Authentication
Every request to the REST API and the MCP server is authenticated. There are no anonymous endpoints.
API keys
Send your key as a bearer token:
curl https://api.zonio.tech/v1/layers \
-H "Authorization: Bearer zk_live_8a1f…"| Prefix | Environment | Data |
|---|---|---|
zk_test_ | sandbox.api.zonio.tech | Kraków and Wrocław only, free, rate-limited |
zk_live_ | api.zonio.tech | All of Poland, billed per plan |
Keys are created and revoked in the Zonio app under Settings → API keys. A key belongs to an organization, not a person, so it survives team changes.
Scopes
Restrict a key to what it needs. A key handed to an AI agent should usually be read-only.
| Scope | Grants |
|---|---|
parcels:read | Parcel lookup, regulations, constraints, terrain, proximity |
search:read | Structured, natural-language and scenario search |
market:read | Transaction comparables and price medians |
layers:read | Raw layer queries and vector tiles |
reports:create | Due-diligence reports (JSON and PDF) |
OAuth for MCP clients
Clients that support the MCP authorization flow (Claude.ai, Claude Desktop, ChatGPT connectors) don't need a key at all. Add https://mcp.zonio.tech/mcp as a connector, sign in with your Zonio account in the browser window that opens, and approve the scopes. Tokens are short-lived and can be revoked from Settings → Connected apps.
Headless agents, CI jobs and servers use an API key in the Authorization header instead. See Connect your agent.
Keeping keys safe
- Never ship a live key in a browser bundle or mobile app. Proxy through your backend, or use a test key for prototypes.
- Use one key per integration so you can revoke one without breaking the others.
- Every response carries a
Zonio-Request-Idheader. Include it when you contact support.