
Short answer: the Regulations.gov API (version 4, run by GSA) gives you the rulemaking record: dockets, the documents filed in them, and the public comments on those documents. It does not give you the codified rule. You call https://api.regulations.gov/v4/ with a free api.data.gov key in an X-Api-Key header. To follow a rule from proposal to final text, you join three federal sources: Regulations.gov for the docket and comments, the Federal Register for the published notice, and the eCFR for the section the rule changed.
TL;DR
- Regulations.gov holds three object types: dockets (folders), documents (proposed rules, final rules, notices, supporting material) and comments. Each has a search endpoint and a detail endpoint.
- Authentication is a free api.data.gov key, sent as
X-Api-Key. The api.data.gov default is 1,000 requests per hour per key. - One query returns at most 5,000 records (250 per page, 20 pages). Past that, you page by
lastModifiedDate. - The join that trips people up: a comment points at a document's
objectId(a hex string), not at itsdocumentId. - To reach the CFR, use the Federal Register document number on the Regulations.gov record, then look up the part in the eCFR. The diagram below shows the path.
A final rule was published in the Federal Register last spring, and the docket page on Regulations.gov shows it. A colleague wants to cite that page as 'current law' in a client memo. Better plan?
Part of our MCP and developer guide series.
Three federal sources, three jobs
People say "regulatory data" and mean any of these. They are published by different offices, and each answers a different question.
| Source | What it holds | Key needed | Best for |
|---|---|---|---|
| Regulations.gov (GSA) | Dockets, documents, public comments | Yes, free api.data.gov key | Who commented, when the comment period ran, the whole rulemaking file |
| Federal Register | The daily published notice of each proposed and final rule | No (the docs say keys are not needed) | What was published on what date, with agency and CFR references |
| eCFR / CFR | The codified regulations as they stand now | No | The current text of a section, and its version dates |
Regulations.gov is the only one of the three with public comments. The Federal Register carries the dated notice of each rule, and the CFR is where the codified text ends up. Our guides to the Federal Register API and the CFR API cover those two. This post stays on the first and shows how the three connect.
A short history of Regulations.gov
The site went live in January 2003, and it was cheap. Kimberly Nelson, then EPA's chief information officer, told a House subcommittee in March 2004 that five federal agencies built it "in just 3 months and for less than $300,000." It began as a clearinghouse where citizens could find and comment on proposed rules. A bigger system, the Federal Docket Management System, followed (Nelson testimony).
The API you call today is much younger. GSA announced a pilot in August 2020 of a "read" API for downloads and, for the first time, a "write" API for posting bulk comments. A new version of the site launched on February 18, 2021, after testing at beta.Regulations.gov since July 2019. GSA's pitch for the comment API was accountability: "In the former environment, the source of comments was not discernable in any way and many came from bots." Identity-checked organizations would be traceable instead (GSA blog, August 2020, GSA news release, February 2021).
That sentence about bots is also a warning for anyone reading the data. A comment count tells you how many submissions were filed. It does not tell you how many people care, so look at the text, the submitters and the duplicates before you call a count "support."
Regulations.gov API authentication and rate limits
Sign up for a key at api.data.gov. Send it in a header:
X-Api-Key: YOUR_KEY
The docs also allow api_key as a query parameter, but a header keeps the key out of your logs. The special DEMO_KEY works for trying the API, with much lower limits. It was throttled hard when we tested it, so sign up before you build anything.
The details in this section come from GSA's Regulations.gov API page and the api.data.gov developer manual. On limits, there are two numbers to know. The api.data.gov developer manual says the default is 1,000 requests per hour per key, applied across all api.data.gov APIs, and that limits may vary by service. Every response carries X-RateLimit-Limit and X-RateLimit-Remaining headers, so read those rather than counting. The Regulations.gov FAQ says GSA may grant a higher limit on a GET key for an indefinite period if you justify the need, and that the commenting API is limited to 50 requests per minute with a secondary limit of 500 per hour. The FAQ also says POST keys cannot be raised. Plan for a 429 or a blocked key: the developer manual says exceeding a limit blocks the key temporarily, and the block lifts after an hour. Back off, check X-RateLimit-Remaining before each batch, and cache detail responses, since a docket's documents rarely change once posted.
The three object types and how they relate
A docket is a folder. A document is one item filed in it. A comment is a public submission on a document. The relationship runs one way:
docket (FINCEN-2021-0005)
└── document (FINCEN-2021-0005-0217, a proposed rule)
└── comment (FINCEN-2021-0005-0227)
| Object | Search endpoint | Detail endpoint | Link to its parent |
|---|---|---|---|
| Docket | /v4/dockets | /v4/dockets/{docketId} | none |
| Document | /v4/documents | /v4/documents/{documentId} | filter[docketId] |
| Comment | /v4/comments | /v4/comments/{commentId} | filter[commentOnId] takes the document's objectId |
Documents have a documentType. The aggregation counts the live API returns list five values: Proposed Rule, Rule, Notice, Supporting & Related Material and Other. A document also has a subtype (for example, Final Rule) and a frDocNum, the Federal Register document number, when it was published there. The docket detail endpoint returns the RIN (regulation identifier number). In v3 you could get it from search, but the FAQ says v4 moved it to the single-docket call, one of several changes when the old combined search was split into three.
