Identity
One organisation's accounts across every network, from any one of them
/data-api/v2/identity/graph- Scope
- directory:read
- Freshness
- catalog read
- Group
- Identity
- Platforms
- 7 of 7
What this endpoint answers
Cross-platform identity resolution. Give a handle on any of nine networks, a website domain, or a LinkedIn company slug, and get the same organisation's accounts everywhere else we can prove it, with the proof attached. Every link was read off the company's own website by our enrichment crawl, so each one is a first-party claim rather than a name-similarity guess, and the response says which company published it, how many companies publish that same handle, and how safely it can be attributed.
This is a catalog read: it is served from the CRM Solid database in milliseconds, costs one budget unit, and reports how old the reading is in meta.cache_age_s. It needs the directory:read scope (Directory): Read the account and channel catalog across all seven platforms.
Good to know
- Exactly one of handle (with platform), domain or company is required. Passing more than one is rejected rather than silently ranked.
- Every link comes from the company's own website. The enrichment crawl fetches only that host and only paths robots.txt permits, so provenance is always the organisation publishing about itself.
- confidence is high when one company publishes the handle and it matches the company's domain label exactly, medium when one company publishes it without that agreement, and low when several companies publish the same handle. 7,357 handle pairs are shared this way and all claimants are returned rather than one being picked.
- in_our_catalog is coverage, not corroboration. The engine matches by string equality against our own directories, and handles that do not match are seeded back into those crawl queues, so an account can be in our catalog because this table put it there. It drives the follower figure and deliberately does not drive confidence.
- followers is null wherever we do not carry the account. Null means unknown; it is never a zero audience. Per-network match coverage is in coverage.catalog_match_coverage: 97 percent on TikTok, 65 percent on X, and 0 percent on Instagram, Facebook, LinkedIn and GitHub, where the matching pass has not run.
- url is constructed from the platform and handle, not stored. It is null for YouTube rows whose handle is a lower-cased channel ID, because channel IDs are case sensitive and the case is not recoverable.
- 57,490 companies have at least one published account and 48,470 have two or more, so a graph with a single entry is a normal answer rather than a failure.
- Corporate identifiers only. No staff counts, no locations, no contacts and no people, which is why this is gated on directory:read rather than leads:read.
Parameters
Every value the call accepts, with the example the spec ships so the request runs as written.
| Name | In | Required | Example | What it does |
|---|---|---|---|---|
platform | query | optional | x | Network the handle belongs to. Required with handle, ignored otherwise. |
handle | query | optional | dropbox | Account handle, an @handle, or a full profile URL. Normalised before lookup. |
domain | query | optional | dropbox.com | Company website domain. A bare host, a full URL or an email address all work. |
company | query | optional | dropbox | LinkedIn company slug, as it appears in the company page URL. |
Call it
Authenticate with a bearer token or the x-api-key header. Keys are server-to-server credentials. Never embed one in front-end code - call the API from your own backend and forward the result.
curl "https://crmsolid.com/data-api/v2/identity/graph" \
-H "Authorization: Bearer psk_live_..."
const res = await fetch("https://crmsolid.com/data-api/v2/identity/graph", {
headers: {
Authorization: `Bearer ${process.env.CRM_SOLID_DATA_API_KEY}`,
},
});
if (!res.ok) {
const { error } = await res.json();
throw new Error(`${error.code}: ${error.message} (${error.request_id})`);
}
const { data, meta } = await res.json();
import os
import requests
res = requests.get(
"https://crmsolid.com/data-api/v2/identity/graph",
headers={"Authorization": f"Bearer {os.environ['CRM_SOLID_DATA_API_KEY']}"},
timeout=30,
)
res.raise_for_status()
payload = res.json()
data, meta = payload["data"], payload["meta"]
Keys look like psk_live_... for production keys, psk_test_... for test keys and are minted in the panel.
What comes back
Success is { data, meta }. Failure is { error: { code, message, request_id } }. The body below is the spec's own example: the values in it are illustrative readings, not live numbers.
