The GrantCue API
Search the grant catalog and keep your pipeline in sync with your own tools. Plain REST and JSON, organization API keys, and an OpenAPI 3.1 spec.
Get a key
The API is included with the Team plan and higher. An organization admin creates keys in Settings, Integrations, API keys, picks what each key may do, and optionally sets an expiry. The full key is shown once and stored only as a hash, so keep it somewhere safe. Revoking a key stops it at once.
Send the key in the Authorization header. Keys in a URL are refused.
Authorization: Bearer $GRANTCUE_API_KEY
Base URL: https://www.grantcue.com/api/v1
Permissions
A key never does more than an organization member could. It acts as the admin who created it, only reads and writes that admin's organization, and stops working if that admin leaves or the organization leaves a plan that includes the API.
Endpoints
| Endpoint | Scope | What it does |
|---|---|---|
| GET /catalog | catalog:read | Search the catalog with the same filters as Discover. |
| GET /catalog/{id} | catalog:read | One grant by id. |
| GET /pipeline | pipeline:read | Your organization's saved grants, optionally filtered by stage. |
| POST /pipeline | pipeline:write | Add a catalog grant to your pipeline in the first stage. |
Search the catalog
The catalog endpoints return the same grants the public GrantCue site shows, with a fixed set of public fields.
curl "https://www.grantcue.com/api/v1/catalog?q=youth+literacy&status=posted&due_in_days=60&page_size=10" \ -H "Authorization: Bearer $GRANTCUE_API_KEY"
{
"data": [
{
"id": "0f0c6a52-5c1b-4d7e-9a53-2f4f7d2a1b10",
"source": "grants_gov",
"title": "Community Literacy Initiative",
"agency": "Department of Education",
"status": "posted",
"award_ceiling": 250000,
"close_date": "2026-12-01T00:00:00Z",
"source_url": "https://www.grants.gov/search-results-detail/000000"
}
],
"meta": { "total": 41, "page_size": 10, "offset": 0, "has_more": true }
}Filters
- q
- Keywords, an opportunity number, or a quoted phrase.
- agency
- Funding agency or organization (partial match).
- funding_category
- Funding category.
- status
- posted, forecasted, closed or archived, comma separated. Default: posted and forecasted.
- eligibility
- Grants.gov applicant type code.
- min_funding, max_funding
- Funding range in dollars.
- aln
- Assistance Listing Number.
- due_in_days
- Only grants closing within 1 to 365 days.
- source
- Source keys, comma separated.
- location
- A location page slug.
- include_expired
- true to include grants past their deadline.
- sort
- relevance, due_soon or newest.
- page_size, offset
- Paging. page_size is 1 to 100 (default 25).
Add a grant to your pipeline
The grant enters the first stage, researching. Adding one that is already in the pipeline is a harmless no-op. Only grant_id and an optional priority are accepted, and your plan's limit on active opportunities applies.
curl -X POST "https://www.grantcue.com/api/v1/pipeline" \
-H "Authorization: Bearer $GRANTCUE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"grant_id": "0f0c6a52-5c1b-4d7e-9a53-2f4f7d2a1b10", "priority": "high"}'Rate limits
Each key may make 120 reads and 30 writes per minute. Responses carry X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset; over the limit you get a 429 with a Retry-After header.
Errors
Errors are JSON: { "error": { "code", "message" }, "request_id" }. Quote the request_id if you contact support.
| Code | Status | Meaning |
|---|---|---|
| invalid_api_key | 401 | The key is missing, malformed, revoked or expired. |
| key_in_query | 400 | A key was sent in the URL. Use the Authorization header. |
| insufficient_scope | 403 | The key does not have the scope this endpoint needs. |
| plan_required | 403 | The organization is not on a plan that includes the API. |
| key_owner_removed | 403 | The member who created the key has left the organization. |
| rate_limited | 429 | Too many requests. Wait for the Retry-After header. |
| plan_limit_reached | 402 | The pipeline is at its plan's limit of active opportunities. |
Security
- Keys are stored only as a SHA-256 hash and compared in constant time.
- Keys are accepted only in the Authorization header, over HTTPS.
- Every key use, refusal and rate-limit hit is recorded in an audit log.
- Call the API from your servers, not from browser code, so a key is never exposed to your users.