> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usecroma.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Caixa FGTS Regularity Certificate (CRF)

> Check whether a Brazilian employer is up to date with the FGTS, by CNPJ, from Caixa Econômica Federal: `regular` with the current Certificado de Regularidade do FGTS (number, validity, establishment address), or `irregular` with which body reports the impediment (PGFN or Caixa). Optionally the certificates issued in the last 24 months. `found: false` when the CNPJ is not registered as an employer.



## OpenAPI

````yaml /api-reference/openapi.json post /br/caixa/fgts-certificate/v1
openapi: 3.1.0
info:
  title: Croma Marketplace API
  version: 1.0.0
  description: >-
    Government-data APIs for Colombia, Peru, Mexico, and global web search.
    Croma normalizes public-sector data into structured JSON for product teams
    and AI agents.


    Every operation is a POST with a JSON body and an organization API key as a
    bearer token; every operation is an idempotent lookup and accepts an
    optional `Idempotency-Key` header. Paths carry their major version (`/v1`);
    the versioning and deprecation policy, including the `Deprecation` and
    `Sunset` headers a retiring endpoint sends, is at
    https://docs.usecroma.com/versioning. Rate limits are per organization and
    reported on every response (`RateLimit-Policy`, `X-RateLimit-*`):
    https://docs.usecroma.com/rate-limits.
  termsOfService: https://usecroma.com/en/terms
  contact:
    name: Croma support
    url: https://usecroma.com/en/support
    email: tomas@usecroma.com
servers:
  - url: https://api.croma.run
security: []
paths:
  /br/caixa/fgts-certificate/v1:
    post:
      tags:
        - Brazil
        - Caixa Econômica Federal (FGTS)
      summary: Caixa FGTS Regularity Certificate (CRF)
      description: >-
        Check whether a Brazilian employer is up to date with the FGTS, by CNPJ,
        from Caixa Econômica Federal: `regular` with the current Certificado de
        Regularidade do FGTS (number, validity, establishment address), or
        `irregular` with which body reports the impediment (PGFN or Caixa).
        Optionally the certificates issued in the last 24 months. `found: false`
        when the CNPJ is not registered as an employer.
      operationId: caixa_fgts_certificate
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - document_number
              properties:
                document_number:
                  type: string
                  pattern: >-
                    ^(?:[A-Za-z0-9]{12}\d{2}|[A-Za-z0-9]{2}\.[A-Za-z0-9]{3}\.[A-Za-z0-9]{3}\/[A-Za-z0-9]{4}-\d{2})$
                  description: >-
                    CNPJ de la empresa, con o sin puntuación, p. ej.
                    `33.000.167/0001-01`. Solo empresas: un CPF no se acepta.
                include_history:
                  type: boolean
                  default: false
                  description: >-
                    Si es `true`, la respuesta incluye `history`, los
                    certificados emitidos en los últimos 24 meses (opcional).
              additionalProperties: false
            example:
              document_number: 33.000.167/0001-01
      responses:
        '200':
          description: Successful response
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
            X-Cache:
              $ref: '#/components/headers/X-Cache'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CaixaFgtsCertificateResponse'
        '400':
          description: Invalid request body
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '401':
          description: Missing or invalid API key
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '429':
          description: Rate limit exceeded
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
            Retry-After:
              $ref: '#/components/headers/Retry-After'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '500':
          description: Internal error
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '502':
          description: Upstream source returned an error
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Idempotency-Key:
              $ref: '#/components/headers/Idempotency-Key'
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Sunset:
              $ref: '#/components/headers/Sunset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
      security:
        - bearerAuth: []
      externalDocs:
        description: Interactive documentation and examples
        url: https://docs.usecroma.com/guides/brazil/caixa
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: false
      description: >-
        Optional client-chosen key for this request (any string up to 255
        characters, e.g. a UUID). Every Croma operation is an idempotent lookup:
        repeating a request with the same body returns the same result and
        creates nothing, so retrying after a timeout or network failure is
        always safe. The key is echoed back in the `Idempotency-Key` response
        header so you can correlate a retry with its first attempt. Each attempt
        that reaches the API counts against the rate limit.
      schema:
        type: string
        maxLength: 255
        example: 0f8e9a42-6b7c-4d1e-9a3f-2c5d7e8f9a0b
  headers:
    X-Request-Id:
      description: Unique id for the request (req_…). Include it in support reports.
      schema:
        type: string
    RateLimit-Policy:
      description: >-
        Quota policy for this endpoint as an IETF RateLimit-Policy structured
        field, e.g. `"default";q=100;w=86400` (100 requests per 86400-second
        window per organization). Endpoints with an extra hourly ceiling list
        both policies, e.g. `"webSearch";q=10;w=3600, "default";q=100;w=86400`.
        Present on every response, including 401 and 429.
      schema:
        type: string
        example: '"default";q=100;w=86400'
    Idempotency-Key:
      description: >-
        The `Idempotency-Key` the request carried, echoed back unchanged. Absent
        when the request sent none.
      schema:
        type: string
    Deprecation:
      description: >-
        Present only on an endpoint version scheduled for removal: the date the
        deprecation took effect (RFC 9745). A `Sunset` header and a `Link` with
        `rel="successor-version"` accompany it. Policy:
        https://docs.usecroma.com/versioning
      schema:
        type: string
        example: '@1767225600'
    Sunset:
      description: >-
        Present only on an endpoint version scheduled for removal: the date
        after which it answers 410 (RFC 8594). Announced in the changelog at
        least 90 days ahead.
      schema:
        type: string
        format: date-time
        example: Wed, 01 Apr 2026 00:00:00 GMT
    X-RateLimit-Limit:
      description: Requests allowed in the current window.
      schema:
        type: integer
    X-RateLimit-Remaining:
      description: Requests left before you are throttled.
      schema:
        type: integer
    X-RateLimit-Reset:
      description: ISO 8601 timestamp when the window resets.
      schema:
        type: string
        format: date-time
    X-Cache:
