---
title: "Largest institutional buys per CUSIP this quarter (cross-fund leaderboard)"
method: GET
path: "/api/v1/sec/13f/top-buys"
tags: ["Hedge Fund Intelligence"]
---

# Largest institutional buys per CUSIP this quarter (cross-fund leaderboard)

`GET /api/v1/sec/13f/top-buys`

Derived cross-fund leaderboard of quarter-over-quarter institutional accumulation. Walks the top-N filers in the requested quarter (ranked by AUM), diffs each filer's per-position share count against the immediately-prior retained quarter, aggregates the POSITIVE share-deltas by CUSIP, and returns the largest rollups by dollar value. Each row reports total shares added, total value added (in $thousands), distinct fund count, and a sample of the top contributing buyers. PUT/CALL option rows are excluded (stock-accumulation signal only). Sales are excluded - this is a strict 'buy' signal. Optional `?quarter=<stem>` scans a historical quarter (default: newest retained stem; from_stem is auto-resolved to the next-prior stem in the retention manifest). v1 limitation: scope bounded to top-N filers (default 100, max 300); full-universe scan deferred to v2 via ingest-side pre-aggregation.

## Query parameters

- `quarter` string, nullable — Optional retention-manifest stem. When omitted, scan the newest available stem.
- `filer_top_n` integer — Top-N institutional managers by AUM to include in the scan (10..80, default 50). The ceiling is measured, not chosen: on prod, one request at a time, 80 answers in about 7s and 90 kills the worker outright (INFRA-46). The previous range allowed up to 300 and defaulted to 100, so the DEFAULT call took the whole API down. Raising this bound means re-measuring MemoryWorkingSet under a scan, not reasoning about it.
- `limit` integer — Maximum CUSIP rows returned (1..200, default 50).

## Response `200`

Cross-fund leaderboard of CUSIPs accumulated this quarter.

