Skip to content

Loading…

Quickstart

Create an API key and make your first authenticated request to the Vestta API.

On this page

This guide takes you from no credentials to a working API call. You need a Vestta workspace on the Premium or Enterprise plan and a user with permission to manage API keys.

Create an API key

In Vestta, open Settings → API and select Nueva API Key. The Vestta app is in Spanish; the fields are:

  • Nombre — where the key will be used, for example Website.
  • Duración — how long the key stays valid: 1, 3, 6 or 12 months.
  • Permisos — the scopes. For this guide, select Propiedades (properties:read).

Save the key securely

The full key is shown only once, right after you create it. It has this format:

Text
AC_LIVE_<key_id>.<secret>

Store it in a secret manager or an environment variable on your server. Never put it in front-end code or commit it to a repository. For this guide, export it in your terminal:

Terminal
export VESTTA_API_KEY="AC_LIVE_..."

Make your first request

Call Retrieve key context. It works with any active key and returns the business and scopes behind it, which makes it the safest first call:

curl "https://api.vestta.app/v1/ext/me" \
  -H "X-Api-Key: $VESTTA_API_KEY"

Inspect the response

A 200 response confirms the key works. Check that scopes contains everything your integration needs:

200 response
{
  "status": "ok",
  "user": {
    "company_name": "Inmobiliaria Ejemplo",
    "scopes": [
      "properties:read",
      "leads:read"
    ],
    "auth_method": "api_key"
  }
}

If you get a 401 instead, the body tells you why — a missing header, a typo in the key, or a revoked or expired key. See Errors.

Continue with Properties or Leads

With properties:read granted, list the first page of your public catalogue:

curl "https://api.vestta.app/v1/ext/properties?limit=20" \
  -H "X-Api-Key: $VESTTA_API_KEY"

From here, go deeper into the resource you need:

  • Properties — filters, prices, map areas and the property object.
  • Leads — read leads, or send them from your forms with the leads:ingest scope.

Next steps

  • Authentication — both supported headers and what each scope unlocks.
  • API keys — expiry, revocation and rotating a key without downtime.
  • Pagination — walk through every page of a list.