Prewave Scores - Externals API

Upload and read custom supplier scores from your systems (e.g. SAP). Bulk upload, list event types, and view history per supplier. Available from June 2026.

Business capability
Supplier Risk Management BC-510.30

Operations 3

GET /public/v1/scores/externals Get external score history for one supplier #
POST /public/v1/scores/externals Upload external scores for one or more suppliers #
GET /public/v1/scores/externals/event-types List event types for a perspective #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/prewave-scores-externals-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

prewave-scores-externals-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Public Prewave Scores - Externals API
  description: Documentation of the Public Prewave API.
  version: '1.0'
servers:
- url: https://api.prewave.com
  description: Production Environment
security:
- Token authentication: []
tags:
- name: Scores - Externals
  description: Upload and read custom supplier scores from your systems (e.g. SAP). Bulk upload, list event types, and view history per supplier. Available from June 2026.
paths:
  /public/v1/scores/externals:
    get:
      tags:
      - Scores - Externals
      summary: Get external score history for one supplier
      description: 'Returns score history per event type for one supplier. Identify the supplier using query parameters such as supplier ID, customer ID, own site ID, or Prewave ID — the same identifiers you use elsewhere in the public supplier APIs.


        **When to use this**

        - Auditing what scores are stored for one supplier after an integration run.

        - Showing score history in a customer-facing report or internal dashboard.

        - Verifying that an upload landed as expected for a given supplier.


        **Optional filters**

        - `perspectiveId` — limit results to a specific perspective (defaults to your account’s default).

        - `groupId` — narrow results to a score group when needed.


        **If something goes wrong**

        - **400** — No supplier identifier was provided, or more than one supplier matched. Add or refine identifiers (for example include `source`).

        - **404** — No supplier matched the identifiers you sent.


