X-API-Key header. You obtain this key from your mapping.travel account dashboard. Requests without a valid key are rejected with a 401 response before they reach any endpoint logic.
Get your API key
Sign in to your mapping.travel account at mapping.travel and navigate to Settings → API tokens. Generate a key for your organization. Copy it immediately: it is only shown once.Include the key in requests
Pass your key in theX-API-Key header on every request:
Example
<your-key> with your actual key value.
Authentication errors
401 Unauthorized
You receive a401 response when the X-API-Key header is missing or the key is invalid (expired, malformed, or revoked).
401, verify that:
- The
X-API-Keyheader is present and spelled correctly - The key value is sent exactly as issued, with no extra whitespace or
Bearerprefix - The key has not expired or been revoked in your dashboard
403 Forbidden
A403 response means your token is valid but your account cannot perform the action. This typically occurs when your plan quota is exhausted.
GET /api/v1/billing/usage to inspect remaining quota programmatically.
Rate limiting
The API enforces per-organization rate limits. When you exceed the limit, the API returns a429 Too Many Requests response.