SAM.gov's federal debarment list accessible without API key via undocumented endpoint
SAM.gov's federal exclusions list — containing over 168,000 debarment and suspension records — is publicly accessible without an API key through an undocumented backend endpoint, despite official documentation stating a registered key is required. A developer discovered that SAM.gov's own search interface retrieves data from a separate internal API at sam.gov/api/prod/sgs/v1/search/, which bypasses the key-gated endpoint described in the docs. The same backend serves at least seven distinct federal datasets, including contract opportunities, Davis-Bacon wage determinations, and the federal grants catalog, each distinguished only by an index parameter whose values do not match any UI labels. The discovery was made by reading SAM.gov's own frontend network requests rather than relying on official documentation. Investigators also found that certain filters, such as is_active=true, behave inconsistently across datasets — silently returning unfiltered exclusion data without any error when applied to the debarment list.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in