# ESMA Investment Firm Permissions Register (`nexgenwatch/esma-permissions`) Actor

One structured permission_record per authorised investment firm in ESMA's Union authorisation/passporting register — from the official ESMA registers machine endpoint, keyless and logged-out.

- **URL**: https://apify.com/nexgenwatch/esma-permissions.md
- **Developed by:** [NexGen Watch](https://apify.com/nexgenwatch) (community)
- **Categories:** Automation, Lead generation, Developer tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $13.40 / 1,000 permission records

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## 🔔 ESMA Investment Firm Permissions Register

One structured `permission_record` per authorised investment firm in ESMA's Union authorisation/passporting register — from the official ESMA registers machine endpoint, keyless and logged-out.

**Difference:** One organisation-level record per authorised entity — firm identity (name, commercial name, LEI, entity type), competent authority, home and host member state, status, authorisation dates, office type, organisational address, legal form, and website — with its ACTIVE authorised MiFID services and its passported host member states aggregated from the register's child records. This is the "who is authorised for what, and where" view, not a raw activity dump.

Output is one `esma_investment_firm_permission` row per result; billing is pay-per-event, the value event being one permission record (a $0.02 start fee per run, then $0.02 per permission record). Source: registers.esma.europa.eu.

No login, no API key and no CAPTCHA solving are involved: the source is read logged-out with an identified contact User-Agent.

### 📊 Sample Output

[![ESMA Investment Firm Permissions Register sample output — a table of real permission record rows (entity_name, lei, entity_type_label, competent_authority) from run mJKy27T60nTQdcD8Q on build 0.1.5](https://api.apify.com/v2/key-value-stores/80Y7h3rmVN5CWK7Mw/records/esma-permissions-sample)](https://apify.com/nexgenwatch/esma-permissions?fpr=2ayu9b)

Real rows from run `mJKy27T60nTQdcD8Q` on build 0.1.5 (2026-09-18), the same input as the Quick start below — every value is as the source published it (emails masked, long text shortened):

| entity_name | lei | entity_type_label | competent_authority | office_type | head_office_address |
|---|---|---|---|---|---|
| Catam Asset Management AG | 529900RUQ6E2Z710XY62 | Investment firm | Finanzmarktaufsicht (FMA) | Head office | Landstrasse 34, 9494 Schaan |
| PRIVATCONSULT Vermögensverwaltung GmbH | 529900YSU5UDSBC3TQ23 | Investment firm | Austrian Financial Market Authority (FMA) | Head office | Rennweg 33B/202, 1030 Wien, Austria |
| Superfund Asset Management GmbH | 5493000YMLOEF5VK6419 | Investment firm | Austrian Financial Market Authority (FMA) | Head office | Marc-Aurel-Straße 10-12, 1010 Wien, Austria |
| Ithuba Capital AG | 529900JPKYD3K9OY2W04 | Investment firm | Austrian Financial Market Authority (FMA) | Head office | Stallburggasse 4, 1010 Wien, Austria |
| FINAD GmbH | 529900VG6346RXYHEY36 | Investment firm | Austrian Financial Market Authority (FMA) | Head office | Dorotheergasse 6-8/L/021, 1010 Wien, Austria |
| OVB Allfinanzvermittlungs GmbH | 529900X3EIZINOTJX849 | Investment firm | Austrian Financial Market Authority (FMA) | Head office | Sirona Strasse 4/1/C, 5071 Wals bei Salzburg, Austria |
| PORTFOLIO INVEST Vermögensmanagement GmbH | 529900WRO3TK8XNFXU04 | Investment firm | Austrian Financial Market Authority (FMA) | Head office | Hermann-Löns-Strasse 11A, 5020 Salzburg, Austria |
| Impact Asset Management GmbH | 529900ZKAL0KA0NNRP34 | Investment firm | Austrian Financial Market Authority (FMA) | Head office | Stella Klein Löw Weg 15, 5. OG Rund Vier, Haus B, 1020 Wien, Austria |

