Apier
Machine-verifiable Norwegian company authority: status, roles and coded signing authority.
- 2026.10.0
- Version
- remote
- Transport
- 25
- Tools
Security review
Review passedReviewed 18h ago.
- tools: 25 tools scanned
- metadata: scanned
No findings.
Tools (25)
get_company_summary
A one-shot summary of obligations and deadlines for a Norwegian organisation: your FIRST call when you orient against a company. One call gives you entity_type, nace_codes, mva_registered, data_tier, obligations[] and deadlines[] (tier_2 adds filing_status), all from one version of the rules. It is not the identity from the registry: use get_company_context instead; for a drill down call get_company_obligations; to set a horizon_months call get_company_deadlines. Failure modes: NOT_FOUND, UPSTREAM_TIMEOUT, VALIDATION_FAILED; a credential without `read:brreg` can't see the tool; a call returns unknown tool (-32602). No API key? Use Bearer apier_sandbox_test_<suffix> (a fresh suffix) to get fixtures; valid orgs are the 818, 99966 and 99977 series and 999000002 (see GET /api/v1/sandbox/fixtures). Cost: 50 øre (NOK 0.50) per call, prepaid (prices: the get_pricing tool or GET /api/v1/pricing; a shortfall returns INSUFFICIENT_CREDITS with top_up_url). Docs: https://www.apier.no/docs/guides/c
get_public_obligations
Keyless. Retrieve the universal obligation set for a Norwegian entity type — every regulatory obligation that applies by virtue of BEING that organisational form, before per-company Tier-2 data is layered on. Use it for 'what does an AS owe?' or 'what are the baseline filings for an Enkeltpersonforetak?' without naming a company. Each obligation carries tier_2_required: true means the rule engine needs commercial data to decide for a SPECIFIC company, false means it applies unconditionally. Input: { entity_type } from the closed enum AS / ENK / ANS / DA / NUF (no 'OTHER' fallback). Failure modes: VALIDATION_FAILED, UPSTREAM_TIMEOUT; a credential without `read:rulebook` can't see the tool; a call returns unknown tool (-32602). For a specific company's evaluated obligations, call get_company_obligations; for the universal calendar, use get_public_deadlines. Docs: https://www.apier.no/docs/guides/norwegian-company-obligations
get_exchange_rate
Keyless. Norges Bank reference exchange rate for a currency against NOK — the benchmark Norwegian tax and accounting rules accept for foreign-currency obligations. No Norwegian-company input. Input: { base, quote, date? } — ISO 4217 codes, NOK-anchored: exactly one side MUST be 'NOK'. The response is always base NOK and quote = the other currency, whatever order you sent; rate = NOK per 1 unit of quote; date = the day the rate is valid for (weekends and holidays fall back to the prior business day, so it can differ from requested_date). A pair without a NOK side is rejected client-side as UNSUPPORTED_CURRENCY_PAIR: derive cross rates from two NOK legs. Failure modes: VALIDATION_FAILED, UNSUPPORTED_CURRENCY_PAIR, INVALID_DATE, UPSTREAM_TIMEOUT, NO_RATE_AVAILABLE; a credential without `read:norgesbank` can't see the tool; a call returns unknown tool (-32602). For obligations or deadlines rather than a rate, use get_company_summary instead. Docs: https://www.apier.no/docs/mcp
list_acting_capacity
Resolve every Norwegian regulatory action a person is currently authorised to perform on behalf of a specific organisation. Combines the actor's Altinn role assignments (DAGL, LEDE, MEDL, NESTL, INNH, REGN, REVI) with a conservative role-to-action map, returning the raw role list AND the derived action tokens an agent may pass to /v1/actions/execute (dry-run them first via validate_action), each with a lovdata legal_reference. Inputs: an 11-digit fødselsnummer / D-nummer — HMAC-hashed; the raw value is never persisted, logged or returned — plus the 9-digit organisasjonsnummer. Failure modes: VALIDATION_FAILED; a credential without `read:altinn` can't see the tool; a call returns unknown tool (-32602). For your own consumer's delegation snapshot, use check_authorization instead; for statutory signing authority with no actor input, use get_company_authority. No sandbox mirror; returns SANDBOX_TOOL_UNAVAILABLE under a sandbox bearer. Docs: https://www.apier.no/docs/guides/altinn-system-us
