
API integration for API Particulier
We build your API Particulier connector
API Particulier is not open data. It is the DINUM « Tell us once » bundle, under a DataPass authorisation, for a local authority or a vendor carrying a public-service mission. We scope the authorisation, then the connector.
- Senior product team
- public-data connectors in production
- from scoping to monitoring
What does the API Particulier provide and who is it for?
The API Particulier gives access to a citizen's official personal data: family quotient, job-seeker status, scholarship, disability benefit, with their consent, without requiring supporting documents. It is reserved for government bodies, local authorities and private organisations carrying out a public service mission authorised by DataPass. You integrate it into a benefits portal to simplify administrative procedures: the user identifies themselves, the application automatically verifies eligibility, and the collection of documents the State already holds is eliminated.
What our clients build on API Particulier
Social pricing for canteen / holiday care
The CAF/MSA family quotient arrives when the family file is opened, no uploaded certificate and no agent re-keying.
CCAS casework
RSA, AAH, C2S, activity allowance without a pile of PDFs, within the authorised scopes, nothing more.
Secondary and student grants
Enrolled / grant status, Cnous status. The user does not re-submit a document the administration already holds.
Childhood vendor, one token, N municipalities
Publisher delegation: recipient = client SIRET, unit revocation, no more a spreadsheet of tokens.
What it changes in your citizen procedures
Engineering in service of a measurable outcome: a certified quotient, a tenable authorisation, not a private HR SaaS refused at DataPass.
This is not open data
Without a public-service mission and DataPass accreditation, there is no production access. Passing staging proves nothing.
Editor delegation changes the commercial model
One editor access, N municipalities. You no longer store hundreds of commune tokens in a spreadsheet.
Everything goes through your server
No browser call: the token would stay exposed. The journey stays secured on the back end.
A fallback if the provider is down
CAF, MSA, France Travail… We detect unavailability, and the user can still upload the proof.
How we ship your API Particulier connector
Scoping
Authorisation, purpose, scopes, FranceConnect or pivot identity, publisher model or authority token. DataPass before code.
Development
Token in a managed secret, recipient, a queue under 20 req/s, 5 s timeout, never log user data, provider pings.
Acceptance testing
Tests for 401 / 403 / 409 / 422, staging then production, a document fallback UX if the API does not answer.
Monitoring
X-Request-ID, RateLimit-Remaining, status page, alert before a ban. You see a 429 before the 12-hour ban.
What API Particulier allows
- CAF / MSA family quotient
- Household composition and QF, pivot identity or FranceConnect depending on the API. That is the canteen / conservatory / school-transport flow.
- Social benefits
- RSA, activity allowance, AAH, ARS, ASF, C2S, AEEH, within authorised scopes. Never a 200 empty « because of scopes »: a 403 if no scope matches.
- Schooling and grants
- Enrolled / grant status, higher-education enrolment, Cnous grant. Call modes: pivot identity, FranceConnect or a business id (INE).
- Publisher delegation
- One publisher token, recipient = SIRET, list of delegations, delegation_id if several on the same SIRET. Rate-limit and scopes = the client's.
The vocabulary of API Particulier
- DataPass
- The authorisation: legal basis, purpose, minimisation, security. Without an approved DataPass, no production token. Staging does not prejudge it.
- Scopes
- They hide unauthorised fields. A 403 if no scope matches the endpoint, never a 200 empty. GET /api/introspect lists those on the token.
- recipient
- SIRET of the beneficiary, mandatory on FranceConnect APIs and in publisher delegation. Forgetting recipient is a 4xx, not a « it will work in prod ».
- Pivot identity / FranceConnect
- Two call modes. FranceConnect is not optional on part of the catalogue (vehicle, several benefits). Mixing the two DataPass applications is a classic.
- Publisher delegation
- One publisher token, N clients, GET /editeur/api/v1/delegations, delegation_id if several delegations on the same SIRET. Rate-limit = the client's authorisation.
- 12 h ban
- Ignoring 429s, or exceeding the IP ceiling, bans the IP for 12 hours, not revocable, with no HTTP code: the server simply stops answering. Bulk batches run at night.
The real constraints of API Particulier
Authorisation before code
Without DataPass, no production. A private HR SaaS with no public-service mission will be refused. We say so before writing a line, not after six sprints.
