Developer API
Read-only JSON over the same public records the pages show, plus your own imported lists. Three endpoints take a key; everything that was free and token-less before is still free and token-less.
| Endpoint | Auth | What it returns |
|---|---|---|
GET /api/v1/parcels?bbox=w,s,e,n&layers= | key | Our public parcels inside a bounding box (max 2° per side), with each parcel's layer signals. Never contact data. |
GET /api/v1/lists | key | Your own imported lists. |
GET /api/v1/lists/<list_id>/rows?limit=&offset=&signals=1&include_contact=1 | key | The rows of one of YOUR lists. signals=1 adds our layer matches and the motivation score; include_contact=1 returns the phone/e-mail columns your own upload carried. |
GET /api/v1/signals/<lead_id|apn> | key | Which of our layers name that parcel, each one's source date, last crawl, first-seen and last-seen, plus the motivation score and the arithmetic behind it. |
GET /api/v1/data-sources | none | Per-layer freshness, coverage counties, cadence, known gaps and the outlet registry. Same payload as /data-sources. |
GET /api/v1 and the rest of /api/v1/* | none | The original token-less API (states, counties, records, tax-sales, lenders) — unchanged, still no key. |
Getting a key
Create one at /account/api-keys (a free account, e-mail only). The key is shown once and stored only as a SHA-256 hash, so we cannot recover it for you — revoke and mint a new one instead. Up to 5 active keys per account.
Sending it
curl -H 'Authorization: Bearer whk_...' \
'https://wholesaleheaven.eliteaiempire.com/api/v1/parcels?bbox=-97.5,32.6,-97.2,32.9&layers=tax_delinquent,code_violation'X-API-Key: whk_... works too.
Rate limit
1000 requests per hour per key, in a fixed window. Every keyed response carries X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset; going over returns 429 with Retry-After. It is a courtesy brake, not a security control, and it is counted per key rather than per IP so your traffic and the public endpoints' per-IP brake cannot exhaust each other.
What the key does not unlock
- No phone number or e-mail address for a property owner, at any price, under any key, under any parameter. The only contact columns these endpoints will ever return are the ones in a file you uploaded, from your list, with
include_contact=1. - States whose public-records law restricts commercial use of a list of individuals stay excluded. The exclusion is keyed on a field in our state matrix, not a hardcoded code, so it changes when the law does.
- An owner opt-out is honoured on the next request, with no moderation wait.
- Nothing of someone else's.
/lists/<id>/rowsanswers404for a list your key does not own — deliberately not403, so a key cannot probe what other accounts hold.
Honesty of the numbers
Every freshness date, count and county list in /api/v1/data-sources is read out of the table that feeds the layer at request time. A layer with nothing loaded returns null rows and says why, rather than 0. The motivation score ships with its own arithmetic and its own weights in the payload, so you can recompute it or ignore it.
The records are public records published by county and state offices; each row carries the source URL it came from. We claim no copyright in them. Check the county's own terms before you redistribute.