Skip to main content

Request access

Partner access is reviewed and provisioned manually. You receive a client_id and client_secret for the catalog:read permission.

Tell us about your integration​

Include your project or company, technical contact, what you want to build, expected request volume, whether you use REST or MCP, and how you intend to use scan URLs.

After approval​

Store the credentials in a server-side or local secret store. Exchange them for an access token using the authentication guide. Never embed the client secret in a browser application or commit it to a repository.

For rotation or revocation, contact the person who issued your credentials. Already-issued access tokens may remain valid until expiry.