> ## Documentation Index
> Fetch the complete documentation index at: https://docs.halal.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenAPI document

> This document, as JSON. Also available as YAML at `/openapi.yaml`.
**No key required.** Point an OpenAPI-aware client or agent framework
at `https://api.halal.sh/v1/openapi.json`. Limited to 60 requests a
minute per IP address, shared with `/openapi.yaml` and the index.




## OpenAPI

````yaml GET /openapi.json
openapi: 3.1.0
info:
  title: halal.sh API
  version: 1.0.0
  description: >
    The halal.sh API provides Shariah compliance screening for public equities

    and ETFs, based on AAOIFI Shari'ah Standard No. 21.


    Unlike a black-box verdict, every determination exposes the individual

    screens, the financial ratios with their thresholds, the revenue breakdown,

    and the source filings behind each number. The Evidence Packet endpoint

    returns the full audit trail (each screen's calculation, the values it used

    and the filing they came from) for compliance, reporting, and
    reproducibility.


    ## Conventions


    - **Base URL** — `https://api.halal.sh/v1`

    - **Authentication** — send your key in the `X-API-Key` header.

    - **Envelope** — every success response is `{ "data": …, "meta": … }`. Every
      error is `{ "error": { "code", "message" } }`.
    - **Ratios** — screen `value`, `threshold`, and `buffer` are decimals
      (`0.082` means 8.2%, `0.30` means 30%). Fields named `*percentage`,
      `purity.percentage`, and holding `weight` are whole-number percentages
      (`66.74` means 66.74%). Each field documents its unit.
    - **Status** — compliance status is always `compliant`, `non-compliant`, or
      `pending`. Treat unknown future values as `pending`.
    - **Money** — values are in the instrument's reporting currency (USD for US
    filers).
  contact:
    name: halal.sh API support
    url: https://halal.sh/developers
    email: api@halal.sh
servers:
  - url: https://api.halal.sh/v1
    description: Production
security:
  - apiKey: []
tags:
  - name: Instruments
    description: Compliance, financials, evidence, history, and health for a single stock.
  - name: Screening
    description: Batch screening and search across the instrument universe.
  - name: ETFs
    description: Shariah purity and holdings breakdown for ETFs.
  - name: Methodology
    description: The screening methodology, its thresholds, and version.
  - name: Account
    description: Who is calling, on what plan, and where everything is.
paths:
  /openapi.json:
    get:
      tags:
        - Account
      summary: OpenAPI document
      description: |
        This document, as JSON. Also available as YAML at `/openapi.yaml`.
        **No key required.** Point an OpenAPI-aware client or agent framework
        at `https://api.halal.sh/v1/openapi.json`. Limited to 60 requests a
        minute per IP address, shared with `/openapi.yaml` and the index.
      operationId: getOpenApi
      responses:
        '200':
          description: The OpenAPI 3.1 document
          content:
            application/json:
              schema:
                type: object
        '429':
          $ref: '#/components/responses/RateLimited'
      security: []
components:
  responses:
    RateLimited:
      description: |
        Rate limit exceeded: your key's daily or per-minute allowance, or a
        per-IP limit (600 a minute on every request before its key is checked,
        60 a minute on the index and the OpenAPI document). `Retry-After` and
        `error.retry_after` give the wait in seconds whichever limit refused.
      headers:
        X-RateLimit-Limit:
          schema:
            type: integer
          description: >-
            Maximum requests allowed in the current window (a day for the key's
            quota, a minute for the per-IP limits).
        X-RateLimit-Remaining:
          schema:
            type: integer
          description: Requests remaining in the current window.
        X-RateLimit-Reset:
          schema:
            type: string
            format: date-time
          description: ISO 8601 timestamp when the current window resets.
        Retry-After:
          schema:
            type: integer
          description: Seconds to wait before retrying.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            error:
              code: rate_limit_exceeded
              message: Daily request limit (100) exceeded. Resets at midnight UTC.
              retry_after: 3600
            meta:
              request_id: req_abc123
  schemas:
    ErrorResponse:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              enum:
                - bad_request
                - unauthorized
                - sandbox_restricted
                - not_found
                - rate_limit_exceeded
                - service_unavailable
                - internal_error
              example: not_found
            message:
              type: string
              example: No instrument found for symbol 'XYZ'.
            retry_after:
              type: integer
              description: Seconds until the rate limit resets (only on 429).
        meta:
          $ref: '#/components/schemas/Meta'
    Meta:
      type: object
      properties:
        request_id:
          type: string
          description: Unique ID for this request. Include it in support requests.
          example: req_abc123
        as_of:
          type: string
          format: date-time
          description: When this response was generated.
        methodology:
          type: string
          description: >
            Methodology used, as `id@version`. Present on compliance responses.

            `aaoifi-ss21` for an operating company; `aaoifi-ss57`, `aaoifi-ss20`
            or

            `halal-sh-etf-taxonomy` for a pooled vehicle decided on its
            structure

            (see `screens.structural` on the compliance resource).
          example: aaoifi-ss21@2026.1
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: X-API-Key

````