Catho Vagas de Emprego Data API
Vagas de Emprego: Catho is Catho's Android client for the Brazilian vacancy market. A device session starts at POST /v1/auth/device-session and returns access_token/refresh_token; later calls send Bearer plus X-Origin: app-android and a per-service X-Api-Key. Vacancy search posts filters to POST /v1/vacancies/query and returns cards with job.id, title, activities, salary.range_description and hirer.name; a single posting loads from GET /v1/vacancies/{jobId}/expanded.
The candidate side reads the profile at GET /v1/candidates/{userId}/card (email, name, phone_number), the CV at GET /v1/curriculum/{resumeId}, recruiter views at GET /v1/me/cv-viewers, and ranking at POST /v1/ranking/applicant-scores (paying_position vs non-paying_position).
Vagas de Emprego: Catho (package br.com.catho.app.vagas.empregos, version 2.59.5-20260724_1600) is Catho's Android client for Brazil's vacancy board: candidates search jobs, open a posting, apply with a CV, watch recruiter views and rank against other applicants. Behind those screens the app talks to a first-party JSON API. Sign-in at POST /v1/auth/device-session returns access_token/refresh_token; later calls send Authorization: Bearer plus X-Origin: app-android, platform: android and a per-service X-Api-Key. Field names below (job_id, title, activities, salary.range_description, hirer.name, email, resumeId, paying_position) are the properties on the app's API models.
Screenshots
API surface
Sign in device session
POST
/v1/auth/device-sessionosintAuthenticates a Catho candidate with login/password (PKCE fields client_id, code_challenge, redirect_uri) and returns access_token plus refresh_token used as Bearer on later BFF calls.
Auth: Unauthenticated PKCE-style login. Response access_token/refresh_token become the Bearer session for later calls.
- client_id
- code_challenge
- code_challenge_method
- login
- password
- provider
- redirect_uri
- response_type
- state
- token
- access_token
- refresh_token
Illustrative example reconstructed from the app's interface — not a live capture.
POST /v1/auth/device-session HTTP/1.1 X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android) { "client_id": "catho-android", "code_challenge": "<code-challenge>", "code_challenge_method": "S256", "login": "[email protected]", "password": "******", "provider": "password", "redirect_uri": "com.catho.app://authorize-callback", "response_type": "code", "state": "<state>", "token": "" }{ "access_token": "<access_token>", "refresh_token": "<refresh_token>" }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the email/password device sign-in screen and the PKCE fields on the login form
Search job ads
POST
/v1/vacancies/queryopendataPosts a Catho vacancy search (keywords plus city_id/state_id/salary_range_id/work_model filters) and returns paginated job ads with title, activities, salary.range_description, hirer.name and isBookmarked.
Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.
- query
- keywords
- filters
- jobs
- city_id
- exclude_aggregator
- hierarchical_level_id
- ppd_profile_id
- professional_area_id
- profile_id
- region_id
- salary_range_id
- segment_id
- state_id
- work_model
- facets
- fields
- job_id
- job_customized_data
- score
- browser
- referrer
- device
- user
- candidate_id
- device_id
- ip
- subscriber
- api
- origin
- service
- sort_by
- page
- results_per_page
- location_form
- meta
- type
- total
- jobAds
- jobsExpanded
- apply
- isBookmarked
- isReported
- exclusiveFeatures
- id
- title
- status
- period
- activities
- entry_date
- contracting_models
- profiles
- salary
- value
- range
- range_description
- is_confidential
- benefits
- positions
- hirer
- name
- description
- role
- requirements
- questions
- disabilities
- aggregated_job
- ats_job
- is_pandape
- company_id_hash
Illustrative example reconstructed from the app's interface — not a live capture.
