← Files Compliance Horizon ScannerARCHIVED FILE

references/sources-us-federal.md

9.17 KB · Oct 5, 2026 · 18:34 UTC

↓ Download file

# Source registry — US federal

Verification labels below are original author notes, not results of the Codex compatibility
review. Recheck every endpoint and claim at run time. HTTP status alone does not verify
content. Runtime behavior is governed by `runtime-safety.md`.


Every URL here was fetched and confirmed live on **2026-09-09**. If a source fails at scan time,
report it as a named coverage gap; do not substitute recall. Re-verify anything that looks stale.

Tiers: `primary` = official publisher of the instrument · `regulator` = the regulator's own site ·
`secondary` = anything else (leads only, never findings).

---

## 1. Federal Register API — `primary`, the workhorse

**No API key required.** This provides searchable renditions of the daily publication for federal rules, proposed
rules, notices, and presidential documents. Prefer it over every agency website: it is structured,
date-filterable, gives stable identifiers, and carries the comment deadline.

FederalRegister.gov HTML is an informational rendition, not the official legal edition.
For reliance on an official edition, follow the document's govinfo.gov PDF link and
cross-check relevant provisions when accessible; disclose if that comparison was not done.

Base: `https://www.federalregister.gov/api/v1/documents.json`

### Parameters

| Parameter | Notes |
|---|---|
| `conditions[publication_date][gte]` | `YYYY-MM-DD`. **This is the delta boundary** — set to the profile's `last_scan_date`. |
| `conditions[publication_date][lte]` | Optional window end. |
| `conditions[type][]` | Repeatable. `RULE` (final), `PRORULE` (proposed), `NOTICE`, `PRESDOCU`. |
| `conditions[agencies][]` | Repeatable. Agency **slug** — see the table below. |
| `conditions[term]` | Full-text search. Use for `watch_keywords`. |
| `fields[]` | Repeatable. Always request: `document_number`, `title`, `publication_date`, `type`, `agencies`, `html_url`, `comments_close_on`, `effective_on`, `abstract`. |
| `per_page` | Max 1000. |
| `order` | `newest`, `oldest`, `relevance`. |

Response envelope: `count`, `total_pages`, `results[]`. Check `count` before paging — a broad query
over a long window returns thousands.

### Verified example

Proposed rules from the Labor Department since 2026-06-01:

```
https://www.federalregister.gov/api/v1/documents.json?conditions[agencies][]=labor-department&conditions[type][]=PRORULE&conditions[publication_date][gte]=2026-06-01&per_page=20&fields[]=title&fields[]=document_number&fields[]=publication_date&fields[]=comments_close_on&fields[]=effective_on&fields[]=html_url
```

Confirmed 2026-09-09: `count: 22`, first result document `2026-15717`.

### Provenance mapping

- `official_id` ← `document_number` (e.g. `2026-15717`)
- `source_url` ← `html_url` — already a deep link to the document. **Never cite the API query URL as
  the source**; cite `html_url`.
- `publisher` ← `"Federal Register"`, plus the agency name from `agencies[].name`
- Comment deadline ← `comments_close_on`; effective date ← `effective_on`
- `supporting_quote` ← fetch `html_url` and quote the document. The API's `abstract` is an editorial
  summary, **not** the instrument's own words — acceptable for triage, not as a `supporting_quote`
  for a date, threshold, or penalty.

### Traps

- **`effective_on` is `null` on proposed rules.** Verified: document `2026-15717` (PRORULE) returns
  `effective_on: null` with `comments_close_on: 2026-09-30`. Report the timeline as measured to the
  comment deadline and the effective date as `undated`. Never estimate one.
- **`significant` is unreliably populated** — verified `null` on a 2026 notice. Do not use it to
  filter or to justify an impact score.
- A `Notice` can carry real obligations (information collection, enforcement policy). Don't assume
  notices are low impact.

### Agency slugs (verified from `/api/v1/agencies`, 2026-09-09)

| Slug | Agency | Domain |
|---|---|---|
| `labor-department` | Labor Department | employment |
| `occupational-safety-and-health-administration` | OSHA | employment |
| `equal-employment-opportunity-commission` | EEOC | employment |
| `national-labor-relations-board` | NLRB | employment |
| `labor-management-standards-office` | Labor-Management Standards | employment |
| `federal-trade-commission` | FTC | consumer protection, privacy, AI |
| `consumer-financial-protection-bureau` | CFPB | consumer protection |
| `securities-and-exchange-commission` | SEC | ESG disclosure, governance |
| `industry-and-security-bureau` | BIS | export controls |
| `foreign-assets-control-office` | OFAC | sanctions |
| `u-s-customs-and-border-protection` | CBP | trade, forced-labour import bans |
| `environmental-protection-agency` | EPA | ESG, environmental |
| `health-and-human-services-department` | HHS | privacy (HIPAA) |
| `homeland-security-department` | DHS | employment eligibility, cyber |

Full list: `https://www.federalregister.gov/api/v1/agencies` (verified 200). Resolve a slug from
this endpoint rather than guessing — a wrong slug silently returns zero results, which reads exactly
like "nothing new," and that is a dangerous false negative.