        **Required permission:** `access_public_internal_score`'
      operationId: getExternalScoresForTargetByIdentifier
      parameters:
      - name: supplierId
        in: query
        description: Supplier ID of the target. Can be combined with customerId, ownId, and/or prewaveId.
        required: false
        schema:
          type: string
          description: Supplier ID of the target. Can be combined with customerId, ownId, and/or prewaveId.
          example: SAP-12345
        example: SAP-12345
      - name: customerId
        in: query
        description: Customer ID of the target. Can be combined with supplierId, ownId, and/or prewaveId.
        required: false
        schema:
          type: string
          description: Customer ID of the target. Can be combined with supplierId, ownId, and/or prewaveId.
          example: CRM-67890
        example: CRM-67890
      - name: ownId
        in: query
        description: Own site ID of the target. Can be combined with supplierId, customerId, and/or prewaveId.
        required: false
        schema:
          type: string
          description: Own site ID of the target. Can be combined with supplierId, customerId, and/or prewaveId.
          example: OWN-SITE-01
        example: OWN-SITE-01
      - name: prewaveId
        in: query
        description: Prewave ID of the target. Can be combined with supplierId, customerId, and/or ownId.
        required: false
        schema:
          type: integer
          description: Prewave ID of the target. Can be combined with supplierId, customerId, and/or ownId.
          format: int32
          example: 102006215
        example: 102006215
      - name: source
        in: query
        description: Optional source system to filter by. Applies to supplierId, customerId, and ownId (not prewaveId).
        required: false
        schema:
          type: string
          description: Optional source system to filter by. Applies to supplierId, customerId, and ownId (not prewaveId).
          example: SAP
        example: SAP
      - name: perspectiveId
        in: query
        description: Optional. Perspective to filter scores by. If omitted, your account default is used.
        required: false
        schema:
          type: integer
          format: int32
        example: 1
      - name: groupId
        in: query
        description: Optional. Score group to filter results by.
        required: false
        schema:
          type: integer
          format: int32
        example: 10
      responses:
        '200':
          description: Score history for the supplier that matched your identifiers.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicExternalScoreResponse'
              examples:
                Score history for one supplier:
                  summary: Multiple event types with revision history
                  description: Score history for one supplier
                  value: '{"identifier":{"supplierId":"SAP-12345","customerId":null,"ownId":null,"prewaveId":null,"source":"SAP"},"scores":[{"group":{"id":10,"name":"Environmental","sname":"env"},"eventTypeKey":"carbon","score":{"value":85,"risk":"Low"},"comment":"Q1 2026 sustainability review — improved emissions tracking","updatedAt":"2026-01-15T10:30:00Z","validFrom":"2026-01-15T00:00:00Z","validTo":null,"history":[{"group":{"id":10,"name":"Environmental","sname":"env"},"eventTypeKey":"carbon","score":{"value":78,"risk":"Mid"},"comment":"Initial Q4 2025 assessment","updatedAt":"2025-10-01T09:00:00Z","validFrom":"2025-10-01T00:00:00Z","validTo":"2025-12-31T23:59:59Z","history":[]},{"group":{"id":10,"name":"Environmental","sname":"env"},"eventTypeKey":"carbon","score":{"value":82,"risk":"Low"},"comment":"Revised after on-site supplier audit","updatedAt":"2025-12-15T14:00:00Z","validFrom":"2026-01-01T00:00:00Z","validTo":"2026-01-14T23:59:59Z","history":[]}]},{"group":{"id":20,"name":"Physical Risk","sname":"physical"},"eventTypeKey":"flood","score":{"value":42,"risk":"Mid"},"comment":"Primary site located in a medium flood-risk zone","updatedAt":"2026-02-01T08:00:00Z","validFrom":"2026-02-01T00:00:00Z","validTo":null,"history":[]},{"group":{"id":30,"name":"Financial Risk","sname":"financial"},"eventTypeKey":"credit_risk","score":{"value":72,"risk":"Mid"},"comment":"Credit rating imported from external risk platform","updatedAt":"2026-01-20T16:45:00Z","validFrom":"2026-01-20T00:00:00Z","validTo":"2026-07-19T23:59:59Z","history":[]}]}'
        '400':
          description: Supplier could not be identified uniquely — provide at least one identifier or narrow the match (for example with `source`).
          content:
            application/json: {}
        '404':
          description: No supplier found for the identifiers provided, or you do not have access to that supplier.
          content:
            application/json: {}
        '403':
          description: '403 Forbidden - Authentication or authorization failure. This status code is returned when: (1) the request lacks valid authentication credentials (missing or invalid X-Auth-Token header), or (2) the authenticated user does not have the required permission to access this resource.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessDeniedErrorDTO'
              examples:
                Access denied example:
                  summary: User lacks necessary permissions or authentication
                  value: "{\n        \"loggedIn\": true,\n        \"code\": \"access_denied\",\n        \"message\": \"Access denied: you don't have necessary permissions to access this resource\",\n        \"solution\": \"Contact support for appropriate permissions\"\n    }"
        '500':
          description: 500 Internal Server Error - An unexpected error occurred on the server. The request may or may not have been processed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDTO'
              examples:
                Error - Server Error:
                  summary: Unexpected server error
                  value: "{\n        \"code\": \"internal_error\",\n        \"message\": \"An unexpected error occurred\",\n        \"solution\": \"Please try again later or contact support\"\n    }"
        '429':
          description: '429 Too Many Requests - API rate limit exceeded. The request has been rejected because the rate limit for this endpoint has been exceeded. Default rate limits: GET requests - 100 per 10 seconds, 500 per minute; POST/PUT/PATCH/DELETE requests - 20 per 10 seconds, 100 per minute. For increased access, please contact customer success.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiRateLimitResponse'
              examples:
                Rate limit exceeded example:
                  summary: API rate limit exceeded
                  value: "{\n        \"error\": \"API rate limit exceeded\",\n        \"message\": \"You have reached the maximum allowed requests. Please try again later or upgrade your plan for increased access\",\n        \"requestLimit\": 100,\n        \"requestCount\": 100,\n        \"limits\": [\n            {\n                \"requestLimit\": 100,\n                \"timeInSeconds\": 10\n            },\n            {\n                \"requestLimit\": 500,\n                \"timeInSeconds\": 60\n            }\n        ],\n        \"currentTime\": \"2026-01-15T10:30:00\",\n        \"nextResetAt\": \"2026-01-15T10:30:10\"\n    }"
    post:
      tags:
      - Scores - Externals
      summary: Upload external scores for one or more suppliers
      description: 'Uploads scores per supplier and event type. Event types are the risk dimensions you score for a supplier (e.g. Carbon, Flood).


        **What you send**

        - A list of suppliers, each with how to find that supplier in Prewave and one or more scores.

        - At most 100 supplier entries in `data` per request.

        - At most 50 score rows per supplier in `scores` (one per event type).

        - Each score needs an event type key (`eventTypeKey`), a value from 1 to 100, and an optional comment.