POST /v1/vacancies/query?sort_by=relevance&page=1&results_per_page=20&location_form=city HTTP/1.1 Authorization: Bearer <access_token> X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android) { "query": { "keywords": "analista de dados", "filters": { "jobs": { "city_id": [ 347 ], "exclude_aggregator": false, "hierarchical_level_id": [], "ppd_profile_id": [], "professional_area_id": [ 12 ], "profile_id": 1, "region_id": [], "salary_range_id": [ 4 ], "segment_id": [], "state_id": [ 26 ], "work_model": [ "hybrid" ] } } }, "facets": [], "fields": [ "job_id", "job_customized_data", "score" ], "browser": { "referrer": "com.catho.app", "device": "mobile" }, "user": { "candidate_id": 8845123, "device_id": "<device_id>", "ip": "177.92.0.1", "subscriber": true }, "api": { "origin": "catho_search", "service": "search" } }{ "meta": { "page": 1, "type": "job_ad", "total": { "jobAds": 1284, "jobs": 980 } }, "jobs": [ { "apply": { "applyCount": 0 }, "isBookmarked": false, "isReported": false, "exclusiveFeatures": null, "job": { "id": 71225000123, "title": "Analista de Dados Pleno", "status": "published", "period": "full_time", "activities": "Modelar dashboards e pipelines de dados em São Paulo.", "entry_date": "2026-09-20", "contracting_models": [ { "id": 1, "name": "CLT" } ], "profiles": [ "PROFESSIONAL" ], "salary": { "value": 8500.0, "range": "7000-9000", "range_description": "R$ 7.000 a R$ 9.000", "is_confidential": false }, "benefits": [ { "name": "VR" } ], "positions": [ { "city": "São Paulo", "state": "SP", "quantity": 2 } ], "hirer": { "name": "Example Corp", "description": "Empresa de tecnologia", "is_confidential": false }, "role": { "id": 441, "name": "Analista de Dados", "profile": "PROFESSIONAL" }, "requirements": { "experience": "3 a 5 anos" }, "questions": [], "disabilities": {}, "aggregated_job": null, "ats_job": false, "is_pandape": false, "company_id_hash": "c-hash-441" } } ], "jobsExpanded": [] }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the vacancy search filters (city, salary, work model) and the result cards
Fetch expanded job ad
GET
/v1/vacancies/{jobId}/expandedopendataLoads one vacancy by jobId as an expanded job ad: title, activities, salary, hirer, questions and apply/isBookmarked flags used by the job-detail screen.
Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.
- apply
- isBookmarked
- isReported
- exclusiveFeatures
- job
- id
- title
- status
- period
- activities
- entry_date
- contracting_models
- profiles
- salary
- value
- range
- range_description
- is_confidential
- benefits
- positions
- hirer
- name
- description
- role
- requirements
- questions
- disabilities
- aggregated_job
- ats_job
- is_pandape
- company_id_hash
Illustrative example reconstructed from the app's interface — not a live capture.
GET /v1/vacancies/71225000123/expanded HTTP/1.1 Authorization: Bearer <access_token> X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android){ "apply": { "applyCount": 1 }, "isBookmarked": true, "isReported": false, "exclusiveFeatures": { "highlighted": true }, "job": { "id": 71225000123, "title": "Analista de Dados Pleno", "status": "published", "period": "full_time", "activities": "Modelar dashboards e pipelines de dados em São Paulo.", "entry_date": "2026-09-20", "contracting_models": [ { "id": 1, "name": "CLT" } ], "profiles": [ "PROFESSIONAL" ], "salary": { "value": 8500.0, "range": "7000-9000", "range_description": "R$ 7.000 a R$ 9.000", "is_confidential": false }, "benefits": [ { "name": "VR" }, { "name": "Plano de saúde" } ], "positions": [ { "city": "São Paulo", "state": "SP", "quantity": 2 } ], "hirer": { "name": "Example Corp", "description": "Empresa de tecnologia", "is_confidential": false }, "role": { "id": 441, "name": "Analista de Dados", "profile": "PROFESSIONAL" }, "requirements": { "experience": "3 a 5 anos" }, "questions": [ { "id": 11, "text": "Tem disponibilidade para híbrido?" } ], "disabilities": {}, "aggregated_job": null, "ats_job": false, "is_pandape": false, "company_id_hash": "c-hash-441" } }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the job-detail screen that expands a single posting
Apply to a job ad
POST
/v1/vacancies/{jobId}/applicationsopendataSubmits a candidate apply for a job ad (resumeId plus questionnaireAnswers) and returns applyCount, applyDate, jobAdId and postApplySnackbar.
Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP. Apply calls also send a client_id header.
- userId
- jobId
- device_apply
- entrada_apply
- origem_apply
- canal_apply
- acao_apply
- other
- resumeId
- questionnaireAnswers
- chargedApply
- applyCount
- applyDate
- jobAdId
- presentationLetter
- postApplySnackbar
Illustrative example reconstructed from the app's interface — not a live capture.
POST /v1/vacancies/71225000123/applications?device_apply=android&entrada_apply=job_detail&origem_apply=search&canal_apply=app&acao_apply=apply HTTP/1.1 Authorization: Bearer <access_token> X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android) client_id: 123123123 { "resumeId": 44189012, "questionnaireAnswers": [ { "questionId": 11, "answer": "Sim" } ], "chargedApply": null }{ "applyCount": 1, "applyDate": 1758902400000, "resumeId": 44189012, "jobAdId": 71225000123, "presentationLetter": null, "postApplySnackbar": { "title": "Candidatura enviada" } }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the apply confirmation flow that posts a resumeId
List apply history
GET
/v1/me/application-pipelineopendataPages the candidate apply pipeline (lastItem cursor, jobAdStatus) as totalApplies plus applies[].apply / applies[].jobAd used by the Minhas candidaturas screen.
Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.
- lastItem
- origin
- jobAdStatus
- totalApplies
- applies
- apply
- applyCount
- applyDate
- resumeId
- jobAdId
- jobAd
- id
- title
- status
Illustrative example reconstructed from the app's interface — not a live capture.
GET /v1/me/application-pipeline?lastItem=0&origin=app&jobAdStatus=all HTTP/1.1 Authorization: Bearer <access_token> X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android){ "totalApplies": 12, "applies": [ { "apply": { "applyCount": 1, "applyDate": 1758902400000, "resumeId": 44189012, "jobAdId": 71225000123 }, "jobAd": { "id": 71225000123, "title": "Analista de Dados Pleno", "status": "published" } } ] }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the Minhas candidaturas apply-history screen
Load candidate home BFF
GET
/v1/me/home-feedopendataReturns the signed-in candidate home payload: acl flags, communication unread, resume completeness, suggestion job cards, user and campaign blocks.
Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.
- action
- acl
- ads
- communication
- hiring-process
- resume
- suggestion
- user
- campaign
- userParameters
Illustrative example reconstructed from the app's interface — not a live capture.
GET /v1/me/home-feed?action=open HTTP/1.1 Authorization: Bearer <access_token> X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android){ "acl": { "canApply": true, "isSubscriber": true }, "ads": { "slots": [] }, "communication": { "unread": 3 }, "hiring-process": { "active": 1 }, "resume": { "resumeId": 44189012, "completeness": 82 }, "suggestion": [ { "id": 71225000123, "title": "Analista de Dados Pleno", "entry_date": "2026-09-20" } ], "user": { "id": 8845123, "name": "Ana Silva" }, "campaign": { "id": "home-sep" }, "userParameters": { "profileId": 1 } }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the signed-in candidate home dashboard
Fetch candidate profile
GET
/v1/candidates/{userId}/cardosintReads the signed-in candidate card: id, name, email, phone_number (cellPhone/phone), photo and address.city/state.
Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP. This call also sends x-audit-info with a ReasonEnum.
- id
- profile_id
- name
- photo
- phone_number
- number
- type
- address
- city
- state
Illustrative example reconstructed from the app's interface — not a live capture.
GET /v1/candidates/8845123/card HTTP/1.1 Authorization: Bearer <access_token> X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android) x-audit-info: <base64-audit-info>{ "id": 8845123, "profile_id": 1, "name": "Ana Silva", "email": "[email protected]", "photo": "ana.jpg", "phone_number": [ { "number": "11987654321", "type": "cellPhone" }, { "number": "1133334444", "type": "phone" } ], "address": { "city": "São Paulo", "state": "SP" } }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the candidate profile card (email, phone, address)
Fetch curriculum by resumeId
GET
/v1/curriculum/{resumeId}osintReturns the candidate CV envelope (data) with resumeId, profileName, goal, educations, experiences, resumeSkills and salaryRange used by the curriculum screen.
Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP. Resume calls also send api-client-id and client_id plus x-audit-info.
- data
- resumeId
- userId
- profileId
- profileName
- goal
- goalId
- miniResume
- default
- salaryRange
- specializations
- educations
- experiences
- resumeSkills
- resumeCourseComps
- resumeHierarchicalLevels
- resumeProfessionalAreas
- resumeControl
Illustrative example reconstructed from the app's interface — not a live capture.
GET /v1/curriculum/44189012 HTTP/1.1 Authorization: Bearer <access_token> X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android) x-audit-info: <base64-audit-info> api-client-id: 2 client_id: 123123123{ "data": { "resumeId": 44189012, "userId": 8845123, "profileId": 1, "profileName": "Analista de Dados", "goal": "Atuar com analytics em São Paulo", "goalId": 88, "miniResume": "5 anos em BI e SQL.", "default": true, "salaryRange": 4, "specializations": "Python, SQL", "educations": [ { "course": "Estatística", "institution": "USP" } ], "experiences": [ { "company": "Example Corp", "role": "Analista Jr" } ], "resumeSkills": [ { "name": "SQL" } ], "resumeCourseComps": [], "resumeHierarchicalLevels": [ { "id": 2 } ], "resumeProfessionalAreas": [ { "id": 12 } ], "resumeControl": { "showSalaryRange": 1 } } }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the curriculum screen (educations, experiences, skills)
List recruiter resume views
GET
/v1/me/cv-viewersosintPages who viewed the candidate CV (resumeViewType) as resumeViews with hirerName, isConfidentialCompany, lastSeen and total view counts.
Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.
- page
- resumeViewType
- title
- description
- total
- pagination
- resumeViews
- hirerName
- isConfidentialCompany
- lastSeen
- site
- companyActivities
Illustrative example reconstructed from the app's interface — not a live capture.
GET /v1/me/cv-viewers?page=1&resumeViewType=all HTTP/1.1 Authorization: Bearer <access_token> X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android){ "title": "Quem viu seu currículo", "description": "Empresas que visualizaram seu CV", "total": 18, "pagination": { "page": 1, "pageSize": 10 }, "resumeViews": [ { "hirerName": "Example Corp", "description": "Visualizou seu currículo", "isConfidentialCompany": false, "lastSeen": "2026-09-24T12:00:00Z", "site": "https://www.example.com", "total": 3, "companyActivities": [ { "name": "Tecnologia" } ] } ] }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the Quem viu seu currículo recruiter-view list
Rank CV among applicants
POST
/v1/ranking/applicant-scoresopendataScores the candidate CV against other applicants for a job_id and returns paying_position vs non-paying_position, score and total_of_cvs.
Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.
- items
- origin
- candidate_id
- job_id
- cv_profile_id
- errors
- meta
- positions
- non-paying_position
- paying_position
- score
- total_of_cvs
Illustrative example reconstructed from the app's interface — not a live capture.
POST /v1/ranking/applicant-scores HTTP/1.1 Authorization: Bearer <access_token> X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android) { "items": [ { "candidate_id": "8845123", "job_id": "71225000123", "cv_profile_id": "1" } ], "origin": "modal-pos-apply-android" }{ "errors": [], "meta": { "count": 1 }, "positions": [ { "candidate_id": "8845123", "cv_profile_id": "1", "job_id": "71225000123", "non-paying_position": 42, "paying_position": 8, "score": 0.81, "total_of_cvs": 186 } ] }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the post-apply ranking modal (paying vs non-paying position)
List candidate recruiter chats
GET
/v1/inbox/recruiter-threadsopendataPages the candidate message-box (page, itensPerPage) as chats with chatId, title, unread, lastMessage and recipient used by recruiter chat.
Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.
- page
- itensPerPage
- meta
- chats
- chatId
- isChatBlocked
- title
- unread
- lastMessage
- recipient
Illustrative example reconstructed from the app's interface — not a live capture.
