THE SHORT VERSION

Resolve the legal supplier before attaching a tax number. Evaluate coverage and status semantics on a representative sample, then retain the source and timestamps for each decision.

Review the API contract

BEFORE YOU START

Collect the inputs that prevent a false match.

  • The supplier's legal name and registration country
  • Registration number and address for ambiguous candidates
  • The exact evidence required by procurement policy
  • Representative supplier records from each relevant jurisdiction
  • Monthly search, check and monitoring volumes
  • Licensing, retention and security requirements

SOURCE MAP

Use the source that answers the actual question.

Questions, evidence sources and records to retain
QuestionEvidence sourceRetain
Which company issued this invoice?Company-name search and legal-entity matchingSubmitted name, candidate selection, country, registration number and address
Which VAT number is reported for the supplier?Source-labelled company recordIdentifier, source, retrieval time and missing-field state
Is the VAT registration currently valid?Separate tax-authority response where requiredAuthority status, response time, service state and reference
May an agent approve the supplier?Customer policy and independent approval controlsPolicy outcome, exceptions, reviewer and evidence

1. Define what the procurement check must establish

A supplier record needs a legal identity, a usable tax identifier and the evidence required by the transaction. Those are separate requirements. A correctly formatted VAT number does not establish that it belongs to the invoice issuer; an active company record does not establish current VAT registration.

Write the required output before selecting a service: the legal company to approve, its country and registration number, the identifier to store, any live authority response and the action to take when evidence is incomplete. Bank-account ownership, sanctions and credit decisions need their own controls. A lookup supports those decisions without replacing them.

2. Evaluate coverage with your actual supplier mix

Start with a representative sample from the jurisdictions and entity types your business uses. Include trading names, subsidiaries, duplicate names, missing tax IDs and suppliers whose invoices differ from the vendor master. Aggregate country counts alone cannot establish whether the fields you need are available for those entities.

Measure entity resolution and tax-ID availability separately. Review the unresolved records and false selections, not just the proportion of requests with a response. Ask whether a timestamp describes retrieval or an underlying source update. Retain the evaluation sample and criteria so procurement can assess later changes on the same basis.

3. Resolve the legal company before checking the number

When the tax number is missing, POST a name and country_code to VATFind's /v1/companies/search endpoint. Through MCP, the equivalent find_vat_number tool uses company_name and country_code. Both are billable live searches and require a stable retry key. Compare the candidates with the supplier's registration number and address.

Once the legal entity is resolved, store a source-reported tax identifier only when it is supplied. A separate /v1/checks request or MCP check tool can assess the number and company-record association. Each operation has its own idempotency key. Keep a no-match, ambiguous match and source error as different outcomes.

4. Preserve the evidence an auditor will need

Store the submitted input and selected company together with format_status, registry_match_status, tax_authority_status and company_legal_status. Include returned sources, retrieval times and warnings. Record a separate authority result with its own timestamp when the workflow requires one.

The application's approval decision should state which evidence it used and which policy it applied. If an agent summarizes the response, it should keep unsupported or unchecked dimensions visible. Avoid reducing every result to one green badge: later reviewers need to distinguish a sourced match from a decision made despite missing evidence.

5. Test retries, permissions and cost before rollout

Use a vf_test_ REST key for deterministic fixtures without consuming checks. Test malformed input, duplicate requests, idempotency conflicts, missing permissions and unavailable-source handling. Sandbox results verify application behaviour; they do not measure live supplier coverage.

For the live evaluation, agree the sample and budget first. Handle 401 and 403 as authentication or permission failures, 402 as a paid-access requirement and 429 using the returned retry instructions. Retry the same operation with the same body and idempotency key. Bound automatic retries so an unresolved dependency does not occupy the workflow indefinitely.

6. Calculate the cost of the complete workflow

A supplier workflow may need a name search, a number check and recurring refreshes. Estimate each operation separately using the current plan allowance and any agreed enterprise rates. Compare the cost per completed supplier decision, including exceptions and manual review, with the cost per API call.

VATFind live REST and MCP use the same workspace check allowance. Monitoring creates a billable baseline and successful refreshes use checks; reading coverage, usage and stored evidence does not add another check. Review current pricing and licensing before running bulk jobs or reusing data in another product.

7. Introduce agents with explicit operating boundaries

Connect a client that supports remote HTTP MCP and OAuth to https://vatfind.com/api/mcp. The user signs in and approves the required scopes. Start with a country-capability query, then exercise candidate selection and a check. Confirm that the application shows structured results and handles expired tokens before wider deployment.

Agents should ask when the legal entity remains ambiguous and obtain confirmation before creating or changing monitoring. Company changes can prompt a review under your policy, while source-health events need an operational response. Neither event automatically authorizes a payment, supplier approval or account closure.

PRACTICAL QUESTIONS

Frequently asked questions

What is a VAT lookup API?

It gives software a structured route to company records and available tax identifiers. Some services start from a company name, while others require a VAT number. Check whether the response is a company-record match, an authority result or both.

Can an API find a VAT number by company name?

VATFind can search by legal company name and country. It returns candidates and any tax identifier supplied in the selected record. An absent identifier is a coverage state, not proof that the supplier has no VAT registration.

Does VATFind replace VIES or HMRC validation?

VATFind's current REST checks return company-record evidence rather than a live tax-authority response. Use the relevant authority service separately when procurement or tax policy requires current registration evidence.

How should an integration handle several matching companies?

Compare jurisdiction, registration number and address with current supplier documents. Request more information if those fields do not resolve the selection. Preserve the candidate chosen and the reason for choosing it.

How can AI agents connect to VATFind?

A compatible client can connect to the remote MCP endpoint through OAuth, or a server-side application can use REST with a Bearer API key. The user authorizes scopes; the integration preserves independent result states and obtains confirmation before starting monitoring.

How much does VAT lookup cost?

Evaluate the published plan against the searches, checks and monitoring refreshes your workflow will run. VATFind live REST and MCP share a workspace allowance. Read current pricing rather than assuming one supplier always needs one billable operation.

Can we test the API without buying live checks?

A VATFind sandbox REST key returns deterministic fixtures without consuming checks. Use it for integration behaviour and retries. Assess real-world match rates separately on an agreed live sample.

What happens when the data source is unavailable?

Preserve the service error and retryable state. Retry according to Retry-After and your bounded retry policy, reusing the original idempotency key for the same operation. Escalate unresolved cases; do not convert an outage into a rejected supplier.

What evidence should procurement keep?

Keep the original input, resolved legal entity, identifiers, independent statuses, source, retrieval time and warnings, plus any separate authority response and approval decision. Review the permitted retention and reuse terms for the specific contract.

When was this guide last reviewed?

VATFind reviewed this guide on 6 October 2026. Rules, authority services, and source coverage can change, so check the linked official reference before making a current tax or legal decision.

Editorial boundary

This guide explains the lookup and evidence process; it is not tax or legal advice. Official services, coverage and requirements can change. The review date records VATFind's content review, not a guarantee that every linked authority changed on that date.

Put it into practice. Find a company.