Skip to content

Every assessment connects conclusions to official sources.

Developers

API documentation

Market-access intelligence: product checks, assessments, reports, documents, monitoring, and webhooks. Every response carries an x-request-id header; errors follow {error_code, message, request_id, details}. Results are decision-support information, not legal advice.

Specification version 1.0.0 · served live from /api/openapi.json

Authentication

Authenticate with an API key issued in your account dashboard. Send it on every request using either the x-api-key header or Authorization: Bearer <key>. Keep keys server-side — never ship them in client-side code — and rotate a key immediately if it is exposed. Keys carry scopes (for example monitoring:read); an endpoint that needs a scope your key lacks returns 403. Revoked or expired keys return 401.

curl https://api.example.com/api/v1/products \
  -H "x-api-key: YOUR_API_KEY"

Market Access Check

Run a market-access check for a product and destination: the rule engine matches verified regulations and returns requirements, evidence and sources with a confidence level.

POST/api/v1/market-access/check

Market-access check (public, rate-limited, key-optional)

Products

Manage the product catalog the API assesses: create products with their attributes and categories, then reference them from checks and monitoring.

GET/api/v1/products

List products

POST/api/v1/products

Create product

GET/api/v1/products/{id}

Get product

PATCH/api/v1/products/{id}

Update product

DELETE/api/v1/products/{id}

Archive product

Assessments

Full assessments go beyond the quick check: staged evaluation, follow-up questions for missing attributes, requirement-level results and review state.

GET/api/v1/assessments

List assessments

POST/api/v1/assessments

Run assessment (rule engine)

GET/api/v1/assessments/{id}

Get assessment

PATCH/api/v1/assessments/{id}

Review assessment (§19)

DELETE/api/v1/assessments/{id}

Delete assessment

GET/api/v1/assessments/{id}/requirements

List requirements

POST/api/v1/assessments/{id}/requirements

Update requirement status

GET/api/v1/assessments/{id}/questions

List questions + answers

POST/api/v1/assessments/{id}/questions

Answer a question

Reports

Generate shareable market-access reports from assessments and export them for stakeholders, auditors or customs brokers.

GET/api/v1/reports

List reports

POST/api/v1/reports

Create report (publishes immutable v1)

GET/api/v1/reports/{id}

Get report + latest version

PATCH/api/v1/reports/{id}

Change status (publishes new version on approve/deliver)

DELETE/api/v1/reports/{id}

Archive report

GET/api/v1/reports/{id}/export

Export report

Documents

Upload evidence documents (certificates, test reports, declarations) and have them analyzed against the requirements they support.

GET/api/v1/documents

List documents

POST/api/v1/documents

Upload document (multipart → pipeline)

Monitoring

Subscribe products to regulatory change monitoring. When a verified regulation changes, subscribers are alerted and affected rules are re-verified.

GET/api/v1/monitoring

List subscriptions (or ?alerts=true)

POST/api/v1/monitoring

Create monitoring subscription

GET/api/v1/monitoring/{id}

Get subscription

PATCH/api/v1/monitoring/{id}

Update subscription (or ?type=alert for alert status)

DELETE/api/v1/monitoring/{id}

Delete subscription

Webhooks

Subscribe to outbound events instead of polling. Deliveries are signed with HMAC-SHA256 (header x-map-signature, format t=<timestamp>,v1=<signature> over <timestamp>.<raw JSON body>) and retried up to 5 times with doubling backoff from 30 seconds. Events: assessment.completed, assessment.review_needed, report.ready, document.analyzed, alert.created, monitoring.change_detected, subscription.updated.

GET/api/v1/webhooks

List webhooks

POST/api/v1/webhooks

Create webhook (secret shown once)

GET/api/v1/webhooks/{id}

Get webhook (?show=deliveries)

PATCH/api/v1/webhooks/{id}

Update or ?action=rotate secret

DELETE/api/v1/webhooks/{id}

Delete webhook

Rate limits

Two layers protect the API. Short-window sliding limits apply per API key (or per IP for anonymous traffic); a breach returns 429 with a rate_limited code and the message “Rate limit exceeded. Slow down and retry.” Monthly quotas come from your plan and are enforced per API key.

Short-window limits

ScopeLimitApplies to
Authenticated API traffic300 requests per minuterequests authenticated with an API key
Public anonymous checker20 requests per hourunauthenticated use of the public check endpoints, per IP
Expensive operations30 requests per hourexports and document uploads
Auth endpoints30 requests per 15 minutessign-in, sign-up and token endpoints

Monthly quotas by plan

PlanAPI requests
FreeAPI access not included
Professional1,000 requests / month
Business25,000 requests / month
EnterpriseUnlimited

Quotas are defined by the plan limits and may change with plan updates; the dashboard always shows your current usage. Need higher throughput? Talk to sales about an enterprise plan.

Errors

Errors use standard HTTP status codes with a JSON body describing the problem. Authentication failures return 401, authorization failures 403, validation problems 422, and rate-limit breaches 429.

Versioning

The API is versioned in the request path (currently v1). Breaking changes ship as a new version with a migration window; additive fields and endpoints are added without a version bump and are safe to ignore.

Examples

Run a market-access check for a product against a destination market:

curl -X POST https://api.example.com/api/v1/market-access/check \
  -H "x-api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "product": { "name": "Bluetooth speaker", "category": "consumer-electronics" },
    "destination": "DE"
  }'

List your monitored products and their latest alerts:

curl "https://api.example.com/api/v1/monitoring?alerts=true" \
  -H "Authorization: Bearer YOUR_API_KEY"

SDKs

No official SDKs are published yet. The API is plain REST over HTTPS with JSON bodies, so any HTTP client works — the curl examples above translate directly. SDKs for popular languages are on the roadmap; until then, the OpenAPI spec at /api/openapi.json can generate a client for your stack.

Common questions

Start free

Check a Product Free

Instant screen against verified regulations: evidence-backed, source-cited.

Check a Product FreeGet a Market Access Report

Free initial check, no signup required. Save or export after you see the result.