get_company_profile
Resolve a Norwegian organisasjonsnummer (9 digits) into a structured company profile from Brønnøysund Enhetsregisteret: display name, form of organisation, NACE codes with descriptions, addresses, the dates of registration and dissolution, the `active` / `dissolved` status enum, the MVA-registered flag, and the role CODES of persons — never personal identifiers. The backing REST route is POST /api/v1/brreg/company-profile. For deadlines and filing status, use get_company_summary instead; for the signaturrett / prokura role-code summary, use get_company_context instead. No sandbox mirror; it returns SANDBOX_TOOL_UNAVAILABLE under a sandbox bearer. Failure modes: NOT_FOUND, VALIDATION_FAILED; a credential without `read:brreg` can't see the tool; a call returns unknown tool (-32602). Cost: 50 øre (NOK 0.50) per call, prepaid (prices: the get_pricing tool or GET /api/v1/pricing; a shortfall returns INSUFFICIENT_CREDITS with top_up_url). Docs: https://www.apier.no/docs/guides/norwegian-comp
check_authorization
Return the authorisation snapshot for the calling consumer's delegation on a Norwegian organisation: the `status` enum (`full` / `partial` / `none`), `active_scopes`, `missing_scopes` (empty on `full`) and `delegated_rights`. To check whether a SPECIFIC action is permitted, compare `active_scopes` to the scopes it requires. Always runs against the calling consumer. Always a 200: with no delegation the verdict is `status: "none"`, never a 404. Input: { org_number } (9 digits, MOD-11). Failure modes: VALIDATION_FAILED; a credential without `read:altinn` can't see the tool; a call returns unknown tool (-32602). For a SPECIFIC person's actions, use list_acting_capacity instead. Before a live execute, use validate_action to preflight at zero upstream cost. For the per-agent-principal breakdown, use check_fullmakt; for statutory signing authority, use get_company_authority. No sandbox mirror; returns SANDBOX_TOOL_UNAVAILABLE under a sandbox bearer. Docs: https://www.apier.no/docs/fullmakt
get_company_context
Brønnøysund identity slice for a Norwegian organisation: legal name, form of organisation, NACE codes, addresses, the dates it was formed or dissolved, and the signaturrett / prokura role-code summary (never personal identifiers). Identity ONLY, no verdict on obligations; add get_company_obligations or get_company_deadlines for the regulatory layer. Failure modes: NOT_FOUND, UPSTREAM_TIMEOUT, VALIDATION_FAILED; a credential without `read:brreg` can't see the tool; a call returns unknown tool (-32602). For an obligations verdict, use get_company_summary instead; for NACE descriptions, use get_company_profile instead. No API key? Use Bearer apier_sandbox_test_<suffix> (a fresh suffix) to get fixtures; valid orgs are the 818, 99966 and 99977 series and 999000002 (see GET /api/v1/sandbox/fixtures). Cost: 50 øre (NOK 0.50) per call, prepaid (prices: the get_pricing tool or GET /api/v1/pricing; a shortfall returns INSUFFICIENT_CREDITS with top_up_url). Docs: https://www.apier.no/docs/guides/
get_company_deadlines
The upcoming filing calendar for one organisation, horizon_months ahead. One entry per obligation and period: obligation_id (the rule_id of get_company_obligations; the public calendar uses other ids), period_label, due_at, adjusted_for with original_due_at, and filing_status. In the sandbox the dates are fixed and far ahead, and horizon_months is ignored; for a real window use get_public_deadlines. Failure modes: NOT_FOUND, VALIDATION_FAILED; a credential without `read:brreg` can't see the tool; a call returns unknown tool (-32602). For the verdict per obligation, use get_company_obligations instead. No API key? Use Bearer apier_sandbox_test_<suffix> (a fresh suffix) to get fixtures; valid orgs are the 818, 99966 and 99977 series and 999000002 (see GET /api/v1/sandbox/fixtures). Cost: 50 øre (NOK 0.50) per call, prepaid (prices: the get_pricing tool or GET /api/v1/pricing; a shortfall returns INSUFFICIENT_CREDITS with top_up_url). Docs: https://www.apier.no/docs/guides/norway-corporat
get_company_obligations
