CIIFragments Studio is CII-accredited: recover up to 20% of your software development spendLearn more

API integration for INSEE / Sirene

We build your Sirene connector

We wire the Sirene registry into your forms to the Sirene registry to prefill your forms from a SIRET, keep your customer records reliable and detect closures.

  • Senior product team
  • public data connectors in production
  • from scoping to monitoring
In short

What does the Sirene API provide and why integrate it to verify a company?

The Sirene API gives access to the official register of French companies maintained by INSEE: legal name, address, legal form, NAF code, headcount, administrative status (active or ceased). It allows you to identify and verify a company from its SIREN or SIRET number. You integrate it to make client onboarding reliable: confirming that a company exists and is active, pre-fill a record automatically from a SIRET entered by the user, or detect that a client has ceased trading before sending them an order or a payment reminder.

Use cases

What our clients build on the Sirene API

01

A prefilled signup form

The prospect types a SIRET. Company name, legal form, head office address and NAF code fill themselves in, and drop-off falls.

02

Cleaning up your customer registry

Every existing record is matched against the registry, with a discrepancy report submitted for human validation before any bulk correction.

03

Watching your customer portfolio

An alert when a customer ceases trading, moves its head office or closes the establishment you invoice, before the invoice goes out.

04

Supplier checks before payment

The SIRET on the invoice is checked against the registry: does the establishment exist, and does it match the vendor already on file.

For you

What it changes in your customer registry

Engineering in service of a measurable outcome: less data entry, a clean customer registry, fewer invoices lost.

A form with a single field

The SIRET is enough. The six fields nobody wanted to fill in arrive on their own, and your drop-off rate falls exactly where it is decided.

A registry that stops drifting

No more four spellings of the same company and no more APE codes invented on the fly. The data comes from the source, not from a sales rep.

Closures caught in time

You know a customer has been struck off, or that an establishment is closed, before issuing an invoice that will never be paid.

Segmentation you can act on

NAF code, headcount bracket, company category and municipality become targeting criteria, with no external list to buy.

Method

How we ship your Sirene connector

01

Scoping

Which flows, what volume, what freshness the registry needs. We list the edge cases before writing a line of code.

02

Development

Typed connector, a limiter calibrated on the quota, a retry queue, the key isolated in a managed secret. A demo every week.

03

Acceptance testing

Replay on your real data, record by record discrepancy checks, and testing what happens when the API returns 429 or stops answering.

04

Monitoring

Alerts on sync failures, a call log, a freshness dashboard. You know a flow is broken before your teams do.

The API

What the Sirene API allows

Legal units by SIREN
The company's identity: name, legal form, creation date, category, principal activity and administrative status.
Establishments by SIRET
Each establishment with its address, activity, headcount bracket and status, head office or secondary. That is the level you invoice.
Multi-criteria search
Selection by NAF code, municipality, headcount bracket or date, to build a perimeter instead of querying identifier by identifier.
Data status
The Informations service reports the state of the registry and its update dates, which lets you date what you show the user.
Glossary

The vocabulary of the Sirene API

Legal unit
The company, identified by a 9-digit SIREN. This is the legal level: name, form, category. A legal unit always carries at least one establishment.
Establishment
The place of activity, identified by a 14-digit SIRET, that is the SIREN followed by a NIC. A company often has several, one of them the head office. You invoice an establishment, not a company.
X-INSEE-Api-Key-Integration
The header that carries the INSEE portal API key. The key is personal, unlimited in duration, revocable and renewable. Any code that mentions a consumer key, a consumer secret or an OAuth token for Sirene predates the new portal.
Partial disclosure
The status of a unit whose identifying details are not published. It exists in the registry but arrives with empty fields: you have to detect it, label it as such and remove it from prospecting workloads.
NAF 2025
The new activity nomenclature approved by decree no. 2025-736 of 31 July 2025, taking effect on 1 January 2027. The future code has been published in advance since 16 December 2025, alongside the NAF rev. 2 code.
Luhn check
The arithmetic check that validates the shape of a SIREN or a SIRET. It catches typos, but not a valid identifier pointing at a different company than the one expected: only the API call does that second job.
Good to know

The real constraints of the Sirene API

01

The portal changed, old credentials are dead

A new catalogue on 17 October 2024, the old portal unmaintained from 28 February 2025 and closed on 10 September 2025. Accounts had to be recreated, not migrated: an integration written before 2025 no longer answers.

