No owner data, ever
Responses tell you whether an item is registered and its status. Owner identities are never returned, and we log a SHA-256 hash of each query rather than the identifier itself.
Finder API v1
Check whether an item is registered, lost or stolen with one HTTPS call. Query by serial number, IMEI, frame number, VIN or Regimate ID, and never touch an owner's personal data.
# Is this bike lost or stolen? curl "https://my.regimate.app/api/finder/v1/lookup\ ?q=WTU412C0918&type=frame" \ -H "Authorization: Bearer rmf_••••.••••" # 200 OK { "registered": true, "status": "lost", "category": "bike", "registeredAt": "2026-03", "contactLink": "https://my.regimate.app/find/RM-4K7X2QPA", "assetUrl": "https://my.regimate.app/find/RM-4K7X2QPA" }
Built for trust
Responses tell you whether an item is registered and its status. Owner identities are never returned, and we log a SHA-256 hash of each query rather than the identifier itself.
When you look up an item that's been reported lost or stolen, its owner is notified that your organisation checked it, and you get a private contact link to start a conversation.
Get an item.status_changed event when an item you looked up in the last 90 days changes status. Signed with HMAC-SHA256 and retried five times.
Create as many keys as you need, with optional expiry, and revoke any of them instantly. Secrets are shown once and stored hashed.
A dashboard with monthly and daily usage, a live playground that copies requests as curl, and clear error codes when you hit a limit.
Sign in with a Regimate account, verify your email and your Sandbox key is ready: 50 free lookups a month to build your integration.
Who it's for
| Parameter | Description |
|---|---|
| q | The identifier to check. Required, up to 256 characters. |
| type | serial (default), imei, frame, vin or regimateId. |
| partnerRef | Optional. Your own reference, stored with the lookup. |
Authenticate with Authorization: Bearer rmf_<keyId>.<secret>. Limits are shared across all of your keys.
import { createHmac, timingSafeEqual } from "node:crypto"; // header: X-Regimate-Signature: t=<unix>,v1=<hex> export function verify(rawBody, header, secret) { const { t, v1 } = Object.fromEntries( header.split(",").map((p) => p.split("="))); const expected = createHmac("sha256", secret) .update(`${t}.${rawBody}`).digest("hex"); const fresh = Math.abs(Date.now() / 1000 - t) < 300; return fresh && timingSafeEqual( Buffer.from(expected), Buffer.from(v1)); }
Webhooks
Register an HTTPS endpoint and we'll tell you when the status of an item you've checked changes, for example when a lost phone is found or a bike is reported stolen.
Plans
Monthly plans, billed through Stripe. Prices exclude VAT. Overage is added to your next invoice.
| Plan | Price | Lookups / month | Daily cap | Requests / min | Extra lookups |
|---|---|---|---|---|---|
| Sandbox | Free | 50 | 10 | 10 | Hard stop |
| Starter | £49 | 1,000 | 500 | 60 | 8p each |
| Growth Popular | £149 | 5,000 | 2,500 | 120 | 5p each |
| Scale | £449 | 25,000 | 10,000 | 300 | 3p each |
| Enterprise | Custom | Custom | Custom | Custom | Custom |
Reference
| HTTP | Code | Meaning |
|---|---|---|
| 400 | MISSING_QUERY · INVALID_QUERY | The q parameter is missing or invalid. |
| 401 | MISSING_API_KEY · API_KEY_INVALID · API_KEY_EXPIRED · API_KEY_REVOKED | Check your Authorization header and key. |
| 403 | ACCOUNT_SUSPENDED · SUBSCRIPTION_INACTIVE | Your account or plan needs attention. |
| 429 | RATE_LIMIT_EXCEEDED · DAILY_CAP_EXCEEDED · MONTHLY_LIMIT_EXCEEDED | You've hit a limit. Rate limits include a Retry-After header. |
Use of the Finder API is subject to our Finder API Terms.