curl --request GET \
--url https://api.openagent.to/api/v1/reports/mshf \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openagent.to/api/v1/reports/mshf"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openagent.to/api/v1/reports/mshf', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openagent.to/api/v1/reports/mshf",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openagent.to/api/v1/reports/mshf"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openagent.to/api/v1/reports/mshf")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openagent.to/api/v1/reports/mshf")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"data": {
"docs": [
{
"accountNumber": "5cf7df43-9143-44e5-9557-f854c9d857a6",
"accountType": "individual",
"accreditation": null,
"addressLine1": "123 Main Street",
"addressLine2": null,
"blockchain": "ethereum-sepolia",
"chainTxHash": "0xfedcba…",
"city": "San Francisco",
"country": "US",
"email": "john.doe@example.com",
"entityType": null,
"investorStatus": "active",
"issuerName": "Acme Tokenization LLC",
"kycStatus": null,
"lostHolder": false,
"multiSigAddress": null,
"phone": null,
"postalCode": "94105",
"registrationName": "John Doe",
"registrationType": "individual",
"restriction": null,
"securityName": "Seed Preferred Equity",
"sharesHeld": 45000,
"state": "CA",
"stopTransfer": false,
"taxId": "000-00-0000",
"ticker": "CUSIP-SEED-001",
"tokenAddress": "0x000000000000000000000000000000000000abcd",
"updatedAt": "2026-09-01T09:15:32.104Z",
"walletAddress": "0x1111111111111111111111111111111111111111"
}
],
"hasNextPage": true,
"hasPrevPage": true,
"limit": 0,
"nextPage": 0,
"page": 0,
"pagingCounter": 0,
"prevPage": 0,
"totalDocs": 0,
"totalPages": 0
},
"message": "Success",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 200,
"success": true
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}Master Security Holder File
One row per investor position per security: the holder’s registration, contact details and share balance, flattened out of the security, investor, account and balance collections. This is the register of record. These rows carry investor PII, including an unmasked taxId, full postal address, email and phone. report:read is held by ta_admin, issuer_admin, compliance_officer and the read-only audit_user. Scoped to the caller’s issuer: an issuer_admin sees only its own securities, applied as a pipeline $match so the page counts are scoped too. ta_admin, compliance_officer and audit_user see every issuer. Defaults: page 1, 20 per page, -updatedAt. search matches registrationName, walletAddress, accountNumber, email and securityName. sharesHeld is a JSON number, unlike the /transactions endpoints which return share quantities as exact decimal strings.
curl --request GET \
--url https://api.openagent.to/api/v1/reports/mshf \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openagent.to/api/v1/reports/mshf"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openagent.to/api/v1/reports/mshf', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openagent.to/api/v1/reports/mshf",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openagent.to/api/v1/reports/mshf"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openagent.to/api/v1/reports/mshf")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openagent.to/api/v1/reports/mshf")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"data": {
"docs": [
{
"accountNumber": "5cf7df43-9143-44e5-9557-f854c9d857a6",
"accountType": "individual",
"accreditation": null,
"addressLine1": "123 Main Street",
"addressLine2": null,
"blockchain": "ethereum-sepolia",
"chainTxHash": "0xfedcba…",
"city": "San Francisco",
"country": "US",
"email": "john.doe@example.com",
"entityType": null,
"investorStatus": "active",
"issuerName": "Acme Tokenization LLC",
"kycStatus": null,
"lostHolder": false,
"multiSigAddress": null,
"phone": null,
"postalCode": "94105",
"registrationName": "John Doe",
"registrationType": "individual",
"restriction": null,
"securityName": "Seed Preferred Equity",
"sharesHeld": 45000,
"state": "CA",
"stopTransfer": false,
"taxId": "000-00-0000",
"ticker": "CUSIP-SEED-001",
"tokenAddress": "0x000000000000000000000000000000000000abcd",
"updatedAt": "2026-09-01T09:15:32.104Z",
"walletAddress": "0x1111111111111111111111111111111111111111"
}
],
"hasNextPage": true,
"hasPrevPage": true,
"limit": 0,
"nextPage": 0,
"page": 0,
"pagingCounter": 0,
"prevPage": 0,
"totalDocs": 0,
"totalPages": 0
},
"message": "Success",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 200,
"success": true
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}Authorizations
Staff access token. Sent as Authorization: Bearer <token>, or — when that header is absent — read from the accessToken cookie, which is how the admin app authenticates. Tokens carry a tokenVersion; logout and password reset bump it, revoking every outstanding token for that account.
Query Parameters
Narrow the report to one security. Omit for every security in scope.
^[a-f\d]{24}$1-based page number. Defaults to 1.
x <= 9007199254740991Records per page, 1-100. Defaults to 20.
x <= 100Field names separated by spaces (or commas, which are normalized to spaces), - prefix for descending. Defaults to -createdAt.
^-?[A-Za-z_]\w*(?:\.[A-Za-z_]\w*)*(?:[\s,]+-?[A-Za-z_]\w*(?:\.[A-Za-z_]\w*)*)*$Case-insensitive substring matched against registrationName, walletAddress, accountNumber, email, securityName.
Comma-separated subset of registrationName, walletAddress, accountNumber, email, securityName to match search against. Names outside that list are ignored, and an empty intersection falls back to all of them.