The objectId rule is the one that wastes an afternoon. A document's readable id looks like FINCEN-2021-0005-0217. Its objectId looks like 0900006484eaee2d. Search comments with the second one. The docs show the same two-step pattern: list documents for a docket, then list comments for each document by objectId.
A working Regulations.gov API request
This lists the final rule documents in a real docket, FinCEN's beneficial ownership reporting rulemaking. Note -g, which stops curl from treating the square brackets as a glob.
curl -sg "https://api.regulations.gov/v4/documents?filter[docketId]=FINCEN-2021-0005&filter[documentType]=Rule" \
-H "X-Api-Key: $DATA_GOV_KEY"
The response is JSON:API style. Counts and dates in this post were captured from live responses on 2026-10-04 and will drift. Trimmed to one record:
{
"data": [{
"id": "FINCEN-2021-0005-0461",
"type": "documents",
"attributes": {
"objectId": "0900006485389d06",
"frDocNum": "2022-21020",
"documentType": "Rule",
"subtype": "Final Rule",
"postedDate": "2022-09-30T04:00:00Z",
"docketId": "FINCEN-2021-0005",
"title": "Beneficial Ownership Information Reporting Requirements",
"withdrawn": false,
"openForComment": false
}
}],
"meta": { "totalElements": 1, "pageSize": 25 }
}
Swap Rule for Proposed Rule and the same docket returns three records, posted on 2021-04-05, 2021-12-08 and 2022-12-16. Take the objectId of the 2021-12-08 one, 0900006484eaee2d, and list its comments:
curl -sg "https://api.regulations.gov/v4/comments?filter[commentOnId]=0900006484eaee2d&page[size]=250" \
-H "X-Api-Key: $DATA_GOV_KEY"
meta.totalElements came back as 243 for that document. The list endpoint returns headers only: id, title, posted date. The comment text comes from the detail endpoint, /v4/comments/{commentId}, one call per comment.
Posting a comment
Check the status before you build on this. In August 2025 approved key holders were told, in a notice that circulated publicly, that "the POST method will no longer be allowed for all users with the exception of approved use cases by federal agencies," and that attempted submissions would get a 403 error. Public Citizen, 404 Media and a coalition letter signed by more than 120 groups all describe the change and date the removal to August 8 (Public Citizen, August 2025, 404 Media, August 2025). The documentation page we link to still describes the endpoint. Confirm with GSA's help desk whether your key can post before you plan around it. Comments can still be submitted through the Regulations.gov website.
The rest of this section describes what the documentation page says about the endpoint. The exact JSON:API payload is in the "Posting a comment" section of the official page. The documented API accepts comments. A POST to /v4/comments needs a commentOnDocumentId, the comment text (5,000 characters or fewer), a submissionType of API and a submitterType of ANONYMOUS, INDIVIDUAL or ORGANIZATION. The content type is application/vnd.api+json. A comment sent this way is not public right away, because the agency has to approve it first. Attachments go through two helper endpoints, /v4/submission-keys and /v4/file-upload-urls. Test against the staging URL, https://api-staging.regulations.gov, before you send anything to a live docket.
What developers and advocates say
Most of what people say about this API is about the write side, because that is where it changed. A notice to key holders, which the poster shared as an email, went up on Hacker News on August 11, 2025, and the thread shows more than one reaction.
One commenter, who said they spoke as a nonprofit, wrote: "Without this functionality, our advocacy tools have essentially broken overnight." (quietlycoder, Hacker News, August 2025). A commenter from Fight for the Future, an advocacy group, said it had built simple action pages on top of the endpoint because "The Regulations.gov user interface is really clunky for the average person to navigate" (SRGFight, Hacker News, August 2025). Another reader, who said they lacked context, read the notice's description of third parties submitting comments for a group and asked, "So... lobbyists?" (codingdave, Hacker News, August 2025). It is a fair question. The endpoint was built for any approved organization that collects comments for others, and GSA's 2021 announcement pitched it at "advocacy or membership organizations."
The practical lesson holds either way. If your product depends on write access to a government system, keep the plain web-form path in your plan.
Paging past 5,000 records
Page size runs up to 250, and paging stops at page 20, so one query reaches 5,000 records. For a large docket the official docs give a recipe. Sort by lastModifiedDate, read the last record on page 20, then start a new query with filter[lastModifiedDate][ge] set to that value and page again. The filter is inclusive (greater than or equal), so the boundary record comes back twice and you should de-duplicate by id. Their example docket holds 88,061 comments on a single proposed rule.
Two smaller points. Date filters use values like 2020-08-10 11:58:52, in Eastern time, so convert the UTC timestamp from the response before you reuse it. And a withdrawn boolean on documents tells you whether an item was pulled.
