Independent. No commercial relationship with UnGovr — no funding, no agreement, no conversation of any kind — checked 9 September 2026. Disclosures · how every claim here is evidenced

ungovr.providers.sgit.ai

UnGovr — the open-data provider, and the one edge that stops short

UnGovr publish an Atlas of 327,138 government entities and a corpus of 398 open-records laws, free, under CC BY 4.0, with no credential needed for most of it. This is a report on that API, written to the nine sections of the providers contract. It is the family's first open-data provider, and admitting one required arguing with the family's own definition of the word — §3 does that. The finding it exists to report is in §9, and it is one edge long.

Prose from the government-graph vault dkeclt5r, 9 September 2026. The retrievals, the two computations and the seven-step join were produced in this session against the live API. When the vault moves ahead, this page is behind — and says so rather than guessing.

0 of 49sampled entities carrying open_records.law
96.6%reachable if the edge is inferred
$0.00what this whole report cost
70requests, inside a free tier of 100

Read the first number with the second. A missing law reference is not an error. It is an entity whose records law has not been mapped yet, and for much of the world it may not exist in a mappable form. The number measures how far the join can currently reach. It is not a defect count. measured 9 Sep 2026

What the Atlas is, before anything else

UnGovr are a nonpartisan nonprofit. They publish the Atlas — every government entity they can identify, from national governments down to a reclamation district in Sutter County — with boundaries, hierarchy, websites and domains, and they publish it free, under CC BY 4.0, mostly without asking for a credential. vendor docs 9 Sep 2026 Alongside it they publish a corpus of 398 open-records laws, and 254 of those are sub-national: not just "the United States has FOIA" but California, Idaho, Chaco, Baja California Sur. verified 9 Sep 2026

That corpus is better than this report expected to find. The California record is not a citation and a link — it carries initial_response_days: 10, extension_days: 14, private_right_of_action: true, per-page copy rates, submission methods, and a structured list of what a valid request must contain. Somebody read the statute and modelled it.

Their stated purpose is helping a person reach their government, and for that purpose the data is shaped exactly right. This report is about what happens when you want to do the next thing with it.

1 · Disclosure

None. No commercial relationship with UnGovr — no funding, no agreement, no credits, no programme. No conversation of any kind has taken place, which matters more than the absence of money: every statement on this site about what UnGovr intend, need, or would want is inference from what they publish, and is marked as such. verified 9 Sep 2026

This page ships before there is anything to disclose, so that its existence is never evidence that something appeared later.

UnGovr's data is used here under CC BY 4.0, which is the licence they chose. This report is published under the same one.

2 · What it grants

Capability tuples — verb × object class × reach, reversibility marked — in two layers: what the platform can grant per product, and what our access actually reaches.

The interesting row is the one that is missing. Across the entire open surface there is no write, no delete, and no spend. Every verb is read and every one is reversible. The single irreversible verb on the platform is spend × wallet, and it lives behind the 402 path that we never touched.

What the platform can grant, per product

verbobject classreachreversibilityproductnote
readentityworldreversibleOpen Data API — entities327,138 entities across 205 countries. No credential at all
readboundaryworldreversibleOpen Data API — boundaries161,603 GeoJSON boundaries, one per entity that has one
readrecords-lawworldreversibleOpen Data API — laws398 open-records laws, 254 of them sub-national
readgrand-jury-reporttenantreversibleOpen Data API — CGJ report detailkey-gated, 50/day per key. The indices are ungated and unlimited
readai-law-verdicttenantreversibleOpen Data API — AI and crawling lawkey-gated. Unread here — blocker B2
spendwallettenantirreversibleMachine Payments Protocolthe 402 path. The only irreversible verb on the whole surface

What our key grants — scoped to text to speech and voices-read

verbobject classreachreversibilitybounded by
readentityworldreversible100 requests a day per **IP address** — there is no key to scope, because we hold none
readrecords-lawworldreversiblethe same IP budget. Nothing here writes, and nothing here spends

Not granted by a key scoped this way, and it should stay that way: write, delete, spend, ai-laws, grand jury report detail.

The same rows are emitted as front-matter in this page’s markdown source, so a capability index can join across providers without parsing English.

3 · Which pattern, per product

First, the definitional problem, because it changes the answers. This family defines provider narrowly — the sibling site states it plainly:

“Provider” here means one thing only: a service that serves models over an API — the sense this estate's own code uses, where a constant of that name holds an entry per model service.

elevenlabs.providers.sgit.ai § What this site is, and is not, read 9 September 2026

UnGovr serve data, not models. By that definition they do not belong here. Written as though they were a model vendor, the nine sections would answer the wrong questions well.

