# Search or browse the catalog

> The agency's catalog (products, destinations and places): destinations (`destino`), places (`punto`), accommodation (`alojamiento`), activities and services.

`GET /v1/catalog/entities`

The agency's catalog (products, destinations and places): destinations (`destino`), places (`punto`), accommodation (`alojamiento`), activities and services. Filters: `kind` and `tag`. Without `q`, browses the most recently changed entries first, paged by `nextCursor` — and takes `updatedSince`, `externalId`, `includeDeleted` and `deletedOnly`. For a polling trigger, pass the last `updatedAt` you saw as `updatedSince` with `includeDeleted=true`, and follow `nextCursor` until it is null. With `q`, returns one page of the best matches, ranked, with no cursor. Summaries only; GET /catalog/entities/{entityId} returns an entry in full.

**Permissions:** `catalog:read` · **Kind:** read · **Cost:** 1 unit · MCP tool [`search_catalog`](https://api.bymundi.com/docs/mcp/tools/search_catalog.md)



## Path parameters

_None._

## Query parameters

| Field | Type | Required | Description |
|---|---|---|---|
| `q` | string |  | max 200 chars |
| `tag` | string |  | max 60 chars |
| `limit` | integer |  | 1–100, default 25 |
| `cursor` | string |  | max 500 chars |
| `kind` | "destino" \| "punto" \| "alojamiento" \| "actividad" \| "servicio" |  |  |
| `updatedSince` | datetime |  | Only entries changed at or after this instant — a polling trigger's watermark (deletes and restores count as changes). |
| `externalId` | string |  | The entry with this external id. max 200 chars |
| `includeDeleted` | boolean \| "true" \| "false" |  | Also return deleted entries (`deletedAt` set) — what a sync needs to see deletions. |
| `deletedOnly` | boolean \| "true" \| "false" |  | Only deleted entries — what can be restored. |

## Response `200`

| Field | Type | Required | Description |
|---|---|---|---|
| `object` | "list" | yes |  |
| `data` | object[] | yes |  |
| `data[].object` | "catalog_entity_summary" | yes |  |
| `data[].id` | uuid | yes |  |
| `data[].kind` | "destino" \| "punto" \| "alojamiento" \| "actividad" \| "servicio" | yes |  |
| `data[].name` | string | yes |  |
| `data[].placeId` | string | yes |  |
| `data[].cityKey` | string | yes |  |
| `data[].externalId` | string | yes |  |
| `data[].tags` | string[] | yes |  |
| `data[].partOf` | string \| null | yes |  |
| `data[].category` | string | yes |  |
| `data[].coverUrl` | string \| null | yes |  |
| `data[].updatedAt` | string | yes |  |
| `data[].deletedAt` | string \| null | yes |  |
| `nextCursor` | string \| null | yes |  |

## Errors

Errors are [problem details](https://api.bymundi.com/docs/guides/errors.md). Besides the refusals described above, any call like this one can return:

- [`invalid_request`](https://api.bymundi.com/problems/invalid_request.md) — Invalid request
- [`unauthorized`](https://api.bymundi.com/problems/unauthorized.md) — Missing or invalid API key
- [`insufficient_scope`](https://api.bymundi.com/problems/insufficient_scope.md) — Missing permission
- [`rate_limited`](https://api.bymundi.com/problems/rate_limited.md) — Rate limit reached

## Examples

#### curl

```bash
curl https://api.bymundi.com/v1/catalog/entities \
  -H "Authorization: Bearer $BYMUNDI_KEY"
```

#### JavaScript

```javascript
const res = await fetch("https://api.bymundi.com/v1/catalog/entities", {
  method: "GET",
  headers: {
    Authorization: `Bearer ${process.env.BYMUNDI_KEY}`,
  },
});
if (!res.ok) throw new Error((await res.json()).detail);
const data = await res.json();
```

#### Python

```python
import os, uuid, requests

res = requests.get(
    "https://api.bymundi.com/v1/catalog/entities",
    headers={"Authorization": f"Bearer {os.environ['BYMUNDI_KEY']}"},
)
res.raise_for_status()
data = res.json()
```
