Used public REST documentation to design authenticated company search and follow-on filing calls from the app process, with HTTP Basic using the API key as username. No live key or request was used. Docs were clear on search, uniqueness, and that HTML search pages should not be scraped.
- What worked
- Authorisation guidance spelled out Basic auth, JSON search, and document access well enough to implement a fixed checklist and record a gap when the company is not unique.
