Skip to main content
All public API endpoints require a Mapsdata API key in the x-api-key request header.

Create and manage keys

Open API access while signed in. You can create, reveal, copy, rename, and revoke keys there. Use a separate named key for every integration so usage can be attributed and one integration can be rotated without interrupting another.
Never place an API key in browser code, a Git repository, screenshots, analytics events, or logs. Load it at runtime from your server’s secret manager or environment.
Keys belong to the signed-in account. They can read only that account’s searches and enrichment jobs, and share the account’s subscription, credits, concurrency allowance, and 1,000-request rolling rate limit.

Authentication errors

Revocation takes effect on the next request. Treat an exposed key as compromised: revoke it, issue a replacement, update the integration, and verify recent activity in API analytics.