02

30 calls a minute, and that is the whole project

That is the public plan ceiling, and INSEE reserves the right to change it. Enriching 100,000 SIREN takes more than 55 hours of calls at full rate: bulk work is designed as a persistent queue spread over several nights.

03

Sirene is not a legal register

No directors, no beneficial owners, no deeds, no articles of association, no financial statements. Those come from the INPI national business register or from a commercial aggregator. Sirene identifies and locates, nothing more.

04

99.5 % availability, so plan a fallback

The commitment is assessed month by month, which leaves several hours of downtime a year. The form has to stay usable with manual entry, the record flagged as unverified and pushed back into the verification queue.

Sirene or Pappers

Sirene API or Pappers?

Two ways to get a French company record. The right one depends on what you have to do with it, not on the sticker price.

CriterionINSEE / SireneOfficial sourcePappersPaid aggregator
AccessINSEE account, free keySubscription, cost per credit
PerimeterIdentification, locationIdentity, directors, deeds
Directors and ownersNot coveredYes, subject to clearance
Official documentsNot coveredArticles, accounts, extracts
Rate30 calls per minuteDepends on your plan
FreshnessThe reference registryOne refresh per day
The right caseVerify and prefill a SIRETBuild a KYC file

The two combine: Sirene for identification and as a free fallback, an aggregator for the enrichment that carries value. It is a scoping trade-off.

Our expertise

What we measure on a Sirene integration

15 d
first SIRET flow in production
30/min
rate held by our call limiter
1 field
typed by the user instead of six
4
senior developers on the project

We combine INSEE / Sirene with

The stack that surrounds Sirene on our projects.

  • PostgreSQL
  • Redis
  • HubSpot
  • n8n
  • TypeScript
FAQ

Sirene integration: your questions

Three steps. Create an account on the INSEE portal, declare an application there and subscribe to the public plan of the Sirene API, which generates a personal API key with unlimited duration. Then build a server-side connector that queries the registry by SIRET or by SIREN, respecting the ceiling of 30 calls per minute and keeping the key in a managed secret. Finally, put in a local cache with an explicit validity period: the quota is low, every call is a scarce resource, and displaying a customer record must not trigger a call each time. The sensitive part is not the HTTP call, it is rate handling and the fallback when the API does not answer.

Access to the API on its public plan is free, with an account. The cost therefore sits entirely in development, and it depends on the perimeter. Prefilling a form from a SIRET, with a cache and a manual fallback, is a short piece of work. Reconciling an existing customer base against the registry, with a discrepancy report, human validation and periodic refreshing, is a project in its own right: volume drives duration, since the rate is capped. We scope the perimeter up front and give you a firm estimate before we start.

These are three different APIs that search engines keep mixing up. The INSEE Sirene API queries the registry by identifier or by criteria, requires an account and caps at 30 calls per minute. The DINUM Recherche d'Entreprises API, the one behind the Annuaire des entreprises, is open with no account, combines the INPI business register with Sirene and serves full-text search by name. The API Entreprise, also from DINUM, is reserved for public administrations under formal clearance: a private software vendor cannot access it, whatever the use case. In practice we combine the first two.

No. Sirene contains no directors, no beneficial owners, no deeds, no articles of association and no financial statements. It is a registry for identification and location. That information comes from the national business register held by INPI, exposed directly or through an aggregator such as Pappers. On a product this has a concrete consequence: prefilling from a SIRET runs on Sirene, building a compliance file goes through another source, and personal data about individuals requires a documented processing framework.

A full copy through API calls makes no sense with a ceiling of 30 calls per minute. INSEE also publishes the Sirene data as open data under the Licence Ouverte 2.0, which requires crediting the source and the last update date wherever the data is displayed. On substance, we advise against a frozen copy: a company's disclosure status changes, companies cease trading, and the NAF code switches on 1 January 2027. We prefer a refreshed cache, with a verification date stored next to each record.

A Sirene integration project?

Let's talk. 30 minutes to scope your need, check what the Sirene API actually allows and tell you honestly what is feasible.

Discuss my INSEE / Sirene project
Discuss my INSEE / Sirene project