Zoopla · Authentication Profile
Zoopla Authentication
Authentication
Zoopla secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).
Real-EstateUnited KingdomProperty ListingsProperty PortalPropTechRentalsEstate AgentsLeadsCRM Integration
Methods: oauth2
Schemes: 1
OAuth flows: clientCredentials
API key in:
Security Schemes
OAuth2 oauth2
· flows: clientCredentials
Source
Authentication Profile
generated: '2026-07-26'
method: searched
docs: https://developers.zoopla.co.uk/pages/authentication
source: openapi/zoopla-leads-api-openapi.json, openapi/zoopla-premium-listing-activations-openapi.json,
openapi/zoopla-weekly-featured-property-activations-openapi.json, https://developers.zoopla.co.uk/pages/authentication,
https://developers.zoopla.co.uk/leads/docs/push-service
summary:
types:
- oauth2
oauth2_flows:
- clientCredentials
self_serve: false
identity_provider: Amazon Cognito (eu-west-1)
api_request_header: 'Authorization: Bearer {access_token}'
schemes:
- name: OAuth2
type: oauth2
flows:
- flow: clientCredentials
tokenUrl: https://services-auth.services.zoopla.co.uk/oauth2/token
scopes: 2
sources:
- openapi/zoopla-leads-api-openapi.json
- openapi/zoopla-premium-listing-activations-openapi.json
- openapi/zoopla-weekly-featured-property-activations-openapi.json
token_request:
method: POST
url: https://services-auth.services.zoopla.co.uk/oauth2/token
client_authentication: >-
HTTP Basic — Authorization: Basic base64(client_id:client_secret). The Leads
documentation also shows the credentials form-encoded in the body with an
`audience` parameter set to the integration URL (https://services.zoopla.co.uk),
and notes the fields are form-encoded rather than sent as a JSON body.
content_type: application/x-www-form-urlencoded
grant_type: client_credentials
scope_parameter: scope=api/api_access (activation APIs)
response:
token_type: Bearer
expires_in: 3600
issuer: https://cognito-idp.eu-west-1.amazonaws.com/eu-west-1_g0qeZRnbT
issuer_evidence: >-
The sample access token published on the authentication page decodes to an
`iss` claim naming that Cognito user pool, which places the auth tier in AWS
eu-west-1.
credential_issuance:
self_serve: false
process: >-
Generate a 4096-bit RSA GPG key pair, export the public key and give it to
your Zoopla technical contact. Zoopla returns a plaintext client_id and a
PGP-encrypted client_secret which you decrypt with your private key.
prerequisite: >-
You must already be a Zoopla customer subscribed to a listings package with
the relevant features.
contact: members@zoopla.co.uk
revocation: >-
Contact your technical contact immediately to revoke a compromised
client_id/client_secret pair and be issued a new one.
errors:
invalid_or_expired_token:
- 401
- 403
token_handling:
caching: >-
Cache the access token for its full expires_in window. The Leads docs name
per-request token minting as the cause of HTTP 429 "service busy" responses.
inbound_authentication:
context: Lead Push Service — Zoopla is the client, the member is the server.
methods:
- method: oauth2
grant: client_credentials
note: >-
The member supplies client_id, client_secret, a token endpoint and
(configuration dependent) an audience. Zoopla mints a token and sends
'Authorization: Bearer {access_token}'.
- method: api_key
note: >-
The member supplies a key; Zoopla sends it verbatim as the Authorization
header value with no scheme prefix.
signature_verification: none
docs: https://developers.zoopla.co.uk/leads/docs/push-service
discovery:
openid_configuration: 404
oauth_authorization_server: 404
note: >-
Neither the API host nor the Cognito-fronted token host serves OIDC discovery
or RFC 8414 authorization-server metadata; the OAuth setup is documented in
prose only.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/zoopla-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.