
API integration for INSEE / Sirene
We build your Sirene connector
We wire the Sirene registry into your forms to the Sirene registry to prefill your forms from a SIRET, keep your customer records reliable and detect closures.
- Senior product team
- public data connectors in production
- from scoping to monitoring
What does the Sirene API provide and why integrate it to verify a company?
The Sirene API gives access to the official register of French companies maintained by INSEE: legal name, address, legal form, NAF code, headcount, administrative status (active or ceased). It allows you to identify and verify a company from its SIREN or SIRET number. You integrate it to make client onboarding reliable: confirming that a company exists and is active, pre-fill a record automatically from a SIRET entered by the user, or detect that a client has ceased trading before sending them an order or a payment reminder.
What our clients build on the Sirene API
A prefilled signup form
The prospect types a SIRET. Company name, legal form, head office address and NAF code fill themselves in, and drop-off falls.
Cleaning up your customer registry
Every existing record is matched against the registry, with a discrepancy report submitted for human validation before any bulk correction.
Watching your customer portfolio
An alert when a customer ceases trading, moves its head office or closes the establishment you invoice, before the invoice goes out.
Supplier checks before payment
The SIRET on the invoice is checked against the registry: does the establishment exist, and does it match the vendor already on file.
What it changes in your customer registry
Engineering in service of a measurable outcome: less data entry, a clean customer registry, fewer invoices lost.
A form with a single field
The SIRET is enough. The six fields nobody wanted to fill in arrive on their own, and your drop-off rate falls exactly where it is decided.
A registry that stops drifting
No more four spellings of the same company and no more APE codes invented on the fly. The data comes from the source, not from a sales rep.
Closures caught in time
You know a customer has been struck off, or that an establishment is closed, before issuing an invoice that will never be paid.
Segmentation you can act on
NAF code, headcount bracket, company category and municipality become targeting criteria, with no external list to buy.
How we ship your Sirene connector
Scoping
Which flows, what volume, what freshness the registry needs. We list the edge cases before writing a line of code.
Development
Typed connector, a limiter calibrated on the quota, a retry queue, the key isolated in a managed secret. A demo every week.
Acceptance testing
Replay on your real data, record by record discrepancy checks, and testing what happens when the API returns 429 or stops answering.
Monitoring
Alerts on sync failures, a call log, a freshness dashboard. You know a flow is broken before your teams do.
What the Sirene API allows
- Legal units by SIREN
- The company's identity: name, legal form, creation date, category, principal activity and administrative status.
- Establishments by SIRET
- Each establishment with its address, activity, headcount bracket and status, head office or secondary. That is the level you invoice.
- Multi-criteria search
- Selection by NAF code, municipality, headcount bracket or date, to build a perimeter instead of querying identifier by identifier.
- Data status
- The Informations service reports the state of the registry and its update dates, which lets you date what you show the user.
The vocabulary of the Sirene API
- Legal unit
- The company, identified by a 9-digit SIREN. This is the legal level: name, form, category. A legal unit always carries at least one establishment.
- Establishment
- The place of activity, identified by a 14-digit SIRET, that is the SIREN followed by a NIC. A company often has several, one of them the head office. You invoice an establishment, not a company.
- X-INSEE-Api-Key-Integration
- The header that carries the INSEE portal API key. The key is personal, unlimited in duration, revocable and renewable. Any code that mentions a consumer key, a consumer secret or an OAuth token for Sirene predates the new portal.
- Partial disclosure
- The status of a unit whose identifying details are not published. It exists in the registry but arrives with empty fields: you have to detect it, label it as such and remove it from prospecting workloads.
- NAF 2025
- The new activity nomenclature approved by decree no. 2025-736 of 31 July 2025, taking effect on 1 January 2027. The future code has been published in advance since 16 December 2025, alongside the NAF rev. 2 code.
- Luhn check
- The arithmetic check that validates the shape of a SIREN or a SIRET. It catches typos, but not a valid identifier pointing at a different company than the one expected: only the API call does that second job.