        **Recommended workflow**

        1. Call **List event types for a perspective** to see which event type keys are set up for your perspective.

        2. Send this request with those keys where possible.

        3. Review the response: if `success` is false, open `errors` to see which suppliers or scores failed and why.


        **How to read the response**

        - The request is accepted even when some rows fail. Check `success` for an all-clear result.

        - Counters show how many suppliers were received, matched, and saved (`totalCount`, `validCount`, `resolvedCount`, `writtenCount`, `skippedCount`).

        - Problems (unknown supplier, unknown event type key, and similar) are listed in `errors`, not only as an HTTP error.


        **Required permission:** `access_public_internal_score`'
      operationId: createExternalScoresBulk
      requestBody:
        description: 'List of suppliers and their scores. Limits are enforced at validation time: at most 100 suppliers and at most 50 scores per supplier. See the request schema and examples for the expected shape.'
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PublicExternalScoreCreationRequest'
            examples:
              Multiple suppliers:
                summary: Three suppliers with multiple scores and identifier types
                description: Multiple suppliers
                value: '{"data":[{"identifier":{"supplierId":"SAP-12345","customerId":null,"ownId":null,"prewaveId":null,"source":"SAP"},"scores":[{"eventTypeKey":"carbon","scoreValue":24,"comment":"Scope 1 and 2 emissions review — Q1 2026"},{"eventTypeKey":"flood","scoreValue":5,"comment":"Low flood exposure at primary manufacturing site"}]},{"identifier":{"supplierId":null,"customerId":null,"ownId":null,"prewaveId":102006215,"source":null},"scores":[{"eventTypeKey":"credit_risk","scoreValue":72,"comment":"Credit rating imported from external risk platform"}]},{"identifier":{"supplierId":null,"customerId":"CRM-67890","ownId":null,"prewaveId":null,"source":"SAP"},"scores":[{"eventTypeKey":"carbon","scoreValue":55,"comment":null}]}]}'
        required: true
      responses:
        '200':
          description: Upload finished. Check `success`, the counters, and `errors` to see whether every supplier and score was saved.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicExternalScoreCreationResponse'
              examples:
                Bulk write result — all succeeded:
                  summary: Every supplier and score was saved
                  description: Bulk write result — all succeeded
                  value: '{"success":true,"totalCount":3,"validCount":3,"resolvedCount":3,"writtenCount":4,"skippedCount":0,"errors":[]}'
                Bulk write result — partial success:
                  summary: Some scores saved; check errors for failed rows
                  description: Bulk write result — partial success
                  value: '{"success":false,"totalCount":3,"validCount":3,"resolvedCount":2,"writtenCount":3,"skippedCount":1,"errors":[{"entryIndex":2,"scoreIndex":0,"identifier":{"supplierId":null,"customerId":"CRM-UNKNOWN","ownId":null,"prewaveId":null,"source":"SAP"},"eventTypeKey":"carbon","reason":"TARGET_NOT_FOUND","message":"No supplier found matching customerId=CRM-UNKNOWN, source=SAP"},{"entryIndex":0,"scoreIndex":1,"identifier":{"supplierId":"SAP-12345","customerId":null,"ownId":null,"prewaveId":null,"source":"SAP"},"eventTypeKey":"unknown_event","reason":"UNKNOWN_EVENT_TYPE","message":"Event type key ''unknown_event'' is not configured"}]}'
        '400':
          description: The request could not be processed — for example the supplier list was empty, more than 100 suppliers were sent, more than 50 scores were sent for one supplier, a score was outside 1–100, or an event type key was missing.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDTO'
        '403':
          description: '403 Forbidden - Authentication or authorization failure. This status code is returned when: (1) the request lacks valid authentication credentials (missing or invalid X-Auth-Token header), or (2) the authenticated user does not have the required permission to access this resource.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessDeniedErrorDTO'
              examples:
                Access denied example:
                  summary: User lacks necessary permissions or authentication
                  value: "{\n        \"loggedIn\": true,\n        \"code\": \"access_denied\",\n        \"message\": \"Access denied: you don't have necessary permissions to access this resource\",\n        \"solution\": \"Contact support for appropriate permissions\"\n    }"
        '500':
          description: 500 Internal Server Error - An unexpected error occurred on the server. The request may or may not have been processed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDTO'
              examples:
                Error - Server Error:
                  summary: Unexpected server error
                  value: "{\n        \"code\": \"internal_error\",\n        \"message\": \"An unexpected error occurred\",\n        \"solution\": \"Please try again later or contact support\"\n    }"
        '429':
          description: '429 Too Many Requests - API rate limit exceeded. The request has been rejected because the rate limit for this endpoint has been exceeded. Default rate limits: GET requests - 100 per 10 seconds, 500 per minute; POST/PUT/PATCH/DELETE requests - 20 per 10 seconds, 100 per minute. For increased access, please contact customer success.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiRateLimitResponse'
              examples:
                Rate limit exceeded example:
                  summary: API rate limit exceeded
                  value: "{\n        \"error\": \"API rate limit exceeded\",\n        \"message\": \"You have reached the maximum allowed requests. Please try again later or upgrade your plan for increased access\",\n        \"requestLimit\": 20,\n        \"requestCount\": 20,\n        \"limits\": [\n            {\n                \"requestLimit\": 20,\n                \"timeInSeconds\": 10\n            },\n            {\n                \"requestLimit\": 100,\n                \"timeInSeconds\": 60\n            }\n        ],\n        \"currentTime\": \"2026-01-15T10:30:00\",\n        \"nextResetAt\": \"2026-01-15T10:30:10\"\n    }"
  /public/v1/scores/externals/event-types:
    get:
      tags:
      - Scores - Externals
      summary: List event types for a perspective
      description: 'Lists event types configured for a perspective—the risk dimensions you can score (e.g. Carbon, Flood). Use this before a bulk upload so your integration sends event type keys that match what customers see in the product.


