Vagas de Emprego: Catho icon

Catho Vagas de Emprego Data API

Catho · Jobs & Careers

Vagas de Emprego: Catho is Catho's Android client for the Brazilian vacancy market. A device session starts at POST /v1/auth/device-session and returns access_token/refresh_token; later calls send Bearer plus X-Origin: app-android and a per-service X-Api-Key. Vacancy search posts filters to POST /v1/vacancies/query and returns cards with job.id, title, activities, salary.range_description and hirer.name; a single posting loads from GET /v1/vacancies/{jobId}/expanded.

The candidate side reads the profile at GET /v1/candidates/{userId}/card (email, name, phone_number), the CV at GET /v1/curriculum/{resumeId}, recruiter views at GET /v1/me/cv-viewers, and ranking at POST /v1/ranking/applicant-scores (paying_position vs non-paying_position).

Vagas de Emprego: Catho (package br.com.catho.app.vagas.empregos, version 2.59.5-20260724_1600) is Catho's Android client for Brazil's vacancy board: candidates search jobs, open a posting, apply with a CV, watch recruiter views and rank against other applicants. Behind those screens the app talks to a first-party JSON API. Sign-in at POST /v1/auth/device-session returns access_token/refresh_token; later calls send Authorization: Bearer plus X-Origin: app-android, platform: android and a per-service X-Api-Key. Field names below (job_id, title, activities, salary.range_description, hirer.name, email, resumeId, paying_position) are the properties on the app's API models.

Screenshots

  • Vagas de Emprego: Catho screenshot 1
  • Vagas de Emprego: Catho screenshot 2
  • Vagas de Emprego: Catho screenshot 3
  • Vagas de Emprego: Catho screenshot 4
  • Vagas de Emprego: Catho screenshot 5
  • Vagas de Emprego: Catho screenshot 6
  • Vagas de Emprego: Catho screenshot 7
  • Vagas de Emprego: Catho screenshot 8

API surface

  • Sign in device session

    POST /v1/auth/device-session osint

    Authenticates a Catho candidate with login/password (PKCE fields client_id, code_challenge, redirect_uri) and returns access_token plus refresh_token used as Bearer on later BFF calls.

    Auth: Unauthenticated PKCE-style login. Response access_token/refresh_token become the Bearer session for later calls.

    • client_id
    • code_challenge
    • code_challenge_method
    • login
    • password
    • provider
    • redirect_uri
    • response_type
    • state
    • token
    • access_token
    • refresh_token

    Illustrative example reconstructed from the app's interface — not a live capture.

    POST /v1/auth/device-session HTTP/1.1
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    
    {
      "client_id": "catho-android",
      "code_challenge": "<code-challenge>",
      "code_challenge_method": "S256",
      "login": "[email protected]",
      "password": "******",
      "provider": "password",
      "redirect_uri": "com.catho.app://authorize-callback",
      "response_type": "code",
      "state": "<state>",
      "token": ""
    }
    {
      "access_token": "<access_token>",
      "refresh_token": "<refresh_token>"
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the email/password device sign-in screen and the PKCE fields on the login form
  • Search job ads

    POST /v1/vacancies/query opendata

    Posts a Catho vacancy search (keywords plus city_id/state_id/salary_range_id/work_model filters) and returns paginated job ads with title, activities, salary.range_description, hirer.name and isBookmarked.

    Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.

    • query
    • keywords
    • filters
    • jobs
    • city_id
    • exclude_aggregator
    • hierarchical_level_id
    • ppd_profile_id
    • professional_area_id
    • profile_id
    • region_id
    • salary_range_id
    • segment_id
    • state_id
    • work_model
    • facets
    • fields
    • job_id
    • job_customized_data
    • score
    • browser
    • referrer
    • device
    • user
    • candidate_id
    • device_id
    • ip
    • subscriber
    • api
    • origin
    • service
    • sort_by
    • page
    • results_per_page
    • location_form
    • meta
    • type
    • total
    • jobAds
    • jobsExpanded
    • apply
    • isBookmarked
    • isReported
    • exclusiveFeatures
    • id
    • title
    • status
    • period
    • activities
    • entry_date
    • contracting_models
    • profiles
    • salary
    • value
    • range
    • range_description
    • is_confidential
    • benefits
    • positions
    • hirer
    • name
    • description
    • role
    • requirements
    • questions
    • disabilities
    • aggregated_job
    • ats_job
    • is_pandape
    • company_id_hash

    Illustrative example reconstructed from the app's interface — not a live capture.

