---
title: "ETF holdings from the SEC NPORT-P quarterly filing"
method: GET
path: "/api/v1/etf/{symbol}/holdings/sec"
tags: ["Funds & ETFs"]
---

# ETF holdings from the SEC NPORT-P quarterly filing

`GET /api/v1/etf/{symbol}/holdings/sec`

Full fund-holdings snapshot from the SEC's NPORT-P quarterly filing for one ETF underlier. Replaces the prior commercial fund-profile holdings field (Tier C, disabled in DATA-N1) with the SEC Tier S equivalent. NPORT-P carries the FULL holdings list (NOT top-10), CUSIP/ISIN/LEI, asset-cat + issuer-cat (for sector derivation), and ``invCountry`` (for country weightings). Public NPORT-P refreshes only ONCE per fiscal quarter (the SEC's month-3-of-quarter rule), so freshness is typically 3-5 months. Compare ``rep_pd_date`` against today to gauge staleness. Returns 404 ``holdings_unavailable`` when the ETF is a commodity-pool / grantor-trust structure (USO/UNG/GLD/SLV) that files 10-K/10-Q instead of NPORT-P.

API-83: returns 410 Gone when this symbol's universe row records that it stopped trading - ``delisted`` with the filing date of the fund's own Form 25, or ``renamed`` naming the ticker the fund continues under. A symbol with NO universe row is unaffected: this route does not check membership, only whether we know the fund is gone.

## Path parameters

- `symbol` string, required — ETF underlier ticker.

## Response `200`

SEC NPORT-P holdings payload.

