Developers

A small, read-only API for pulling your own properties, units, leases, ledger and syndication status into your own systems. Current version: 2026-09-04.

Authenticating

There are two ways in, depending on what is calling:

curl -X POST https://your-domain/api/oauth/token \
  -u "{client_id}:{client_secret}" \
  -d grant_type=client_credentials \
  -d scope="properties:read units:read"

# {"access_token":"mat_…","token_type":"Bearer","expires_in":3600,"scope":"properties:read units:read"}

Either credential is then sent the same way, to the same endpoints — Authorization: Bearer {key or token}. Nothing downstream needs to know which kind you used.

Scopes

Every scope is read-only, and none implies another — reading a property's units needs both properties:read and units:read, because the response names the property.

properties:read — Read your properties
units:read — Read the units in your properties
leases:read — Read your tenancies — dates, rent and status, never the people
ledger:read — Read your book — the entries behind every charge and payment
syndication:read — Read the syndication feed — the listings opted in to a channel, for publishing

Try it

curl https://your-domain/api/public/v1/whoami \
  -H "Authorization: Bearer {your key or token}"

Start there — it reports back exactly what your credential can read and how much of its hour is left, before you point anything at a real endpoint.

Rate limits

Every response carries X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. A 429 carries Retry-After too. The cap applies per key or per OAuth client — minting a fresh token does not reset it, because it is tracked against the client behind the token, not the token itself.

What is not here yet

There is no sandbox or test-mode environment — every credential reads your real account. If that matters for your integration, tell us and we will treat it as a real request rather than build one nobody asked for the shape of.