GET /v1/inbox/recruiter-threads?page=1&itensPerPage=20 HTTP/1.1 Authorization: Bearer <access_token> X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android){ "meta": { "page": 1, "total": 6 }, "chats": [ { "chatId": 90011, "isChatBlocked": false, "title": "Analista de Dados Pleno", "unread": 2, "lastMessage": { "text": "Podemos agendar uma entrevista?", "messageTime": 1758902400 }, "recipient": { "name": "Carla Mendes", "company": { "name": "Example Corp", "logo": "https://cdn.example.com/logo.png" } } } ] }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the recruiter chat inbox
List bookmarked job ads
GET
/v1/me/saved-vacanciesopendataPages saved job ads for a userId as job_ads plus pagination.itens_per_page/total_itens used by the bookmarks screen.
Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.
- page
- job_ads
- id
- title
- status
- entry_date
- company_id_hash
- is_pandape
- has_questions
- pagination
- itens_per_page
- total_itens
Illustrative example reconstructed from the app's interface — not a live capture.
GET /v1/me/saved-vacancies?page=1 HTTP/1.1 Authorization: Bearer <access_token> X-Origin: app-android platform: android Content-Type: application/json Accept: application/json Cache-Control: no-cache X-Api-Key: <service-api-key> User-Agent: Catho/2.59.5 (Android){ "job_ads": [ { "id": 71225000123, "title": "Analista de Dados Pleno", "status": "published", "entry_date": "2026-09-20", "company_id_hash": "c-hash-441", "is_pandape": false, "has_questions": true } ], "pagination": [ { "itens_per_page": 10, "total_itens": 7 } ] }Derived from the app's interface; endpoint details are illustrative, not a live capture.
Reconstructed from the saved and bookmarked job-ads screen
Data categories
- job listings
- job details
- applications
- candidate profiles
- resumes
- recruiter views
- ranking
- messaging
- auth sessions
Where teams use this data
Brazil vacancy market census
Nightly jobs pulls filter Brazilian openings by city, state, salary band and work model, then store title, activities, salary range text and hirer name to track CLT vs hybrid demand in São Paulo and other metros.
Candidate CRM enrichment
A recruiting CRM loads the signed-in candidate card and curriculum after device sign-in and stores email, name, phone numbers, educations and experiences so outreach matches the CV the candidate already maintains on Catho.
Recruiter-view monitoring
Career coaches page who viewed a candidate CV and keep hirer name, confidential-company flag, last-seen timestamp and view totals so follow-up can target employers that already opened the résumé.
Apply-pipeline ranking
ATS bots submit an apply with resumeId, then read paying versus non-paying rank, score and total CVs for that job so dropped applications and paid-boost gaps are flagged in the in-house pipeline.
Frequently asked questions
What does the Catho Vagas data API expose?
A paginated vacancy search with city/state/salary/work-model filters, a job-ad detail view, apply plus apply history, the signed-in candidate profile and CV, recruiter resume-view history, CV ranking among other applicants, recruiter chat and saved job ads.
How is the vacancy and CV API authenticated?
The app signs in at POST /v1/auth/device-session with login/password and PKCE fields, then sends Authorization: Bearer plus X-Origin: app-android, platform: android and a per-service X-Api-Key. Some user/resume calls also send x-audit-info.
What fields identify a vacancy and a candidate?
Vacancies use job.id, title, activities, salary.range_description, hirer.name and company_id_hash. The candidate profile uses id, email, name, phone_number and address; the CV uses resumeId, profileName, educations and experiences.
Does the app expose recruiter visibility and ranking?
Yes. GET /v1/me/cv-viewers returns hirerName, lastSeen and isConfidentialCompany, and POST /v1/ranking/applicant-scores returns paying_position, non-paying_position, score and total_of_cvs.
Topics
- catho vagas api
- br.com.catho.app.vagas.empregos endpoints
- catho job search api
- catho vacancy query
- candidate CV email
- paying_position
- cv viewers
- catho apply api
Need this app's data API integrated?
We deliver scoped integrations for any named app — from USD 500 with source-code handoff, or hosted access billed per call. Tell us the data you need.
- NDA + SOW on every engagement
- Delivery in 3–7 days
- Payment only after acceptance
- Work scoped to authorized use