The run finished with the status message: `NORMAL: 50 unique rows (0 duplicates collapsed). billable=50`

### ✅ What you get

Each row is flat JSON with these fields (from the dataset schema and the sample run; a field the source does not publish for a given row is `null`):

- `record_type` (string) — e.g. `esma_investment_firm_permission`
- `entity_id` (string/null) — e.g. `ae42`
- `entity_name` (string/null) — e.g. `Catam Asset Management AG`
- `commercial_name` (string/null) — null in every sample row
- `lei` (string/null) — e.g. `529900RUQ6E2Z710XY62`
- `head_office_lei` (string/null) — null in every sample row
- `entity_type_code` (string/null) — e.g. `MIF`
- `entity_type_label` (string/null) — e.g. `Investment firm`
- `competent_authority` (string/null) — e.g. `Finanzmarktaufsicht (FMA)`
- `home_member_state` (string/null) — e.g. `LIECHTENSTEIN`
- `host_member_state` (string/null) — null in every sample row
- `office_type` (string/null) — e.g. `Head office`
- `head_office_address` (string/null) — e.g. `Landstrasse 34, 9494 Schaan`
- `branch_address` (string/null) — null in every sample row
- `legal_form` (string/null) — null in every sample row
- `website` (string/null) — null in every sample row
- `status` (string/null) — e.g. `Active`
- `authorisation_notification_date` (string/null) — e.g. `12/09/2006`
- `authorisation_withdrawal_end_date` (string/null) — e.g. `31/08/2022`
- `last_update` (string/null) — e.g. `30/07/2025`
- `authorised_services` (string/null) — e.g. `["Advice on capital structure", "Execution of orders", "Investment advice", "Por`
- `authorised_service_count` (string/integer/null) — e.g. `6`
- `passported_host_states` (string/null) — null in every sample row
- `passported_host_state_count` (string/integer/null) — e.g. `0`
- `source` (string/null) — e.g. `esma-permissions`
- `release_date` (string/null) — null in every sample row
- `source_url` (string/null) — e.g. `https://registers.esma.europa.eu/solr/esma_registers_upreg/select`
- `observed_at` (string/null) — e.g. `2026-09-18T21:38:44Z`
- `license` (string/integer/null) — e.g. `Reuse per ESMA legal notice (European Securities and Markets Authority open data`
- `attribution` (string/integer/null) — e.g. `Source: ESMA registers — registers.esma.europa.eu (Union authorisation/passporti`
- `terminal` (string/integer/null) — null in every sample row
- `reported_total` (string/integer/null) — null in every sample row
- `raw_seen` (string/integer/null) — null in every sample row
- `duplicates` (string/integer/null) — null in every sample row
- `unique_found` (string/integer/null) — null in every sample row
- `delivered` (string/integer/null) — null in every sample row
- `scope` (string/integer/null) — null in every sample row
- `note` (string/integer/null) — null in every sample row

