Docs
On this page
Docs/Data Bank/Authentication and Access

Get Started · Data Bank

Authentication and Access

Every documented Data Bank route requires authentication, including catalogue, coverage, release and area lookups and every continuation page.

http
Authorization: Bearer YOUR_VALTAIC_API_KEY

Use HTTPS. Never place a key in a URL, screenshot, public repository, front-end bundle or analytics event. Your application's backend should make requests on behalf of signed-in users where a browser interface is involved.

Access Is Granted at Two Levels

CheckMeaning
Family permissionThe key may access Property Markets (markets:read) or Rates and Financing (rates:read).
Product/metric entitlementThe account may retrieve the requested dataset and measures within that family.

The permission names are not query parameters. Sending scope=markets:read, a plan name or a customer ID does not grant access.

Valuation API access, market access and rates access are distinct. Possession of a valid key does not imply access to every product. Commercial plans, quotas, pricing and key-management arrangements will be supplied separately; this reference does not promise a particular allowance or self-service dashboard.

Use the Catalogue to Check Your Access

GET /v1/markets/datasets and GET /v1/rates/datasets return metrics permitted for the authenticated account. A dataset may have standard default metrics that exceed your access. In that case, requires_metric_selection is true.

For example, an account entitled to sales counts but not estimated price per square metre should request:

http
GET /v1/markets/series?dataset=market_activity&area=E08000025&property_type=flat&metrics=sales_count

If any explicitly or implicitly requested measure is outside the account's entitlement, the request returns 403. The API does not silently remove the restricted measure and present an incomplete group as a complete result.

Errors and Revocation

Missing or invalid credentials result in authentication failure. An authenticated key without permission receives 403. Do not retry either indefinitely; correct the key or access configuration.

Each page of a paginated request is authorised again. A continuation cursor is not a substitute for a key and does not preserve access after it has been revoked. It is bound to the original authenticated identity, so do not share it with another customer or key.

A gateway may reject a request before the Data Bank service processes it. Such a response can have a different error envelope. Client code should check HTTP status and content type before assuming the structured service error described in Errors.

Safe Integration

Use server-side environment variables or a managed secret store. Redact the Authorization header and continuation tokens from logs. Do not disable certificate verification. Rotate or revoke an exposed key through your agreed account-support process.

Only GET data retrieval is documented here. There is no public endpoint in this contract for changing entitlements, creating customers, setting plans or triggering a data build.