        **When to use this**

        - Planning a score import: see which event types apply before building the file or API payload.

        - Explaining to stakeholders which risk dimensions external scores can refer to for that perspective.

        - Troubleshooting failed uploads: compare your source data with the keys returned here.


        **Typical workflow**

        1. Call this endpoint with a `perspectiveId` your API token can access.

        2. Use the returned `eventTypeKey` values when uploading scores.

        3. If some rows fail on upload, check whether the event type key exists in this list.


        **Note:** Upload may still accept event type keys that exist globally but are not listed here. Keys that do not exist at all are reported in the upload response `errors`.


        **Required permission:** `access_public_internal_score`'
      operationId: listExternalScoreEventTypes
      parameters:
      - name: perspectiveId
        in: query
        description: Perspective to list event types for. Use the same perspective as your uploads or reads when possible. Your API token must have access to this perspective.
        required: true
        schema:
          type: integer
          format: int32
        example: 5484774
      responses:
        '200':
          description: Event types configured for this perspective. Each row includes an event type key (`eventTypeKey`) and a display name.
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/PublicExternalScoreEventTypeDTO'
              examples:
                Event types — sample:
                  summary: Event types configured for the perspective
                  description: Event types — sample
                  value: '[{"id":101,"eventTypeKey":"carbon","name":"Carbon"},{"id":102,"eventTypeKey":"flood","name":"Flood"},{"id":103,"eventTypeKey":"credit_risk","name":"Credit Risk"},{"id":104,"eventTypeKey":"water_stress","name":"Water Stress"}]'
                Event types - empty:
                  summary: No event types configured for this perspective
                  description: Empty list — no event types are set up for this perspective in Prewave.
                  value: '[]'
        '400':
          description: Perspective ID is missing — add `perspectiveId` to the request.
          content:
            application/json: {}
        '403':
          description: This perspective is not available for your account.
          content:
            application/json: {}
        '500':
          description: 500 Internal Server Error - An unexpected error occurred on the server. The request may or may not have been processed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorDTO'
              examples:
                Error - Server Error:
                  summary: Unexpected server error
                  value: "{\n        \"code\": \"internal_error\",\n        \"message\": \"An unexpected error occurred\",\n        \"solution\": \"Please try again later or contact support\"\n    }"
        '429':
          description: '429 Too Many Requests - API rate limit exceeded. The request has been rejected because the rate limit for this endpoint has been exceeded. Default rate limits: GET requests - 100 per 10 seconds, 500 per minute; POST/PUT/PATCH/DELETE requests - 20 per 10 seconds, 100 per minute. For increased access, please contact customer success.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiRateLimitResponse'
              examples:
                Rate limit exceeded example:
                  summary: API rate limit exceeded
                  value: "{\n        \"error\": \"API rate limit exceeded\",\n        \"message\": \"You have reached the maximum allowed requests. Please try again later or upgrade your plan for increased access\",\n        \"requestLimit\": 100,\n        \"requestCount\": 100,\n        \"limits\": [\n            {\n                \"requestLimit\": 100,\n                \"timeInSeconds\": 10\n            },\n            {\n                \"requestLimit\": 500,\n                \"timeInSeconds\": 60\n            }\n        ],\n        \"currentTime\": \"2026-01-15T10:30:00\",\n        \"nextResetAt\": \"2026-01-15T10:30:10\"\n    }"
components:
  schemas:
    PublicExternalTargetScoreCollection:
      required:
      - identifier
      - scores
      type: object
      properties:
        identifier:
          $ref: '#/components/schemas/PublicExternalTargetIdentifier'
        scores:
          maxItems: 50
          minItems: 0
          type: array
          description: Scores for this supplier, one per event type. At most 50 per supplier.
          items:
            $ref: '#/components/schemas/PublicExternalTargetScore'
          example: null
      description: Suppliers and their scores. At most 100 suppliers per request.
      example: null
    PublicExtScoreHistory:
      required:
      - eventTypeKey
      - group
      - history
      - score
      - updatedAt
      type: object
      properties:
        group:
