Authentication
Public read endpoints require no authentication. You can call the endpoints in this reference without an authorization header.
Some endpoints can return additional user-specific data when called by a signed-in Wander user. Those requests use Wander account sessions and are not yet available to third-party integrations.
API keys (coming soon)
Section titled “API keys (coming soon)”Self-serve API keys are on the way. They are not yet available; until they launch, partners that need write access—for example, to push events—should contact their Wander partner manager.
Keys are scoped to your organization: a key can only read content belonging to the organization that created it.
Here is what to expect so you can plan your integration:
- Organization keys. Keys are issued to an organization and act on its behalf across all of that organization’s maps. There are no personal keys.
- Two environments. Every key is created as either a live key or a test key, and the key itself tells you which: live keys start with
wk_live_and test keys withwk_test_. - Shown once. The full key value is displayed a single time, at creation. Wander stores only a hash, so a lost key cannot be recovered—revoke it and create a new one.
- Scopes. Each key is created with read-only or read/write access.
- Expiry and revocation. Keys can optionally be given an expiry of up to 365 days, and can be revoked at any time.
Treat API keys like passwords: keep them out of client-side code, repositories, and logs. This page will be updated with request examples when keys launch.
Fair use
Section titled “Fair use”Wander does not publish rate limits today. Abusive traffic may be blocked. Cache responses where possible and avoid repeating requests when the underlying content has not changed.