Blog · 2026-10-05

SEC 8-K API: Material Events and Red Flags as JSON

SEC 8-K API: Material Events and Red Flags as JSON
Item codes decoded, a notable flag, and a standing scan for the two items that matter.

A company misses earnings, loses its CFO, or dismisses its auditor, and the news lands as a terse SEC filing called an 8-K. It is public the second it hits EDGAR. Turning it into data you can act on is the part that takes work.

A SEC 8-K API returns a company's 8-K current reports as structured JSON, with each filing's item codes decoded into plain labels like earnings, executive change, or auditor dismissal. Instead of scraping EDGAR and parsing HTML, you get a typed list of events, a link to the filing, and a flag for the market-moving ones. The sharpest options also scan the whole market for the red-flag items, not just one ticker.

Key takeaway: A SEC 8-K API turns a company's 8-K current reports into JSON with each item code decoded (2.02 earnings, 5.02 exec change, 1.05 cyber, 4.01 auditor change, 4.02 restatement). Most APIs return per-ticker filings; the useful extra is a market-wide scan for the red-flag items. Edgrapi's /v1/events returns typed 8-K events per ticker plus standing /restatements and /auditor-changes feeds on one key, with a notable flag for the market-movers.

What does a SEC 8-K API actually return?

A SEC 8-K API returns each 8-K a company has filed as a JSON object: the filing date, the accession number, a link to the document on EDGAR, and a list of item codes with human labels. One Apple 8-K from July 30, 2026 comes back tagged with item 2.02 (results of operations) and item 9.01 (financial statements and exhibits). You read the shape of the news without opening the filing.

The 8-K is the catch-all. Companies use the 10-K and 10-Q for scheduled quarterly and annual reports, but anything material that happens between those reports goes out as an 8-K.

That is why it is the filing to watch for events. Earnings, acquisitions, executive departures, bankruptcies, delistings, and auditor changes all arrive here first.

The value a good API adds is the item code. Every 8-K carries one or more numbered items, and that number tells you what kind of event it is before you read a word of prose. A feed that decodes the code into a label is doing the first pass of reading for you.

Key 8-K item codes and what they mean
A few items carry most of the signal; items 4.01 and 4.02 are the accounting red flags.

What do the 8-K item codes mean?

The 8-K uses a fixed set of numbered items, 1.01 through 9.01, and each number maps to one kind of event. The SEC groups them into sections: business and operations, financials, securities, accountants and financial statements, corporate governance, and asset-backed securities. There are roughly thirty defined events. A handful carry most of the signal, so learn those first.

Here are the codes that matter most to an investor or a monitoring tool.

Item 2.02 is results of operations, meaning earnings. Item 5.02 is the departure or appointment of a director or officer, so CFO and CEO exits land here. Item 1.01 and 1.02 cover entering or ending a material agreement. Item 1.03 is bankruptcy. Item 2.06 is a material impairment.

Then there are the accounting items, which is where the warning signs cluster. Item 4.01 is a change in the company's certifying accountant, an auditor change. Item 4.02 is non-reliance on previously issued financials, which is the formal start of a restatement.

Item 1.05, cybersecurity incidents, is the newest of the group. The SEC added it under the cyber-disclosure rules that took effect in December 2023, with a four-business-day clock that starts once a breach is judged material.

A single 8-K can carry several items at once, and the combination is often the story. An earnings miss filed as 2.02 alongside a 5.02 executive departure on the same day reads differently than either alone. A feed that returns the full item list, not just the first code, lets you catch those pairings.

A decent 8-K API returns the code and the label together, so your code can branch on 4.02 without maintaining your own lookup table of what every number means.

Four ways to get 8-K filings as JSON
Raw EDGAR, the edgartools library, Apify actors, or a hosted API, trading effort against control.

How do you get 8-K filings as JSON without parsing EDGAR?

You have four honest routes to 8-K JSON, and they trade effort against control. You can parse EDGAR yourself, run a Python library locally, pay a scraper per run, or call a hosted API that returns typed events. The raw filings are free and public either way, so what you pay for is the parsing, the decoding, and the uptime.

The do-it-yourself route starts at the SEC's own submissions endpoint. EDGAR gives you every filing as structured metadata, free, no key. The catch is that it hands you filing references, not decoded events, so you still parse each 8-K's primary document to pull the item codes and the body.

That parsing is where the work hides. Item codes live in the filing header on some documents and in the body on others, exhibit numbering shifts between filers, and amendments arrive as separate 8-K/A filings you have to reconcile. None of it is hard, all of it is tedious, and it is the part a hosted API is actually selling.