Evaluate the Apier Rulebook for a Norwegian organisation: one entry per rule with rule_id, obligation_name, evaluation_result (applicable, not_applicable or insufficient_data), a reason, the legal_reference, frequency, data_tier_required and the bokmål description, which is inherited byte for byte (never re-translate it). Failure modes: NOT_FOUND, VALIDATION_FAILED; a credential without `read:brreg` can't see the tool; a call returns unknown tool (-32602). For the calendar alone, use get_company_deadlines instead; for the entity-type set that needs no org number or key, use get_public_obligations instead. No API key? Use Bearer apier_sandbox_test_<suffix> (a fresh suffix) to get fixtures; valid orgs are the 818, 99966 and 99977 series and 999000002 (see GET /api/v1/sandbox/fixtures). Cost: 50 øre (NOK 0.50) per call, prepaid (prices: the get_pricing tool or GET /api/v1/pricing; a shortfall returns INSUFFICIENT_CREDITS with top_up_url). Docs: https://www.apier.no/docs/guides/norwegian-c
get_public_deadlines
Keyless. The universal Norwegian filing calendar: the deadlines for every Norwegian business in the covered categories (MVA, A-melding, Skattemelding, Årsregnskap), which do not depend on any one organisation. One entry per obligation and period for a single Europe/Oslo calendar year: a per-period obligation_id (such as `mva-termin-4-2026`; the company tools use rule ids such as `MVA_FILING_BIMONTHLY` instead), period, deadline (Europe/Oslo), submission_window_closes, adjusted_from (the legal date before a shift, else null), legal_reference and applies_to_entity_types. The output is deterministic for a given rulebook_version. The only input is an optional `year` (2020–2100; defaults to the current Oslo year). Failure modes: VALIDATION_FAILED on year shape; a credential without `read:rulebook` can't see the tool; a call returns unknown tool (-32602). For a specific company's calendar, use get_company_deadlines instead. Docs: https://www.apier.no/docs/guides/norway-corporate-tax-return-d
validate_action
Dry-run a proposed regulatory action with NO upstream side effect (no government call). Use it BEFORE a live execute to catch missing delegations and payload-shape errors. Returns `outcome`: `all_passed` (boolean), five ordered `checks` (each with `passed` and a reason) and the DRY_RUN_DISCLAIMER (a pass is NOT a guarantee of upstream success), plus the preview echo `would_be_payload` + `preview_notice`. Inputs match the /v1/actions/execute body: { org_number, action_type (`mva_melding` | `a_melding`), period, payload }; the nested `payload` mirrors the upstream government payload schema, so it is not flattened. Failure modes: a credential without `read:actions` can't see the tool; a call returns unknown tool (-32602). VALIDATION_FAILED on invalid input. To file a sandbox VAT return, use submit_vat_return instead; under a sandbox bearer this tool returns SANDBOX_TOOL_UNAVAILABLE, and for a sandbox dry-run you call submit_vat_return without an approval_token. Docs: https://www.apier.no/
explain_compliance_error
Keyless. Resolve a structured Apier compliance error code into a Norwegian-bokmål Explanation envelope: summary, bokmål why, ordered fix_steps, optional documentation link + legal_basis, and an optional handover block (who / where / what / why) for errors a human must resolve (e.g. AUTH_INSUFFICIENT_ROLE, AUTH_NO_DELEGATION, SCOPE_MISSING) — agent-resolvable errors ship `handover: null`. Accepts any code from the closed EXPLAINER_ERROR_CODES catalogue. Optional flat context_org_number / context_scope / context_role / context_field / context_upstream_system strings carry placeholder values interpolated into the bokmål text; missing values fall back to 'ukjent <noun>'. Failure modes: VALIDATION_FAILED on an unknown code; a credential without `read:rulebook` can't see the tool; a call returns unknown tool (-32602). For a company's live obligations rather than an error explanation, use get_company_obligations instead. Docs: https://www.apier.no/docs/guides/error-handling
search_companies
