PlanningTrack API · Free beta
Authentication and keys
Every developer request belongs to a verified account.
Send a bearer key
Authorization: Bearer YOUR_API_KEYCreate up to five named keys in your account. Each has the same read-only API access and shares the account’s allowance. Keys cannot access account settings, other users, or collector administration.
Store keys on your server
Use an environment variable or your hosting provider’s secret store. A browser should call your own backend, which calls PlanningTrack. CORS support does not make secret keys safe to publish.
Rotate without interrupting service
- Create a replacement key.
- Update your server’s secret and deploy it.
- Verify access with
GET /v1/me. - Revoke the previous key in your account.
Revocation takes effect on subsequent requests. Requests already accepted may complete. If you lose a key, create a replacement; we cannot recover its value.
Account sessions
Sign-in codes expire after ten minutes and permit five attempts. You can request another after one minute, up to ten per email address each UTC day. Sign-in sessions expire after seven days of inactivity. Account deletion requires a new sign-in within five minutes.