- EnvelopeSec13fTopBuysLeaderboard
  - `data` Sec13fTopBuysLeaderboard, required — UC-1.8 cross-fund leaderboard of largest positive share-deltas per CUSIP. Derived layer over B1 retention. Scans top-N institutional managers by AUM in the requested quarter, diffs their per-position share counts against the immediately-prior retained quarter, aggregates positive deltas per CUSIP, and returns the largest rollups by dollar value. Methodology limits (v1): - Scope bounded to top-N filers (default 100, max 300) - full universe scan would require ingest-side pre-aggregation deferred to v2. - PUT/CALL option rows are excluded - stock-accumulation signal only. - Sales (negative deltas) are excluded - we only count buys. - Share counts are NOT split-adjusted (carry-forward from B1 retention).
    - `comparison` Sec13fComparison — The interval a comparison actually covers. The baseline quarter is chosen from what retention holds, not from the calendar, so when a quarter is missing the two compared quarters are not adjacent and the delta spans more than one. Without this block the response would describe six months in the words of three.
      - `from_period_end` string, nullable — Reported quarter-end of the baseline.
      - `to_period_end` string, nullable — Reported quarter-end of the target.
      - `quarters_apart` integer, nullable — How many quarters the comparison covers; 1 is quarter-over-quarter. Null when the interval cannot be determined.
      - `calendar_adjacent` boolean, nullable — Whether the two quarters are consecutive. Absent when the interval could not be determined - false would read as a known answer.
      - `skipped_quarters` string[], nullable — Reported quarter-ends lying between the two that this comparison does not cover.
      - `note` string, nullable — Present only when quarters were skipped.
    - `to_stem` string, required — 13F quarter stem the leaderboard reflects (i.e. the period buys were filed for).
    - `from_stem` string, required — Immediately-prior retained stem used as the baseline.
    - `filer_top_n` integer, required — Echoed scope: requested top-N filers by AUM at to_stem.
    - `filers_scanned` integer, required — Actual filers visited (min of filer_top_n and the universe size in to_stem).
    - `funds_with_buys` integer, required — Subset of filers_scanned that had at least one positive position-delta.
    - `cusip_count` integer, required — Distinct CUSIPs with at least one positive delta across scanned funds (BEFORE limit truncation).
    - `limit` integer, required — Echoed truncation cap.
    - `top_buys` Sec13fTopBuyEntry[], required — Largest CUSIP rollups sorted by total_value_added_usd_thousands DESC then total_shares_added DESC.
      - `cusip` string, required
      - `issuer` string, required — Issuer name first seen across contributing funds (may be empty when only synthetic positions exist).
      - `title` string, required — Position title first seen (e.g. 'COM', 'CL A').
      - `total_shares_added` integer, required — Sum of positive share-deltas across scanned funds for this CUSIP.
      - `total_value_added_usd_thousands` integer, required — Sum of value-deltas in $thousands across scanned funds. Can be negative when share-deltas are positive but quarter-end mark-to-market dropped.
      - `funds_buying` integer, required — Distinct count of scanned funds with a positive share-delta on this CUSIP.
      - `sample_buyers` Sec13fTopBuyBuyer[], required — Top contributing funds (up to 5) sorted by value_delta_usd_thousands DESC.
        - `cik` string, required — 10-digit zero-padded SEC EDGAR CIK.
        - `manager_name` string, required
        - `shares_delta` integer, required — Positive change in share count this fund contributed (sales excluded).
        - `value_delta_usd_thousands` integer, required — Change in market value in $thousands for this fund's position (may be negative on quarter-end mark-to-market even when shares_delta is positive).
  - `meta` SugraMeta, required — Metadata on a /api/v1/* response envelope built through `helpers.response.sugra_response`, which is how routes are expected to answer. A route that assembles its own `meta` dict carries only the keys it writes itself, so an optional field below can be absent because this response has nothing to report OR because that route does not build its envelope here - the two are not distinguishable from the outside (API-43).
    - `endpoint` string, required — Requested endpoint path.
    - `data_time` string, required — ISO 8601 timestamp the data on this response is stamped with. It is the source's own timestamp whenever the source supplied one this API could read; when it did not, this field falls back to the value of `response_time` and `data_age_days` is omitted, so the PRESENCE of that field is the signal to read - with the one exception named in its own description, a route that substitutes its own current time for a source timestamp it never received. Usually UTC (`Z`), but a source stating its own numeric offset keeps it (2026-04-16T14:30:00+09:00) rather than being converted a second time. For a source that publishes by period this is the period's START (see `period`) and for one that publishes by calendar day it is that day's midnight - in neither case a moment at which anything was observed or released.
    - `response_time` string, required — ISO 8601 UTC timestamp when this response was produced.
    - `provider` string, required — API name and version.
    - `data_age_days` number, nullable — Age of the data in days at the moment this response was produced, i.e. `response_time` minus `data_time`. Present ONLY when the timestamp this response is stamped with is a clock time that could be read as a real instant. It is ABSENT - never 0 - in every other case. Absent when no readable source timestamp was supplied, because `data_time` then repeats `response_time` and a zero age would assert that the data is current precisely where its true age is unknown. Absent when the source names a calendar day, a month, a quarter or a year (see `period`): the instant is then a boundary this API anchored at midnight, and time since a day or a quarter BEGAN is a different quantity from the age of the data - a daily series is out by up to a day, a quarterly one by up to a quarter. A midnight counts as such a boundary whichever zone it is stated in, and whether the source stated it or this API anchored it. The one case this field cannot see is a route that substitutes its own current time for a source timestamp it never received: the substituted value is a real, readable instant and is indistinguishable from one the source stated, so the age reads as roughly 0. The shared cache-and-fetch helper behind most routes stopped doing that (API-43), but the presence of this field is a statement about the timestamp the response carries, not a guarantee about the route that supplied it. Rounded to 0.001 day (86.4 seconds), so 0.0 is a real measured age anywhere within roughly +/-43 seconds and not a stand-in for unknown; a source stamping an instant in the future reports a negative value (-0.001 or less) rather than being clamped. Sources publish on very different cadences, so a non-zero age is normal, not an error. Preserve absence in client code: a generated client that materialises a missing optional number as its numeric default turns 'age unknown' back into 'age zero', which is the exact confusion this field exists to remove.
    - `source` string, nullable — Identifier of the primary upstream source used for this response.
    - `attribution` string, nullable — Human-readable attribution mandated by an upstream source (e.g. a securities regulator or self-regulatory organization). Present only on responses whose source requires the owner and source to be clearly identified. Do not remove or alter it when using the response.
    - `fallback_used` boolean, nullable — True when the primary source failed and a fallback produced the data.
    - `fallback_chain` string[], nullable — Ordered list of sources attempted, in the order they were tried.
    - `cached` boolean, nullable — True when this response was served from the internal cache.
    - `stale` boolean, nullable — True when the cached response was returned after the upstream rate-limited or errored. Clients can use this to detect degraded data.
    - `period` string, nullable — Unit of observation, when the source publishes by period rather than by instant. `data_time` carries the period's START instant so it stays machine-readable; this field preserves what that instant used to mean, which the conversion would otherwise erase. Present only for such sources, and only when the source hands the API the label itself - a client that converts the period to its start instant before building the envelope loses the label, though not the age exclusion, which is decided by the instant. Note that `data_age_days` is omitted whenever this is present, because an age measured from a period start is not a freshness figure.
    - `notes` string, nullable — Data-quality caveat about THIS response - how old the underlying report is, a chokepoint AIS lower-bound, or that a source-reported `data_time` could not be read and the response time is shown instead. Distinct from `attribution`, which is a licensing obligation. Multiple caveats are joined with ' | '. Present only when there is one.

## Other responses

- `401` — Missing or invalid `x-api-key` header. JSON body with a stable `code` distinguishing `missing_api_key` (no header sent) from `invalid_api_key` (header sent, key not accepted); any other 401 source carries the generic `unauthorized` with its detail as `reason`. Plus `hint`. `plan` is always null on 401 - an unauthenticated request has no plan; quota exhaustion is 429, not 401.
- `422` — Validation Error
- `429` — Daily rate limit exceeded. Check `X-RateLimit-Reset` for the next window.
- `503` — Upstream source is temporarily unavailable. Retry after a short delay.

## Changes

- **2026-09-01** `328d061c12ca` — 3 info
  - added the optional property `meta/data_age_days` to the response with the `200` status
  - added the optional property `meta/notes` to the response with the `200` status
  - added the optional property `meta/period` to the response with the `200` status
- **2026-08-20** `652554d2aae1` — 1 info
  - added the optional property `data/comparison` to the response with the `200` status
- **2026-08-08** `4c4530760ba1` — 12 info
  - added the optional property `code` to the response with the `401` status
  - added the optional property `code` to the response with the `429` status
  - added the optional property `code` to the response with the `503` status
  - added the optional property `hint` to the response with the `401` status
  - …8 more
- **2026-07-31** `a32a1c79455d` — 2 breaking
  - for the `query` request parameter `filer_top_n`, default value was changed from `100` to `50`
  - for the `query` request parameter `filer_top_n`, the max was decreased from `300.00` to `80.00`

[Change history](https://skmtc.dev/sugra/apis/sugra-api/changes/api/v1/sec/13f/top-buys/get.md)

---

[API](https://skmtc.dev/sugra/apis/sugra-api.md) · [All operations](https://skmtc.dev/sugra/apis/sugra-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/sugra/sugra-api/revisions/cdcc60731935/schema)
