PlanningTrack API · Free beta

Authentication and keys

Every developer request belongs to a verified account.

Send a bearer key

HTTP header
Authorization: Bearer YOUR_API_KEY

Create up to five named keys in your account. Each has the same read-only API access and shares the account’s allowance. Keys cannot access account settings, other users, or collector administration.

Store keys on your server

Use an environment variable or your hosting provider’s secret store. A browser should call your own backend, which calls PlanningTrack. CORS support does not make secret keys safe to publish.

Rotate without interrupting service

  1. Create a replacement key.
  2. Update your server’s secret and deploy it.
  3. Verify access with GET /v1/me.
  4. Revoke the previous key in your account.

Revocation takes effect on subsequent requests. Requests already accepted may complete. If you lose a key, create a replacement; we cannot recover its value.

Account sessions

Sign-in codes expire after ten minutes and permit five attempts. You can request another after one minute, up to ten per email address each UTC day. Sign-in sessions expire after seven days of inactivity. Account deletion requires a new sign-in within five minutes.