01 / PURPOSE
Connect any storefront
The planned API lets a custom-built store register its domain, request scans, receive findings with citations, and keep evidence current — the same workflow the connectors provide, without a plugin.
- Register and verify a storefront
- Request scans and read findings with exact citations
- Receive change alerts by webhook
- Export sealed records and evidence files
02 / ACCESS
Keys, scopes, and logs
Access uses scoped API keys tied to your account. Every call is logged, keys can be rotated or revoked at any time, and no endpoint can change a finding, a score input, or a payment state.
03 / SECURITY
Signed requests and safe limits
Requests are signed and rate-limited, with replay protection and tenant binding. The API never accepts customer card data or health information.