Requests
The base URL, versioning, HTTP methods, request bodies and cross-origin rules shared by every CoverageMap API.
The CoverageMap APIs are REST APIs over HTTPS. They share a base URL, a version in the path and the same rules for bodies and headers, so a client written for one API works for the others.
Base URL
Every endpoint path in these docs is relative to this base URL:
https://enterprise.coveragemap.com/api/v1All requests must use HTTPS.
Versioning
The API version is part of the path, for example /api/v1/status. The current version is v1. New fields can be added to responses over time, so write your integration to ignore fields it does not recognise.
HTTP methods
Endpoints use standard HTTP methods. Each endpoint page lists the one it expects.
| Method | Used for |
|---|---|
GET | Reading data. Options are passed as query parameters. |
POST | Lookups and actions that send a JSON body, such as a batch of locations. |
Headers
| Header | When | Value |
|---|---|---|
Authorization | Every authenticated request | Bearer YOUR_API_KEY. See Authentication. |
Content-Type | Requests with a body | application/json |
Referer | Keys with associated domains | Sent by browsers automatically. Server side requests must set it themselves. |
Request bodies
Send bodies as a JSON object with the Content-Type: application/json header. A body that is missing its content type, is not valid JSON, or is not an object is rejected with a 400 before any work is done, and is not billed.
Query parameters
GET endpoints take their options as URL encoded query parameters, for example ?country=US. Unknown query parameters are ignored.
Browser requests (CORS)
The APIs allow cross-origin requests, so you can call them directly from a web page. Browser preflight requests are answered without an API key. Allowed request headers are Authorization, Content-Type and X-Requested-With.
Protect browser keys
Code that runs in the browser exposes its key to anyone who looks. Always set associated domains on keys used in a front end.
Service status
The status endpoint is public and needs no key. It returns Online in data when the API and its services are healthy, or a 503 with the failing services in messages.errors.
curl "https://enterprise.coveragemap.com/api/v1/status"Incidents and maintenance are posted on the CoverageMap status page.