20 per second, 1,000 per minute, then a ban
Official ceilings, RateLimit-* headers, Retry-after on 429. A back-to-school peak is sized on that, not « we'll see ». Queue, backoff, no retry on 409.
Neither API Entreprise nor France Travail Offers
API Entreprise = companies, admin authorisation. FT Offers = job board, dev account. Jobseeker status here serves a social procedure, not an ATS.
Front end forbidden
CORS refused, a token in the browser is a security incident. The user who does not pass the API must still be able to upload the document: the file is not thrown away.
API Particulier or API Entreprise?
Two DINUM bundles, two authorisations, two audiences. Search engines mix them up.
| Criterion | API ParticulierA person's data | API EntrepriseA company's data |
|---|---|---|
| Subject | A person (QF, benefits, schooling) | A company (certificates, deeds, headcount) |
| Access | DataPass, public-service mission | Administration authorisation |
| Open data | No | No |
| Front end | Forbidden, CORS refused | Back end only |
| Documented rate | 20/s per authorisation, 1,000/min per IP | Depends on the authorisation |
| Publisher model | Yes, delegations by SIRET | Depends on the publisher offer |
| The right case | Canteen, CCAS, grants | Public procurement, company aid |
Neither is an open register. A private vendor with no authorised public user gets neither. That is a scoping call, often a no.
What we measure on an API Particulier integration
The other public APIs
These bricks come up during scoping; none of them replaces a DataPass.
API ParticulierWe build your API Particulier connectorThis page
API AdresseBAN geocoding, open, no key. Useful to the file, unrelated to the QF.
Météo FranceWarnings and observations, portal account, not a person's data.
URSSAFStatistical open data or employer DPAE. Not an allottee's family quotient.
SNCF & transportWe build your SNCF connector
France TravailWe build your France Travail connector
DVF & cadastreWe build your DVF and cadastre connector
LegifranceWe build your Légifrance connector
API GéoWe build your API Géo connectorWe combine API Particulier with
The stack around a citizen procedure on our projects.
API Particulier integration: your questions
DataPass authorisation first (purpose, minimisation, security), JWT token in a managed secret, back-end calls only. Honour recipient and scopes, test 401 / 403 / 409 / 422. A queue under 20 requests a second, backoff on 429 / 502 / 503, no aggressive retry on 409, batches at night. A 5 s timeout and a fallback UX: if the API does not answer, the user uploads the document. Staging has a public token: passing staging does not prejudge production authorisation.
No. It is an authorised service, CRPA L. 114-8, for a public-service mission. A commercial SaaS vendor with no authorised local-authority client does not get it for its own account. There is no open-data equivalent of the family quotient. Selling a connector « for our private HR SaaS » that will be refused at DataPass is the first error on this page. If there is no public-service mission, we stop the quote and we propose something else, or nothing.
API Particulier talks about a person (QF, benefits, schooling). API Entreprise talks about a company (certificates, deeds), for administrations. Both are under authorisation, neither is open. Jobseeker status in API Particulier is not France Travail's Offers API. Three products, three authorisations, three nos if you pick the wrong target. Jobseeker status in API Particulier is not France Travail Offers either: a third product, a third no.
429, RateLimit-* headers, Retry-after. If you ignore 429s, a 12-hour IP ban, not revocable: the server stops answering, including for the other tokens on the same IP. That is how a back-to-school peak is sized. A queue, backoff, no naive parallelism, batches off peak. A back-to-school peak is sized on these ceilings: a queue, backoff, night batches, never naive parallelism from the front end. Night batches are the official recommendation for bulk work.
The API is free after authorisation. The cost is DataPass (legal, security, often an accreditation questionnaire) plus the connector (delegation, queue, fallback, logging without user data). One authority, one QF flow, is a measured job. A vertical vendor, N municipalities, FranceConnect on top, is an architecture project. We scope the authorisation before we quote the code. The security questionnaire and accreditation often required in DataPass weigh as much as the code, sometimes more.
An API Particulier integration project?
Let's talk. 30 minutes to check whether a DataPass is tenable, what the catalogue actually allows, and tell you frankly what is feasible.
Discuss my API Particulier project