Partner integration

Building ora scores into your own product takes two endpoints: one runs a scan, one reads the latest stored result. Call both from your server with a scan API key, and render the response as ora returns it.

Get a key
Keys are issued manually, one per partner. Contact us for one. Send it as Authorization: Bearer <key> from your server only. Never ship it to browser code.

1. Run a scan. Stream it, and forward the events to your UI. Add force=1 to rescan a result younger than the 6-hour freshness window.

Run a scan
curl -N "https://ora.ai/api/scan/stream?domain=example.com&format=audit&include=siteType" \ -H "Authorization: Bearer $ORA_API_KEY"

scan_complete carries the audit in result and the site-type reading beside it in siteType. A live scan may then send relevance_assessed (checks marked not applicable, plus the corrected score and grade) and summary_ready; both are optional. Read events until the stream closes, then go to step 2. A closed stream is not always a final score: when deep checks are still running, ora finishes the analysis in the background. If you cannot hold a stream open, POST /api/scan returns the same audit in one response, and a 202 points you at the score endpoint to poll.

2. Read the stored score. This never starts a scan. While analysisStatus is partial, the score can still change: poll until it reads complete. Add &siteType=store (or content, business, app) to read the scan as that type. The siteType reading is experimental: its shape can change without a contract version bump.

Read the stored score
curl "https://ora.ai/api/score/example.com?format=audit&include=siteType" \ -H "Authorization: Bearer $ORA_API_KEY"

It reads by hostname, so a path such as example.com/mcp returns the scan for example.com. A 404 means the site has not been scanned yet: run step 1.

Render the response as-is
Show score, grade, every check in layers[].checks[], and topFixes in the order ora sends them. Do not recompute scores, drop checks, or rewrite statuses. Accept contractVersion major 1 and ignore fields you do not recognize: minor releases add them. The versioning policy lists which fields are stable.