    POST /v1/vacancies/query?sort_by=relevance&page=1&results_per_page=20&location_form=city HTTP/1.1
    Authorization: Bearer <access_token>
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    
    {
      "query": {
        "keywords": "analista de dados",
        "filters": {
          "jobs": {
            "city_id": [
              347
            ],
            "exclude_aggregator": false,
            "hierarchical_level_id": [],
            "ppd_profile_id": [],
            "professional_area_id": [
              12
            ],
            "profile_id": 1,
            "region_id": [],
            "salary_range_id": [
              4
            ],
            "segment_id": [],
            "state_id": [
              26
            ],
            "work_model": [
              "hybrid"
            ]
          }
        }
      },
      "facets": [],
      "fields": [
        "job_id",
        "job_customized_data",
        "score"
      ],
      "browser": {
        "referrer": "com.catho.app",
        "device": "mobile"
      },
      "user": {
        "candidate_id": 8845123,
        "device_id": "<device_id>",
        "ip": "177.92.0.1",
        "subscriber": true
      },
      "api": {
        "origin": "catho_search",
        "service": "search"
      }
    }
    {
      "meta": {
        "page": 1,
        "type": "job_ad",
        "total": {
          "jobAds": 1284,
          "jobs": 980
        }
      },
      "jobs": [
        {
          "apply": {
            "applyCount": 0
          },
          "isBookmarked": false,
          "isReported": false,
          "exclusiveFeatures": null,
          "job": {
            "id": 71225000123,
            "title": "Analista de Dados Pleno",
            "status": "published",
            "period": "full_time",
            "activities": "Modelar dashboards e pipelines de dados em São Paulo.",
            "entry_date": "2026-09-20",
            "contracting_models": [
              {
                "id": 1,
                "name": "CLT"
              }
            ],
            "profiles": [
              "PROFESSIONAL"
            ],
            "salary": {
              "value": 8500.0,
              "range": "7000-9000",
              "range_description": "R$ 7.000 a R$ 9.000",
              "is_confidential": false
            },
            "benefits": [
              {
                "name": "VR"
              }
            ],
            "positions": [
              {
                "city": "São Paulo",
                "state": "SP",
                "quantity": 2
              }
            ],
            "hirer": {
              "name": "Example Corp",
              "description": "Empresa de tecnologia",
              "is_confidential": false
            },
            "role": {
              "id": 441,
              "name": "Analista de Dados",
              "profile": "PROFESSIONAL"
            },
            "requirements": {
              "experience": "3 a 5 anos"
            },
            "questions": [],
            "disabilities": {},
            "aggregated_job": null,
            "ats_job": false,
            "is_pandape": false,
            "company_id_hash": "c-hash-441"
          }
        }
      ],
      "jobsExpanded": []
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the vacancy search filters (city, salary, work model) and the result cards
  • Fetch expanded job ad

    GET /v1/vacancies/{jobId}/expanded opendata

    Loads one vacancy by jobId as an expanded job ad: title, activities, salary, hirer, questions and apply/isBookmarked flags used by the job-detail screen.

    Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.

    • apply
    • isBookmarked
    • isReported
    • exclusiveFeatures
    • job
    • id
    • title
    • status
    • period
    • activities
    • entry_date
    • contracting_models
    • profiles
    • salary
    • value
    • range
    • range_description
    • is_confidential
    • benefits
    • positions
    • hirer
    • name
    • description
    • role
    • requirements
    • questions
    • disabilities
    • aggregated_job
    • ats_job
    • is_pandape
    • company_id_hash

    Illustrative example reconstructed from the app's interface — not a live capture.

