# Catalog Guard > A bounded, fail-closed catalog preflight service for Shopify-shaped supplier product CSVs. > Two unauthenticated JSON operations: validate CSV text or normalized product rows and get > back deterministic blockers and warnings, or read service health. It accepts no file uploads, > no credentials, no payment data and no store connection; it never imports or modifies a > catalog, and it stores nothing. Generated by API Evangelist from the provider's live surface on 2026-08-09. The provider does not publish an llms.txt of its own (https://catalogguard.noahcortezj-c.workers.dev/llms.txt returns 404). It does publish an APIs.json 0.21 index at /apis.json. ## Quick start No signup, no API key, no OAuth. One call: ``` curl -sS https://catalogguard.noahcortezj-c.workers.dev/api/v1/catalog/check \ -H 'content-type: application/json' \ --data '{"rows":[{"supplier_sku":"SKU-1","title":"Widget","price":"12.50","stock":3,"published":true}]}' ``` ## APIs - [Catalog Guard Catalog Check API](https://catalogguard.noahcortezj-c.workers.dev/api/v1/catalog/docs): Base URL https://catalogguard.noahcortezj-c.workers.dev - `POST /api/v1/catalog/check` — validate a catalog. Body is exactly one of `{"csv": ""}` or `{"rows": [ ... ]}`. - `GET /api/v1/catalog/health` — status, contract version, storage mode, self-reported rate limit. ## Specs - [OpenAPI 3.1.0](https://catalogguard.noahcortezj-c.workers.dev/openapi.json): 2 paths. Declares no operationIds, no response schemas and no examples. - [APIs.json 0.21](https://catalogguard.noahcortezj-c.workers.dev/apis.json): the provider's own discovery index. ## Docs - [API docs (plain text)](https://catalogguard.noahcortezj-c.workers.dev/api/v1/catalog/docs) - [Home — free in-browser CSV preflight](https://catalogguard.noahcortezj-c.workers.dev/) - [Shopify CSV required and dependent fields](https://catalogguard.noahcortezj-c.workers.dev/guides/shopify-csv-fields) - [Matching-handle overwrite risk](https://catalogguard.noahcortezj-c.workers.dev/guides/matching-handle-risk) - [UTF-8 and CSV header troubleshooting](https://catalogguard.noahcortezj-c.workers.dev/guides/utf8-and-headers) - [$149 CSV Diagnostic — bounded human review](https://catalogguard.noahcortezj-c.workers.dev/diagnostic) - [Privacy](https://catalogguard.noahcortezj-c.workers.dev/privacy) - [Terms](https://catalogguard.noahcortezj-c.workers.dev/terms) ## What an agent needs to know - **Authentication: none.** No key, no token, no signup. There is also no tenancy — nothing is scoped to you and nothing can be retrieved later. - **Exactly one input key.** Sending both `csv` and `rows`, neither, or any extra top-level key returns 400 `invalid_shape`. Both branches are `additionalProperties: false`. - **The CSV branch wants NORMALIZED headers**, not Shopify's export headers. Use `supplier_sku,title,price,stock,published`. A CSV with Shopify's own documented headers (`Handle,Title,Variant SKU,...`) parses fine but every row comes back fully blocked with `missing_required_field`. This is undocumented; it was verified by probe. - **Bounds, not pagination.** 250 rows max, 98304 CSV characters max, 131072-byte body ceiling. Chunk client-side. Over the row limit is 400 `invalid_rows`; over the byte ceiling is 413 `body_too_large`. - **Always send `content-type: application/json`.** Otherwise 415 `unsupported_media_type`. The check endpoint is POST-only; GET returns 405. - **Errors are not RFC 9457.** The envelope is `{"schemaVersion": "...", "error": {"code": "...", "message": "..."}}`. Branch on `error.code`; the message is not stable. - **Findings are the product, not errors.** A 200 carries `result.blockers[]` and `result.warnings[]`, each `{row, field, code, message}`. `row` is 1-based and includes the header row, so the first data row reports as row 2. Observed codes: `missing_required_field`, `invalid_price`, `invalid_stock`, `invalid_published`, `duplicate_normalized_sku`. - **Rate limit: best-effort 20 requests per minute per Cloudflare isolate**, 429 on exceed. No `RateLimit-*` or `Retry-After` headers, so back off blindly. - **Retry-safe but no idempotency contract.** The endpoint is a pure function with no storage, so retries are harmless — but there is no `Idempotency-Key` header and no published guarantee. - **It will not guess.** Ambiguous input is refused rather than coerced: unclosed quotes, malformed rows, duplicate headers, duplicate normalized SKUs and incomplete variant pairs all become blockers. Supplier categories are audit-only and are never mapped to a Shopify taxonomy. - **Every response carries `disclosures`** — machine-readable statements that no credentials or payment data are handled, no store connection or import occurs, no outcome is guaranteed, plus the Shopify referral-commission arrangement and non-affiliation with Shopify. ## Not available No MCP server, no A2A agent card, no GraphQL, no webhooks or events, no SDKs or CLI, no sandbox keys, no changelog, no status page, no GitHub organization, no security.txt or `/.well-known/` documents. All probed on 2026-08-09; all 404.