Authentication
API key
Every request carries your API key in the api-key query parameter. It is the only place the key is read
from: an api-key header, Basic auth or a bearer token is not accepted. DAWA ignored parameters it did not
know, so adding api-key to a DAWA URL changes nothing else.
GET https://api.getaddress.dk/adresser?postnr=2300&vejnavn=Amagerbrogade&husnr=217A&api-key={your-api-key}
- From your server only. A request that carries an API key and comes from a web page (it has an
Originheader) is refused with401, so a key pasted into page source stops working rather than being quietly used by others. In the browser, use a domain token. - Your subscription also has an admin key. It reads usage and renames the subscription, and nothing else: address requests made with it are refused with
403. - A missing or unknown key answers
401. See Errors.
Domain tokens
Code in your visitors' browsers uses a domain token in place of your API key. You make one in the
console for your site's domain; it works on that domain and its sub-domains. It starts dtoken_.
A domain token works on every address endpoint — the autocompletes, /adresser,
/adgangsadresser, /vejnavne and /postnumre. It cannot read your usage or
rename your subscription. A revoked domain token stops working within a minute.
Each token is throttled per visitor IP address: 60 requests per minute by default, and the limit
can be set per token (1–10,000 over a window of 1–60 minutes). Requests over the limit get
429 with a Retry-After header. There is a second ceiling on the token's total traffic across
all visitors, so a token used somewhere other than your site is throttled even when every request comes from a
different address.
Look-ups made with a domain token count against your plan's allowance exactly as look-ups made with your API key do.
What a domain token is, and what it isn't. It keeps your API key out of your page source, and it makes a token copied out of your page close to worthless: it works only on your domain and only at the rate you set. It is not a secret — you publish it in your page — and the domain check reads request headers, which a determined caller can set to anything. The throttle is the protection; set it no higher than your address form needs.
A domain token in the path
Some browser code builds its own query strings and has nowhere to put api-key — DAWA's
dawa-autocomplete2 widget takes only a base URL. For these, the domain token can go in the path instead:
https://api.getaddress.dk/t/{your-domain-token}/autocomplete?q=Amagerbrogade
/t/{domain-token} in front of any address path works as if the token had been sent as api-key.
Only a domain token (dtoken_…) is read there, never an API key, and an api-key in the query
string wins over it. So the widget is pointed at us with one option:
dawaAutocomplete.dawaAutocomplete(document.getElementById('adresse'), {
baseUrl: 'https://api.getaddress.dk/t/{your-domain-token}',
select: function (selected) {
console.log(selected.tekst);
}
});
The widget asks once per keystroke, and an autocomplete answer that suggests addresses costs one look-up. Street-name suggestions stay free. See Autocomplete.