          $ref: '#/components/schemas/PublicInfotagGroup'
        eventTypeKey:
          type: string
          example: null
        score:
          $ref: '#/components/schemas/Score'
        comment:
          type:
          - string
          - 'null'
          example: null
        updatedAt:
          type: string
          description: Last update. Timestamp (ISO 8601 UTC)
          format: date-time
          example: '2026-01-15T10:30:00Z'
        validFrom:
          type:
          - string
          - 'null'
          description: Start of validity period. Timestamp (ISO 8601 UTC)
          format: date-time
          example: '2026-01-01T00:00:00Z'
        validTo:
          type:
          - string
          - 'null'
          description: End of validity period. Timestamp (ISO 8601 UTC)
          format: date-time
          example: '2026-12-31T23:59:59Z'
        history:
          type: array
          items:
            $ref: '#/components/schemas/PublicExtScoreHistory'
          example: null
      example: null
    ApiRateLimitResponse:
      type: object
      properties:
        error:
          type: string
          description: Error type identifier
          example: RateLimitExceeded
        message:
          type: string
          description: Human-readable error message explaining the rate limit violation
          example: API rate limit exceeded. Please reduce your request rate.
        requestLimit:
          type: integer
          description: Maximum number of requests allowed in the current time window
          format: int32
          example: 100
        requestCount:
          type: integer
          description: Number of requests made in the current time window
          format: int32
          example: 101
        limits:
          type: array
          description: All rate limits that apply to this endpoint, showing different time windows
          items:
            $ref: '#/components/schemas/ApiRateLimitTimeRequestLimit'
          example: null
        currentTime:
          type: string
          description: Current server time in ISO 8601 format
          format: date-time
          example: '2026-01-19T10:30:00'
        nextResetAt:
          type: string
          description: Time when the rate limit will reset in ISO 8601 format
          format: date-time
          example: '2026-01-19T10:30:10'
      description: Response returned when API rate limit is exceeded (HTTP 429)
      example: null
    PublicExternalScoreCreationResponse:
      required:
      - errors
      - resolvedCount
      - skippedCount
      - success
      - totalCount
      - validCount
      - writtenCount
      type: object
      properties:
        success:
          type: boolean
          example: null
        totalCount:
          type: integer
          format: int32
          example: null
        validCount:
          type: integer
          format: int32
          example: null
        resolvedCount:
          type: integer
          format: int32
          example: null
        writtenCount:
          type: integer
          format: int32
          example: null
        skippedCount:
          type: integer
          format: int32
          example: null
        errors:
          type: array
          items:
            $ref: '#/components/schemas/PublicExternalScoreCreationError'
          example: null
      example: null
    ApiRateLimitTimeRequestLimit:
      type: object
      properties:
        requestLimit:
          type: integer
          description: Maximum number of requests allowed in this time window
          format: int32
          example: 100
        timeInSeconds:
          type: integer
          description: Time window duration in seconds
          format: int32
          example: 10
      description: Rate limit configuration for a specific time window
      example: null
    PublicExternalScoreResponse:
      required:
      - identifier
      - scores
      type: object
      properties:
        identifier:
          $ref: '#/components/schemas/PublicExternalTargetIdentifier'
        scores:
          type: array
          items:
            $ref: '#/components/schemas/PublicExtScoreHistory'
          example: null
      example: null
    PublicExternalTargetScore:
      required:
      - eventTypeKey
      - scoreValue
      type: object
      properties:
        eventTypeKey:
          minLength: 1
          type: string
          example: null
        scoreValue:
          maximum: 100
          minimum: 1
          type: integer
          format: int32
          example: null
        comment:
          type:
          - string
          - 'null'
          example: null
      description: Scores for this supplier, one per event type. At most 50 per supplier.
      example: null
    PublicExternalTargetIdentifier:
      type: object
      properties:
        supplierId:
          type:
          - string
          - 'null'
          description: Supplier ID of the target. Can be combined with customerId, ownId, and/or prewaveId.
