Business data APIsbehind one API key
Company records, identity verification, bank branch codes and exchange rates share one authentication scheme and one response format. Keys are issued per app, credits are charged per call, and repeat queries are free.
- 014 data groups · 8 APIs
- 02One key for REST and MCP
- 03Errors are never charged
Request
$ curl -H "Authorization: Bearer $DATO_KEY" \ "https://dato.aidb.com.cn/api/v1/company/search?keyword=飞沐"Response
200 OK
{ "data": { "keyword": "飞沐", "page": 1, "total": 266, "items": [{ "name": "北京飞沐网络科技有限公司", "creditNo": "9111010808280962XP", "regDate": "2013-11-25" }] }, "meta": { "op": "company.search", "fetchedAt": "2026-10-09T10:12:05+08:00", "credits": 0, "deduplicated": true, "requestId": "9d2459aa3d9b7b18" }}Repeat query: deduplicated is true, credits is 0
- GET/api/v1/company/searchWithin 7 days
- GET/api/v1/company/queryWithin 7 days
- POST/api/v1/idcard/verifyReal time
- POST/api/v1/mobile/verifyReal time
- POST/api/v1/bankcard/verifyReal time
- GET/api/v1/bank/searchWithin 30 days
- GET/api/v1/fx/rateWithin 1 hour
- GET/api/v1/fx/convertWithin 1 hour
01Data
Four kinds of data, one way to call them
Every API shares one path prefix and one auth scheme. Success returns {data, meta}; errors return RFC 9457 problem details, so you branch on code.
01company
Company records
Search Chinese companies by name keyword, or fetch registry details by unified social credit code, full name or registration number.
- name
- 北京飞沐网络科技有限公司
- creditNo
- 9111010808280962XP
- regDate
- 2013-11-25
company.searchcompany.queryUsed for · Supplier onboarding, contract party checks, customer records02verify
Identity verification
Check whether a name matches an ID number, mobile number or bank card. Returns only match, mismatch or not found.
idcard.verifymobile.verifybankcard.verifyUsed for · Identity checks before account opening, signing or payout03bank
Bank branch codes
Look up bank branches by name or code. Returns the 12-digit CNAPS code, full branch name, address and phone.
12-digit bank code
bank.searchUsed for · Payment forms, verifying the payee’s bank branch04fx
Exchange rates
Bank of China RMB rates for 23 currencies: middle rate plus spot and cash buy/sell. Amounts are returned as strings, so no precision is lost.
USD → CNY · Mid rate
6.7367
23
currencies
Bank of China RMB rates
fx.ratefx.convertUsed for · Converting foreign-currency contract amounts and quotes02Integration
Business systems and AI assistants use the same key
Callers
Dato
One key · one auth scheme
Data
REST
/api/v1/{group}/{op}
Call /api/v1/{group}/{name} with GET or POST and a Bearer key. No SDK needed: any HTTP client works, and the docs include a Java example (OkHttp, Java 8+).
MCP
POST /mcp
POST /mcp over Streamable HTTP. Each tool maps to a REST API, so Claude, FIM One and other assistants get the same params, results and billing.
OpenAPI
/api/openapi.json
/api/openapi.json is generated from the live API registry and can produce a typed client; the reference page lets you try calls. /llms.txt is there for AI coding tools.
{
"mcpServers": {
"dato": {
"type": "http",
"url": "https://dato.aidb.com.cn/mcp",
"headers": { "Authorization": "Bearer <API Key>" }
}
}
}03Billing
Credits per call, repeat queries free
Credits are issued to a tenant and shared by all of its apps. Each call is charged once at the API’s price, and meta.credits tells you how much.
Repeat queries are already free, so callers do not need their own cache to save credits.
Billing rulesA normal result
At the API’s price
Same tenant, same params, the same data already returned
meta.deduplicated is true
Invalid params, API not enabled, daily limit reached
Rejected before the lookup
Data source error or timeout
The hold is refunded at once
force=1 to refetch from the data source
At the API’s price
04Personal data
Verification APIs return a verdict, nothing more
No echo, redacted logs
Names, ID, mobile and card numbers are never echoed back, and call logs record them as [redacted].
Never in the URL
Verification APIs accept POST only. Personal fields travel in the JSON body, out of URLs and access logs.
Enabled per app
An administrator has to enable personal-data APIs for each app. Apps do not include them by default.
Hashed before lookup
For mobile three-factor checks, all three fields are SHA-256 hashed before they reach the data source.
Obtain the data subject’s consent before calling.
Security and compliance05Management
Tenants, apps and keys
Each customer is a tenant; credits and bills belong to the tenant. Apps represent one environment of one calling system, and keys, enabled APIs, daily limits and usage all live on the app.
- 01
Tenant
- Credit batches
- Monthly bills
- Members
- 02
App
- Enabled APIs
- Daily call limit
- Usage
- 03
Key
- dato_3f9a1c2e_…
- Expiry
- Rotate and revoke
Keys shown once
Set an expiry when issuing. To rotate, issue a new key, switch services over, then revoke the old one with no downtime.
Daily call limit
Stops a misbehaving caller from burning credits. Calls past the limit return 429 until midnight Beijing time.
One-click disable
Suspect a leak? Disable the app and all its keys stop working at once. Re-enable it and the same keys work again.
Usage and bills
Calls and credits by tenant, app and API, with 7/30/90-day trends and monthly CSV exports.
Balance alerts
Email alerts when the balance falls below a threshold, runs out, or a credit batch expires within 7 days.
Traceable
Every response carries X-Request-Id. Send X-Dato-Actor to record who acted on your side.
Get an account and your first key
FIM opens accounts. Tell us about your company and use case, and we will set up a tenant and issue credits.
- 01REST and MCP
- 02Repeat queries free
- 03Errors refunded