curl --request GET \
--url https://api.openagent.to/api/v1/securities/{id} \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openagent.to/api/v1/securities/{id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openagent.to/api/v1/securities/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openagent.to/api/v1/securities/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openagent.to/api/v1/securities/{id}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openagent.to/api/v1/securities/{id}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openagent.to/api/v1/securities/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"data": {
"_id": "ccc000000000000000000001",
"allowsNonAccredited": false,
"authorizationSource": "board_resolution",
"authorizedShares": "1000000",
"canceledShares": {
"$numberDecimal": "0"
},
"chain": "ethereum-sepolia",
"chainId": "1",
"chainType": "evm",
"corporateActionBlackoutActive": false,
"createdAt": "2026-09-01T09:15:32.104Z",
"cusip": "CUSIP-SEED-001",
"decimalPlaces": 0,
"ercStandard": "ERC-20",
"externalId": "ext-seed-security",
"isin": null,
"issuedShares": {
"$numberDecimal": "45000"
},
"issuerId": "aaa000000000000000000001",
"lastReconciliationAt": null,
"multiSigAddress": null,
"name": "Seed Preferred Equity",
"onChainTotalSupply": {
"$numberDecimal": "45000"
},
"outstandingShares": {
"$numberDecimal": "45000"
},
"parValue": {
"$numberDecimal": "1.25"
},
"reconciliationStatus": "matched",
"reservedShares": {
"$numberDecimal": "10000"
},
"securityClass": null,
"securityType": "equity",
"status": "active",
"ticker": "SEEDTICK",
"tokenAddress": "0x000000000000000000000000000000000000abcd",
"treasuryShares": {
"$numberDecimal": "0"
},
"updatedAt": "2026-09-01T09:15:32.104Z",
"updatedBy": null,
"uuid": "1ebab7be-bfec-4888-85ef-dfddb135b922",
"whitelistOnly": false
},
"message": "Success",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 200,
"success": true
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"data": "<unknown>",
"message": "Success",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 404,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}Get one security
Returns one security as a hydrated document: every optional field is present, as null or its default where unset, and there is no issuerName — nothing is resolved on this path, unlike a list row. Share figures are BSON extended JSON here too, with authorizedShares again the plain-string exception. An issuer_admin asking for another issuer’s security gets 404, not 403, the same way the issuer endpoint behaves: the service returns null on a scope mismatch, which the controller cannot tell apart from a missing record, and a 403 would confirm the security exists. Requires security:read.
curl --request GET \
--url https://api.openagent.to/api/v1/securities/{id} \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.openagent.to/api/v1/securities/{id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.openagent.to/api/v1/securities/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openagent.to/api/v1/securities/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.openagent.to/api/v1/securities/{id}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.openagent.to/api/v1/securities/{id}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openagent.to/api/v1/securities/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"data": {
"_id": "ccc000000000000000000001",
"allowsNonAccredited": false,
"authorizationSource": "board_resolution",
"authorizedShares": "1000000",
"canceledShares": {
"$numberDecimal": "0"
},
"chain": "ethereum-sepolia",
"chainId": "1",
"chainType": "evm",
"corporateActionBlackoutActive": false,
"createdAt": "2026-09-01T09:15:32.104Z",
"cusip": "CUSIP-SEED-001",
"decimalPlaces": 0,
"ercStandard": "ERC-20",
"externalId": "ext-seed-security",
"isin": null,
"issuedShares": {
"$numberDecimal": "45000"
},
"issuerId": "aaa000000000000000000001",
"lastReconciliationAt": null,
"multiSigAddress": null,
"name": "Seed Preferred Equity",
"onChainTotalSupply": {
"$numberDecimal": "45000"
},
"outstandingShares": {
"$numberDecimal": "45000"
},
"parValue": {
"$numberDecimal": "1.25"
},
"reconciliationStatus": "matched",
"reservedShares": {
"$numberDecimal": "10000"
},
"securityClass": null,
"securityType": "equity",
"status": "active",
"ticker": "SEEDTICK",
"tokenAddress": "0x000000000000000000000000000000000000abcd",
"treasuryShares": {
"$numberDecimal": "0"
},
"updatedAt": "2026-09-01T09:15:32.104Z",
"updatedBy": null,
"uuid": "1ebab7be-bfec-4888-85ef-dfddb135b922",
"whitelistOnly": false
},
"message": "Success",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 200,
"success": true
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"data": "<unknown>",
"message": "Success",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 404,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}{
"error": {
"code": "Validation error",
"details": [
{
"field": "email",
"message": "Invalid email format",
"allowedValues": [
"<string>"
]
}
]
},
"message": "Validation error",
"meta": {
"timestamp": "2026-09-01T09:15:32.104Z",
"requestId": "3f1c9d2e-6b7a-4f18-9c53-0a2b6d4e8f10"
},
"statusCode": 422,
"success": false
}Authorizations
Staff access token. Sent as Authorization: Bearer <token>, or — when that header is absent — read from the accessToken cookie, which is how the admin app authenticates. Tokens carry a tokenVersion; logout and password reset bump it, revoking every outstanding token for that account.
Path Parameters
^[a-f\d]{24}$Response
The security.
Standard success envelope. The endpoint payload is in data.
Show child attributes
Show child attributes
{
"_id": "ccc000000000000000000001",
"allowsNonAccredited": false,
"authorizationSource": "board_resolution",
"authorizedShares": "1000000",
"canceledShares": { "$numberDecimal": "0" },
"chain": "ethereum-sepolia",
"chainId": "1",
"chainType": "evm",
"corporateActionBlackoutActive": false,
"createdAt": "2026-09-01T09:15:32.104Z",
"cusip": "CUSIP-SEED-001",
"decimalPlaces": 0,
"ercStandard": "ERC-20",
"externalId": "ext-seed-security",
"isin": null,
"issuedShares": { "$numberDecimal": "45000" },
"issuerId": "aaa000000000000000000001",
"lastReconciliationAt": null,
"multiSigAddress": null,
"name": "Seed Preferred Equity",
"onChainTotalSupply": { "$numberDecimal": "45000" },
"outstandingShares": { "$numberDecimal": "45000" },
"parValue": { "$numberDecimal": "1.25" },
"reconciliationStatus": "matched",
"reservedShares": { "$numberDecimal": "10000" },
"securityClass": null,
"securityType": "equity",
"status": "active",
"ticker": "SEEDTICK",
"tokenAddress": "0x000000000000000000000000000000000000abcd",
"treasuryShares": { "$numberDecimal": "0" },
"updatedAt": "2026-09-01T09:15:32.104Z",
"updatedBy": null,
"uuid": "1ebab7be-bfec-4888-85ef-dfddb135b922",
"whitelistOnly": false
}
"Success"
Show child attributes
Show child attributes
200
true

