Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.
openapi: 3.2.0
info:
title: Cape Partners — Sniffer Agent Valuation API
version: 1.0.0
description: Machine-readable API backing the Cape Partners M&A deal-flow workspace (click, humans).
contact:
name: Cape Partners
url: https://www.capepartners.fr
servers:
- url: https://www.capepartners.fr
description: Production (www) via Cloudflare
- url: https://sniffer.capepartners.fr
description: Workspace host
- url: http://localhost:3000
description: Local dev
tags:
- name: Valuation
paths:
/api/valuation/{session_id}:
get:
summary: Return the seller's valuation for the session.
tags:
- Valuation
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/Valuation'
'404':
description: No seller for this session
content:
application/json:
schema:
type: object
description: No seller found
properties:
error:
type: string
required:
- error
'403':
description: Session authorization failed
content:
application/json:
schema:
type: object
description: Guard rejection
properties:
error:
type: string
required:
- error
parameters:
- name: session_id
in: path
required: true
schema:
type: string
format: uuid
description: Workspace session UUID (acts as the scoped credential)
operationId: getApiValuationBySessionId
x-operation-id-source: derived
components:
schemas:
Valuation:
type: object
properties:
valuation_revenue:
type: number
format: float
valuation_ebitda:
type: number
format: float
valuation_dcf:
type: number
format: float
valuation_conservative:
type: number
format: float
valuation_triangulated:
type: number
format: float
status:
type: string
enum:
- ok
- no_data
message:
type: string
securitySchemes:
SessionToken:
type: apiKey
in: header
name: X-Session-Id
description: 'The workspace session UUID is a capability token carried in the URL PATH (not this header — shown here only because OpenAPI securitySchemes cannot model a path parameter as a credential). A valid request must present a well-formed UUID-v4 in the path segment {session_id} AND a first-party Origin/Referer (or none). Requests carrying a known-foreign Origin/Referer are refused 403. Per-IP rate limiting applies. All responses carry Referrer-Policy: strict-origin-when-cross-origin.'
NdaSigned:
type: apiKey
in: header
name: X-Nda-Signed
description: 'Precondition (not a literal header): a server-side NDA signature for {session_id} must be recorded in the nda_signatures table via POST /api/nda/sign before NDA-gated resources (/api/matched-names, /api/infomemo/*) will serve data. Recorded signatures are enforced server-side (helper `nda_signed`), not by trusting a client header.'