Developers

Partner API

Programmatic access for brokers and Central Agents: submit your fleet, sync pricing, read inquiries and receive a webhook when a listing changes.

Get API keyhttps://xplor.io/api/v1

Authentication

Every request needs an Authorization: Bearer <token> header.

API keys start with xplr_ and are issued from your broker dashboard. A key only reaches the scopes it was issued with.

JWT tokens from an active xplor session are also accepted for dashboard-initiated requests.

List your inquiries · scope inquiries:read
curl "https://xplor.io/api/v1/inquiries?limit=20" \
  -H "Authorization: Bearer xplr_your_api_key_here"

Endpoints

Loading the API reference

Webhooks

Event types

yacht.updatedPricing or details changed{ id, updated_at }
yacht.publishedListing approved and live{ id, slug }
yacht.rejectedListing needs changes{ id, reason }

Verifying signatures

Every delivery carries an X-Xplor-Signature header: an HMAC-SHA256 digest of the request body, signed with your webhook secret.

Node.js
const crypto = require('crypto')

function verifyWebhook(rawBody, signature, secret) {
  const expected = crypto
    .createHmac('sha256', secret)
    .update(rawBody)
    .digest('hex')
  return `sha256=${expected}` === signature
}

Rate limits

Standard tier

100 req / min

Premium tier

500 req / min

Rate limit headers will be added in a future release. Requests over the limit return HTTP 429.

Error responses

Every error returns { statusCode: number, message: string }.

400Bad request — validation failed
401Unauthorized — missing or invalid token
403Forbidden — valid token but wrong owner
429Too many requests — rate limit exceeded
500Internal server error

Ready to integrate

Issue your first API key from the broker dashboard and start submitting your fleet.

Open broker dashboard