- EnvelopeSecNportHoldingsPayload
  - `data` SecNportHoldingsPayload, required — DATA-N3 derived endpoint: fund-holdings snapshot from the SEC NPORT-P quarterly filing for one ETF underlier. Per-ETF blob written by the ``quarterly_sec_nport`` Timer (5th of Jan/Apr/Jul/Oct UTC). Holdings are as-of the fund's most recent *public* fiscal-quarter-end (``rep_pd_date``) - typically 3-5 months stale by the time it's publicly disclosed per the SEC NPORT-P month-3 rule. Compare ``rep_pd_date`` against today to gauge freshness. Replaces the legacy ``fundProfile.topHoldings`` field (Tier C, disabled in DATA-N1) with the SEC Tier S equivalent. SEC's NPORT-P carries the FULL holdings list (not top-10), CUSIP/ISIN/LEI, asset-cat + issuer-cat for sector derivation, and ``invCountry`` for country weightings.
    - `ticker` string, required — ETF underlier ticker.
    - `cik` integer, required — SEC Central Index Key of the fund.
    - `fund_name` string, nullable — Fund's registered name as reported in NPORT-P ``regName``.
    - `accession` string, required — SEC filing accession number (dashed format).
    - `filing_date` string, nullable — Date the NPORT-P was filed (YYYY-MM-DD).
    - `rep_pd_date` string, nullable — Fund's fiscal-quarter-end date (holdings as-of). Typically lags filing_date by 60-90 days.
    - `holdings_count` integer, required — Number of distinct holdings rows in this filing.
    - `total_val_usd` number, nullable — Sum of ``val_usd`` across all holdings rows.
    - `net_assets` number, nullable — Fund-level net assets (``fundInfo/netAssets``) in USD - the true NAV-basis total. NOT the holdings gross sum ``total_val_usd``. Used by the snapshot builder to derive NAV and AUM.
    - `total_assets` number, nullable — Fund-level total assets (``fundInfo/totAssets``) in USD.
    - `total_liabilities` number, nullable — Fund-level total liabilities (``fundInfo/totLiabs``) in USD.
    - `monthly_returns` number[], nullable — Up to three monthly total-return percentages (``returnInfo/monthlyTotReturns``), chronological - earliest first, the ``rep_pd_date`` month last. Shorter when the fund reported fewer than three months.
    - `monthly_flows` SecNportMonthlyFlow[], nullable — API-1.14.5: NPORT-P Part B item B.6 monthly flow rows (sales / reinvestment / redemption / net, USD), oldest first, the ``rep_pd_date`` month last. Absent on blobs ingested before the field (blob version 1.1) and on the 10-K-derived commodity-trust blobs; null when the filing carries no B.6 element.
      - `month` string, nullable — Calendar month (YYYY-MM) the row covers, derived from the filing's ``repPdDate``: the last row is the ``rep_pd_date`` month, the first row two months earlier. Null only when the filing's ``repPdDate`` was unparseable (the row is kept, never relabelled).
      - `sales` number, nullable — B.6 ``sales`` - total net asset value of shares sold (including exchanges, excluding reinvestment), USD, cents. Null when the filing omits or malforms it; never a fabricated zero.
      - `reinvestment` number, nullable — B.6 ``reinvestment`` - shares sold through dividend or distribution reinvestment, USD.
      - `redemption` number, nullable — B.6 ``redemption`` - shares redeemed or repurchased, USD.
      - `net` number, nullable — sales + reinvestment - redemption, rounded to cents. Positive = net creations. Null when any component is null (a partial sum is never published).
    - `holdings` SecNportHolding[], required — Full holdings list from the filing. Default sort matches the filing's row order (typically by ``pct_val`` DESC). Clients computing 'top N' should sort client-side.
      - `name` string, nullable — Issuer / security name as reported.
      - `title` string, nullable — Security title (e.g. share class).
      - `cusip` string, nullable
      - `isin` string, nullable
      - `lei` string, nullable — Legal Entity Identifier (ISO 17442).
      - `balance` number, nullable — Number of shares / units of the security held.
      - `val_usd` number, nullable — Aggregate USD value of the position at fiscal-quarter-end.
      - `pct_val` number, nullable — Position weight as percent of the fund's net assets.
      - `asset_cat` string, nullable — SEC asset-category code. Common values: ``EC`` (equity-common), ``DBT`` (debt), ``DIV`` (derivative), ``RA`` (repurchase agreement).
      - `issuer_cat` string, nullable — SEC issuer-category code. Common values: ``CORP`` (corporation), ``USGSE`` (US government-sponsored entity), ``MUN`` (municipal).
      - `country` string, nullable — ISO-3166-1 alpha-2 country code of investment.
      - `currency` string, nullable — Currency code of the position.
    - `data_source` string, required — Always ``sec_nport`` for this endpoint. Reserved for forward-compat (e.g. ``sec_n_csr`` fallback for funds without NPORT-P).
    - `license_attribution` string, required — U.S. Public Domain (federal data, 17 USC §105).
  - `meta` SugraMeta, required — Metadata on a /api/v1/* response envelope built through `helpers.response.sugra_response`, which is how routes are expected to answer. A route that assembles its own `meta` dict carries only the keys it writes itself, so an optional field below can be absent because this response has nothing to report OR because that route does not build its envelope here - the two are not distinguishable from the outside (API-43).
    - `endpoint` string, required — Requested endpoint path.
    - `data_time` string, required — ISO 8601 timestamp the data on this response is stamped with. It is the source's own timestamp whenever the source supplied one this API could read; when it did not, this field falls back to the value of `response_time` and `data_age_days` is omitted, so the PRESENCE of that field is the signal to read - with the one exception named in its own description, a route that substitutes its own current time for a source timestamp it never received. Usually UTC (`Z`), but a source stating its own numeric offset keeps it (2026-04-16T14:30:00+09:00) rather than being converted a second time. For a source that publishes by period this is the period's START (see `period`) and for one that publishes by calendar day it is that day's midnight - in neither case a moment at which anything was observed or released.
    - `response_time` string, required — ISO 8601 UTC timestamp when this response was produced.
    - `provider` string, required — API name and version.
    - `data_age_days` number, nullable — Age of the data in days at the moment this response was produced, i.e. `response_time` minus `data_time`. Present ONLY when the timestamp this response is stamped with is a clock time that could be read as a real instant. It is ABSENT - never 0 - in every other case. Absent when no readable source timestamp was supplied, because `data_time` then repeats `response_time` and a zero age would assert that the data is current precisely where its true age is unknown. Absent when the source names a calendar day, a month, a quarter or a year (see `period`): the instant is then a boundary this API anchored at midnight, and time since a day or a quarter BEGAN is a different quantity from the age of the data - a daily series is out by up to a day, a quarterly one by up to a quarter. A midnight counts as such a boundary whichever zone it is stated in, and whether the source stated it or this API anchored it. The one case this field cannot see is a route that substitutes its own current time for a source timestamp it never received: the substituted value is a real, readable instant and is indistinguishable from one the source stated, so the age reads as roughly 0. The shared cache-and-fetch helper behind most routes stopped doing that (API-43), but the presence of this field is a statement about the timestamp the response carries, not a guarantee about the route that supplied it. Rounded to 0.001 day (86.4 seconds), so 0.0 is a real measured age anywhere within roughly +/-43 seconds and not a stand-in for unknown; a source stamping an instant in the future reports a negative value (-0.001 or less) rather than being clamped. Sources publish on very different cadences, so a non-zero age is normal, not an error. Preserve absence in client code: a generated client that materialises a missing optional number as its numeric default turns 'age unknown' back into 'age zero', which is the exact confusion this field exists to remove.
    - `source` string, nullable — Identifier of the primary upstream source used for this response.
    - `attribution` string, nullable — Human-readable attribution mandated by an upstream source (e.g. a securities regulator or self-regulatory organization). Present only on responses whose source requires the owner and source to be clearly identified. Do not remove or alter it when using the response.
    - `fallback_used` boolean, nullable — True when the primary source failed and a fallback produced the data.
    - `fallback_chain` string[], nullable — Ordered list of sources attempted, in the order they were tried.
    - `cached` boolean, nullable — True when this response was served from the internal cache.
    - `stale` boolean, nullable — True when the response is known stale under its source freshness policy, or when a cached response was returned after the upstream rate-limited or errored. Clients can use this to detect degraded data.
    - `stale_since` string, nullable — ISO 8601 UTC timestamp of the last good copy this response was served from. Present only when stale is true.
    - `period` string, nullable — Unit of observation, when the source publishes by period rather than by instant. `data_time` carries the period's START instant so it stays machine-readable; this field preserves what that instant used to mean, which the conversion would otherwise erase. Present only for such sources, and only when the source hands the API the label itself - a client that converts the period to its start instant before building the envelope loses the label, though not the age exclusion, which is decided by the instant. Note that `data_age_days` is omitted whenever this is present, because an age measured from a period start is not a freshness figure.
    - `notes` string, nullable — Data-quality caveat about THIS response - how old the underlying report is, a chokepoint AIS lower-bound, or that a source-reported `data_time` could not be read and the response time is shown instead. Distinct from `attribution`, which is a licensing obligation. Multiple caveats are joined with ' | '. Present only when there is one.