The Python route is edgartools, an open-source library that parses an 8-K into objects with the items, press releases, and financial tables already separated. It is a strong fit if you are doing batch work in a notebook and do not need a hosted service.

The scraper route is the Apify actors. Several turn 8-Ks into JSON with the item codes decoded, priced per run from roughly $0.90 to $100 per thousand filings depending on the actor. Good for a one-off pull, less so for a feed you need every day.

The hosted-API route is where you stop owning the plumbing. You call one endpoint, you get back typed events, and someone else keeps up with EDGAR's quirks. That is the trade: less control, far less code.

Which 8-K items are the real red flags?

Two items carry outsized weight: item 4.01, an auditor change, and item 4.02, non-reliance on prior financials. Both say something about the numbers themselves rather than the business, which is why forensic-accounting researchers watch them closely. A 4.02 is the formal admission that past statements were wrong. A 4.01, especially a sudden one, is often the quieter signal that comes first.

A restatement under item 4.02 means the company is telling you not to trust financials it already published. That is as direct a warning as filings get.

An auditor change under item 4.01 is softer but still worth a hard look. Auditors leave for dull reasons, a merger of firms or a fee dispute, but a dismissal right before a filing deadline, or one that mentions disagreements, reads very differently. Audit Analytics has documented cases where a severe auditor-change disclosure preceded a collapse.

Other distress items sit nearby. Item 2.06 is a material impairment, a write-down. Item 1.03 is bankruptcy. Item 3.01 is a delisting notice. None of these is proof of anything on its own, but a cluster of them on one ticker is a pattern.

The practical move is to treat 4.01 and 4.02 as alerts, not reading. When one fires, a human looks. The API's job is to make sure you never miss one.

Market-wide red-flag feeds for items 4.02 and 4.01
Point a standing feed at the item code and it surfaces every restatement or auditor change market-wide.

How do you track auditor changes and restatements across the market?

You point a standing feed at the item, not at a ticker. Most 8-K tools answer "what did this company file," which assumes you already know which company to watch. A red flag is more useful in reverse: show me every company that filed a restatement or dropped its auditor this week, across the whole market, so I find the name before I know to look for it.

This is the gap most 8-K APIs leave open. They are built around a ticker you supply.

Edgrapi's /v1/events splits out two standing feeds for exactly this. /v1/events/restatements scans recent filings market-wide for item 4.02 and returns the companies that filed one. /v1/events/auditor-changes does the same for item 4.01. Each tells you how many filings it scanned, so you know the window you are covering.

curl -s -H "X-API-Key: $KEY" \
  "https://api.edgrapi.com/v1/events/restatements?days=90&limit=25"
# -> {"scope":"market-wide 8-K restatements (item 4.02, non-reliance)",
#     "count": N, "filings_scanned": M, "events": [ ... ]}

Run that on a schedule and you have a forensic watchlist that populates itself. No ticker list to maintain, no filing to read until the feed hands you a name.

For a single company you still use the per-ticker call, and you can filter it. Pass item=4.02,5.02 to narrow to specific codes, or notable=true to get only the market-moving events and skip the routine exhibits.

What is the best SEC 8-K API for developers?

There is no single best SEC 8-K API, because the options optimize for different jobs: raw access, local parsing, one-off scraping, deep per-item extraction, or market-wide red-flag scanning. Pick by the one question you need answered. The table below lines them up on the axes that actually differ, since every one of them reads the same public SEC filings underneath.

OptionDecodes item codesMarket-wide 4.01/4.02 scanAuth and priceBest for
Raw SEC EDGARNo, you parseNoFree, no keyFull control, the source
edgartools (Python)Yes, localNoFree, self-runPython batch jobs
Apify 8-K actorsYesNo, per-ticker or streamPay per run, ~$0.90 to $100 per 1kOne-off scrapes
EODhd SEC Filings APIYes, sections and exhibitsNoSubscriptionClean per-ticker GET
sec-api.io Form 8-KYes, deep text to JSONPer-item querySubscriptionDeepest forensic extraction
Edgrapi /v1/eventsYes, plus notable flagYes, standing feedsOne key, SEC + government, MCPRed-flag scanning and agents

Be clear-eyed about the trade-offs. If you need every sentence of an item 4.02 parsed into fields, the reason for the dismissal, the disagreements, the going-concern language, sec-api.io extracts deeper per-item text than anyone, and that is the right tool.

Edgrapi's lane is different. It is the standing market-wide scanner for 4.01 and 4.02, a notable flag on every event, and the same key that also reads insider trades, 13F holdings, and US government data. If your agent needs to ask "who restated this week" and then pivot to "what else is going on with that filer," that breadth on one key is the point.