    GET /v1/vacancies/71225000123/expanded HTTP/1.1
    Authorization: Bearer <access_token>
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    {
      "apply": {
        "applyCount": 1
      },
      "isBookmarked": true,
      "isReported": false,
      "exclusiveFeatures": {
        "highlighted": true
      },
      "job": {
        "id": 71225000123,
        "title": "Analista de Dados Pleno",
        "status": "published",
        "period": "full_time",
        "activities": "Modelar dashboards e pipelines de dados em São Paulo.",
        "entry_date": "2026-09-20",
        "contracting_models": [
          {
            "id": 1,
            "name": "CLT"
          }
        ],
        "profiles": [
          "PROFESSIONAL"
        ],
        "salary": {
          "value": 8500.0,
          "range": "7000-9000",
          "range_description": "R$ 7.000 a R$ 9.000",
          "is_confidential": false
        },
        "benefits": [
          {
            "name": "VR"
          },
          {
            "name": "Plano de saúde"
          }
        ],
        "positions": [
          {
            "city": "São Paulo",
            "state": "SP",
            "quantity": 2
          }
        ],
        "hirer": {
          "name": "Example Corp",
          "description": "Empresa de tecnologia",
          "is_confidential": false
        },
        "role": {
          "id": 441,
          "name": "Analista de Dados",
          "profile": "PROFESSIONAL"
        },
        "requirements": {
          "experience": "3 a 5 anos"
        },
        "questions": [
          {
            "id": 11,
            "text": "Tem disponibilidade para híbrido?"
          }
        ],
        "disabilities": {},
        "aggregated_job": null,
        "ats_job": false,
        "is_pandape": false,
        "company_id_hash": "c-hash-441"
      }
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the job-detail screen that expands a single posting
  • Apply to a job ad

    POST /v1/vacancies/{jobId}/applications opendata

    Submits a candidate apply for a job ad (resumeId plus questionnaireAnswers) and returns applyCount, applyDate, jobAdId and postApplySnackbar.

    Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP. Apply calls also send a client_id header.

    • userId
    • jobId
    • device_apply
    • entrada_apply
    • origem_apply
    • canal_apply
    • acao_apply
    • other
    • resumeId
    • questionnaireAnswers
    • chargedApply
    • applyCount
    • applyDate
    • jobAdId
    • presentationLetter
    • postApplySnackbar

    Illustrative example reconstructed from the app's interface — not a live capture.

    POST /v1/vacancies/71225000123/applications?device_apply=android&entrada_apply=job_detail&origem_apply=search&canal_apply=app&acao_apply=apply HTTP/1.1
    Authorization: Bearer <access_token>
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    client_id: 123123123
    
    {
      "resumeId": 44189012,
      "questionnaireAnswers": [
        {
          "questionId": 11,
          "answer": "Sim"
        }
      ],
      "chargedApply": null
    }
    {
      "applyCount": 1,
      "applyDate": 1758902400000,
      "resumeId": 44189012,
      "jobAdId": 71225000123,
      "presentationLetter": null,
      "postApplySnackbar": {
        "title": "Candidatura enviada"
      }
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the apply confirmation flow that posts a resumeId
  • List apply history

    GET /v1/me/application-pipeline opendata

    Pages the candidate apply pipeline (lastItem cursor, jobAdStatus) as totalApplies plus applies[].apply / applies[].jobAd used by the Minhas candidaturas screen.

    Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.

    • lastItem
    • origin
    • jobAdStatus
    • totalApplies
    • applies
    • apply
    • applyCount
    • applyDate
    • resumeId
    • jobAdId
    • jobAd
    • id
    • title
    • status

    Illustrative example reconstructed from the app's interface — not a live capture.

