Skip to main content
COT-Reports
COT-Reports.com
COT-Reports
COT-Reports
PAID · REST API · BEARER AUTH

Pull every CFTC market — programmatically.

Bearer auth · JSON · 60 req/min · 500 req/day

+380 markets across all four CFTC report families, normalized columns, weekly history, REST endpoints. $9.99/month — cancel any time.

The COT Data API is a $9.99/month REST API that exposes the same CFTC Commitments of Traders dataset that powers cot-reports.com. Bearer authentication, JSON responses, four endpoints (markets list, history, latest week, COT Index) plus a free static demo for shape validation. Underlying CFTC data is U.S. federal public domain (17 USC §105); the value of this product is the normalized columns, the rate-limited delivery, and the OpenAPI 3.0 spec.

$9.99 / monthCancel anytime. Access through your billed period.
GET /cot/{code}/latest
$ curl -H "Authorization: Bearer cot_live_..." \
         https://cot-reports.com/api/v1/cot/DEMO_FUTURES/latest

  {
  "cftc_code": "DEMO_FUTURES",
  "family": "legacy",
  "row": {
    "report_date": "2026-04-22",
    "cftc_code": "DEMO_FUTURES",
    "market_name": "DEMO FUTURES (Sample / not a real market)",
    "open_interest": 412876,
    "change_open_interest": 8234,
    "noncomm_long": 156000,
    "noncomm_short": 234000,
    "noncomm_spreading": 18500,
    "change_noncomm_long": 4200,
    "change_noncomm_short": -3100,
    "change_noncomm_spreading": 540,
    "comm_long": 198400,
    "comm_short": 121900,
    "change_comm_long": -2100,
    "change_comm_short": 6800,
    "nonrept_long": 39976,
    "nonrept_short": 38476,
    "change_nonrept_long": 320,
    "change_nonrept_short": -185,
    "pct_oi_noncomm_long": 37.78,
    "pct_oi_noncomm_short": 56.67,
    "pct_oi_noncomm_spreading": 4.48,
    "pct_oi_comm_long": 48.06,
    "pct_oi_comm_short": 29.53,
    "pct_oi_nonrept_long": 9.68,
    "pct_oi_nonrept_short": 9.32,
    "contract_units": "DEMO 100,000 (synthetic)"
  }
}
Real shape from the entry tier. Same response on production and the free demo endpoint.

Four endpoints, plus a free demo

GET /api/v1/markets

List every CFTC market with category, exchange, and report-family membership. Filter by category, family, tracked-only, or substring search.

GET /api/v1/cot/{cftc_code}

Weekly history for one market. Default returns the last 520 weeks; from / to / family / limit are optional query params.

GET /api/v1/cot/{cftc_code}/latest

Most recent report for one market. Pre-computed for the typical Friday-after-release polling pattern.

GET /api/v1/cot/{cftc_code}/index

Briese-style COT Index (0–100 percentile) for the latest report against the lookback window. Default 52 weeks.

Plus a free, no-auth GET /api/v1/demo endpoint that returns a static synthetic response — use it to validate your parser before subscribing. 10 req/day per IP.

Rate limits

  • 60 requests per minute
  • 500 requests per day
  • Standard X-RateLimit-* headers on every response
  • On 429, the Retry-After header tells you seconds to wait

Built secure

Tokens are 36-character bearer strings (cot_live_<32 hex>). We hash with SHA-256 and store only the hash; the raw token is shown to you exactly once at creation. Constant-time comparison on validation. Per-token + per-IP-hash logging for abuse detection. Cancellation respects the period you paid for — token stays active until the current billing period ends, then auto-revokes. Manual immediate revoke is one click on /account/api.

Ship a COT integration this afternoon.

No SODA pagination. No CFTC column-name typos. No weekly cron babysitting. Five endpoints, one bearer token, ready to consume.

Cancel anytime. Bearer auth. JSON responses. Free demo endpoint for shape validation.

Read the API reference

Frequently asked questions

What's covered by the entry tier?

Every endpoint, every market, every report family. The only difference between Entry, Pro, and Business tiers is the per-minute and per-day rate limits — Pro and Business launch later.

Can I share the token across machines?

One token per subscription. Sharing across systems is a Terms violation; we log per-token AND per-IP-hash and revoke tokens that show distributed-IP patterns. Use the API key in your CI / production server, keep it out of clients.

How does cancellation work?

Cancel anytime in the Stripe Customer Portal. Default cancellation keeps your API access live until the end of your current billed period — you paid through that date, you keep using it. At period end the token is revoked automatically. If you ever need to revoke immediately (e.g. token leaked, CI key rotation), use the Revoke button on /account/api — that takes effect on the very next request.

What's the demo endpoint?

/api/v1/demo returns a fixed synthetic JSON response with a sample:true flag and the message "This is a sample response." No real CFTC data, no auth, 10 req/day per IP. Use it to validate your parser; don't try to use it as a free data source — every response is identical.

What if the schema changes?

We add columns without breaking — your parser keeps working. Renames, removes or reorders bump the major schema version and are announced 30 days ahead on the changelog at https://cot-reports.com/api plus a notice on the /account/api dashboard for active subscribers. Pin your code to the fields you actually use, add a unit test that fails on unexpected nulls, and trust the contract.

How do I authenticate?

Every request needs an `Authorization: Bearer <token>` header. Tokens are in the form `cot_live_<32 hex chars>` (or `cot_test_…` on preview/dev), 36 characters total including the prefix. Get yours from /account/api after subscribing — it's shown exactly once, so save it immediately. Example: `curl -H 'Authorization: Bearer cot_live_abc123…' https://cot-reports.com/api/v1/markets`. No OAuth, no signed requests, no client IDs — just the bearer token.

What programming languages and libraries can I use?

Anything that makes HTTPS requests. The API is plain REST + JSON, so Python (`requests`, `httpx`), Node.js (`fetch`, `axios`), Go (`net/http`), Rust (`reqwest`), R (`httr`), curl, and Postman all work out of the box. The OpenAPI 3.0 spec at /api/v1/openapi.json lets you auto-generate typed clients with `openapi-generator-cli` for any of the above plus C#, Java, Swift, Kotlin, PHP, Ruby. No SDK is required — keeping the API plain REST is a deliberate choice.

How fresh is the data — and how does the API stay updated?

Same freshness as the CFTC publish itself. Our auto-watcher polls CFTC SODA every hour in a 4-hour window around the 15:30 ET Friday release, covering both Eastern Daylight and Standard Time plus delayed releases on US-holiday weeks. Once new data lands, `/api/v1/cot/<code>/latest` and `/api/v1/cot/<code>/index` return the new week within minutes. The historical endpoint `/api/v1/cot/<code>` always returns the full series up to the latest published week.

Is there a free tier or a trial?

Not for real data. Free use is limited to `/api/v1/demo` — a no-auth endpoint that returns a fixed synthetic JSON response with `sample: true` for parser validation. 10 requests/day per IP. Real CFTC data requires the paid subscription. We don't run a freemium because the underlying CFTC publish costs us nothing; what you pay for is the normalization, the rate-limited delivery, the OpenAPI spec, the bearer-token lifecycle, and the 24/7 uptime around the Friday release window.