Scan a domain into a setup draft
Beta — behind the sonar-onboarding feature flag. Workspaces the flag is off for get 404 FEATURE_DISABLED.
Reads a company’s website and returns a setup draft carrying the scan profile: name, description, product areas (from the site’s navigation), own accounts, protected vocabulary and competitor candidates. domain defaults to the workspace’s own company domain. Results are cached per domain for 7 days and a draft is reused for 24 hours (force: true scans again). A collector that fails never fails the scan: it is listed in degraded. A domain that cannot be parsed returns 400 INVALID_DOMAIN.
Authorizations
Clerk API key. Create one in Settings → API Keys. Pass as Authorization: Bearer <key>. Keys carry a scope — read, write (implies read) or admin (implies write) — chosen when the key is minted. Each operation's security requirement (and its x-required-scope extension) names the minimum scope it needs; request the least-privileged key that covers the operations you call.
Body
Response
200 response
draft_… id.
"draft_k3v9x0q2m1"
Where the draft is in the setup engine. The scan moves scanning → scanned (or failed).
scanning, scanned, proposing, measuring, sampling, ready, needs_narrowing, failed, applied What the domain scan learned about the company. Every field the wizard renders is editable.
True when the profile came from the domain cache.
True when an existing draft (same owner + domain, < 24 h) was returned.
ISO-8601.