    GET /v1/me/application-pipeline?lastItem=0&origin=app&jobAdStatus=all HTTP/1.1
    Authorization: Bearer <access_token>
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    {
      "totalApplies": 12,
      "applies": [
        {
          "apply": {
            "applyCount": 1,
            "applyDate": 1758902400000,
            "resumeId": 44189012,
            "jobAdId": 71225000123
          },
          "jobAd": {
            "id": 71225000123,
            "title": "Analista de Dados Pleno",
            "status": "published"
          }
        }
      ]
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the Minhas candidaturas apply-history screen
  • Load candidate home BFF

    GET /v1/me/home-feed opendata

    Returns the signed-in candidate home payload: acl flags, communication unread, resume completeness, suggestion job cards, user and campaign blocks.

    Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.

    • action
    • acl
    • ads
    • communication
    • hiring-process
    • resume
    • suggestion
    • user
    • campaign
    • userParameters

    Illustrative example reconstructed from the app's interface — not a live capture.

    GET /v1/me/home-feed?action=open HTTP/1.1
    Authorization: Bearer <access_token>
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    {
      "acl": {
        "canApply": true,
        "isSubscriber": true
      },
      "ads": {
        "slots": []
      },
      "communication": {
        "unread": 3
      },
      "hiring-process": {
        "active": 1
      },
      "resume": {
        "resumeId": 44189012,
        "completeness": 82
      },
      "suggestion": [
        {
          "id": 71225000123,
          "title": "Analista de Dados Pleno",
          "entry_date": "2026-09-20"
        }
      ],
      "user": {
        "id": 8845123,
        "name": "Ana Silva"
      },
      "campaign": {
        "id": "home-sep"
      },
      "userParameters": {
        "profileId": 1
      }
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the signed-in candidate home dashboard
  • Fetch candidate profile

    GET /v1/candidates/{userId}/card osint

    Reads the signed-in candidate card: id, name, email, phone_number (cellPhone/phone), photo and address.city/state.

    Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP. This call also sends x-audit-info with a ReasonEnum.

    • id
    • profile_id
    • name
    • email
    • photo
    • phone_number
    • number
    • type
    • address
    • city
    • state

    Illustrative example reconstructed from the app's interface — not a live capture.

    GET /v1/candidates/8845123/card HTTP/1.1
    Authorization: Bearer <access_token>
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    x-audit-info: <base64-audit-info>
    {
      "id": 8845123,
      "profile_id": 1,
      "name": "Ana Silva",
      "email": "[email protected]",
      "photo": "ana.jpg",
      "phone_number": [
        {
          "number": "11987654321",
          "type": "cellPhone"
        },
        {
          "number": "1133334444",
          "type": "phone"
        }
      ],
      "address": {
        "city": "São Paulo",
        "state": "SP"
      }
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the candidate profile card (email, phone, address)
  • Fetch curriculum by resumeId

    GET /v1/curriculum/{resumeId} osint

    Returns the candidate CV envelope (data) with resumeId, profileName, goal, educations, experiences, resumeSkills and salaryRange used by the curriculum screen.

    Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP. Resume calls also send api-client-id and client_id plus x-audit-info.

    • data
    • resumeId
    • userId
    • profileId
    • profileName
    • goal
    • goalId
    • miniResume
    • default
    • salaryRange
    • specializations
    • educations
    • experiences
    • resumeSkills
    • resumeCourseComps
    • resumeHierarchicalLevels
    • resumeProfessionalAreas
    • resumeControl

    Illustrative example reconstructed from the app's interface — not a live capture.

    GET /v1/curriculum/44189012 HTTP/1.1
    Authorization: Bearer <access_token>
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    x-audit-info: <base64-audit-info>
    api-client-id: 2
    client_id: 123123123
    {
      "data": {
        "resumeId": 44189012,
        "userId": 8845123,
        "profileId": 1,
        "profileName": "Analista de Dados",
        "goal": "Atuar com analytics em São Paulo",
        "goalId": 88,
        "miniResume": "5 anos em BI e SQL.",
        "default": true,
        "salaryRange": 4,
        "specializations": "Python, SQL",
        "educations": [
          {
            "course": "Estatística",
            "institution": "USP"
          }
        ],
        "experiences": [
          {
            "company": "Example Corp",
            "role": "Analista Jr"
          }
        ],
        "resumeSkills": [
          {
            "name": "SQL"
          }
        ],
        "resumeCourseComps": [],
        "resumeHierarchicalLevels": [
          {
            "id": 2
          }
        ],
        "resumeProfessionalAreas": [
          {
            "id": 12
          }
        ],
        "resumeControl": {
          "showSalaryRange": 1
        }
      }
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the curriculum screen (educations, experiences, skills)
  • List recruiter resume views

    GET /v1/me/cv-viewers osint

    Pages who viewed the candidate CV (resumeViewType) as resumeViews with hirerName, isConfidentialCompany, lastSeen and total view counts.

    Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.

    • page
    • resumeViewType
    • title
    • description
    • total
    • pagination
    • resumeViews
    • hirerName
    • isConfidentialCompany
    • lastSeen
    • site
    • companyActivities

    Illustrative example reconstructed from the app's interface — not a live capture.

    GET /v1/me/cv-viewers?page=1&resumeViewType=all HTTP/1.1
    Authorization: Bearer <access_token>
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    {
      "title": "Quem viu seu currículo",
      "description": "Empresas que visualizaram seu CV",
      "total": 18,
      "pagination": {
        "page": 1,
        "pageSize": 10
      },
      "resumeViews": [
        {
          "hirerName": "Example Corp",
          "description": "Visualizou seu currículo",
          "isConfidentialCompany": false,
          "lastSeen": "2026-09-24T12:00:00Z",
          "site": "https://www.example.com",
          "total": 3,
          "companyActivities": [
            {
              "name": "Tecnologia"
            }
          ]
        }
      ]
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the Quem viu seu currículo recruiter-view list
  • Rank CV among applicants

    POST /v1/ranking/applicant-scores opendata

    Scores the candidate CV against other applicants for a job_id and returns paying_position vs non-paying_position, score and total_of_cvs.

    Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.

    • items
    • origin
    • candidate_id
    • job_id
    • cv_profile_id
    • errors
    • meta
    • positions
    • non-paying_position
    • paying_position
    • score
    • total_of_cvs

    Illustrative example reconstructed from the app's interface — not a live capture.

    POST /v1/ranking/applicant-scores HTTP/1.1
    Authorization: Bearer <access_token>
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    
    {
      "items": [
        {
          "candidate_id": "8845123",
          "job_id": "71225000123",
          "cv_profile_id": "1"
        }
      ],
      "origin": "modal-pos-apply-android"
    }
    {
      "errors": [],
      "meta": {
        "count": 1
      },
      "positions": [
        {
          "candidate_id": "8845123",
          "cv_profile_id": "1",
          "job_id": "71225000123",
          "non-paying_position": 42,
          "paying_position": 8,
          "score": 0.81,
          "total_of_cvs": 186
        }
      ]
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the post-apply ranking modal (paying vs non-paying position)
  • List candidate recruiter chats

    GET /v1/inbox/recruiter-threads opendata

    Pages the candidate message-box (page, itensPerPage) as chats with chatId, title, unread, lastMessage and recipient used by recruiter chat.

    Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.

    • page
    • itensPerPage
    • meta
    • chats
    • chatId
    • isChatBlocked
    • title
    • unread
    • lastMessage
    • recipient

    Illustrative example reconstructed from the app's interface — not a live capture.

    GET /v1/inbox/recruiter-threads?page=1&itensPerPage=20 HTTP/1.1
    Authorization: Bearer <access_token>
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    {
      "meta": {
        "page": 1,
        "total": 6
      },
      "chats": [
        {
          "chatId": 90011,
          "isChatBlocked": false,
          "title": "Analista de Dados Pleno",
          "unread": 2,
          "lastMessage": {
            "text": "Podemos agendar uma entrevista?",
            "messageTime": 1758902400
          },
          "recipient": {
            "name": "Carla Mendes",
            "company": {
              "name": "Example Corp",
              "logo": "https://cdn.example.com/logo.png"
            }
          }
        }
      ]
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the recruiter chat inbox
  • List bookmarked job ads

    GET /v1/me/saved-vacancies opendata

    Pages saved job ads for a userId as job_ads plus pagination.itens_per_page/total_itens used by the bookmarks screen.

