Authentication and scopes
API keys are shown once, hashed at rest and limited by explicit scopes. Rotate or revoke keys from the workspace.
- Read and write scopes
- Tenant and entitlement checks
- No credentials in URLs
Developers
Use the API to import products, request evidence, publish approved passports and receive lifecycle events while tenant, plan and role boundaries remain enforced server-side.
Read the API documentationAPI keys are shown once, hashed at rest and limited by explicit scopes. Rotate or revoke keys from the workspace.
Mutation endpoints accept an idempotency key, validate the request schema and return a stable error envelope. Rate limits are visible in headers.
Outgoing webhook envelopes are signed, timestamped and replayable. Documentation uses fictional Loopback data and never indexes private API responses.
Try the data-readiness assessment, inspect the live demo or talk to the team about your catalogue.
Read the API documentation Check readiness