- Query mode
- handle
- Query platform
- x
- Query handle
- dropbox
- Entities
- 1 items
- Coverage measured at
- 2026-08-31
- Coverage companies with any account
- 57,490
- Coverage companies with two or more platforms
- 48,470
- Coverage links total
- 178,191
- Coverage links matched to our catalog
- 25,393
- Coverage catalog match coverage x
- 65
- Coverage catalog match coverage tiktok
- 97
- Coverage catalog match coverage instagram
- 0
- Coverage entities returned
- 1
- Coverage accounts returned
- 3
{
"data": {
"query": {
"mode": "handle",
"platform": "x",
"handle": "dropbox",
"domain": null,
"company": null
},
"entities": [
{
"company": {
"slug": "dropbox",
"name": "Dropbox",
"website": "http://www.dropbox.com",
"website_domain": "dropbox.com",
"linkedin_url": "https://www.linkedin.com/company/dropbox"
},
"matched_via": {
"platform": "x",
"handle": "dropbox"
},
"platforms": [
"x",
"facebook",
"youtube"
],
"accounts": [
{
"platform": "x",
"handle": "dropbox",
"url": "https://x.com/dropbox",
"followers": 3272392,
"in_our_catalog": true,
"catalog_ref": "14749606",
"first_seen": "2026-08-22T20:26:09.435Z",
"last_seen": "2026-08-22T20:26:09.435Z",
"link": {
"provenance": "company_website",
"published_on_domain": "dropbox.com",
"claimed_by_companies": 1,
"exclusive": true,
"domain_affinity": "exact"
},
"confidence": "high"
}
]
}
],
"coverage": {
"measured_at": "2026-08-31",
"companies_with_any_account": 57490,
"companies_with_two_or_more_platforms": 48470,
"links_total": 178191,
"links_matched_to_our_catalog": 25393,
"catalog_match_coverage": {
"x": 65,
"tiktok": 97,
"instagram": 0
},
"entities_returned": 1,
"accounts_returned": 3
}
},
"meta": {
"request_id": "req_9f2c41a8b3d5",
"generated_at": "2026-08-23T09:14:02.317Z",
"took_ms": 42
}
}
The meta block
request_idstringrequiredUnique id for this request. Quote it in a support ticket.
generated_atstringrequiredServer time the response was produced.
took_msintegerrequiredMilliseconds spent server-side.
pagePageoptionalsourcestringoptionalWhich backend served the payload, for endpoints with more than one.
cache_age_sintegeroptionalAge of the underlying data in seconds. 0 for live reads.
When it fails
GET /identity/graph documents 7 failure statuses. Branch on error.code, which is stable and enumerated; message is prose and may change.
- 401Unauthorized
unauthorized | invalid_keyNo key was presented, or the key is unknown, revoked or expired.
- 402PaymentRequired
payment_required | subscription_inactiveThe key is valid but the plan behind it cannot serve the call: the included requests are spent and overage is switched off, capped or unfunded (payment_required), or the billing period lapsed and was not renewed (subscription_inactive). Retrying does not help; paying does. The X-Plan-* headers on this response say how far past the line you are.
Carries X-Plan, X-Plan-Limit, X-Plan-Overage, X-Plan-Period-End, X-Plan-Remaining.
- 403Forbidden
forbidden_scope | forbidden_ipThe key is valid but not allowed to make this call: it lacks the scope, or the request came from an address outside the key's allowlist.
- 422InvalidRequest
invalid_requestA parameter is malformed, out of range or mutually exclusive with another. `details` names the offending fields.
- 429RateLimited
rate_limited | quota_exceededEither the burst ceiling for the current minute or the daily quota is spent. Distinguish with the code: rate_limited clears within the minute, quota_exceeded does not clear until 00:00 UTC.
Carries Retry-After, X-Quota-Limit, X-Quota-Remaining, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, X-Request-Id.
- 500InternalError
internal_errorSomething failed on our side. Internals are never leaked; quote the request id.
- 503Unavailable
upstream_timeout | upstream_error | not_configuredThe request could not be served right now. BRANCH ON error.code, not on the status: 'upstream_timeout' means a source was too slow (this is what a catalog query hitting its 15-second statement timeout returns, so it is reachable from any endpoint that reads the corpus, not only the live-scrape ones) and the same call is worth retrying with backoff - narrowing it with a smaller limit, a filtered scope or a less popular account makes it far less likely; 'upstream_error' means a source was unreachable, so back off further; 'not_configured' means the capability has no backing service in this deployment, and retrying will never help.
Every response carries X-Request-Id and meta.request_id. Quote it in support requests.
Coverage and limits
This endpoint covers X, Instagram, TikTok, YouTube, Telegram, Bluesky, LinkedIn. Rate limits come from the tier on your key.
| Tier | Requests a minute | Requests a day | Live reads a minute |
|---|---|---|---|
| free | 30 | 1,000 | 5 |
| standard | 120 | 25,000 | 20 |
| pro | 600 | 250,000 | 60 |
| unlimited | 6,000 | 10,000,000 | 600 |
This call only draws on the ordinary per-minute and per-day columns. Every response reports where you stand in X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset and the X-Plan headers.
Start calling it
A key takes a minute to mint in the panel, no card. The reference covers authentication, the envelope, scopes, rate limits and every error code in one page.
Reference path: /data-api/reference/identity-graph