code: invalid_api_key
              message: >-
                Invalid API key provided. Check that your API key is correct and
                active.
              doc_url: https://www.finta.com/docs/api-reference/errors#invalid_api_key
    Forbidden:
      description: >-
        The API key was successfully authenticated, but the caller is not
        allowed to access this resource. The fix is not "get a new key" (that
        returns 401) but "regain access" (reactivate the user, restore company
        access, restore an active subscription). Four codes can be returned,
        distinguished by `error.code`:
          - `user_inactive` - the user that owns the API key has been deactivated.
          - `user_removed_from_company` - the user no longer has access to the company the key was created for.
          - `company_closed` - the company is closed, closing, or deleted.
          - `subscription_required` - the company does not have an active subscription.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            user_inactive:
              summary: User has been deactivated
              value:
                error:
                  type: permission_error
                  code: user_inactive
                  message: >-
                    The user associated with this API key is no longer active.
                    Reactivate the user or create a new API key under an active
                    user.
                  doc_url: >-
                    https://www.finta.com/docs/api-reference/errors#user_inactive
            user_removed_from_company:
              summary: User no longer has access to this company
              value:
                error:
                  type: permission_error
                  code: user_removed_from_company
                  message: >-
                    The user associated with this API key no longer has access
                    to this company. Ask a company admin to re-grant access,
                    then create a new API key.
                  doc_url: >-
                    https://www.finta.com/docs/api-reference/errors#user_removed_from_company
            company_closed:
              summary: Company is closed
              value:
                error:
                  type: permission_error
                  code: company_closed
                  message: >-
                    This company is closed. The API is not available for closed
                    companies.
                  doc_url: >-
                    https://www.finta.com/docs/api-reference/errors#company_closed
            subscription_required:
              summary: Company subscription is not active
              value:
                error:
                  type: permission_error
                  code: subscription_required
                  message: >-
                    This company does not have an active subscription. Visit
                    Settings -> Plans at app.finta.com to resolve, then retry.
                  doc_url: >-
                    https://www.finta.com/docs/api-reference/errors#subscription_required
    RateLimited:
      description: >-
        Too many requests. Two distinct limits can trigger a 429: (1) Per-minute
        burst limit (6,000 requests per 60 seconds per API key) returns
        `rate_limit_error` / `rate_limit_exceeded` with `Retry-After` header.
        (2) Monthly API call limit per company returns `limit_error` /
        `monthly_limit_exceeded` with the reset date in the message. Monthly
        limits vary by plan: Formation (10/month), Startup (300/month), Growth
        (30,000/month). Blocked requests do not count toward the limit.
      headers:
        Retry-After:
          schema:
            type: integer
          description: >-
            Seconds until the burst rate limit resets. Only present for
            rate_limit_error responses.
        X-RateLimit-Limit:
          schema:
            type: integer
          description: >-
            Maximum requests per burst window. Only present for rate_limit_error
            responses.
        X-RateLimit-Remaining:
          schema:
            type: integer
          description: >-
            Requests remaining in burst window (0 when rate limited). Only
            present for rate_limit_error responses.
        X-RateLimit-Reset:
          schema:
            type: integer
          description: >-
            Unix timestamp when the burst window resets. Only present for
            rate_limit_error responses.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            burst_rate_limit:
              summary: Per-minute burst rate limit exceeded
              value:
                error:
                  type: rate_limit_error
                  code: rate_limit_exceeded
                  message: >-
                    Too many requests. Please retry after the Retry-After
                    period.
                  doc_url: >-
                    https://www.finta.com/docs/api-reference/errors#rate_limit_exceeded
            monthly_limit:
              summary: Monthly API call limit exceeded
              value:
                error:
                  type: limit_error
                  code: monthly_limit_exceeded
                  message: >-
                    Monthly API limit reached. Your plan allows 300 calls per
                    company per month. Resets on April 1, 2026. Upgrade in
                    Settings -> Plans at app.finta.com.
                  doc_url: >-
                    https://www.finta.com/docs/api-reference/errors#monthly_limit_exceeded
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key prefixed with `finta_`

````