          example: SAP-12345
        customerId:
          type:
          - string
          - 'null'
          description: Customer ID of the target. Can be combined with supplierId, ownId, and/or prewaveId.
          example: CRM-67890
        ownId:
          type:
          - string
          - 'null'
          description: Own site ID of the target. Can be combined with supplierId, customerId, and/or prewaveId.
          example: OWN-SITE-01
        prewaveId:
          type:
          - integer
          - 'null'
          description: Prewave ID of the target. Can be combined with supplierId, customerId, and/or ownId.
          format: int32
          example: 102006215
        source:
          type:
          - string
          - 'null'
          description: Optional source system to filter by. Applies to supplierId, customerId, and ownId (not prewaveId).
          example: SAP
      description: Supplier site identifier. At least one lookup key (`supplierId`, `customerId`, `ownId`, or `prewaveId`) should be set; `source` optionally narrows text identifiers.
      example: swagger.example.external-score.target-identifier
    PublicExternalScoreCreationError:
      required:
      - entryIndex
      - identifier
      - message
      - reason
      type: object
      properties:
        entryIndex:
          type: integer
          format: int32
          example: null
        scoreIndex:
          type:
          - integer
          - 'null'
          format: int32
          example: null
        identifier:
          $ref: '#/components/schemas/PublicExternalTargetIdentifier'
        eventTypeKey:
          type:
          - string
          - 'null'
          example: null
        reason:
          type: string
          enum:
          - INVALID_IDENTIFIER
          - TARGET_NOT_FOUND
          - MULTIPLE_TARGETS_MATCHED
          - UNKNOWN_EVENT_TYPE
          - PERSIST_ERROR
          - UNEXPECTED_ERROR
          example: null
        message:
          type: string
          example: null
      example: null
    PublicInfotagGroup:
      required:
      - id
      - name
      - sname
      type: object
      properties:
        id:
          type: integer
          description: Id of the infotag group
          format: int32
          example: null
        name:
          type: string
          description: Name of the infotag group
          example: null
        sname:
          type: string
          description: Short name/code of the infotag group
          example: null
      example: null
    AccessDeniedErrorDTO:
      required:
      - code
      - loggedIn
      - message
      type: object
      properties:
        loggedIn:
          type: boolean
          example: null
        permission:
          type:
          - string
          - 'null'
          example: null
        code:
          type: string
          description: Error code
          example: null
        message:
          type: string
          description: Error message
          example: null
        solution:
          type:
          - string
          - 'null'
          description: Possible solution to the error
          example: null
      example: null
    PublicExternalScoreEventTypeDTO:
      required:
      - eventTypeKey
      - id
      - name
      type: object
      properties:
        id:
          type: integer
          format: int32
          example: null
        eventTypeKey:
          type: string
          example: null
        name:
          type: string
          example: null
      example: null
    Score:
      required:
      - risk
      - value
      type: object
      properties:
        value:
          type: integer
          format: int32
          example: null
        risk:
          type: string
          enum:
          - NA
          - 'No'
          - Low
          - Mid
          - High
          - Critical
          example: null
      example: null
    PublicExternalScoreCreationRequest:
      required:
      - data
      type: object
      properties:
        data:
          maxItems: 100
          minItems: 0
          type: array
          description: Suppliers and their scores. At most 100 suppliers per request.
          items:
            $ref: '#/components/schemas/PublicExternalTargetScoreCollection'
          example: null
      example: null
    ErrorDTO:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: Error code
          example: null
        message:
          type: string
          description: Error message
          example: null
        solution:
          type:
          - string
          - 'null'
          description: Possible solution to the error
          example: null
      description: Error response
      example: null
  securitySchemes:
    Token_authentication:
      type: apiKey
      description: Generate an API token at https://www.prewave.com/management/api and paste it in here.
      name: X-Auth-Token
      in: header