Product evidence and controls
Scoped API access and bounded webhooks
Integrate with the evidence already retained in a project. The v1 API keeps provider credentials private and does not trigger paid measurements on read requests.
01
Choose minimal key scope
Owners and administrators can issue a project-scoped key for selected read resources or internal task creation. The secret is shown once and stored only as a hash; it expires after ninety days. Current issuer membership, scope and revocation are checked for each request.
02
Page through saved metadata
Content and report metadata use project-owned document cursors, at most fifty rows per page. Task creation requires an idempotency key. Nominal limits are thirty requests per key per minute and one hundred twenty per organization; concurrent coordination pressure can reject a burst sooner.
03
Deliver small signed events
Configured customer webhooks send stable event, project and entity identifiers with timestamped HMAC signatures. Endpoints begin disabled; public HTTPS validation, finite budget, three-attempt ceiling and bounded scheduling apply. Signing encryption and runtime configuration are required before delivery.
Practical questions
Where is the API contract?
The implemented OpenAPI description is served at /api/v1/openapi. It documents current resources rather than planned endpoints.
Does a webhook contain provider tokens?
No. The supported payload contains identifiers and event metadata, not credentials, raw reports or private provider bodies.
Start with observable evidence
Run the bounded public scan on the homepage, then save a project when you are ready. Connected measurements need real authorization and available quota.