Developers
Partner API
Programmatic access for brokers and Central Agents: submit your fleet, sync pricing, read inquiries and receive a webhook when a listing changes.
Authentication
Every request needs an Authorization: Bearer <token> header.
API keys start with xplr_ and are issued from your broker dashboard. A key only reaches the scopes it was issued with.
JWT tokens from an active xplor session are also accepted for dashboard-initiated requests.
curl "https://xplor.io/api/v1/inquiries?limit=20" \ -H "Authorization: Bearer xplr_your_api_key_here"
Endpoints
Webhooks
Event types
Verifying signatures
Every delivery carries an X-Xplor-Signature header: an HMAC-SHA256 digest of the request body, signed with your webhook secret.
const crypto = require('crypto')
function verifyWebhook(rawBody, signature, secret) {
const expected = crypto
.createHmac('sha256', secret)
.update(rawBody)
.digest('hex')
return `sha256=${expected}` === signature
}Rate limits
Standard tier
100 req / min
Premium tier
500 req / min
Rate limit headers will be added in a future release. Requests over the limit return HTTP 429.
Error responses
Every error returns { statusCode: number, message: string }.
Ready to integrate
Issue your first API key from the broker dashboard and start submitting your fleet.
Open broker dashboard