The resolution, and it makes the contract better rather than weaker. The family's real question was never which model service is this. It is: where does the credential live, and what bounds it? UnGovr answer that question — and answer it in a way no model provider in this family can, because for most of their surface the answer is that there is no credential. Pattern 0 is not a hazard here; it is the intended mode, and it is the first row in this matrix where pattern 0 is not a warning. vendor docs 9 Sep 2026

So UnGovr is this family's first open-data provider, and the extension is deliberate. It is filed as a correction against the hub's contract rather than as an edit to it, per the house rule — and per the contract's own closing rule, that if admitting a legitimate new member requires template surgery, the fix belongs in the contract.

ProviderProduct0 · key in the page1 · bounded key in the page2 · short-lived token3 · host holds the keyNeeds a server for the safe pattern
UnGovrOpen Data API — entities, boundaries, laws, CGJ indicesno credential exists for this surface, so the question dissolvesthe bound is per IP, not per keynothing to mint a token fornothing for a host to holdNo — there is no credential to hold
UnGovrOpen Data API — AI-laws and CGJ report detail (key-gated)a free, read-only key with a per-key daily cap. The first yes here that is not a warningno per-key scoping is documented; the daily cap is the only bound×no token minter is offeredpossible, and unnecessary at this risk levelYes for pattern 3 — but the key is free and read-only
UnGovrMachine Payments Protocol (the 402 path)a wallet credential in a page is spendable by anyone who reads ita per-request price exists; a per-key spend cap is not documentedthe natural shape for this, and not offered todaywhat we would build before spending a cent from a browserYes — a funded wallet must never reach a browser

available · × unavailable · available and never acceptable · specified here, not shipped · not applicable

Generated at build time from the patterns: front-matter of every provider page. Adding a provider is one Markdown file; this table follows.

Note the three products are bounded by three different things, which is exactly why this section is per product and never per vendor: the open surface by an IP budget, the gated surface by a free key's daily cap, and the payment path by a wallet balance.

4 · Where the key goes

For most of this API: nowhere. There is no key. That is the honest answer for entities, boundaries, records laws and the CGJ indices, and it is the reason this provider is worth adding to the comparison.

For the two gated corpora — AI-laws, and CGJ report detail — the API advertises two different mechanisms in the same 401 response: verified 9 Sep 2026

HTTP/2 401
www-authenticate: Bearer resource_metadata="https://data.ungovr.org/.well-known/oauth-protected-resource", scope="opendata:read"

{"error":"API key required. Include X-API-Key header.",
 "register":"https://www.ungovr.org/open-data/api-keys"}

The body says X-API-Key. The header offers OAuth 2.0 Protected Resource Metadata — the shape an MCP client expects. Both are documented; a reader meeting only one of them would not know the other existed. Product: Open Data API, AI-laws endpoints. Read at https://data.ungovr.org/v1/ai-laws/index.json on 9 September 2026.

Where it goes in our estate, if we ever hold one: owner-sealed under the vault's write key, never in this repository. The key-shape scan in tools/secret-scan.sh runs over the whole tree including the built output, and it deliberately does not match sgit_private_read_…, because a read key is publishable and is how this estate shares a vault — the same way sgit.ai/llms.txt does. The vault page carries one.

5 · The bounding primitive

What caps the blast radius here is not a property of a key. It is a property of the network path, and then a payment protocol. vendor docs 9 Sep 2026

ResourceFree tierBounded by
Entity data100/day per IPyour IP address
CGJ indices and county listingsunlimitednothing
CGJ report detail50/day per keythe key
Conditional revalidation (304)free, 5,000/day per keythe key, then 429 + Retry-After

Past the free tier the API answers HTTP 402 with a Machine Payments Protocol challenge, payable per request from a Stripe-funded wallet: $0.001 per entity request, $0.01 per report, $5.00 minimum top-up. vendor docs 9 Sep 2026

And what it does not cap. Nothing scopes a wallet. The rate limit protects UnGovr from a client; the wallet balance is the only thing protecting a client from itself, and a runaway agent with a funded wallet has no per-key spend ceiling documented anywhere. That is the same finding this family recorded against a model vendor's per-key quota, arrived at from the opposite direction.

One practical gap. X-RateLimit-Remaining and X-Quota-Remaining are advertised in the API's CORS Access-Control-Expose-Headers, but were not emitted on any of the 70 responses taken here — so a client cannot see how much budget is left until it is gone. verified 9 Sep 2026

6 · The minimal working example

As files, not snippets — and these are not illustrations. They are the scripts that produced every number on this site. verified 9 Sep 2026

FileWhat it doesState
00-smoke.shThe smallest thing that runs: prove the API answers, with no credential at all.written, not run
coverage-sample.pystratum -> (frame file, how many to draw, what the stratum is)written, not run
fetch.shfetch.sh — retrieve one UnGovr endpoint, write the raw bytes unmodified, hashwritten, not run
inferred-join.pyBodies whose governing records law is not reliably given by geography.written, not run
santa-barbara.shThe worked example's three retrievals, in order: resolve the county slug from thewritten, not run

The discipline they encode: write the raw response bytes to disk unmodified, hash those bytes, and log before parsing anything. A node that cannot name the bytes it came from is an assertion, not a retrieval. Every row of the log is published, including the failures.

