Developers
API documentation
Market-access intelligence: product checks, assessments, reports, documents, monitoring, and webhooks. Every response carries an x-request-id header; errors follow {error_code, message, request_id, details}. Results are decision-support information, not legal advice.
/api/openapi.jsonAuthentication
Authenticate with an API key issued in your account dashboard. Send it on every request using either the x-api-key header or Authorization: Bearer <key>. Keep keys server-side — never ship them in client-side code — and rotate a key immediately if it is exposed. Keys carry scopes (for example monitoring:read); an endpoint that needs a scope your key lacks returns 403. Revoked or expired keys return 401.
curl https://api.example.com/api/v1/products \
-H "x-api-key: YOUR_API_KEY"Market Access Check
Run a market-access check for a product and destination: the rule engine matches verified regulations and returns requirements, evidence and sources with a confidence level.
/api/v1/market-access/checkMarket-access check (public, rate-limited, key-optional)
Products
Manage the product catalog the API assesses: create products with their attributes and categories, then reference them from checks and monitoring.
/api/v1/productsList products
/api/v1/productsCreate product
/api/v1/products/{id}Get product
/api/v1/products/{id}Update product
/api/v1/products/{id}Archive product
Assessments
Full assessments go beyond the quick check: staged evaluation, follow-up questions for missing attributes, requirement-level results and review state.
/api/v1/assessmentsList assessments
/api/v1/assessmentsRun assessment (rule engine)
/api/v1/assessments/{id}Get assessment
/api/v1/assessments/{id}Review assessment (§19)
/api/v1/assessments/{id}Delete assessment
/api/v1/assessments/{id}/requirementsList requirements
/api/v1/assessments/{id}/requirementsUpdate requirement status
/api/v1/assessments/{id}/questionsList questions + answers
/api/v1/assessments/{id}/questionsAnswer a question
Reports
Generate shareable market-access reports from assessments and export them for stakeholders, auditors or customs brokers.
/api/v1/reportsList reports
/api/v1/reportsCreate report (publishes immutable v1)
/api/v1/reports/{id}Get report + latest version
/api/v1/reports/{id}Change status (publishes new version on approve/deliver)
/api/v1/reports/{id}Archive report
/api/v1/reports/{id}/exportExport report
Documents
Upload evidence documents (certificates, test reports, declarations) and have them analyzed against the requirements they support.
/api/v1/documentsList documents
/api/v1/documentsUpload document (multipart → pipeline)
Monitoring
Subscribe products to regulatory change monitoring. When a verified regulation changes, subscribers are alerted and affected rules are re-verified.
/api/v1/monitoringList subscriptions (or ?alerts=true)
/api/v1/monitoringCreate monitoring subscription
/api/v1/monitoring/{id}Get subscription
/api/v1/monitoring/{id}Update subscription (or ?type=alert for alert status)
/api/v1/monitoring/{id}Delete subscription
Webhooks
Subscribe to outbound events instead of polling. Deliveries are signed with HMAC-SHA256 (header x-map-signature, format t=<timestamp>,v1=<signature> over <timestamp>.<raw JSON body>) and retried up to 5 times with doubling backoff from 30 seconds. Events: assessment.completed, assessment.review_needed, report.ready, document.analyzed, alert.created, monitoring.change_detected, subscription.updated.
/api/v1/webhooksList webhooks
/api/v1/webhooksCreate webhook (secret shown once)
/api/v1/webhooks/{id}Get webhook (?show=deliveries)
/api/v1/webhooks/{id}Update or ?action=rotate secret
/api/v1/webhooks/{id}Delete webhook
Rate limits
Two layers protect the API. Short-window sliding limits apply per API key (or per IP for anonymous traffic); a breach returns 429 with a rate_limited code and the message “Rate limit exceeded. Slow down and retry.” Monthly quotas come from your plan and are enforced per API key.
Short-window limits
| Scope | Limit | Applies to |
|---|---|---|
| Authenticated API traffic | 300 requests per minute | requests authenticated with an API key |
| Public anonymous checker | 20 requests per hour | unauthenticated use of the public check endpoints, per IP |
| Expensive operations | 30 requests per hour | exports and document uploads |
| Auth endpoints | 30 requests per 15 minutes | sign-in, sign-up and token endpoints |
Monthly quotas by plan
| Plan | API requests |
|---|---|
| Free | API access not included |
| Professional | 1,000 requests / month |
| Business | 25,000 requests / month |
| Enterprise | Unlimited |
Quotas are defined by the plan limits and may change with plan updates; the dashboard always shows your current usage. Need higher throughput? Talk to sales about an enterprise plan.
Errors
Errors use standard HTTP status codes with a JSON body describing the problem. Authentication failures return 401, authorization failures 403, validation problems 422, and rate-limit breaches 429.
Versioning
The API is versioned in the request path (currently v1). Breaking changes ship as a new version with a migration window; additive fields and endpoints are added without a version bump and are safe to ignore.
Examples
Run a market-access check for a product against a destination market:
curl -X POST https://api.example.com/api/v1/market-access/check \
-H "x-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"product": { "name": "Bluetooth speaker", "category": "consumer-electronics" },
"destination": "DE"
}'List your monitored products and their latest alerts:
curl "https://api.example.com/api/v1/monitoring?alerts=true" \
-H "Authorization: Bearer YOUR_API_KEY"SDKs
No official SDKs are published yet. The API is plain REST over HTTPS with JSON bodies, so any HTTP client works — the curl examples above translate directly. SDKs for popular languages are on the roadmap; until then, the OpenAPI spec at /api/openapi.json can generate a client for your stack.
Common questions
Pass your API key in the x-api-key header, or as Authorization: Bearer <key>. Keys are issued in your account dashboard. Keep keys server-side; rotate them immediately if exposed. Keys carry scopes, and endpoints declare the scopes they require.
Yes — short-window limits per API key plus a monthly quota from your plan (see Rate limits below). Slow down and retry when you receive a 429 with a rate_limited code.
The API is versioned in the path (v1). Breaking changes are released as a new version with a migration window; additive changes ship without a version bump.
The API is decision support, like the rest of the platform: it returns requirements, evidence and sources — not legal advice. The same disclaimer applies to every response.
Start free
Check a Product Free
Instant screen against verified regulations: evidence-backed, source-cited.
Free initial check, no signup required. Save or export after you see the result.