Quickstart
Two requests: create a key, then ask whether a product is recalled.
1. Get an API key
Request
curl -X POST https://api.recallsapi.com/v1/keys \
-H "content-type: application/json" \
-d '{"email": "you@example.com"}'
Response (202)
{
"sent": true,
"email": "you@example.com",
"note": "Your API key is on its way to this inbox. It is not shown here."
}
The key arrives by email at that address, and only there: store it in a secret manager or an environment variable. New keys start on the Free plan. One free account per inbox: an address that already has an account, or another alias of the same inbox (a +tag, or dots in a Gmail address), answers 409 account_exists. A lost key is recovered by writing to hello@recallsapi.com from that address.
2. Check a product
Request
export RECALLSAPI_KEY="rk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
curl -s "https://api.recallsapi.com/v1/check?upc=041548000121" \
-H "Authorization: Bearer $RECALLSAPI_KEY"
Response (200)
{
"resolved": {
"identifiers": [
{
"kind": "gtin",
"value": "00041548000121"
}
],
"brand": null,
"name_tokens": []
},
"matches": [
{
"confidence": "exact",
"reasons": [
"gtin 00041548000121"
],
"recall": {
"id": "fda-H-1268-2026",
"agency": "FDA",
"source": "fda_food",
"source_id": "H-1268-2026",
"category": "food",
"title": "Dreyer's Grand Ice Cream Inc.: Outshine Fruit Bars Black Cherry, 6 Bars, 2",
"description": "Outshine Fruit Bars Black Cherry, 6 Bars, 2.5 ounce, with UPC 041548000121, packaged in paper outer cartons; individual fruit bars in plastic wrapper. Keep at 0F (-18C) or colder.",
"hazard": "Foreign object: products may contain glass pieces",
"remedy": null,
"classification": "Class II",
"status": "ongoing",
"firms": [
"Dreyer's Grand Ice Cream Inc."
],
"products": [
"Outshine Fruit Bars Black Cherry, 6 Bars, 2.5 ounce, with UPC 041548000121, packaged in paper outer cartons; individual fruit bars in plastic wrapper. Keep at 0F (-18C) or colder."
],
"distribution": "The adulterated product was distributed to the following States: AL, AR, AZ, CA,CO,CT, FL,GA, IA,ID, IL, KS, LA, MA,MD,MI, MN,MO, NC, ND, NH, NJ, NV, NY, OH, PA, PR, TN TX, UT, VA, VI, WA, and WI.",
"units": "226 pallets",
"flags": [],
"recall_date": "2026-08-18",
"report_date": "2026-09-02",
"url": "https://api.fda.gov/food/enforcement.json?search=recall_number:%22H-1268-2026%22",
"source_url": "https://api.fda.gov/food/enforcement.json?search=recall_number:%22H-1268-2026%22",
"as_of": "2026-10-06T01:18:39.595Z"
}
}
]
}
3. Read the result
resolved- How your input was normalized before matching. The 12-digit UPC
041548000121became the GTIN-1400041548000121. matches[].confidenceexact,strongorpossible. See confidence levels.matches[].reasons- What matched: identifier kind and value,
brand, orname:with the shared words. recall.urlandrecall.source_url- The agency notice and the machine-readable source record. Always show or follow these before acting.
recall.as_of- When recallsapi.com last saw this record change.
A match is information to review against the agency notice, not a safety, legal or compliance determination. An empty matches list is not a safety certification.
Authentication
- Send the key as
Authorization: Bearer <key>or asX-API-Key: <key>. Keys look likerk_live_followed by 40 letters and digits. - Keys are stored only as SHA-256 hashes, so nobody at recallsapi.com can read yours back.
- No key needed:
POST /v1/keys,GET /v1/health,GET /openapi.json, and MCPinitializeandtools/list. - A missing or unknown key answers
401 unauthorized.
Base URL and conventions
- Base URL:
https://api.recallsapi.com. Requests and responses are JSON in UTF-8; catalog items can also be sent as CSV. - CORS is open to any origin, but keep keys on your server: a key in browser code is a key anyone can copy.
- Metered responses carry
x-ratelimit-limit(your daily quota) andx-ratelimit-used(calls so far today, UTC). - Errors share one shape:
{"error": {"code", "message", "details"}}. See errors and limits. - The OpenAPI 3.1 description is at https://recallsapi.com/openapi.json and
https://api.recallsapi.com/openapi.json.
Check your plan and usage
GET /v1/account is not counted against your quota.
Request
curl -s https://api.recallsapi.com/v1/account -H "Authorization: Bearer $RECALLSAPI_KEY"
Response (200)
{
"account_id": "acct_7QmV2kR9sLx4TzNa",
"email": "you@example.com",
"plan": "free",
"status": "active",
"limits": {
"label": "Free",
"monthly_usd": 0,
"daily_calls": 100,
"catalogs": 1,
"monitored_products": 100,
"alerts": false
},
"calls_today": 15
}
Next
- Check and search: every input, confidence levels, batch checks, search and the recall object.
- Catalog monitoring: upload SKUs, CSV columns, matches, alerts and webhook signatures.
- Vehicles: NHTSA campaigns by VIN or make, model and year.
- MCP server: connect Claude, Cursor or your own agent.
- Data and sources: agencies, cadence, identifiers, freshness and known gaps.