Skip to content
Zonio Developers

Authentication

Every request to the REST API and the MCP server is authenticated. There are no anonymous endpoints.

API keys

Send your key as a bearer token:

curl https://api.zonio.tech/v1/layers \
  -H "Authorization: Bearer zk_live_8a1f…"
PrefixEnvironmentData
zk_test_sandbox.api.zonio.techKraków and Wrocław only, free, rate-limited
zk_live_api.zonio.techAll of Poland, billed per plan

Keys are created and revoked in the Zonio app under Settings → API keys. A key belongs to an organization, not a person, so it survives team changes.

Scopes

Restrict a key to what it needs. A key handed to an AI agent should usually be read-only.

ScopeGrants
parcels:readParcel lookup, regulations, constraints, terrain, proximity
search:readStructured, natural-language and scenario search
market:readTransaction comparables and price medians
layers:readRaw layer queries and vector tiles
reports:createDue-diligence reports (JSON and PDF)

OAuth for MCP clients

Clients that support the MCP authorization flow (Claude.ai, Claude Desktop, ChatGPT connectors) don't need a key at all. Add https://mcp.zonio.tech/mcp as a connector, sign in with your Zonio account in the browser window that opens, and approve the scopes. Tokens are short-lived and can be revoked from Settings → Connected apps.

Headless agents, CI jobs and servers use an API key in the Authorization header instead. See Connect your agent.

Keeping keys safe

  • Never ship a live key in a browser bundle or mobile app. Proxy through your backend, or use a test key for prototypes.
  • Use one key per integration so you can revoke one without breaking the others.
  • Every response carries a Zonio-Request-Id header. Include it when you contact support.