How fast does an 8-K hit the API after the event?

An 8-K is on EDGAR within four business days of the triggering event, and an API that reads EDGAR has it minutes later. The four-business-day deadline is the SEC rule, in force since 2004, for most items. Earnings and other time-sensitive events often file the same day. So the filing is the floor on freshness, not the API.

That means a monitoring tool is only as current as its poll interval. If it checks EDGAR every few minutes, you see new 8-Ks almost as fast as the market does.

Be honest with yourself about what "real-time" means here. The event happened before the filing, sometimes days before, and the price may have moved already. An 8-K feed is excellent for not missing the public disclosure. It is not a time machine that front-runs it.

For the red-flag items this lag barely matters. A restatement is a research trigger you will work for days or weeks, so being an hour behind the filing changes nothing about how you use it.

How do you call edgrapi's SEC 8-K API?

You call one GET endpoint with a ticker and an API key. GET /v1/events/{ticker} returns that company's recent 8-K events as decoded JSON, and /v1/8-k/{ticker} is an alias if you prefer the form name. Add notable=true for market-movers only, or item= to filter by code. An empty result costs nothing.

curl -s -H "X-API-Key: $KEY" \
  "https://api.edgrapi.com/v1/events/AAPL?limit=5&notable=true"
# each event: { form, filed, event_date, accession,
#               items: [ {code, label} ], notable, url }

The response gives you the ticker, the resolved CIK, the company name, a count, and the list of events. Every event carries its item codes with labels, the filing date, a notable flag, and a direct link to the document on EDGAR, so you can decide in code and let a human open only the ones that matter.

Because the same data is exposed as an MCP tool, an AI agent can call it directly. Ask Claude or Cursor "did any of my holdings file an 8-K this week," and the agent hits get_events and answers from the live filings. The full endpoint docs cover the parameters and the companion insider and 13F tools.

If you are already pulling insider Form 4 data or 13F holdings, the 8-K events sit on the same key, so adding event monitoring is a new endpoint, not a new integration.

Wire the red-flag items into your own alerts

If you take one thing from this, make it the two red-flag feeds. A SEC 8-K API is useful for any material event, but its highest-value job is telling you the moment a company restates or swaps its auditor. Point /v1/events/restatements and /v1/events/auditor-changes at a daily job, pipe the hits to Slack, and you have a forensic watchlist that builds itself. Start free on the docs and wire the alert before you need it.

Frequently asked questions

What is an SEC 8-K API?

An SEC 8-K API returns a company's 8-K current reports as structured JSON instead of raw EDGAR HTML. Each filing comes back with its item codes decoded into labels like earnings, executive change, or auditor dismissal, plus the filing date and a link to the document. It saves you from building and maintaining an EDGAR parser for material-event disclosures.

How do I get 8-K filings as JSON?

Four ways. Parse the SEC EDGAR submissions API yourself for free, run the open-source edgartools library locally, pay an Apify actor per run, or call a hosted API like edgrapi's /v1/events that returns decoded events directly. The filings are public, so what you pay for is the parsing, the item-code decoding, and not having to maintain any of it.

What do the 8-K item numbers mean?

Each 8-K carries numbered items from 1.01 to 9.01, and the number identifies the event. Item 2.02 is earnings, 5.02 is an executive change, 1.01 is a material agreement, 1.03 is bankruptcy, 1.05 is a cybersecurity incident, 4.01 is an auditor change, and 4.02 is a restatement. A good API returns the code and a plain-English label together.

Is an 8-K item 4.02 a red flag?

Yes, item 4.02 is one of the strongest accounting red flags on EDGAR. It is a formal non-reliance notice, meaning the company is telling investors not to trust financial statements it already published, which signals a coming restatement. Pair it with item 4.01, an auditor change, which often precedes the same kind of trouble. Both warrant a close read.

How do I track auditor changes across companies?

Use a market-wide feed keyed to the item code, not to a ticker. Edgrapi's /v1/events/auditor-changes scans recent 8-K filings across the market for item 4.01 and returns every company that changed its certifying accountant, with a count of filings scanned. Run it on a schedule to build a watchlist that finds the names for you instead of requiring you to know them first.

How quickly is an 8-K filed after the event?

Most 8-K items must be filed within four business days of the triggering event under the SEC rule in force since 2004, and many time-sensitive events like earnings file the same day. An API that polls EDGAR surfaces a new 8-K minutes after it posts. The filing itself is the limit on freshness, so an 8-K feed is for not missing the disclosure, not for beating it.

Get a free API key