California business entity search: the free lookup and the API wall
Every endpoint on this page was live-probed on 2026-07-29 by the Aidenix Atlas catalog.
What is the California business entity search?
The California business entity search is the Secretary of State's public lookup at bizfile Online, and it is the largest state register in the United States with no keyless API behind it. In our data — the Aidenix Atlas catalog, probed on 2026-07-29 — the search page itself answered HTTP 200 while the search endpoint that powers it returned HTTP 403 from two independent networks. That gap is the whole story of this register, and it separates California from every state that publishes an open-data portal:
- The web form is free and complete: name, entity number, status, agent, formation date.
- The endpoint behind that form is protected by a bot-mitigation layer and refuses programmatic clients.
- Bulk and API access exist, but through registration or purchase rather than open data.
Key facts at a glance
A key-facts table is the 60-second version of this page. In our data: 4 routes, 1 of them free and open, 0 keyless APIs, and 2 independent networks confirming the block. Every row from our own probe run of 2026-07-29, according to the Aidenix Atlas catalog logs:
| Question | Answer |
|---|---|
| Free public lookup | yes — bizfile Online web form |
| Keyless API | none |
| Search page status at probe | HTTP 200 |
| Search endpoint status at probe | HTTP 403, from 2 separate networks |
| Official developer portal | calicodev.sos.ca.gov — sign-up required |
Business register on data.ca.gov |
absent — verified by catalog search |
| Bulk files | Master Unload, paid per state fee schedule |
| Data available | name, entity number, status, agent, address, filing history |
Why does the California search API return 403?
A bot-mitigation layer is a service that inspects requests before they reach the application, and California's register sits behind one. We sent the same search request from a European datacenter and a second unrelated network on 2026-07-29; both came back HTTP 403 with an Imperva incident page rather than JSON. What we verified, and what we did not:
- The public page loads normally —
https://bizfileonline.sos.ca.gov/search/businessanswered HTTP 200 in the same probe run, so the service is up. - The
POSTroute that the page itself calls answered 403 with browser-grade headers, a browser User-Agent and anAuthorizationheader present. - The block is applied to programmatic clients, not to the data: the same records are visible to anyone using the form in a browser.
This matters for anyone planning company research at scale, and in our data it is the honest reason California is missing from open company datasets that cover New York and Colorado. Access exists; open access does not.
What are the four routes into California company data?
A route is a distinct way to reach the same register, and California has 4 with very different economics. Status of each checked in our probe run of 2026-07-29:
| Route | Cost | Access | Good for |
|---|---|---|---|
| bizfile Online web form | free | open, browser only | one company at a time |
| Search endpoint behind the form | free | blocked to clients — 403 | nothing, currently |
| Developer portal API | not published publicly | registration and subscription | ongoing programmatic lookups |
| Master Unload bulk files | paid | purchase | building your own copy of the register |
Which route you need follows from volume, not preference:
- If you are checking a handful of companies → the web form, and nothing else is worth the setup.
- If you need lookups inside a product → register on the state developer portal; that is the sanctioned path.
- If you need the whole register → the bulk file, which according to third-party reporting is priced at $100 for the data set and $800 for filing images. We have not purchased it, so we report that as attribution rather than as our own measurement.
Which states do publish an open company API?
An open company register is one that serves the full file as JSON without a key, and in our data 3 US states do it well. Counts live-probed on 2026-07-29 across the nearly 4,000 sources the Aidenix Atlas catalog tracks:
| State | Records | Auth | Status field |
|---|---|---|---|
| New York | 4,254,600 | none | absent — active-only file |
| Colorado | 3,088,214 | none | yes — 6 values |
| Connecticut | 1,288,557 | none | yes, plus ownership flags |
If your research question is national rather than specifically Californian, those three registers plus SEC EDGAR answer most of it at zero cost. California is the gap you buy or scrape around, and pretending otherwise is how projects discover the problem three weeks late.
What the California register does not contain
The California file records legal existence, and in our data it stops at the same 4 walls as every state register — worth stating because vendors selling «California company data» rarely name them:
- No owners. Members, shareholders and beneficial owners are not published; the registered agent is not the owner.
- No financials. Revenue, headcount and assets appear in no state register at any price.
- No industry code. There is no SIC or NAICS field on the entity record.
- No verification of who filed. The register records what was submitted, not whether it is true.
Frequently asked questions
Is the California business entity search free? Yes, through the browser. The bizfile Online form costs nothing and returns entity number, status, formation date, registered agent and filing history. What is not free is programmatic access: our probe on 2026-07-29 confirmed the underlying endpoint returns 403 to non-browser clients.
Is there a California Secretary of State API? Yes, through the state's developer portal at calicodev.sos.ca.gov, which answered HTTP 200 in our probe and requires sign-up and a subscription before product details are visible. It is not an open API in the sense that New York and Colorado are — you register first.
Can I scrape the California business search? The endpoint is deliberately protected, which makes that a terms-of-service question rather than a technical one, and we do not publish a bypass. The sanctioned routes are the developer portal and the bulk file; for open-data work, the three states above are where the free path actually is.
How we verify these claims
Our verification method is a live probe, not a citation chain — every status code and count on this page comes from requests we sent ourselves on 2026-07-29. What the probe run covers, in our data:
- Endpoint behaviour: the 200 on the search page and the 403 on the search endpoint were both observed directly, from two independent networks.
- Negative results published: this page exists because the probe failed, and the failure is the finding.
- Attributed, not measured: the bulk-file prices come from third-party reporting and are labelled as such above.
- Freshness contract: when a source drifts, the probe fleet flags it and this page gets re-verified — the «last probed» date above is that promise. If California opens a keyless route, this page changes.
Source facts from the Aidenix Atlas catalog, probed 2026-07-29. Found an error? The catalog re-probes on every report.
Find these guides useful? Add Aidenix as a preferred source on Google — our pages will surface in your AI Overviews.