Security and limits
- Keys are shown once, stored only as a SHA-256 fingerprint, can expire, and can be revoked instantly.
- Scopes: read-only or read + write. Write is limited to drafts and the address book.
- Rate limit: 120 requests per minute per key. The
X-RateLimit-Remainingheader shows what's left. - Audit: every request is logged against its key; changes appear in the tender audit trail.
- Webhooks must use HTTPS to a public address, and are signed with a per-endpoint secret.
- Credits: AI features used through integrations use credits exactly as in the app.
- AI safety: supplier content is always treated as evidence, never as instructions, including for connected agents.
Questions or a security report? Contact us via the contact page.
