CarStat.dev
Connect key
Getting started

Authentication

Send your key as the api_key query parameter on every request, and send Accept: application/json so errors come back as JSON too.

A request is accepted only when the key exists, the subscription is active and not expired, the key has at least one enabled source, and the caller's IP is on the allowlist when one is configured. Each failure returns 403 with a specific message:

errorWhat to fix
please add your api_key in get paramThe key is missing from the query string.
wrong api keyThe key is mistyped or was revoked.
your api subscription has expiredRenew the subscription.
your api subscription is not activeAsk support to activate the key.
ip address is not in whitelistCall from an allowlisted IP. The response includes the ip we saw.
you don't have any data in your subscriptionNo sources are enabled for this key.
authentication service temporarily unavailableStatus 503. Retry after Retry-After seconds (5).

Call the API from your server. Responses carry no CORS headers, so browsers block direct calls, and a key in front-end code is readable by anyone. Proxy requests through your backend. next_url in the export also contains your key, so don't log it or show it publicly.

Authenticated request
curl -g "https://api.lotarius.com/domains?api_key=$CARS_API_KEY" \
  -H "Accept: application/json"
403 · missing keyLive
{
  "error": "please add your api_key in get param"
}