---
title: "Open a supplier data request by the link token in a header (public; marks it opened)"
method: GET
path: "/shared/supplier-request"
tags: ["Supplier portal"]
---

# Open a supplier data request by the link token in a header (public; marks it opened)

`GET /shared/supplier-request`

No authentication: the link token is the credential. It travels in the X-Greentally-Share-Token header, never in the URL (Cloud Run's request log records URLs). A missing, malformed or unknown token is the same 404. Answers carry Cache-Control no-store and are rate-limited per client IP and per token (429 RATE_LIMITED). A cancelled, accepted or expired request answers 410 REQUEST_CLOSED. No /shared/ route takes the token in its path (spec 2026-10-05).

## Headers

- `X-Greentally-Share-Token` string, required

## Response `200`

The questionnaire

- SharedSupplierRequestResponse
  - `data` SharedSupplierRequest, required — What the supplier's link shows: the request, the customer's name, only the request's own sites, the draft and the uploaded files. No organization, user or other row ids.
    - `contactName` string, required
    - `customerName` string, required
    - `draft` SupplierPortalAnswers, required — The questionnaire answers (supplierportal.Answers); validated in Go.
    - `draftSavedAt` string, date-time, nullable, required
    - `dueDate` string, date, nullable, required
    - `expiresAt` string, date-time, required
    - `files` SupplierPortalFile[], required
      - `contentType` string, required
      - `fileName` string, required
      - `id` string, required
      - `sizeBytes` integer, required
      - `uploadedAt` string, date-time, required
    - `limits` SharedSupplierRequestLimits, required
      - `allowedExtensions` string[], required
      - `maxFileBytes` integer, required
      - `maxFiles` integer, required
      - `maxLines` integer, required
    - `message` string, required
    - `periodEnd` string, date, required — Exclusive: the day after the last day.
    - `periodStart` string, date, required
    - `returnComment` string, required — The customer's comment when the latest submission was returned; empty otherwise.
    - `sections` SupplierPortalSections, required
      - `activityData` boolean, required
      - `allocation` boolean, required
      - `evidenceFiles` boolean, required
      - `productFootprint` boolean, required
      - `sbtiStatus` boolean, required
    - `sites` SupplierPortalSite[], required
      - `id` string, required
      - `name` string, required
      - `supplyPoints` string[], required
    - `status` 'sent' | 'opened' | 'submitted' | 'returned', required
    - `supplierName` string, required

## Other responses

- `404` — Not Found
- `410` — Gone
- `429` — Too Many Requests
- `503` — QUERY_TIMEOUT: the read hit the request statement timeout and was stopped; try again shortly (the writes on this link run without that timeout)

## Changes

- **2026-10-06** `461a0ebc7731` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/greentally/apis/esgai-api/changes/shared/supplier-request/get.md)

---

[API](https://skmtc.dev/greentally/apis/esgai-api.md) · [All operations](https://skmtc.dev/greentally/apis/esgai-api/llms.txt) · [OpenAPI document](https://skmtc.dev/greentally/apis/esgai-api/revisions/461a0ebc7731?raw)