---

## 2. eCFR API — `primary`, for codified text

**No key required. Use the API, not the website.**

- Title list: `https://www.ecfr.gov/api/versioner/v1/titles.json` (verified 200)
  Returns `meta` + `titles[]`, each with `number`, `name`, `latest_amended_on`, `latest_issue_date`,
  `up_to_date_as_of`.
- Title structure: `https://www.ecfr.gov/api/versioner/v1/structure/<YYYY-MM-DD>/title-<n>.json`
  Verified 2026-09-09 — confirms a part exists and returns its official label. Examples confirmed
  this way: title 45 part 164 "Security and Privacy", title 16 part 312 "Children's Online Privacy
  Protection Rule (Coppa Rule)", title 15 part 774 "The Commerce Control List", title 31 part 501
  "Reporting, Procedures and Penalties Regulations", title 29 part 1910 "Occupational Safety and
  Health Standards".
- Point-in-time full text is available under the same `versioner/v1` namespace.

### Two verification traps, both confirmed by control test on 2026-09-09

**The human-facing eCFR site is bot-gated and returns HTTP 200 for parts that do not exist.**
`https://www.ecfr.gov/current/title-99/part-9999` returned 200 with a "Request Access" interstitial —
identical to what real part URLs returned. **A 200 from `ecfr.gov/current/...` proves nothing.**
Verify part existence through the structure API above, where a fake part is correctly absent.

**`uscode.house.gov` is not usable programmatically.** It returned "Document not Found" for real
sections as well as fake ones. Do not cite it as a source you have verified. For US statutory text,
either cite the Federal Register document that amended it or state that you could not reach the
statute and log a coverage gap.

`up_to_date_as_of` matters: eCFR lags the Federal Register, so a very recent final rule may be in the
FR but not yet in eCFR. Cite the Federal Register for new changes and eCFR for the standing text, and
say which you are citing.

## 3. Regulations.gov v4 — `primary`, optional

`https://api.regulations.gov/v4/documents` — verified **403 without a key**. Requires a free
api.data.gov key. Treat as optional: use only if the user supplies a key, otherwise fall back to the
Federal Register, which covers the same rulemakings. Adds docket history and public comments.

## 4. Agency sources — `regulator`

Use for guidance, enforcement policy, and press announcements that never reach the Federal Register.
All verified 200 on 2026-09-09.

| Source | URL | Notes |
|---|---|---|
| FTC press releases | `https://www.ftc.gov/feeds/press-release.xml` | RSS. Enforcement and policy. |
| OFAC recent actions | `https://ofac.treasury.gov/recent-actions` | Sanctions designations, often effective immediately. |
| BIS Federal Register notices | `https://www.bis.doc.gov/index.php/federal-register-notices` | Export control rules. |
| SEC rulemaking activity | `https://www.sec.gov/rules-regulations/rulemaking-activity` | **Requires a descriptive User-Agent with contact details** — SEC returns 403 to generic agents. Verified 200 with a declared UA. |
| CFPB newsroom | `https://www.consumerfinance.gov/about-us/newsroom/` | |
| OSHA news releases | `https://www.osha.gov/news/newsreleases` | **Unreliable — User-Agent-gated.** Returned 200 to a browser-style UA and 403 to a declared tool UA in the same session on 2026-09-09. Treat a failure as a coverage gap, and prefer the `occupational-safety-and-health-administration` Federal Register slug, which is stable. |

Note the opposite UA requirements: SEC rejects generic agents and needs a declared one; OSHA did the
reverse. Neither is a reason to guess at content when a fetch fails — log the gap.

**Not included, deliberately:** `dol.gov/newsroom/releases` (403, bot-blocked) and
`eeoc.gov/newsroom/rss.xml` (404). Reach both agencies through the Federal Register API slugs above
instead — primary, structured, and filterable. Do not write these two URLs back in without
re-verifying them.

---

## 5. Optional US state research

This registry covers federal sources only. When `coverage.us_states` is nonempty, also
follow `sources-us-states.md` for those states. Otherwise disclose that state law was not
searched. Never infer state coverage from a federal result.

SHA-256: 3839d385cb2e40ed4a2ebb08ad311a272f62120dab12ec533cd9c00f48d1df45