      description: HIT or MISS. Cached hits still count against your quota.
      schema:
        type: string
        enum:
          - HIT
          - MISS
    Retry-After:
      description: Seconds to wait before retrying.
      schema:
        type: integer
  schemas:
    CaixaFgtsCertificateResponse:
      type: object
      required:
        - data
      properties:
        data:
          $ref: '#/components/schemas/CaixaFgtsCertificateData'
    ApiError:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - type
            - code
            - message
          properties:
            type:
              type: string
              description: >-
                Broad category: invalid_request_error, authentication_error,
                not_found_error, rate_limit_error, upstream_error, api_error.
            code:
              type: string
              description: Machine-readable specific code.
            message:
              type: string
              description: Human-readable explanation, safe to surface in UI.
            param:
              type: string
              description: Field that triggered the error. Present on validation errors.
            details:
              type: object
              description: Free-form structured detail.
    CaixaFgtsCertificateData:
      type: object
      properties:
        document_number:
          type: string
          description: The CNPJ queried, 14 characters, echoed back.
        found:
          type: boolean
          description: false when the CNPJ is not registered as an employer with the FGTS.
        status:
          anyOf:
            - type: string
              enum:
                - regular
                - irregular
            - type: 'null'
          description: >-
            `regular` (a valid certificate exists) or `irregular` (impediments
            block it); null when not found.
        status_label:
          anyOf:
            - type: string
            - type: 'null'
          description: The source's verdict sentence(s), verbatim.
        impediments:
          type: array
          items:
            type: object
            properties:
              agency:
                type: string
                enum:
                  - PGFN
                  - CAIXA
                description: >-
                  Who reports it: `PGFN` (FGTS debt enrolled with the Union's
                  attorneys) or `CAIXA` (the fund's operator).
              message:
                type: string
                description: What the source says, verbatim.
            required:
              - agency
              - message
          description: What blocks the certificate; empty unless `irregular`.
        company_name:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            The company's name (razão social) as the source prints it, including
            suffixes like `EM RECUPERACAO JUDICIAL`.
        certificate:
          anyOf:
            - type: object
              properties:
                number:
                  type: string
                  description: >-
                    The certificate's number (22 digits), which anyone can check
                    with the source.
                valid_from:
                  type: string
                  description: >-
                    `yyyy-mm-dd` the certificate was issued and starts being
                    valid.
                valid_until:
                  type: string
                  description: '`yyyy-mm-dd` it stops being valid: 30 days after issue.'
                address:
                  type: object
                  properties:
                    street:
                      anyOf:
                        - type: string
                        - type: 'null'
                      description: Street type and name, e.g. `AV REPUBLICA DO CHILE`.
                    number:
                      anyOf:
                        - type: string
                        - type: 'null'
                      description: The street number, as printed.
                    complement:
                      anyOf:
                        - type: string
                        - type: 'null'
                      description: Floor, suite or block; null when there is none.
                    district:
                      anyOf:
                        - type: string
                        - type: 'null'
                      description: The neighbourhood (bairro).
                    city:
                      anyOf:
                        - type: string
                        - type: 'null'
                    state:
                      anyOf:
                        - type: string
                        - type: 'null'
                      description: Two-letter state (UF), e.g. `RJ`.
                    postal_code:
                      anyOf:
                        - type: string
                        - type: 'null'
                      description: CEP, `NNNNN-NNN`.
                    full:
                      type: string
                      description: The whole address on one line, as printed.
                  required:
                    - street
                    - number
                    - complement
                    - district
                    - city
                    - state
                    - postal_code
                    - full
                  description: The establishment's address as the certificate prints it.
              required:
                - number
                - valid_from
                - valid_until
                - address
            - type: 'null'
          description: The current certificate; null unless `regular`.
        history:
          anyOf:
            - type: array
              items:
                type: object
                properties:
                  issued_on:
                    type: string
                    description: '`yyyy-mm-dd` the certificate was issued.'
                  valid_from:
                    type: string
                    description: '`yyyy-mm-dd`.'
                  valid_until:
                    type: string
                    description: '`yyyy-mm-dd`.'
                  number:
                    anyOf:
                      - type: string
                      - type: 'null'
                    description: >-
                      The certificate's number; null on early-2000s entries,
                      which carry none.
                required:
                  - issued_on
                  - valid_from
                  - valid_until
                  - number
            - type: 'null'
          description: >-
            Certificates issued in the last 24 months, newest first, when
            `include_history` was true; null otherwise.
        checked_at:
          type: string
          description: When the source answered, ISO 8601 in Brasília time.
      required:
        - document_number
        - found
        - status
        - status_label
        - impediments
        - company_name
        - certificate
        - history
        - checked_at
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Use Authorization: Bearer YOUR_API_KEY'

````