Torn Intel exposes a small read-only API alongside the faction dashboard. Most of the endpoints below need no key, no header and no cookie — they answer an anonymous request. The three abroad-stock feeds require an approved client key, free but issued by hand. Everything else under /api is scoped to a signed-in player.
The machine-readable version of this page is an OpenAPI 3.1 document, generated from the same source, so the two cannot disagree.
Most endpoints on this page take no credentials. The three listed under Approved-client endpoints need a client key, sent as X-Torn-Intel-Key or as Authorization: Bearer <key>. A key identifies an application rather than a player: it unlocks no faction data and carries its own rate limit.
Those three answered anonymous requests until 2026-08-30. If a client of yours stopped working on that date, this is why — the response shapes did not change, only who may call them. Keys are free and issued manually: write via the contact page, saying which endpoints you need and roughly how often you intend to call them. A refusal is 401 (no key, or a client not yet approved) or 403 (access withdrawn); neither is transient, so retrying will not change the outcome.
Browser extensions are the documented exception: they cannot hold a secret, so a request carrying browser fetch-metadata headers reaches /api/v1/foreign-stock/travel-table without a key, under a per-IP quota. Server-side clients never send those headers and so never enter that lane.
Every other endpoint authenticates with the torn-intel-session cookie, a JWT issued by POST /api/auth/login in exchange for a Torn API key, and returns the signed-in player's own faction data only. There is no endpoint that reads an arbitrary faction and no parameter that makes one.
How Torn API keys are encrypted at rest, and which Torn permission level unlocks what, is documented on the Security page.
Torn Intel MCP server
A remote Model Context Protocol server runs at /api/mcp over the Streamable HTTP transport (spec revision 2025-06-18). It is read-only and exposes exactly the surface below, under the same access levels — an MCP server that could reach further than the REST API, or reach it more cheaply, would be a way around the boundary rather than a convenience. The two abroad-stock tools therefore require the same client key and answer with an error result without one.
claude mcp add --transport http torn-intel https://torn-intel.com/api/mcp
Tools:
get_abroad_stock — Get live abroad stock
get_abroad_stock_history — Get observed stock history for one item
get_platform_stats — Get Torn Intel coverage counters
Versioning & deprecation
The canonical form of every public endpoint is versioned: `https://torn-intel.com/api/v1/public/stats`. Integrate against that.
The unversioned path is a permanent alias of the same handler, kept working indefinitely.
Access level is not part of the version contract. An endpoint may begin requiring a client key without a new version prefix: the response shape is unchanged, only who may call it. Such a change is announced in this list, and the endpoint then documents the key it needs and how to ask for one.
Every API response carries `X-API-Version: 1`.
A breaking change ships as a new version prefix (`/api/v2/...`). A v1 response shape is never mutated in place; adding a field is not breaking, removing or retyping one is.
A version scheduled for removal answers with `Deprecation` (RFC 9745) and `Sunset` (RFC 8594) headers plus a `Link rel="deprecation"`, for at least 180 days before it stops.
Nothing is currently deprecated. On 2026-08-30 the abroad-stock feeds (`/public/foreign-stock`, its `/history`, and `/foreign-stock/travel-table`) began requiring a client key. Their response shapes are unchanged.
Rate limits
Three ceilings, depending on how you reach an endpoint. The session-scoped API is not metered by this policy.
Lane
Per 60s
Counted per
Open endpoints
120
client
Approved key, gated endpoint
1
key — default, raised on request
Browser extension, gated endpoint
30
IP address
The default of 1 on a gated endpoint is not arbitrary: those feeds are refreshed by their own poller roughly every 10 seconds, so a faster caller receives bytes it already has. Say what you need when you ask for the key.
Every response carries RateLimit-Policy and RateLimit (the structured fields from draft-ietf-httpapi-ratelimit-headers-09), plus the older RateLimit-Limit / -Remaining / -Reset triplet that deployed clients read.
Exceeding it returns 429 as application/problem+json with the RFC 9457 quota-exceeded problem type and a Retry-After header. Wait that long — do not retry immediately.
Errors
Every error under /api is JSON, never an HTML page, and carries a stable machine-readable code plus a resolution saying what to do about it. Branch on code, not on the prose fields.
{
"error": "Not Found",
"code": "not_found",
"message": "No API endpoint exists at /api/nope.",
"resolution": "Check the endpoint list at https://torn-intel.com/developers ...",
"status": 404,
"documentation_url": "https://torn-intel.com/developers"
}
Rules of use
Respect the cache window listed on each endpoint. The data behind them refreshes on a schedule, so polling faster returns identical bytes.
Send a User-Agent that identifies your tool, so a misbehaving client can be contacted rather than blocked.
Restock predictions — estimated time to restock, restock windows, model confidence — are never public. They stay behind login under TornTools' terms, and no parameter unlocks them.
Torn Intel is a player-made tool and is not affiliated with Torn.com.
Open endpoints
These answer any anonymous request — no key, no header, no cookie.
GET/api/v1/public/stats
How many Torn players are indexed, how many factions are watched, how many have registered on the site, and how many factions the global scanner walks on every 20-minute pass.
Returns a single boolean keyed by Torn player ID. Exposes no personal data, which is why it is unauthenticated and open to cross-origin calls from the in-game script.
Response
application/json
Cache
not cached
Access
none
CORS
Allowed from any origin
playerId(integer, required) — Torn player ID (XID).
400 — playerId missing or not a number.
{ "registered": true }
GET/api/v1/news/public
Newest first. Each article carries id, title, content, tag, optional image URL and publish date.
These require an approved client key as of 2026-08-30, sent as X-Torn-Intel-Key. They answered anonymous requests before that date and their response shapes are unchanged — only who may call them. Ask for a key on the contact page.
GET/api/v1/public/foreign-stock
Current foreign stock, grouped by country. Each item carries quantity, buy cost, Torn market value and the resulting profit per item. Restock predictions are not exposed here: they are available to signed-in users only. Requires an approved client key.
Quantity and price as observed over a rolling window, oldest point first. Observations only — no forecast. Requires an approved client key.
Response
application/json
Cache
private, max-age=30
Access
approved client key
itemId(integer, required) — Torn item ID.
country(string, required) — Destination code as returned by the stock endpoint.
hours(integer, optional) — Window length in hours. Clamped to 1–48. Defaults to 24.
400 — itemId or country missing, or itemId not a number. Authentication is evaluated before parameters, so a call with no approved key answers 401 whatever the query string says.
Stock per country in the shape the Torn travel-table ecosystem expects: `stocks` keyed by destination code, each with an `update` unix timestamp and a `stocks` array of id/name/quantity/cost. Torn Intel is a first-priority provider for the TornTools Travel Table, which is why this shape is fixed and will not change. Browser extensions reach it without a key; server-side clients need one.
Response
application/json
Cache
private, max-age=10
Access
approved client key, or a request issued by a browser extension
Every public page on Torn Intel serves a Markdown representation from its own URL, so an agent can skip the layout markup. Ask for it with an Accept header, or append .md to the path:
Responses carry Vary: Accept, so a cache in between will not hand you the wrong variant. A request whose Accept rules out both text/html and text/markdown gets a 406 listing the available types rather than a silent fallback.
/llms.txt — This index, in the llmstxt.org format.
/agents.md — When to use Torn Intel, when not to, and how an agent should call it.
/sitemap.xml — Every indexable URL with its last-modified date.
🍪
Cookie Consent
We use analytics to understand how Torn Intel is used. Choose what you allow. Session cookies are strictly necessary and always active. Privacy policy