**✅ What you get**

- `record_type` (string) — e.g. `esma_investment_firm_permission`
- `entity_id` (string/null) — e.g. `ae42`
- `entity_name` (string/null) — e.g. `Catam Asset Management AG`
- `commercial_name` (string/null) — null in every sample row
- `lei` (string/null) — e.g. `529900RUQ6E2Z710XY62`
- `head_office_lei` (string/null) — null in every sample row
- `entity_type_code` (string/null) — e.g. `MIF`
- `entity_type_label` (string/null) — e.g. `Investment firm`
- `competent_authority` (string/null) — e.g. `Finanzmarktaufsicht (FMA)`
- `home_member_state` (string/null) — e.g. `LIECHTENSTEIN`
- `host_member_state` (string/null) — null in every sample row
- `office_type` (string/null) — e.g. `Head office`
- `head_office_address` (string/null) — e.g. `Landstrasse 34, 9494 Schaan`
- `branch_address` (string/null) — null in every sample row
- `legal_form` (string/null) — null in every sample row
- `website` (string/null) — null in every sample row
- `status` (string/null) — e.g. `Active`
- `authorisation_notification_date` (string/null) — e.g. `12/09/2006`
- `authorisation_withdrawal_end_date` (string/null) — e.g. `31/08/2022`
- `last_update` (string/null) — e.g. `30/07/2025`
- `authorised_services` (string/null) — e.g. `["Advice on capital structure", "Execution of orders", "Investment advice", "Por`
- `authorised_service_count` (string/integer/null) — e.g. `6`
- `passported_host_states` (string/null) — null in every sample row
- `passported_host_state_count` (string/integer/null) — e.g. `0`
- `source` (string/null) — e.g. `esma-permissions`
- `release_date` (string/null) — null in every sample row
- `source_url` (string/null) — e.g. `https://registers.esma.europa.eu/solr/esma_registers_upreg/select`
- `observed_at` (string/null) — e.g. `2026-09-18T21:09:38Z`
- `license` (string/integer/null) — e.g. `Reuse per ESMA legal notice (European Securities and Markets Authority open data`
- `attribution` (string/integer/null) — e.g. `Source: ESMA registers — registers.esma.europa.eu (Union authorisation/passporti`
- `terminal` (string/integer/null) — null in every sample row
- `reported_total` (string/integer/null) — null in every sample row
- `raw_seen` (string/integer/null) — null in every sample row
- `duplicates` (string/integer/null) — null in every sample row
- `unique_found` (string/integer/null) — null in every sample row
- `delivered` (string/integer/null) — null in every sample row
- `scope` (string/integer/null) — null in every sample row
- `note` (string/integer/null) — null in every sample row

**What you get**

One `permission_record` per authorised entity, deduplicated on the register entity id, carrying `authorised_services` and `passported_host_states` as structured lists plus their counts. A `run_receipt` row carries the full-register count, scope, license, attribution, and totals.

### ⚙️ Sample inputs

**1. Quick start — the Store example (this is what the sample above came from)**

```json
{
  "maxRecords": 50
}
```

The sample run charged exactly: 1 × $0.02 apify-actor-start + 50 × $0.02 permission_record = **$1.02** on the Free tier — every delivered row was billed.

**2. A smaller, narrowed run**

```json
{
  "maxRecords": 5
}
```

Caps the run at 5 rows — about $0.12 on the Free tier ($0.02 start + 5 × $0.02).

**3. A full-size run**

```json
{
  "maxRecords": 20000
}
```

Up to 20000 rows (the schema default for `maxRecords`) — about $400.02 on the Free tier ($0.02 start + 20000 × $0.02) if the source has that many.

### 🧾 JSON sample record

One real record from run `mJKy27T60nTQdcD8Q`, exactly as it lands in the dataset (emails masked, long text shortened):

```json
{
  "record_type": "esma_investment_firm_permission",
  "entity_id": "ae42",
  "entity_name": "Catam Asset Management AG",
  "commercial_name": null,
  "lei": "529900RUQ6E2Z710XY62",
  "head_office_lei": null,
  "entity_type_code": "MIF",
  "entity_type_label": "Investment firm",
  "competent_authority": "Finanzmarktaufsicht (FMA)",
  "home_member_state": "LIECHTENSTEIN",
  "host_member_state": null,
  "office_type": "Head office",
  "head_office_address": "Landstrasse 34, 9494 Schaan",
  "branch_address": null,
  "legal_form": null,
  "website": null,
  "status": "Active",
  "authorisation_notification_date": "12/09/2006",
  "authorisation_withdrawal_end_date": null,
  "last_update": "30/07/2025",
  "authorised_services": "[\"Advice on capital structure\", \"Execution of orders\", \"Investment advice\", \"Portfolio Management\", \"Reception and transmission of orders\", \"Research and financial analysis\"]",
  "authorised_service_count": "6",
  "passported_host_states": null,
  "passported_host_state_count": "0",
  "source": "esma-permissions",
  "release_date": null,
  "source_url": "https://registers.esma.europa.eu/solr/esma_registers_upreg/select",
  "observed_at": "2026-09-18T21:38:44Z",
  "license": "Reuse per ESMA legal notice (European Securities and Markets Authority open data).",
  "attribution": "Source: ESMA registers — registers.esma.europa.eu (Union authorisation/passporting register)."
}
```