    Auth: Bearer access_token from POST /v1/auth/device-session. Signed-in calls also send X-Origin: app-android, platform: android, Content-Type/Accept: application/json, Cache-Control: no-cache, and a per-service X-Api-Key. When x-audit-info is present the client replaces it with a base64 JSON audit blob plus the public IP.

    • page
    • job_ads
    • id
    • title
    • status
    • entry_date
    • company_id_hash
    • is_pandape
    • has_questions
    • pagination
    • itens_per_page
    • total_itens

    Illustrative example reconstructed from the app's interface — not a live capture.

    GET /v1/me/saved-vacancies?page=1 HTTP/1.1
    Authorization: Bearer <access_token>
    X-Origin: app-android
    platform: android
    Content-Type: application/json
    Accept: application/json
    Cache-Control: no-cache
    X-Api-Key: <service-api-key>
    User-Agent: Catho/2.59.5 (Android)
    {
      "job_ads": [
        {
          "id": 71225000123,
          "title": "Analista de Dados Pleno",
          "status": "published",
          "entry_date": "2026-09-20",
          "company_id_hash": "c-hash-441",
          "is_pandape": false,
          "has_questions": true
        }
      ],
      "pagination": [
        {
          "itens_per_page": 10,
          "total_itens": 7
        }
      ]
    }

    Derived from the app's interface; endpoint details are illustrative, not a live capture.

    • Reconstructed from the saved and bookmarked job-ads screen

Data categories

  • job listings
  • job details
  • applications
  • candidate profiles
  • resumes
  • recruiter views
  • ranking
  • messaging
  • auth sessions

Where teams use this data

  • Brazil vacancy market census

    Nightly jobs pulls filter Brazilian openings by city, state, salary band and work model, then store title, activities, salary range text and hirer name to track CLT vs hybrid demand in São Paulo and other metros.

  • Candidate CRM enrichment

    A recruiting CRM loads the signed-in candidate card and curriculum after device sign-in and stores email, name, phone numbers, educations and experiences so outreach matches the CV the candidate already maintains on Catho.

  • Recruiter-view monitoring

    Career coaches page who viewed a candidate CV and keep hirer name, confidential-company flag, last-seen timestamp and view totals so follow-up can target employers that already opened the résumé.

  • Apply-pipeline ranking

    ATS bots submit an apply with resumeId, then read paying versus non-paying rank, score and total CVs for that job so dropped applications and paid-boost gaps are flagged in the in-house pipeline.

Frequently asked questions

What does the Catho Vagas data API expose?

A paginated vacancy search with city/state/salary/work-model filters, a job-ad detail view, apply plus apply history, the signed-in candidate profile and CV, recruiter resume-view history, CV ranking among other applicants, recruiter chat and saved job ads.

How is the vacancy and CV API authenticated?

The app signs in at POST /v1/auth/device-session with login/password and PKCE fields, then sends Authorization: Bearer plus X-Origin: app-android, platform: android and a per-service X-Api-Key. Some user/resume calls also send x-audit-info.

What fields identify a vacancy and a candidate?

Vacancies use job.id, title, activities, salary.range_description, hirer.name and company_id_hash. The candidate profile uses id, email, name, phone_number and address; the CV uses resumeId, profileName, educations and experiences.

Does the app expose recruiter visibility and ranking?

Yes. GET /v1/me/cv-viewers returns hirerName, lastSeen and isConfidentialCompany, and POST /v1/ranking/applicant-scores returns paying_position, non-paying_position, score and total_of_cvs.

Topics

  • catho vagas api
  • br.com.catho.app.vagas.empregos endpoints
  • catho job search api
  • catho vacancy query
  • candidate CV email
  • paying_position
  • cv viewers
  • catho apply api

Need this app's data API integrated?

We deliver scoped integrations for any named app — from USD 500 with source-code handoff, or hosted access billed per call. Tell us the data you need.

  • NDA + SOW on every engagement
  • Delivery in 3–7 days
  • Payment only after acceptance
  • Work scoped to authorized use

Get a quote