7 · What we use it for

The government-graph vault — one county, one law, one acceptance, and a refusal to widen it. specified, not shipped

The named workload is a seven-step join: entity → instrument → provision → obligation → control → evidence → acceptance, for Santa Barbara County and the California Public Records Act. The whole join is on one page, with the provenance of every node and the state of every claim.

The one thing worth knowing before you read it: only one edge crosses from their data into our model, and UnGovr did not make that claim. It is drawn inferred everywhere it appears, because rendered as an assertion it would be a lie about the source.

Open the vault itself, read-only →

8 · What it cost

Nothing. $0.00. measured 9 Sep 2026

Date9 September 2026
Workload70 requests: 21 named retrievals + 49 entity-detail documents for the coverage sample
Free tier100 entity requests per day, per IP
Spent$0.00. No 402 was ever returned
Above the tier$0.001 per entity request, $0.01 per report, $5.00 minimum wallet

This section stales fastest, and the honest version of it is the arithmetic rather than the invoice. A census of the law edge — one detail request per entity, because there is no bulk surface carrying it — is 327,138 requests: about 9 years free, or $327.14 metered. projected 9 Sep 2026 That number is why the measurement on this site is a sample and says so.

9 · What went wrong

The section nobody else writes. None of these is a failing, and several are things we would want to know if the data were ours. They are dated, checkable observations, in descending order of how much they matter.

The law edge stops one hop short

An entity carries no addressable path to the law that governs it. open_records is in the published schema, as an optional object with one string member — the join point is designed. verified 9 Sep 2026 It was present on 0 of 49 entities sampled, including six US states whose records laws are in UnGovr's own corpus, and including Santa Barbara County and California itself. verified 9 Sep 2026 It is not a defect count — it is the measurement of how far the join reaches today.

And it is one derivable hop. Inferring it by slug prefix reaches 96.6% of California's 16,071 entities, with a two-line rule, over data UnGovr already publish. measured 9 Sep 2026 The reason it must be inferred and not merged is the other 20.5%: geography and jurisdiction come apart for interstate compacts, tribal nations, federal categories and specially-chartered districts — exactly the bodies a requester most often wants. measured 9 Sep 2026

The edge is not in any bulk surface, so nobody can measure it

open_records exists only in the per-entity detail document — one HTTP request each. Their own OpenAPI says the full-depth index is "a compact record ({slug, name, type, parent_slug?, population?})". verified 9 Sep 2026 The consequence is that the coverage of this field is not knowable to anyone on the open tier, ourselves included, which is why the number above is a sample with an interval rather than a census with a total. Putting open_records into the bulk files would be the single cheapest improvement to this API's surface.

Below the law, there is nothing addressable

The CPRA record cites Gov. Code § 7922.535(a) — which is exactly right, and confirms a section number the vault's own pack had only guessed at. verified 9 Sep 2026 But it is prose inside a free-text field. verified 9 Sep 2026 There is no provision array, no clause identifier, no byte range. You can cite the Act; you cannot cite the clause, and so you cannot attach evidence to the clause. Everything downstream of a duty — a control, an observation, an acceptance — needs to hang on something smaller than a statute.

The cross-references are described and not exposed

GeoNames, Wikidata, OCD and FIPS identifiers appear on the platform pages and in none of the published schema definitions. If they were exposed, joining the Atlas to anything else in the world would become free. It is the cheapest possible improvement after the one above.

Small, specific, and probably worth a fix

No public repository, so no corrections path

There is no clone, no fork, no pull request. Everything above had to be written here, on a stranger's website, rather than filed where it belongs. Their own argument makes this awkward: they object to reaching your government becoming a rental metered by whoever owns the index, and an API on one domain is a single point of dependency however good the licence and however good the intentions.

And one that was ours, not theirs

The previous session on this project could not reach data.ungovr.org at all — its container's proxy refused CONNECT on the open endpoints, not only the authenticated ones — and it correctly declined a summarising fetch path rather than commit a retrieval it could not hash. That was our environment, not their API. This session's container reaches the host fine. verified 9 Sep 2026 It is recorded here because the sibling site's ledger opens with the same scar, and because the refusal is worth more as a logged entry than as an absence.


What this report does not claim