Skip to content
OfacScanner

REST API v1

Sanctions Screening API With Scored JSON Results

A sanctions screening API lets your software send a name to a screening service and get back a scored result in one request. The OfacScanner OFAC API checks OFAC and global sanctions lists and returns candidates, scores and list versions as JSON.

OFAC SDN list, published , checked
Developer reviewing a JSON sanctions screening response in a code editor

What is a sanctions screening API

A sanctions screening API is a web service that your own application calls whenever it needs to check a person, company, vessel or payment party. Instead of a person typing names into a search box, the check runs inside your signup form, payout flow or order system and returns a machine readable answer.

The point is consistency. Every customer goes through the same check at the same step, nobody forgets, and every result is stored with the list version it used. People only look at the names that need a human decision.

Screen a name with one request

Send the name, the type and any extra facts you have. Country, date of birth (the dob field, for example 1971-04-12) and up to 10 identifiers raise or lower the score, so include them whenever your form collects them. Add monitor true to also put the subject under ongoing monitoring.

The response lists each candidate with its score, the alias that matched, the sanctions program and the list it is on, plus the version of every list used. Store the id with your customer record so you can fetch the result later with GET /api/v1/screenings/{id}.

Full field lists, error codes and limits are in the API documentation.

Request

curl -X POST https://ofacscanner.com/api/v1/screen \
  -H "Authorization: Bearer ofs_live_YOUR_KEY" \
  -H "Idempotency-Key: onboarding-cus_1042" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Northwind Freight",
    "type": "organization",
    "country": "Panama",
    "reference": "cus_1042"
  }'

Response (shortened)

{
  "object": "screening",
  "id": "scr_example_7f3a",
  "livemode": true,
  "channel": "api",
  "reference": "cus_1042",
  "query": { "name": "Northwind Freight", "type": "organization", "country": "Panama" },
  "result": "review",
  "risk_rating": "review",
  "top_score": 86.4,
  "threshold": 85,
  "sensitivity": "balanced",
  "matches_count": 1,
  "matches": [
    {
      "entity_id": 123,
      "list": "ofac_sdn",
      "list_uid": "12345",
      "primary_name": "NORTHWIND FREIGHT TRADING CO",
      "matched_name": "NORTHWIND FREIGHT",
      "entity_type": "organization",
      "programs": ["SDGT"],
      "score": 86.4,
      "rating": "review",
      "allow_listed": false
    }
  ],
  "list_versions": [
    {
      "list": "ofac_sdn",
      "name": "OFAC Specially Designated Nationals and Blocked Persons List",
      "version_id": 1,
      "published_at": "2026-10-09T00:00:00+00:00"
    }
  ],
  "evidence_hash": "a41c9e07d2b8f5e3",
  "duration_ms": 84
}

Endpoints in API v1

Five endpoints cover single checks, files, monitoring and list status.

Endpoint What it does
POST /api/v1/screen Screens one name and returns a scored result
POST /api/v1/batch Screens 1 to 10,000 records in one job
GET /api/v1/screenings/{id} Fetches a saved result and its evidence
POST /api/v1/monitor Adds a record to ongoing monitoring
GET /api/v1/lists Shows each list with its source and last update

Webhooks tell your system what changed

You do not need to poll. OfacScanner sends events to your endpoint with an OfacScanner-Signature header, an HMAC SHA-256 of the timestamp and raw body made with your endpoint secret. Reject anything older than 5 minutes. Failed deliveries are retried.

  • screening.completed

    A screening finished, with the same JSON the API returns.

  • batch.completed

    A batch job finished and its results are ready to fetch.

  • case.created

    A possible match opened a case for your reviewers.

  • monitoring.alert

    A monitored record matched something new after a list update.

How to add the OFAC API to your product

  1. 01

    Create a sandbox key

    Build and test with an ofs_test_ key. Sandbox answers are predictable and do not use your monthly checks.

  2. 02

    Call it at the right step

    Screen at signup, before a payout or before you ship. Pass your own reference so results tie back to your records.

  3. 03

    Act on the rating

    Let Clear results pass, hold Review and Likely match for a person, and stop Exact match.

  4. 04

    Listen for webhooks

    Subscribe to case and monitoring events so list changes reach your system on their own.

  5. 05

    Switch to the live key

    Swap the key, keep the same code, and every live check is saved with its evidence.

Built for production traffic

Fast responses

Real time screening under 300 ms on Scale, quick enough to sit inside a checkout or signup. See real time sanctions screening.

Safe retries

Send an Idempotency-Key header. The same key and body within 24 hours returns the saved response, marked Idempotent-Replayed, instead of a second check.

Payment parties

Screen originator, beneficiary, bank, free text, vessel and crypto address fields with payment screening.

Your thresholds

Set sensitivity per request or per workspace and keep an allow list for known good customers.

Sanctions screening API questions

Another question? Write to [email protected].

Which plan includes the sanctions screening API?

Live API keys come with Scale and Enterprise. Sandbox keys work for testing so you can build before you switch.

Which lists does the OFAC API check?

The OFAC SDN list and consolidated non-SDN lists, plus the UN, EU, UK, Canadian and Australian lists on the plans that include them.

What happens when my monthly checks run out?

The API answers with HTTP 402 and the error type usage_limit_reached, and no check is run. Monitoring keeps working, and there are no overage fees.

Can I screen a whole customer file through the API?

Yes. Use POST /api/v1/batch for a job, or upload a CSV in the app with batch sanctions screening.

Does the API decide whether to block a customer?

No. It returns a score, a rating and the evidence. Your rules and your compliance team decide what to do. OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.

Screen your first name in seconds

Type a person or company name, see the risk rating and top candidates from the current OFAC list, and keep the evidence when you sign up.

Results support your compliance decisions, and the final decision stays with your team. OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.