From proposed rule to final rule to the CFR
Back to the docket. The docket's documents tell the story of one rulemaking: proposed-rule documents in April and December 2021 (a third, from December 2022, covers access to the reported data), and the final rule on 2022-09-30. The Federal Register shows the final rule as 87 FR 59498, effective 2024-01-01. Every step is a join between sources.
Regulations.gov to the Federal Register. The frDocNum on the document, 2022-21020, is the Federal Register document number. Fetch it from the Federal Register API, which needs no key:
curl -s "https://www.federalregister.gov/api/v1/documents/2022-21020.json"
That response includes cfr_references (here, title 31, part 1010) and a regulations_dot_gov_info block with the docket_id (FINCEN-2021-0005), the document_id (FINCEN-2021-0005-0461) and the regulation_id_number (1506-AB49). It is the cleanest bridge between the two systems. The same RIN shows up on the Regulations.gov docket.
Federal Register to the CFR. The cfr_references field tells you which part changed. The eCFR holds the current text, and its versioner API lists a section's versions:
curl -s "https://www.ecfr.gov/api/versioner/v1/versions/title-31.json?part=1010§ion=1010.380"
For 31 CFR 1010.380, the earliest version in that list is dated 2022-09-30, the day the final rule was published. Later entries follow each amendment up to 2026-08-14. The CFR text for a section is the thing to cite as current law, and the Regulations.gov docket is the file that explains why it reads that way.
Two limits are worth knowing. A rule's effective date can differ from its publication date, as it does here, so read effective_on from the Federal Register record. And the eCFR describes itself as an editorial compilation maintained as an informational resource, so record the version date next to any text you cite.
Where a hosted API fits
The joins above are three APIs with three id schemes. If you want the CFR end of the chain as one record, the Vaquill AI API resolves a citation such as 31 CFR 1010.380 to a section object whose federalRegisterCitations field lists the Federal Register documents behind it (six of them for this section), and its FEDERAL_REGISTER corpus returns the rule with the proposed and final documents that relate to it. Regulations.gov stays the system of record for comments, so the two sit side by side. For tracking changes to the CFR itself, see the compliance data guide and the law change webhooks guide.
This guide is part of US Law Data: The Complete Guide, a map of where US law comes from and how to use it.
FAQ
What is the Regulations.gov API?
It is GSA's REST API for the federal rulemaking record. Version 4 has separate endpoints to search and fetch dockets, documents and comments, plus a documented POST endpoint for submitting comments, which GSA turned off for third parties in August 2025. The base URL is https://api.regulations.gov/v4/.
Do I need an API key for Regulations.gov?
Yes. Register for a free key at api.data.gov and send it in the X-Api-Key header. The DEMO_KEY value works for first experiments, with much lower limits than a registered key.
What are the Regulations.gov API rate limits? The api.data.gov default is 1,000 requests per hour per key, though limits can vary by service, and response headers show your current allowance. The Regulations.gov FAQ adds that the commenting API allows 50 requests per minute and 500 per hour, and that GSA may raise limits on GET keys when you justify the need.
What is the difference between a docket, a document and a comment? A docket is the folder for one rulemaking or other agency action. Documents are the items filed in it, such as a proposed rule, a final rule, a notice or supporting material. Comments are public submissions on a document.
How do I get all comments on a rule?
List the docket's documents, take the objectId of each document that took comments, and query /v4/comments with filter[commentOnId] set to each one, de-duplicating by comment id. Page up to 250 per request and 20 pages per query. For more than 5,000, sort by lastModifiedDate and restart from the last record's date.
Does Regulations.gov have the final text of a regulation? It has the final rule document as published, but the codified, current text of a section lives in the CFR. Use the eCFR for current text and its versioner API for earlier versions.
How do I link a Regulations.gov docket to the Federal Register?
Use the document's frDocNum, which is the Federal Register document number. The Federal Register API returns a regulations_dot_gov_info block for the same document with the docket id, the document id and the RIN, so you can check the match in both directions.
Is Regulations.gov API v3 still the current version? Version 4 is the one documented now. The v4 FAQ explains that v3's single search endpoint was split into three (documents, comments and dockets), and that some fields, such as a docket's RIN, moved to the detail endpoints.
New legal AI guides, weekly.
Further Reading
Compliance API: Two Meanings, and Where Regulatory Data Comes From
Read postOpen States API Guide: v3 Endpoints, Keys, Bulk Data, and Licensing
Read postLegiScan API Guide: Bills, Votes, Datasets, and Joining Them to Enacted Law
Read postCongress.gov API Guide: What It Covers and What It Doesn't
Read postUSLM vs Akoma Ntoso: How to Read Legislative XML
Read postUS Statutes API: The 2026 Guide to USC, CFR, and State Code Access
Read post
Co-Founder & CTO
Priyansh leads engineering and AI at Vaquill AI: the pipelines that pull statutes, regulations and court rules from every US jurisdiction's official publisher, and the REST API, MCP server and open dataset that serve them.