How to create and use an API key
Create an API key on your account page, copy it once, send it as a bearer header to the wind or decision endpoints, and revoke it when finished. Pro and above, up to 5 keys, with a daily call cap.
ON THIS PAGE
Steps
Open your account
Sign in and go to /account, then scroll to the API keys section, or open /account#api. The heading shows how many keys you hold out of 5. On Starter this section has no form, only a note that API keys start on the Pro plan, with links to upgrade and to the docs.
Type a label
In the box headed Key label, with the example site-office dashboard, type a name for the key. The label is limited to 60 characters. Name it after the program that will use it, because you cannot rename a key afterwards.
Tip: One key per program makes it easy to cut off just that one.
Press Create key
Press Create key. The new key appears once in a box above the list, with a note that it is shown once and cannot be retrieved later. It starts with wa_live_ followed by 32 characters.
Copy it now
Press Copy key, which changes to Copied, and paste the key into your password manager or your program's settings. Once you leave the page only the first 12 characters remain on screen, so a lost key must be revoked and replaced.
Send it with each request
Add the header Authorization: Bearer followed by your key to a request to /api/v1/wind or /api/v1/decision. The first needs lat and lon. The second needs lat, lon and mode. The reference at /docs/api lists every parameter and a worked curl call.
Check usage and revoke when needed
Each key in the list shows its label, its first 12 characters, the date created and when it was last used, or that it has never been used. To cut off a key, press the bin icon on its row and confirm. It stops working immediately.
Tip: Use the last used date to spot a key that is no longer in use.
01Who can use API keys
API keys start on Pro. Pro has 1,000 calls a day, Ops 10,000 and Enterprise 100,000. Starter has no API access, and creating a key there returns a message that API keys start on the Pro plan. You can hold up to 5 keys at once on any plan that has access. At the limit, the form shows that you can hold at most 5 keys, so revoke one first. The cap is per account, not per key. All your keys draw from the same daily count, which resets at midnight UTC. See plan comparison and limits.
02What the key opens
Two endpoints take a key. /api/v1/wind returns seven days of hourly wind in mph for a latitude and longitude: the 10 m speed and direction, the same at 80, 120 and 180 m, and the gust at 10 m only. /api/v1/decision takes a latitude, longitude and a mode such as crane, drone, spray, marine, golf, motorsport or events, plus optional limits, and returns the current decision and the candidate windows in site time. Neither is tied to a site you saved, and neither uses your working height or your saved rule. The decision endpoint does not include ensemble odds. Full details are in the reference at /docs/api.
03How the key is sent and stored
Send the key in the header as Authorization: Bearer wa_live_ followed by your 32 characters. We keep only a hash of it, which is why the full key is shown once and cannot be shown again. The list shows the first 12 characters so you can tell keys apart, plus the created and last used dates. Responses allow requests from any web page, so do not put a key in code that runs in a visitor's browser. Call the API from a server you control, since anyone who reads the key can spend your daily calls.
04Daily limits
Every request that reaches the key check uses one call, including a request that then fails because a latitude is missing. Past the limit the API returns 429 with a message that the daily limit of that many requests has been reached, a Retry-After header with the seconds to the next midnight UTC, and X-RateLimit headers showing your limit and what is left. The count is a soft limit, so a burst of parallel requests can slightly overshoot it. If you need more, a higher plan raises the cap. There is no per-key limit and no charge for extra calls.
05Revoking and replacing
Revoking is immediate and permanent. Requests using that key get 401 straight away, and the key cannot be restored. Replace a key by creating a new one, updating your program, then revoking the old one. If you suspect a key was exposed, revoke it first. A lost key cannot be recovered or shown again, so the same applies. There is no way to edit a label, so revoke and re-create if you want a different name.
06If a call fails
A 401 means the header is missing or malformed, or the key is unknown or revoked. A 403 means your plan has no API access, which happens on Starter. A 429 means you have used today's calls. A 400 means a required value such as lat, lon or mode is missing or out of range, and the message lists them. A 502 from the decision endpoint means the forecast source did not answer, so try again. If creating a key shows the max of 5 keys message, revoke one first. If it shows any other error, the message is the reason in plain words.
Questions
What is an API key for?
It identifies your account to the wind and decision endpoints so that your calls are counted against your plan's daily cap. It is not a password for the website and cannot sign in.
Can I use one key for several programs?
You can, but one key per program is better. If one is exposed or no longer needed, you revoke it without breaking the others. All keys share the same daily count either way.
What happens if I leave the label blank?
The key still gets created. The label is only a name for you, and it cannot be edited afterwards, so a clear name saves a revoke and re-create later.
Can I get a revoked or lost key back?
No. Only a hash is stored, and a revoked key is permanently disabled. Create a new key, update your program and revoke the old one.
How many calls do I get?
Pro 1,000 a day, Ops 10,000, Enterprise 100,000, per account, counted per day in UTC. Starter has none. Every request that reaches the key check counts, even one that returns an error.