Introduction
Land Your Home's enterprise partner API.
Getting Started
This section covers api.landyourhome.co.uk — Land Your Home's API for enterprise partner integrations.
Only a couple of endpoints exist so far (/v1/ping and /v1/whoami); data endpoints are being added. Routes are versioned (/v1/...).
Authentication
Every request carries two credentials:
Authorization: Bearer <API key>identifies your application. Keys look likelyh_xxxxxxxx_..., are issued to you per partner, carry scopes and a rate limit, and can be revoked. Treat them like passwords: only a hash is stored on our side.X-User-Token: <access token>identifies the Land Your Home user you are acting for. It is an OAuth 2.1 access token issued to your OAuth client, so requests run with that user's own permissions: you can only see and do what they can.
To get a user's token, send them through the OAuth 2.1 authorization code flow with PKCE:
- Redirect the user to
https://<project>.supabase.co/auth/v1/oauth/authorizewith yourclient_id, your registeredredirect_uri,response_type=code, a PKCEcode_challenge(S256) and astate. - They sign in on Land Your Home and approve your access on our consent screen.
- They are redirected back to your
redirect_uriwith acode. Exchange it athttps://<project>.supabase.co/auth/v1/oauth/token(grant_type=authorization_code, your client credentials via HTTP Basic, thecodeand yourcode_verifier) for an access token and a refresh token. Refresh withgrant_type=refresh_token.
Your client credentials and API key are provided when your partner account is set up.
Errors and limits
Errors are { "error": { "code": "...", "message": "..." } }; switch on code. 401: missing_key, invalid_key, key_revoked, key_expired, missing_user_token, invalid_user_token. 403: partner_suspended, token_not_for_partner, account_inactive, insufficient_scope. 429: rate_limited (honour Retry-After). Responses include X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset.
See "v1" in the sidebar for the full API reference - one page per endpoint, generated from the app's Bruno collection, so it's always current with every build.
Changelogs for every Land Your Home app (Marketing, PropChain, Auth, and this API) are tracked together — see the changelog.

