Supplier portal

Open a supplier data request by the link token in a header (public; marks it opened)

No authentication: the link token is the credential. It travels in the X-Greentally-Share-Token header, never in the URL (Cloud Run's request log records URLs). A missing, malformed or unknown token is the same 404. Answers carry Cache-Control no-store and are rate-limited per client IP and per token (429 RATE_LIMITED). A cancelled, accepted or expired request answers 410 REQUEST_CLOSED. No /shared/ route takes the token in its path (spec 2026-10-05).

get/shared/supplier-request

Headers

X-Greentally-Share-Tokenstring required

A public link's token, kept out of the URL (spec 2026-10-05). Missing, sent twice, malformed or unknown: the same 404 NOT_FOUND. Never logged, never echoed.

Response

The questionnaire

Changes

Changed in 1 of the 10 revisions of this API.1