CIIFragments Studio is CII-accredited: recover up to 20% of your software development spendLearn more

API integration for API Particulier

We build your API Particulier connector

API Particulier is not open data. It is the DINUM « Tell us once » bundle, under a DataPass authorisation, for a local authority or a vendor carrying a public-service mission. We scope the authorisation, then the connector.

  • Senior product team
  • public-data connectors in production
  • from scoping to monitoring
In short

What does the API Particulier provide and who is it for?

The API Particulier gives access to a citizen's official personal data: family quotient, job-seeker status, scholarship, disability benefit, with their consent, without requiring supporting documents. It is reserved for government bodies, local authorities and private organisations carrying out a public service mission authorised by DataPass. You integrate it into a benefits portal to simplify administrative procedures: the user identifies themselves, the application automatically verifies eligibility, and the collection of documents the State already holds is eliminated.

Use cases

What our clients build on API Particulier

01

Social pricing for canteen / holiday care

The CAF/MSA family quotient arrives when the family file is opened, no uploaded certificate and no agent re-keying.

02

CCAS casework

RSA, AAH, C2S, activity allowance without a pile of PDFs, within the authorised scopes, nothing more.

03

Secondary and student grants

Enrolled / grant status, Cnous status. The user does not re-submit a document the administration already holds.

04

Childhood vendor, one token, N municipalities

Publisher delegation: recipient = client SIRET, unit revocation, no more a spreadsheet of tokens.

For you

What it changes in your citizen procedures

Engineering in service of a measurable outcome: a certified quotient, a tenable authorisation, not a private HR SaaS refused at DataPass.

This is not open data

Without a public-service mission and DataPass accreditation, there is no production access. Passing staging proves nothing.

Editor delegation changes the commercial model

One editor access, N municipalities. You no longer store hundreds of commune tokens in a spreadsheet.

Everything goes through your server

No browser call: the token would stay exposed. The journey stays secured on the back end.

A fallback if the provider is down

CAF, MSA, France Travail… We detect unavailability, and the user can still upload the proof.

Method

How we ship your API Particulier connector

01

Scoping

Authorisation, purpose, scopes, FranceConnect or pivot identity, publisher model or authority token. DataPass before code.

02

Development

Token in a managed secret, recipient, a queue under 20 req/s, 5 s timeout, never log user data, provider pings.

03

Acceptance testing

Tests for 401 / 403 / 409 / 422, staging then production, a document fallback UX if the API does not answer.

04

Monitoring

X-Request-ID, RateLimit-Remaining, status page, alert before a ban. You see a 429 before the 12-hour ban.

The API

What API Particulier allows

CAF / MSA family quotient
Household composition and QF, pivot identity or FranceConnect depending on the API. That is the canteen / conservatory / school-transport flow.
Social benefits
RSA, activity allowance, AAH, ARS, ASF, C2S, AEEH, within authorised scopes. Never a 200 empty « because of scopes »: a 403 if no scope matches.
Schooling and grants
Enrolled / grant status, higher-education enrolment, Cnous grant. Call modes: pivot identity, FranceConnect or a business id (INE).
Publisher delegation
One publisher token, recipient = SIRET, list of delegations, delegation_id if several on the same SIRET. Rate-limit and scopes = the client's.
Glossary

The vocabulary of API Particulier

DataPass
The authorisation: legal basis, purpose, minimisation, security. Without an approved DataPass, no production token. Staging does not prejudge it.
Scopes
They hide unauthorised fields. A 403 if no scope matches the endpoint, never a 200 empty. GET /api/introspect lists those on the token.
recipient
SIRET of the beneficiary, mandatory on FranceConnect APIs and in publisher delegation. Forgetting recipient is a 4xx, not a « it will work in prod ».
Pivot identity / FranceConnect
Two call modes. FranceConnect is not optional on part of the catalogue (vehicle, several benefits). Mixing the two DataPass applications is a classic.
Publisher delegation
One publisher token, N clients, GET /editeur/api/v1/delegations, delegation_id if several delegations on the same SIRET. Rate-limit = the client's authorisation.
12 h ban
Ignoring 429s, or exceeding the IP ceiling, bans the IP for 12 hours, not revocable, with no HTTP code: the server simply stops answering. Bulk batches run at night.
Good to know

The real constraints of API Particulier

01

Authorisation before code

Without DataPass, no production. A private HR SaaS with no public-service mission will be refused. We say so before writing a line, not after six sprints.

