Skip to main content
DataVendor has a REST API for each side of the marketplace and one MCP server for coding agents. All of them authenticate with the same team API key. Buying, bidding, publishing, and moving money stay in the web app.

Vendor API

Your listings, inventory, opportunities, estimations, and earnings.

Buyer API

The catalog, your purchases and bids, and the opportunities you posted.
Use the API that matches your organization’s role. An organization with both roles uses both with one key. Both APIs read the catalog and the taxonomy, so those endpoints appear on each page.

Authentication

DataVendor organizations are HUD teams, so the key is a HUD team API key. Create one in Settings → API Keys and send it as a bearer token on every request. The hud-api-key and X-API-Key headers are accepted too.
Missing or invalid credentials return 401. A valid key whose team may not touch the resource returns 403. Catalog reads also require a marketplace role on the team, and vendor-only teams are subject to the browse gate: behind it, GET /v2/listings/browse serves only the first page of the unfiltered catalog with locked: true, and refuses search, filters, sorting, and cursors with 403. GET /v2/listings/browse/access reports where your team stands.

Conventions

Every example on the API pages is generated from that API’s OpenAPI document, so field names match what the server sends and receives. The values are placeholders.

Errors

Failures share one envelope, with a machine-readable code and a human-readable message. The status tells you whether to fix the request, the credentials, or the state.

MCP

The DataVendor MCP is a read-only Model Context Protocol server for coding agents: streamable HTTP JSON-RPC at https://api.datavendor.ai/v2/mcp/, with the same team API key. One server serves both sides; the tools a key can use follow its team’s role. The tools are listed per side under Vendor MCP tools and Buyer MCP tools.
Every tool resolves your team from the key, as the REST routes do, and enforces the same marketplace role, NDA, and browse gate. Missing or invalid credentials fail the call with an Unauthorized error. The tools wrap the same service methods as the REST routes, so a listing id from browse_listings is the id GET /v2/listings/browse/{listing_id} takes.