prospex
Prospex docs

Authentication

How to use, protect, rotate, and revoke feed tokens and API keys.

Use a feed token to download one saved object's feed. Use an API key for scoped access across your account.

Feed tokenAPI key
Where it goes In the URL path In an Authorization header
What it covers One saved object's feed Whatever its scopes reach: the company register, your markets, your watches, your projects
What it permits Reading only Whatever its scopes say
Where it comes from The object's Connect page prospex.ch/app/api-keys/

Feed tokens

All three feed families put the token in the path:

https://prospex.ch/app/markets/feed/<token>.json
https://prospex.ch/app/markets/feed/<token>.csv
https://prospex.ch/app/watch/feed/<token>.json
https://prospex.ch/app/watch/feed/<token>.csv
https://prospex.ch/app/prospect/feed/<token>.json

The URL is the whole credential. Keep it out of shared documents, ticket comments, and anything that logs full URLs.

Each object's Connect page carries a button that mints a new token. The previous one stops answering immediately with 404, the same status as a deleted market, so no response confirms whether a token existed.

API keys

A key looks like this and is shown once:

pxk_a1b2c3d4_<43 more characters>

The first twelve characters are a public prefix, safe to quote in a log or a support thread. The remaining 43 are the secret.

Scopes

Chosen when you issue the key and fixed for its lifetime.

ScopePermits
prospect:read Read projects and prospects
prospect:write Add companies and record decisions
prospect:run Start cycles and request research
prospect:stages Read, claim and complete external stage jobs
prospect:approve Approve a named outreach revision
prospect:outcomes Record downstream outcomes (published, and no route accepts it yet)
webhooks:manage Manage webhook endpoints (published, and no route accepts it yet)
companies:read Search the Swiss company directory
markets:read Read your markets and their companies
watches:read Read your watches and their signals

The Prospect API page lists every route that answers.

Approving is a separate scope because it releases customer-facing copy.

The three :read scopes come with a Prospex subscription. The prospect:* scopes are part of a closed pilot: the keys page offers what your account can use, and the reference lists all of them, so a key issued today needs no reissuing when the pilot opens.

Webhook signatures

Each webhook endpoint has a signing secret, with the previous secret still valid long enough for you to deploy a receiver change. The verification code is on Webhooks.

Cookie preferences

Necessary cookies always run. The other two are on unless you turn them off.