A small, read-only API for pulling your own properties, units, leases, ledger and syndication status into your own systems. Current version: 2026-09-04.
There are two ways in, depending on what is calling:
Authorization: Bearer mk_…. It lasts until you revoke it, or until an expiry you set.curl -X POST https://your-domain/api/oauth/token \
-u "{client_id}:{client_secret}" \
-d grant_type=client_credentials \
-d scope="properties:read units:read"
# {"access_token":"mat_…","token_type":"Bearer","expires_in":3600,"scope":"properties:read units:read"}Either credential is then sent the same way, to the same endpoints — Authorization: Bearer {key or token}. Nothing downstream needs to know which kind you used.
Every scope is read-only, and none implies another — reading a property's units needs both properties:read and units:read, because the response names the property.
properties:read — Read your propertiesunits:read — Read the units in your propertiesleases:read — Read your tenancies — dates, rent and status, never the peopleledger:read — Read your book — the entries behind every charge and paymentsyndication:read — Read the syndication feed — the listings opted in to a channel, for publishingcurl https://your-domain/api/public/v1/whoami \
-H "Authorization: Bearer {your key or token}"Start there — it reports back exactly what your credential can read and how much of its hour is left, before you point anything at a real endpoint.
Every response carries X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. A 429 carries Retry-After too. The cap applies per key or per OAuth client — minting a fresh token does not reset it, because it is tracked against the client behind the token, not the token itself.
There is no sandbox or test-mode environment — every credential reads your real account. If that matters for your integration, tell us and we will treat it as a real request rather than build one nobody asked for the shape of.