The real constraints of the Sirene API
The portal changed, old credentials are dead
A new catalogue on 17 October 2024, the old portal unmaintained from 28 February 2025 and closed on 10 September 2025. Accounts had to be recreated, not migrated: an integration written before 2025 no longer answers.
30 calls a minute, and that is the whole project
That is the public plan ceiling, and INSEE reserves the right to change it. Enriching 100,000 SIREN takes more than 55 hours of calls at full rate: bulk work is designed as a persistent queue spread over several nights.
Sirene is not a legal register
No directors, no beneficial owners, no deeds, no articles of association, no financial statements. Those come from the INPI national business register or from a commercial aggregator. Sirene identifies and locates, nothing more.
99.5 % availability, so plan a fallback
The commitment is assessed month by month, which leaves several hours of downtime a year. The form has to stay usable with manual entry, the record flagged as unverified and pushed back into the verification queue.
Sirene API or Pappers?
Two ways to get a French company record. The right one depends on what you have to do with it, not on the sticker price.
| Criterion | INSEE / SireneOfficial source | PappersPaid aggregator |
|---|---|---|
| Access | INSEE account, free key | Subscription, cost per credit |
| Perimeter | Identification, location | Identity, directors, deeds |
| Directors and owners | Not covered | Yes, subject to clearance |
| Official documents | Not covered | Articles, accounts, extracts |
| Rate | 30 calls per minute | Depends on your plan |
| Freshness | The reference registry | One refresh per day |
| The right case | Verify and prefill a SIRET | Build a KYC file |
The two combine: Sirene for identification and as a free fallback, an aggregator for the enrichment that carries value. It is a scoping trade-off.
What we measure on a Sirene integration
The other company data APIs
If Sirene does not cover your need, these options are worth discussing during scoping.
We combine INSEE / Sirene with
The stack that surrounds Sirene on our projects.
Sirene integration: your questions
Three steps. Create an account on the INSEE portal, declare an application there and subscribe to the public plan of the Sirene API, which generates a personal API key with unlimited duration. Then build a server-side connector that queries the registry by SIRET or by SIREN, respecting the ceiling of 30 calls per minute and keeping the key in a managed secret. Finally, put in a local cache with an explicit validity period: the quota is low, every call is a scarce resource, and displaying a customer record must not trigger a call each time. The sensitive part is not the HTTP call, it is rate handling and the fallback when the API does not answer.
Access to the API on its public plan is free, with an account. The cost therefore sits entirely in development, and it depends on the perimeter. Prefilling a form from a SIRET, with a cache and a manual fallback, is a short piece of work. Reconciling an existing customer base against the registry, with a discrepancy report, human validation and periodic refreshing, is a project in its own right: volume drives duration, since the rate is capped. We scope the perimeter up front and give you a firm estimate before we start.
These are three different APIs that search engines keep mixing up. The INSEE Sirene API queries the registry by identifier or by criteria, requires an account and caps at 30 calls per minute. The DINUM Recherche d'Entreprises API, the one behind the Annuaire des entreprises, is open with no account, combines the INPI business register with Sirene and serves full-text search by name. The API Entreprise, also from DINUM, is reserved for public administrations under formal clearance: a private software vendor cannot access it, whatever the use case. In practice we combine the first two.
No. Sirene contains no directors, no beneficial owners, no deeds, no articles of association and no financial statements. It is a registry for identification and location. That information comes from the national business register held by INPI, exposed directly or through an aggregator such as Pappers. On a product this has a concrete consequence: prefilling from a SIRET runs on Sirene, building a compliance file goes through another source, and personal data about individuals requires a documented processing framework.
A full copy through API calls makes no sense with a ceiling of 30 calls per minute. INSEE also publishes the Sirene data as open data under the Licence Ouverte 2.0, which requires crediting the source and the last update date wherever the data is displayed. On substance, we advise against a frozen copy: a company's disclosure status changes, companies cease trading, and the NAF code switches on 1 January 2027. We prefer a refreshed cache, with a verification date stored next to each record.
A Sirene integration project?
Let's talk. 30 minutes to scope your need, check what the Sirene API actually allows and tell you honestly what is feasible.
Discuss my INSEE / Sirene project


