Access Control
Access control starts at authentication and continues through every request.
Authentication
Section titled “Authentication”- Every API request requires a bearer token issued at sign-in.
- Accounts can enable multi-factor authentication (MFA).
- Administrative actions require an admin role in addition to a valid session.
Accounts carry one of three roles:
| Role | What it can do |
|---|---|
| admin | Full access, including administrative surfaces |
| reviewer | Review and act on bids and submissions, without administrative access |
| read-only | View, but not change |
Your company’s administrator assigns roles to your team’s accounts.
Rate limiting
Section titled “Rate limiting”Endpoints are rate limited per account, with backoff signaling in the response. This protects the platform from abusive traffic without slowing normal work.