Resolve a Norwegian company NAME to its 9-digit organisasjonsnummer. Use this as your FIRST call whenever you have a company's name but NOT its org_number — every other company tool needs the number; guessing one risks the wrong company. Searches Brønnøysund's public Enhetsregisteret and returns up to ten candidates with five fields each (name, org_number, org_form, municipality, registry status). Then call get_company_summary or get_company_context with the chosen org_number. Input: { name } (2–100 chars, æ/ø/å supported). On NOT_FOUND, broaden the name and drop the legal form — never loop on the same name. Failure modes: VALIDATION_FAILED, NOT_FOUND, UPSTREAM_TIMEOUT / UPSTREAM_UNAVAILABLE; a credential without `read:brreg` can't see the tool; a call returns unknown tool (-32602). No sandbox mirror — the sandbox fixtures catalogue already lists every synthetic org. Docs: https://www.apier.no/docs/guides/norwegian-company-register-search
get_company_verification
Fast go / no-go trust check before you act for a Norwegian organisation. It keys ONLY off entity activity and visible signing authority. `verification_status` is `pass` (active and signing authority visible), `fail` (not active: konkurs, avvikling or oppløst) or `unknown` (not determinable; never a claimed absence). `signing_authority_summary` lists roles, not the joint rule; for that use get_company_authority. Fails with NOT_FOUND, UPSTREAM_UNAVAILABLE or VALIDATION_FAILED; a credential without `read:brreg` can't see the tool; a call returns unknown tool (-32602). For identity call get_company_context. No API key? Use Bearer apier_sandbox_test_<suffix> (a fresh suffix) to get fixtures; valid orgs are the 818, 99966 and 99977 series and 999000002 (see GET /api/v1/sandbox/fixtures). Cost: 50 øre (NOK 0.50) per call, prepaid (prices: the get_pricing tool or GET /api/v1/pricing; a shortfall returns INSUFFICIENT_CREDITS with top_up_url). Docs: https://www.apier.no/docs/guides/norwegian-com
get_company_authority
Who can legally sign for this Norwegian company, and how? Call get_company_verification first; this ignores bankruptcy and dissolution. The class (sole, joint, by_role, prokura_only, no_authority, unknown) comes from Fullmakttjenesten and the role holders; `coded_authority` (absent in sandbox) adds coded clauses and stamps. Statutory authority, not Altinn delegation. UPSTREAM_UNAVAILABLE, VALIDATION_FAILED; a credential without `read:brreg` can't see the tool; a call returns unknown tool (-32602). For a person's actions use list_acting_capacity; for your own delegation use check_authorization. No API key? Use Bearer apier_sandbox_test_<suffix> (a fresh suffix) to get fixtures; valid orgs are the 818, 99966 and 99977 series and 999000002 (see GET /api/v1/sandbox/fixtures). Cost: 50 øre (NOK 0.50) per call, prepaid (prices: the get_pricing tool or GET /api/v1/pricing; a shortfall returns INSUFFICIENT_CREDITS with top_up_url). Docs: https://www.apier.no/docs/guides/signature-rights-norweg
get_company_accounts
A current snapshot of a Norwegian company's annual accounts (årsregnskap) from the OPEN Regnskapsregisteret tier: `has_filed_annual_accounts` (null = unknown, never a fabricated false), `last_accounts_year` and that year's minimal `key_figures` (currency always surfaced, presentation basis, totals). No multi-year history. An unknown org_number returns 200 with `null`, not a 404. Failure modes: VALIDATION_FAILED; a credential without `read:brreg` can't see the tool; a call returns unknown tool (-32602). For a go/no-go verdict, use get_company_verification; for identity, use get_company_context. No API key? Use Bearer apier_sandbox_test_<suffix> (a fresh suffix) to get fixtures; valid orgs are the 818, 99966 and 99977 series and 999000002 (see GET /api/v1/sandbox/fixtures). Cost: 50 øre (NOK 0.50) per call, prepaid (prices: the get_pricing tool or GET /api/v1/pricing; a shortfall returns INSUFFICIENT_CREDITS with top_up_url). Docs: https://www.apier.no/docs/guides/norwegian-company-annua
get_company_filing_history
