Getting started
Authentication
Send your key as the api_key query parameter on every request, and send Accept: application/json so errors come back as JSON too.
A request is accepted only when the key exists, the subscription is active and not expired, the key has at least one enabled source, and the caller's IP is on the allowlist when one is configured. Each failure returns 403 with a specific message:
| error | What to fix |
|---|---|
please add your api_key in get param | The key is missing from the query string. |
wrong api key | The key is mistyped or was revoked. |
your api subscription has expired | Renew the subscription. |
your api subscription is not active | Ask support to activate the key. |
ip address is not in whitelist | Call from an allowlisted IP. The response includes the ip we saw. |
you don't have any data in your subscription | No sources are enabled for this key. |
authentication service temporarily unavailable | Status 503. Retry after Retry-After seconds (5). |
Call the API from your server. Responses carry no CORS headers, so browsers block direct calls, and a key in front-end code is readable by anyone. Proxy requests through your backend. next_url in the export also contains your key, so don't log it or show it publicly.
Authenticated request
curl -g "https://api.lotarius.com/domains?api_key=$CARS_API_KEY" \
-H "Accept: application/json"403 · missing keyLive
{
"error": "please add your api_key in get param"
}