---
title: "Funds holding multiple given securities (cross-CUSIP overlap)"
method: GET
path: "/api/v1/sec/13f/funds/overlap"
tags: ["Hedge Fund Intelligence"]
---

# Funds holding multiple given securities (cross-CUSIP overlap)

`GET /api/v1/sec/13f/funds/overlap`

Reverse lookup spanning multiple CUSIPs at once. Pass a comma-separated list of CUSIPs and the endpoint returns every 13F filer holding at least `min_overlap` of them in the requested quarter. Useful for detecting consensus baskets (e.g. 'which funds hold all 5 of these AI infrastructure names?'). Each matched fund's per-CUSIP position detail (shares + value + issuer) is echoed so callers don't need a follow-up scan. `min_overlap` defaults to 2 (the meaningful overlap floor); set to `len(cusips)` for a strict intersection. PUT/CALL option rows are filtered before counting - this is a stock-ownership signal, not derivative exposure. Optional `?quarter=<stem>` selects a historical snapshot (default: newest stem in retention manifest).

## Query parameters

- `cusips` string, required — Comma-separated list of 9-character canonical CUSIPs (2-10 entries; duplicates dropped).
- `min_overlap` integer — Minimum count of requested CUSIPs a fund must hold to appear (1..10). Defaults to 2 (any pair overlap).
- `quarter` string, nullable — Optional retention-manifest stem. When omitted, scan the newest available stem.

## Response `200`

Funds matching the overlap threshold + their per-CUSIP holdings.

- EnvelopeSec13fFundsOverlap
  - `data` Sec13fFundsOverlap, required — Funds holding multiple given securities in one 13F quarter.
    - `stem` string, required — 13F quarter stem used for the scan.
    - `cusips_requested` string[], required — Deduplicated, uppercased input CUSIPs.
    - `cusips_found` string[], required — Subset that had >=1 stock holder in this quarter.
    - `cusips_not_found` string[], required — Subset with zero stock holders (PUT/CALL-only or unknown).
    - `min_overlap` integer, required — Threshold echoed from request. 1=union, len(requested)=strict intersection.
    - `fund_count` integer, required — Number of funds clearing the threshold.
    - `funds` Sec13fOverlapFund[], required — Matched funds sorted by overlap_count DESC then total_overlap_value DESC.
      - `cik` string, required — 10-digit zero-padded SEC EDGAR CIK.
      - `manager_name` string, required
      - `overlap_count` integer, required — Number of requested CUSIPs the fund holds (after PUT/CALL filter).
      - `total_overlap_value_usd_thousands` integer, required — Sum of value across all matched CUSIPs (in $thousands).
      - `holdings` object, required — Per-CUSIP position detail for this fund. Keys are 9-char CUSIPs.
  - `meta` SugraMeta, required — Metadata attached to every /api/v1/* response envelope.
    - `endpoint` string, required — Requested endpoint path.
    - `data_time` string, required — ISO 8601 UTC timestamp of the source data, not of the request.
    - `response_time` string, required — ISO 8601 UTC timestamp when this response was produced.
    - `provider` string, required — API name and version.
    - `source` string, nullable — Identifier of the primary upstream source used for this response.
    - `attribution` string, nullable — Human-readable attribution mandated by an upstream source (e.g. a securities regulator or self-regulatory organization). Present only on responses whose source requires the owner and source to be clearly identified. Do not remove or alter it when using the response.
    - `fallback_used` boolean, nullable — True when the primary source failed and a fallback produced the data.
    - `fallback_chain` string[], nullable — Ordered list of sources attempted, in the order they were tried.
    - `cached` boolean, nullable — True when this response was served from the internal cache.
    - `stale` boolean, nullable — True when the cached response was returned after the upstream rate-limited or errored. Clients can use this to detect degraded data.

## Other responses

- `401` — Missing or invalid `x-api-key` header. JSON body with a stable `code` distinguishing `missing_api_key` (no header sent) from `invalid_api_key` (header sent, key not accepted); any other 401 source carries the generic `unauthorized` with its detail as `reason`. Plus `hint`. `plan` is always null on 401 - an unauthenticated request has no plan; quota exhaustion is 429, not 401.
- `422` — Validation Error
- `429` — Daily rate limit exceeded. Check `X-RateLimit-Reset` for the next window.
- `503` — Upstream source is temporarily unavailable. Retry after a short delay.

---

[API](https://skmtc.net/sugra/apis/sugra-api.md) · [All operations](https://skmtc.net/sugra/apis/sugra-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/sugra/sugra-api/versions/d3e3d9c28132/schema)
