Skip to contentSkip to Content
API ReferenceAuthentication

Authentication

All API requests must include a valid API key.

Creating an API Key

  1. Go to Settings > API Keys in your dashboard
  2. Click Generate New Key
  3. Copy the key immediately — it’s only shown once
  4. Store it securely (environment variable, secrets manager)

Free Trial API keys can be issued while the released trial API is available and the account has a future trial end date. The key expires at that trial deadline. Upgrading an account does not resurrect an already expired trial key; issue a new paid-tier key after upgrading.

Using Your Key

Include the key in the Authorization header of every request:

curl https://rentalot.ai/api/v1/properties \ -H "Authorization: Bearer ra_abc123..."

Key Format

Keys are prefixed with ra_ followed by 32 random bytes (base64url-encoded). They are hashed with SHA-256 before storage — Rentalot cannot recover a lost key, so save it when it’s generated.

Failed Authentication

A missing, malformed, expired, or revoked key returns 401 Unauthorized in RFC 9457  Problem Details format:

{ "type": "https://rentalot.ai/problems/unauthorized", "title": "Unauthorized", "status": 401, "detail": "Missing or invalid API key" }

Revoking Keys

Revoke any key from Settings > API Keys. Revocation is immediate — any requests using that key will return 401 Unauthorized.

API Access by Plan

Your API key inherits the rate limits and permissions of your plan:

PlanAccessAPI KeysGlobal RPMDaily Requests
Free TrialCore property/contact CRUD220/min per account200/day, 700/trial
StarterRead-only230/min5,000/day
ProFull CRUD5120/min50,000/day
ScaleFull + priority20600/min500,000/day

Write operations have additional per-resource daily and monthly limits. Upgrade your plan to increase limits.

The paid-tier API key values in this table are the advertised plan values. For backward compatibility, the current paid issuance path still permits up to 10 active keys for every paid tier. This trial release does not change that behavior or the Starter plan’s write policy.

Free Trial API preview

The Free Trial API is released for production use while the server-side trialApiAccess gate is enabled and the account has a future trial end date. It is limited to account-owned, private, image-free CRUD for properties and contacts. Trial requests cannot use property image endpoints, image URL imports, bulk operations, messages, workflows, showings, webhooks, provider integrations, or AI/outbound actions.

Trial quotas are account-wide across all active keys and key rotation:

  • 20 requests per minute total
  • 10 reads/minute and 5 writes/minute per resource
  • 200 requests per UTC day
  • 700 requests for the trial lifetime
  • 20 writes/resource/day and 50 writes/resource/trial
  • 20 items per list page

The dashboard keeps key listing and revocation available for authenticated owners after API access expires. Only new key issuance is entitlement-gated.

Signup requires email verification. In production, Better Auth applies a 5/minute sign-up rule and a 100/minute general rule, while the development auth limiter is disabled. These controls do not provide cross-account identity or Sybil prevention, and the current account schema/control plane has no account-suspension authority. Do not treat trial API access as a substitute for signup abuse controls.

Security

  • Never commit API keys to version control
  • Use environment variables to store keys
  • Rotate keys periodically
  • Each key is scoped to your account — it can only access your properties and data