---
title: "UN M49 locations catalog"
method: GET
path: "/api/v1/un-population/locations"
tags: ["Statistical Agencies"]
---

# UN M49 locations catalog

`GET /api/v1/un-population/locations`

All 300 locations accepted by the UN Data Portal: 237 countries / areas plus 56 regional, income, and SDG aggregates (900=World, 901=Developed regions, 902=Developing regions, 941=LDC, 1500-1503 World Bank income groups, etc). Includes ISO3 and ISO2 codes where they apply. The Sugra data endpoints accept either ISO3, ISO2, or the M49 numeric id; this catalog is the canonical lookup table.

## Response `200`

UN M49 location catalog with ISO3 / ISO2 mapping.

- EnvelopeUNPopLocationsPayload
  - `data` UNPopLocationsPayload, required
    - `locations` UNPopLocation[], required — All 300 UN M49 locations: 237 countries/areas plus 56 regional, income, and SDG aggregates.
      - `id` integer, required — UN M49 numeric code (840=USA, 826=United Kingdom, 900=World).
      - `name` string, required — Location name in English.
      - `iso3` string, nullable — ISO 3166-1 alpha-3 country code. Null for regional and income aggregates.
      - `iso2` string, nullable — ISO 3166-1 alpha-2 country code. Null for regional and income aggregates.
      - `locationType` string, nullable — Classifier: country, region, or income group. Derived from M49 range.
      - `parentId` integer, nullable — Parent aggregate M49 id when known.
      - `longitude` number, nullable — Representative longitude (country centroid) where published.
      - `latitude` number, nullable — Representative latitude (country centroid) where published.
    - `total` integer, required — Total number of locations returned.
  - `meta` SugraMeta, required — Metadata attached to every /api/v1/* response envelope.
    - `endpoint` string, required — Requested endpoint path.
    - `data_time` string, required — ISO 8601 UTC timestamp of the source data, not of the request.
    - `response_time` string, required — ISO 8601 UTC timestamp when this response was produced.
    - `provider` string, required — API name and version.
    - `source` string, nullable — Identifier of the primary upstream source used for this response.
    - `attribution` string, nullable — Human-readable attribution mandated by an upstream source (e.g. a securities regulator or self-regulatory organization). Present only on responses whose source requires the owner and source to be clearly identified. Do not remove or alter it when using the response.
    - `fallback_used` boolean, nullable — True when the primary source failed and a fallback produced the data.
    - `fallback_chain` string[], nullable — Ordered list of sources attempted, in the order they were tried.
    - `cached` boolean, nullable — True when this response was served from the internal cache.
    - `stale` boolean, nullable — True when the cached response was returned after the upstream rate-limited or errored. Clients can use this to detect degraded data.

## Other responses

- `401` — Missing or invalid `x-api-key` header. JSON body with a stable `code` distinguishing `missing_api_key` (no header sent) from `invalid_api_key` (header sent, key not accepted); any other 401 source carries the generic `unauthorized` with its detail as `reason`. Plus `hint`. `plan` is always null on 401 - an unauthenticated request has no plan; quota exhaustion is 429, not 401.
- `429` — Daily rate limit exceeded. Check `X-RateLimit-Reset` for the next window.
- `503` — Upstream source is temporarily unavailable. Retry after a short delay.

---

[API](https://skmtc.net/sugra/apis/sugra-api.md) · [All operations](https://skmtc.net/sugra/apis/sugra-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/sugra/sugra-api/revisions/652554d2aae1/schema)
