Hometrack · Authentication Profile

Hometrack Authentication

Authentication

Hometrack secures its APIs with oauth2, apiKey, and http across 5 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).

Real EstateUnited KingdomPropTechValuationAVMMortgageProperty DataClimate RiskLendingSurveying
Methods: oauth2, apiKey, http Schemes: 5 OAuth flows: clientCredentials API key in: header, query, path

Security Schemes

OAuth2ClientCredentials oauth2
apiKeyHeader apiKey
· in: header (Ocp-Apim-Subscription-Key)
apiKeyQuery apiKey
· in: query (subscription-key)
ValuationApiToken http
scheme: Token · in: header (Authorization)
PublicApiPathToken apiKey
· in: path (token)

Source

Authentication Profile

Raw ↑
generated: '2026-07-26'
method: searched
docs: https://developer.hometrack.com/api-authentication
source: >-
  https://developer.hometrack.com/api-authentication (OAuth 2.0 client
  credentials via Auth0) + the Auth0 tenant discovery documents in well-known/ +
  the security schemes declared across all six OpenAPI documents in openapi/ +
  live anonymous probes of api.hometrack.com.
summary:
  types: [oauth2, apiKey, http]
  api_key_in: [header, query, path]
  oauth2_flows: [clientCredentials]
  gate: >-
    Three distinct credential mechanisms sit in front of Hometrack's APIs and
    they are not alternatives — they are layers from different eras of the
    platform. (1) OAuth 2.0 client credentials against Hometrack's Auth0 tenant
    is the documented, current way to authenticate; the bearer token is
    presented to api.hometrack.com. (2) Every harvested OpenAPI additionally
    declares Azure API Management subscription-key schemes
    (Ocp-Apim-Subscription-Key header / subscription-key query), which is the
    gateway product key. (3) Two older APIs carry their own bespoke token
    exchange in the contract itself: the Valuation API exchanges an API key for
    a five-minute token used as `Authorization: Token token="<guid>"`, and the
    Hometrack API Public exchanges an API key for a plain-text GUID passed as a
    {token} path segment on nearly every operation. No credential of any kind is
    self-service — the portal directs you to a sales contact form.
oauth2:
  documented: true
  docs: https://developer.hometrack.com/api-authentication
  provider: Auth0
  tenant: https://hometrack-prod.eu.auth0.com/
  issuer: https://hometrack-prod.eu.auth0.com/
  token_endpoint: https://hometrack-prod.eu.auth0.com/oauth/token
  jwks_uri: https://hometrack-prod.eu.auth0.com/.well-known/jwks.json
  grant_type: client_credentials
  audience: https://api.hometrack.com
  request_body_fields: [client_id, client_secret, audience, grant_type]
  token_type: Bearer
  expires_in: 86400
  token_lifetime_note: '"The access token is valid for 24 hours."'
  example_scope: read:valuations write:valuations
  usage: 'Authorization: Bearer <access_token>'
  discovery:
    openid_configuration: well-known/hometrack-auth0-openid-configuration.json
    oauth_authorization_server: well-known/hometrack-auth0-oauth-authorization-server.json
    jwks: well-known/hometrack-auth0-jwks.json
  token_endpoint_auth_methods_supported: [client_secret_basic, client_secret_post, private_key_jwt, none]
  id_token_signing_alg_values_supported: [HS256, RS256, PS256]
  dpop_signing_alg_values_supported: [ES256]
  note: >-
    grant_types_supported on the tenant lists many Auth0 grants; only
    client_credentials is documented for API access, because the audience
    https://api.hometrack.com is a machine-to-machine API, not an end-user login.
schemes:
- name: OAuth2ClientCredentials
  type: oauth2
  flow: clientCredentials
  tokenUrl: https://hometrack-prod.eu.auth0.com/oauth/token
  audience: https://api.hometrack.com
  scopes: [read:valuations, write:valuations]
  sources: [https://developer.hometrack.com/api-authentication]
  note: >-
    Documented on the portal but NOT declared in any harvested OpenAPI — the
    APIM export emits only the gateway subscription-key schemes. This is a
    genuine spec/doc divergence worth reporting to Hometrack.
- name: apiKeyHeader
  type: apiKey
  in: header
  parameter: Ocp-Apim-Subscription-Key
  layer: azure-api-management
  sources:
  - openapi/hometrack-api-public-openapi.yml
  - openapi/hometrack-broker-avm-api-openapi.yml
  - openapi/hometrack-climate-api-v2-openapi.yml
  - openapi/hometrack-climate-graphql-api-openapi.yml
  - openapi/hometrack-prh-core-external-client-api-v2-openapi.yml
  - openapi/hometrack-valuation-api-v1-openapi.yml
- name: apiKeyQuery
  type: apiKey
  in: query
  parameter: subscription-key
  layer: azure-api-management
  sources:
  - openapi/hometrack-api-public-openapi.yml
  - openapi/hometrack-broker-avm-api-openapi.yml
  - openapi/hometrack-climate-api-v2-openapi.yml
  - openapi/hometrack-climate-graphql-api-openapi.yml
  - openapi/hometrack-prh-core-external-client-api-v2-openapi.yml
  - openapi/hometrack-valuation-api-v1-openapi.yml
- name: ValuationApiToken
  type: http
  scheme: Token
  in: header
  parameter: Authorization
  format: 'Token token="<guid>"'
  ttl_seconds: 300
  exchange_operation: openapi/hometrack-valuation-api-v1-openapi.yml#authentication
  sources: [openapi/hometrack-valuation-api-v1-openapi.yml]
  note: >-
    POST /authentication/{apiKey} returns a temporary token "valid for 5
    minutes". The spec documents that the header is also accepted without the
    quotes and without the `token=` prefix.
- name: PublicApiPathToken
  type: apiKey
  in: path
  parameter: token
  exchange_operation: openapi/hometrack-api-public-openapi.yml#AuthenticationApi_Post
  sources: [openapi/hometrack-api-public-openapi.yml]
  note: >-
    POST /api/authentication/{apiKey} returns a plain-text GUID token that is
    then passed as a URL path segment on the reporting, brands, licences,
    partners, pvrplugin and trial operations. Credentials in the path are
    logged by intermediaries — recorded as an observed design weakness, not a
    recommendation.
probes:
- {url: 'https://api.hometrack.com/valuation/v2/broker/order/1', anonymous: true, status: 401, body: '{"statusCode": 401, "message": "Unauthorized. Access token is missing or invalid."}'}
- {url: 'https://api.hometrack.com/climate/graphql', anonymous: true, method: POST, status: 401, body: '{"statusCode": 401, "message": "Unauthorized. Access token is missing or invalid."}'}
- {url: 'https://api.hometrack.com/valuation-api/v1/status', anonymous: true, status: 200, body: '(zero bytes)'}
onboarding:
  self_service: false
  path: https://www.hometrack.com/uk/#contactus
  verbatim: >-
    "To interact with any of our APIs you will need to have a valid API Key for
    that respective product. If you do not yet have an API Key, please contact
    us."
cross_links:
  scopes: scopes/hometrack-scopes.yml
  well_known: well-known/hometrack-well-known.yml
  conventions: conventions/hometrack-conventions.yml
  conformance: conformance/hometrack-conformance.yml