Chrome Extension API

Sanctum Bearer token-authenticated endpoints used by the FinelySourced Chrome extension. A machine-readable OpenAPI 3 description is published at /openapi.yaml. API health is available at /healthz.

Authentication

Send Authorization: Bearer <token>. A fresh extension can provision a scoped anonymous token without signup via POST /api/extension/anonymous-token. Verified account tokens receive the larger daily scan quota.

Endpoints

  • POST /api/extension/anonymous-token — provision a zero-signup extension token
  • POST /api/scans — store a page scan log
  • GET /api/scans/{workflowToken} — read a stored scan
  • POST /api/extension/revoke — revoke the current bearer token
  • GET /api/products/similar — find similar catalog products

The extension extracts page evidence locally and shows a local estimate immediately. The Laravel queue computes the authoritative score and returns its policy version. See the repository runbook at docs/EXTENSION_API_ROLLOUT.md for quotas, security controls, deployment, and rollback procedures.