## Other responses

- `401` — Missing or invalid `x-api-key` header. JSON body with a stable `code` distinguishing `missing_api_key` (no header sent) from `invalid_api_key` (header sent, key not accepted); any other 401 source carries the generic `unauthorized` with its detail as `reason`. Plus `hint`. `plan` is always null on 401 - an unauthenticated request has no plan; quota exhaustion is 429, not 401.
- `422` — Validation Error
- `429` — Daily rate limit exceeded. Check `X-RateLimit-Reset` for the next window.
- `500` — This API answered a shape its own schema refuses. Typed body `error: response_shape_invalid`. Stays a 500 (WEB-28). Not an upstream failure.
- `503` — Upstream source is temporarily unavailable. Retry after a short delay.

## Changes

> 36 revisions in range; 1 not diffed.

- **2026-09-13** `d2472ec2cf81` — 1 info
  - added the non-success response with the status `500`
- **2026-09-09** `4f8853a61440` — 1 info
  - added the optional property `meta/stale_since` to the response with the `200` status
- **2026-09-02** `cdcc60731935` — 1 info
  - added the optional property `data/monthly_flows` to the response with the `200` status
- **2026-09-01** `328d061c12ca` — 3 info
  - added the optional property `meta/data_age_days` to the response with the `200` status
  - added the optional property `meta/notes` to the response with the `200` status
  - added the optional property `meta/period` to the response with the `200` status
- **2026-08-08** `4c4530760ba1` — 12 info
  - added the optional property `code` to the response with the `401` status
  - added the optional property `code` to the response with the `429` status
  - added the optional property `code` to the response with the `503` status
  - added the optional property `hint` to the response with the `401` status
  - …8 more

[Change history](https://skmtc.dev/sugra/apis/sugra-api/changes/api/v1/etf/:symbol/holdings/sec/get.md)

---

[API](https://skmtc.dev/sugra/apis/sugra-api.md) · [All operations](https://skmtc.dev/sugra/apis/sugra-api/llms.txt) · [OpenAPI document](https://skmtc.dev/sugra/apis/sugra-api/revisions/89e859efa425?raw)