Reconcile a company's Altinn 3 filing history against the filings YOUR consumer submitted through Apier: each Altinn instance paired with its Apier audit record (`filed_via_apier` + `apier_record`). Cursor-paginated ({ cursor } from `pagination.next_cursor`, { limit } 1–100). Simulated today (ALTINN_MODE=mock by default) until Digdir grants the `altinn:instances.read` Maskinporten scope and the operator sets ALTINN_MODE=live. AUTH_NO_DELEGATION, VALIDATION_FAILED; a credential without `read:altinn` can't see the tool; a call returns unknown tool (-32602). For upcoming deadlines, use get_company_deadlines instead. No API key? Use Bearer apier_sandbox_test_<suffix> (a fresh suffix) to get fixtures; valid orgs are the 818, 99966 and 99977 series and 999000002 (see GET /api/v1/sandbox/fixtures). Cost: 50 øre (NOK 0.50) per call, prepaid (prices: the get_pricing tool or GET /api/v1/pricing; a shortfall returns INSUFFICIENT_CREDITS with top_up_url). Docs: https://www.apier.no/docs/guides/aud
list_changes
Read Apier's cross-source change archive — created / updated / deleted events detected across the upstreams Apier polls (Brønnøysund, Altinn schemas, Norges Bank, NAV, Skatteetaten Tier-2; the Digdir poller is retired, so `digdir` is a valid but empty filter). Filter by { source, entity_type, entity_id, change_type } and a { from }–{ to } detected_at range. Queries WITHOUT entity_id withhold personal-field rows by design (`personal_fields_withheld: true`); the org-scoped form returns everything. Keyset-paginated newest-first: pass { limit } (1–500, default 50) and carry `next_cursor` back verbatim (HMAC-signed; an edited one is CURSOR_INVALID: start over without a cursor). Failure modes: VALIDATION_FAILED, CURSOR_INVALID; a credential without `read:changes` can't see the tool; a call returns unknown tool (-32602). No sandbox mirror; returns SANDBOX_TOOL_UNAVAILABLE under a sandbox bearer. Docs: https://www.apier.no/docs/guides/webhooks
get_altinn_migration_guidance
Discover the Altinn 3 equivalent of an Altinn 2 service or role code. The 19 June 2026 Altinn 2 deprecation deadline has passed, so this serves remediation for integrations still on Altinn 2. Pass { altinn2_code } (alphanumeric, 1–10 chars, e.g. A0208) for one mapping, or omit it for the whole map. Every response carries the deprecation status computed in Europe/Oslo (deprecation_deadline, days_remaining, deadline_passed). Each entry ships a `verified` flag: gate any production migration on `verified === true`; unverified entries are hints. Deterministic static map (Digdir-sourced); no government system is contacted. Zero-auth REST twin: GET /api/v1/tools/altinn-migration. Failure modes: NOT_FOUND for a code not in the map, VALIDATION_FAILED (INVALID_CODE); a credential without `read:digdir` can't see the tool; a call returns unknown tool (-32602). No sandbox mirror; returns SANDBOX_TOOL_UNAVAILABLE under a sandbox bearer. Docs: https://www.apier.no/docs/guides/altinn-system-users
request_fullmakt
Broker a fullmakt — scoped, revocable company→agent authority via an Altinn systembruker. Brokers and persists the delegation, binding the returned system_user_id write once onto the principal (pending to active); the company's signing authority must approve the returned `delegation_url` before it is usable. Non-empty `warnings[]` on a 201 means a local follow-up degraded: reconcile, never blind retry. Identical retries are dedup safe. Inputs: { agent_principal_id (YOUR OWN), org_number, scopes[], validity_days?, label? }. Agent principals cannot yet be created through the public API. Failure modes: FULLMAKT_PRINCIPAL_NOT_FOUND, FULLMAKT_PRINCIPAL_NOT_ELIGIBLE, FULLMAKT_UPSTREAM_FAILED, VALIDATION_FAILED; a credential without `read:altinn` can't see the tool; a call returns unknown tool (-32602). To inspect the recorded state, use check_fullmakt; to withdraw it, use revoke_fullmakt. No sandbox mirror; returns SANDBOX_TOOL_UNAVAILABLE under a sandbox bearer. Docs: https://www.apier.no/d
check_fullmakt
Check your fullmakt state for a Norwegian company BEFORE acting on its behalf. Per agent principal of yours holding a live delegation there it returns: the bound system_user_id, whether the delegation is `active` or still `pending` signaturrett approval, the scopes carried, and the scopes still missing. `overall_status`: `full` (act now), `partial` (`fix_steps` names the blocker), or `none` — a VALID answer, not an error: 200 with empty `principals[]`, never a 404. Reports the delegation state Apier RECORDED, not a live Altinn PDP decision. Input: { org_number } (9 digits). Failure modes: VALIDATION_FAILED; a credential without `read:altinn` can't see the tool; a call returns unknown tool (-32602). To BROKER a fullmakt use request_fullmakt; to withdraw one use revoke_fullmakt; the CONSUMER-level snapshot is check_authorization. No sandbox mirror; returns SANDBOX_TOOL_UNAVAILABLE under a sandbox bearer. Docs: https://www.apier.no/docs/fullmakt
