Supplier portal
Open a supplier data request by the link token in a header (public; marks it opened)
No authentication: the link token is the credential. It travels in the X-Greentally-Share-Token header, never in the URL (Cloud Run's request log records URLs). A missing, malformed or unknown token is the same 404. Answers carry Cache-Control no-store and are rate-limited per client IP and per token (429 RATE_LIMITED). A cancelled, accepted or expired request answers 410 REQUEST_CLOSED. No /shared/ route takes the token in its path (spec 2026-10-05).
get/shared/supplier-request
Headers
X-Greentally-Share-Tokenstring required
A public link's token, kept out of the URL (spec 2026-10-05). Missing, sent twice, malformed or unknown: the same 404 NOT_FOUND. Never logged, never echoed.
Response
The questionnaire
Changes
Changed in 1 of the 10 revisions of this API.1
- ○
endpoint added
endpoint-added
- ○