Catalog Guard API · Authentication Profile

Catalog Guard Api Authentication

Authentication

Catalog Guard API declares 0 security scheme(s) across its OpenAPI definitions.

ecommercecatalog-validationshopifydata-qualitycsv-validationproduct-data-qadata-preflightdata-validationretail
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-08-09'
method: searched
source: >-
  https://catalogguard.noahcortezj-c.workers.dev/api/v1/catalog/docs,
  https://catalogguard.noahcortezj-c.workers.dev/openapi.json,
  https://catalogguard.noahcortezj-c.workers.dev/privacy
docs: https://catalogguard.noahcortezj-c.workers.dev/api/v1/catalog/docs
summary:
  model: none
  types: []
  api_key_in: []
  oauth2_flows: []
schemes: []
detail: >-
  This API is deliberately and explicitly unauthenticated. The OpenAPI 3.1.0 document declares
  no components.securitySchemes and neither operation carries a security requirement; a POST
  with no credential of any kind returns 200. This was verified live, not assumed from an
  empty spec.

  The absence is a stated product position rather than an oversight. The docs endpoint ends
  with the line "No uploads, credentials, payment data, storage, store connection, or import."
  Every successful response repeats it as machine-readable `disclosures`
  (noCredentialsOrPaymentData, noStoreConnectionOrImport). The privacy page states the free
  preflight processes CSV text in the browser and that Catalog Guard does not ask for store
  credentials or retain CSV contents.
access_control:
  mechanism: input bounds and best-effort rate limiting, not identity
  detail: >-
    With no identity layer, abuse control is entirely bound-based: 250 rows or 98304 CSV
    characters per request, a 131072-byte body ceiling, strict content-type enforcement, and a
    best-effort 20 requests/minute per Cloudflare isolate returning 429. There is no per-caller
    quota, no attribution, and no way to revoke a specific consumer.
agent_guidance: >-
  An agent needs no credential setup, no key rotation and no consent flow to call this API.
  The corresponding caveat is that there is no tenancy: nothing the API returns is scoped to a
  caller, and nothing sent to it can be retrieved later.
signup_required: false