revoke_fullmakt
Revoke a fullmakt — withdraw an agent's delegated authority for a Norwegian company and retire the agent principal. Given ONLY the agent_principal_id (system_user_id and org_number resolve server-side), Apier revokes the bound delegation and flips the principal to terminal `revoked`, never resurrected. Agent principals cannot yet be created through the public API; a new one comes from the account owner. LOCAL revocation is immediate in Apier's own check (recorded state, not an Altinn confirmation). Idempotent: revoking an already-revoked principal is a 200 no-op. `warnings[]` carries NAMED outcome tokens (principal_revoke_failed, delegation_not_found, upstream_revoke_unconfirmed): read the token. Failure modes: FULLMAKT_PRINCIPAL_NOT_FOUND, VALIDATION_FAILED; a credential without `read:altinn` can't see the tool; a call returns unknown tool (-32602). No sandbox mirror; returns SANDBOX_TOOL_UNAVAILABLE under a sandbox bearer. Docs: https://www.apier.no/docs/fullmakt
get_pricing
Call this BEFORE metered work to check per-call cost and whether billing enforcement is live. Keyless: executes WITHOUT an API key, so an agent can price a workflow before it holds any credential. Returns the machine-readable price list: every credit-metered REST endpoint with its MCP tool name and cost in whole øre (always an integer), the enforcement.live flag (while false nothing is debited and a 402 is impossible), the 402 INSUFFICIENT_CREDITS recovery-contract field list, the top-up bounds with top_up_url, and the how_to_pay_guide URL. Prices derive from the SAME configuration the 402 meter debits, so this surface cannot drift from enforcement. Input: none — call with {}. Failure modes: per-IP rate limiting and transient errors only. For the calling key's own balance, use get_credit_balance (Bearer key required) instead. Docs: https://www.apier.no/docs/guides/billing
get_credit_balance
Call this BEFORE a batch of metered calls to confirm the calling key's prepaid credit balance covers it, and AFTER a 402 INSUFFICIENT_CREDITS + human top-up to verify the funds landed. The balance is ALWAYS the authenticated key's own — no parameters, so reading another key's balance is structurally impossible. Returns api_key_id, balance_ore (whole øre, always an integer), currency (NOK), updated_at (null = never topped up = balance 0), and top_up_url (hand it to a human). Affordability: cost_ore from get_pricing times planned calls versus balance_ore. Free, zero side effects. Failure modes: 401 without a key (NOT keyless: use get_pricing for keyless price discovery); a credential without `read:credits` (or `read:*`) can't see the tool; a call returns unknown tool (-32602); CREDIT_BALANCE_UNAVAILABLE (503, retryable; a money read is never fabricated). Under a sandbox bearer it returns SANDBOX_TOOL_UNAVAILABLE. Docs: https://www.apier.no/docs/guides/agent-payments
redeem_issuance_token
Convert an owner-issued key-issuance token into your own API key — the headless onboarding step for an agent that holds no credential yet. Keyless: the one-time token IS the credential. Minting and revocation are dashboard-only, so an agent can never self-issue authority. Redemption is strictly SINGLE-USE and atomic: on success (201) the token is consumed and the result carries {id, name, scopes, created_at, plaintext_key} — returned EXACTLY ONCE; store it immediately. Failure modes: an expired / used / revoked / unknown token yields ONE uniform ISSUANCE_TOKEN_INVALID failure (ask the owner for a fresh token, never retry); MAX_KEYS_REACHED (409) means 3 active keys — the token was NOT consumed, retry with the SAME token after the owner revokes a key. After onboarding, use get_pricing to price metered work and get_credit_balance (with your new key) for the balance. No sandbox mirror; returns SANDBOX_TOOL_UNAVAILABLE under a sandbox bearer. Docs: https://www.apier.no/docs/authentication