Chrome Extension API
Sanctum Bearer token-authenticated endpoints used by the FinelySourced Chrome extension. A machine-readable OpenAPI 3 description is published at /openapi.yaml. API health is available at /healthz.
Authentication
Send Authorization: Bearer <token>.
A fresh extension can provision a scoped anonymous token without signup via
POST /api/extension/anonymous-token.
Verified account tokens receive the larger daily scan quota.
Endpoints
POST /api/extension/anonymous-token— provision a zero-signup extension tokenPOST /api/scans— store a page scan logGET /api/scans/{workflowToken}— read a stored scanPOST /api/extension/revoke— revoke the current bearer tokenGET /api/products/similar— find similar catalog products
The extension extracts page evidence locally and shows a local estimate immediately.
The Laravel queue computes the authoritative score and returns its policy version.
See the repository runbook at docs/EXTENSION_API_ROLLOUT.md
for quotas, security controls, deployment, and rollback procedures.