02

20 per second, 1,000 per minute, then a ban

Official ceilings, RateLimit-* headers, Retry-after on 429. A back-to-school peak is sized on that, not « we'll see ». Queue, backoff, no retry on 409.

03

Neither API Entreprise nor France Travail Offers

API Entreprise = companies, admin authorisation. FT Offers = job board, dev account. Jobseeker status here serves a social procedure, not an ATS.

04

Front end forbidden

CORS refused, a token in the browser is a security incident. The user who does not pass the API must still be able to upload the document: the file is not thrown away.

Particulier or Entreprise

API Particulier or API Entreprise?

Two DINUM bundles, two authorisations, two audiences. Search engines mix them up.

CriterionAPI ParticulierA person's dataAPI EntrepriseA company's data
SubjectA person (QF, benefits, schooling)A company (certificates, deeds, headcount)
AccessDataPass, public-service missionAdministration authorisation
Open dataNoNo
Front endForbidden, CORS refusedBack end only
Documented rate20/s per authorisation, 1,000/min per IPDepends on the authorisation
Publisher modelYes, delegations by SIRETDepends on the publisher offer
The right caseCanteen, CCAS, grantsPublic procurement, company aid

Neither is an open register. A private vendor with no authorised public user gets neither. That is a scoping call, often a no.

Our expertise

What we measure on an API Particulier integration

20/s
authorisation ceiling our queue respects
5 s
client timeout, document fallback beyond
1 token
publisher, N authorities by delegation
4
senior developers on the project

We combine API Particulier with

The stack around a citizen procedure on our projects.

  • Node.js
  • PostgreSQL
  • Redis
  • n8n
  • TypeScript
FAQ

API Particulier integration: your questions

DataPass authorisation first (purpose, minimisation, security), JWT token in a managed secret, back-end calls only. Honour recipient and scopes, test 401 / 403 / 409 / 422. A queue under 20 requests a second, backoff on 429 / 502 / 503, no aggressive retry on 409, batches at night. A 5 s timeout and a fallback UX: if the API does not answer, the user uploads the document. Staging has a public token: passing staging does not prejudge production authorisation.

No. It is an authorised service, CRPA L. 114-8, for a public-service mission. A commercial SaaS vendor with no authorised local-authority client does not get it for its own account. There is no open-data equivalent of the family quotient. Selling a connector « for our private HR SaaS » that will be refused at DataPass is the first error on this page. If there is no public-service mission, we stop the quote and we propose something else, or nothing.

API Particulier talks about a person (QF, benefits, schooling). API Entreprise talks about a company (certificates, deeds), for administrations. Both are under authorisation, neither is open. Jobseeker status in API Particulier is not France Travail's Offers API. Three products, three authorisations, three nos if you pick the wrong target. Jobseeker status in API Particulier is not France Travail Offers either: a third product, a third no.

429, RateLimit-* headers, Retry-after. If you ignore 429s, a 12-hour IP ban, not revocable: the server stops answering, including for the other tokens on the same IP. That is how a back-to-school peak is sized. A queue, backoff, no naive parallelism, batches off peak. A back-to-school peak is sized on these ceilings: a queue, backoff, night batches, never naive parallelism from the front end. Night batches are the official recommendation for bulk work.

The API is free after authorisation. The cost is DataPass (legal, security, often an accreditation questionnaire) plus the connector (delegation, queue, fallback, logging without user data). One authority, one QF flow, is a measured job. A vertical vendor, N municipalities, FranceConnect on top, is an architecture project. We scope the authorisation before we quote the code. The security questionnaire and accreditation often required in DataPass weigh as much as the code, sometimes more.

An API Particulier integration project?

Let's talk. 30 minutes to check whether a DataPass is tenable, what the catalogue actually allows, and tell you frankly what is feasible.

Discuss my API Particulier project
Discuss my API Particulier project