### 🔧 How it works

**Source.** The actor reads registers.esma.europa.eu — endpoints: `https://registers.esma.europa.eu/solr/esma_registers_upreg/select`. Public pages and feeds only; nothing behind a login.

**Transport.** Plain HTTPS from the Apify platform, no proxy. robots.txt is read first and a disallowed path is never fetched. Every request carries an identified contact User-Agent. Pacing: `CRAWL_DELAY`=0.0.

**Charging.** Each permission record is charged at the moment it is pushed (`permission_record`); a row that fails to charge is not delivered, so the dataset count always equals the charged count.

**🔧 How it works**

**How it behaves**

Authorised entities are paged from the official Solr endpoint; for each, active MiFID services and notified host member states are joined from its child docs in batches. Everything emitted is organisation-level — this register contains no personal-contact field. Delivery is bounded to maxRecords.

**Source**

`https://registers.esma.europa.eu/solr/esma_registers_upreg/select`

*Robots note: registers.esma.europa.eu publishes no valid robots.txt; with no published restriction the machine endpoint is treated as permitted.*

**Attribution**

Source: ESMA registers — registers.esma.europa.eu (Union authorisation/passporting register). Reuse per the ESMA legal notice.

**What is not done.** No login, no cookie or CAPTCHA bypass, no private or personal-account data, no browser automation.

### 💰 Pricing example

| Event | Free | Bronze | Silver | Gold |
|---|---|---|---|---|
| Actor Start (`apify-actor-start`) | $0.02 | $0.02 | $0.02 | $0.02 |
| Permission record (`permission_record`) | $0.02 | $0.018 | $0.016 | $0.0134 |

Worked at the live Free-tier price:

- 8 permission records: $0.02 start + 8 × $0.02 = **$0.18**
- 25 permission records: $0.02 start + 25 × $0.02 = **$0.52**
- 100 permission records: $0.02 start + 100 × $0.02 = **$2.02**

A run that delivers zero rows charges the $0.02 start fee only. A BLOCKED run (source refused) fails loud and charges no value event. The start fee is charged once per GB of run memory; the default run memory is 4096 MB.

Yield on the sample run: `NORMAL: 50 unique rows (0 duplicates collapsed). billable=50`. `maxRecords` is a hard ceiling on what is delivered and billed, never a target.

### ⚖️ Legal & ToS

This actor reads public, logged-out pages and feeds published by registers.esma.europa.eu. It collects only what the source publishes to any visitor, keeps to the source's robots rules (checked on every run), identifies itself with a contact User-Agent, and does not access accounts, private data or anything behind authentication. Use the output in line with the source's terms and your local law; the intended use is B2B research and monitoring.

### ❓ FAQ

**Q: Do I need an API key or a login?**\
A: No. The source (registers.esma.europa.eu) is read logged-out; the input schema has no key field and the actor carries no secrets.

**Q: Why did my run return 0 rows?**\
A: Read the run's status message. GENUINE_EMPTY means the source was read and had nothing in scope for your input; BLOCKED means the source refused and the run failed without billing a value event — retry later or narrow the input. A zero-row run bills the start fee only.

**Q: How many rows can one run return?**\
A: Up to `maxRecords` (default 20000). Raise the cap for a bigger run; you pay per delivered row.

**Q: How fresh is the data?**\
A: Every run reads the source live at run time; nothing is cached between runs. Put it on a schedule for a continuous feed.

**Q: What formats can I export?**\
A: The dataset downloads as JSON, CSV, Excel, XML or RSS from the run's Dataset tab or the Apify API, and any run can push to a webhook or integration.

**Q: How is this different from the other NexGen Watch actors actors?**\
A: Same output shape and billing model; this one covers registers.esma.europa.eu. The siblings under **Related Actors** cover the other sources or slices — run several on one schedule for a combined feed.

**Q: Are there rate limits?**\
A: The actor paces itself against the source (`CRAWL_DELAY`=0.0) and honours its robots rules; there is no per-buyer limit beyond your Apify plan's concurrency.

### 🆘 Troubleshooting

- **Run FAILED with BLOCKED** → the source refused the request or changed its page shape → nothing was billed beyond the start fee; retry after a while, and if it persists open an Issue with the run id.
- **Status says CAPPED** → your cap (`maxRecords`) was reached → raise it for a bigger run.
- **Input validation error on start** → a field is outside the schema's allowed values → start from the Quick start block and change one field at a time.
- **Run TIMED-OUT** → a very wide request on a slow day → raise the run timeout in Run options or narrow the input; what was delivered before the timeout is still in the dataset.

### 🔗 Related Actors

- [EPA Pesticide Products (PPIS)](https://apify.com/nexgenwatch/epa-ppis-pesticide-products?fpr=2ayu9b) — One structured pesticide_product_record per EPA pesticide registration — from the official EPA Pesticide Product Information System bulk files, publi…
- [ESMA BMR Benchmarks Register](https://apify.com/nexgenwatch/esma-benchmarks?fpr=2ayu9b) — One structured benchmark_record per benchmark registered under the EU Benchmarks Regulation (BMR) — from the official ESMA registers machine endpoint…
- [ESMA EU Fund Register](https://apify.com/nexgenwatch/esma-eu-fund-register?fpr=2ayu9b) — One fund_record per entry in the official ESMA EU fund register via the ESMA registers machine endpoint — keyless, logged-out
- [Estonia Company Registry (bulk)](https://apify.com/nexgenwatch/estonia-company-registry-bulk?fpr=2ayu9b) — One record per registered company (registry code, name, legal form, VAT, status, first-entry date, address) from the official e-Business Register ope…
- [EU Ecolabel Licensed Products & Services](https://apify.com/nexgenwatch/eu-ecolabel?fpr=2ayu9b) — One structured ecolabel_record per awarded EU Ecolabel licence-line — from the official European Commission open-data export, keyless and logged-out
- [EU (EMA) Medicine Shortages Catalogue](https://apify.com/nexgenwatch/eu-medicines-shortage?fpr=2ayu9b) — One structured medicine_shortage_record per entry in the European Medicines Agency's public catalogue of medicine shortages assessed by the Agency —…
- 🏢 **About NexGenData** — NexGen Watch is NexGenData's fleet of more than 300 public data actors built on official sources, pay-per-result. Browse the catalog at [apify.com/nexgenwatch](https://apify.com/nexgenwatch?fpr=2ayu9b).

### ⭐ Found this useful?

If this actor saved you a manual check, a quick **[review on the Apify Store](https://apify.com/nexgenwatch/esma-permissions?fpr=2ayu9b)** helps other teams find it. Feature request or a source that changed? Open it from the **Issues** tab — every one is read.

# Actor input Schema

## `maxRecords` (type: `integer`):

Max records delivered (buyer bound; billing is one charge per delivered record).

## `userAgent` (type: `string`):

Override the transparent crawler UA.

## Actor input object example

```json
{
  "maxRecords": 50
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "maxRecords": 50
};

// Run the Actor and wait for it to finish
const run = await client.actor("nexgenwatch/esma-permissions").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "maxRecords": 50 }

# Run the Actor and wait for it to finish
run = client.actor("nexgenwatch/esma-permissions").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "maxRecords": 50
}' |
apify call nexgenwatch/esma-permissions --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,nexgenwatch/esma-permissions"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/bRE5dNaJJlFVOZ2am/builds/AaPd0cKAegmhZadlQ/openapi.json
