Authentication
The public layer of JMAD has no authentication. No API key, no OAuth flow, no login. You will never see a 401 from /japan/api/v1 or from the MCP server at /japan/mcp.
curl https://dnk.co/japan/api/v1/assets/DNK-JP-13-01000000That request works from a fresh terminal with nothing configured. So does the same request from an agent, a script, or a browser.
What identifies a client
Nothing that identifies you personally. JMAD applies per-client rate limits (see rate limits and errors), and the only thing behind that limit is a hashed IP address: the first hop of X-Forwarded-For, or the connecting address if that header is absent, run through SHA-256 and truncated. The raw IP is never stored. There is no account, session, or client ID tied to your requests.
NoteIf you are calling the API from a shared NAT or a corporate proxy, you share a rate-limit bucket with everyone else behind that address. That is the only practical consequence of having no auth: no one gets a private allowance.
Why no auth for the public layer
The public layer covers OpenStreetMap-derived footprints, names, and structural fields. It is meant to be as easy to query as a public API can be. Adding a key would put a gate in front of data that carries no cost to license. Requiring registration also breaks the workflow this data is built for: an agent that discovers dnk.co through a search result or a markdown twin should be able to call the API in the same turn, with no signup step in between.
Planned enriched layers
DNK's enriched and proprietary layers, described in the introduction, are planned to add fields from commercially licensed sources, and access to them is expected to require a key. Nothing here is implemented yet, and how that access is granted has not been decided. When it ships, this page will describe the mechanism. Until then, every documented endpoint and MCP tool is open.
What does not change
Even with the enriched layers planned, the free layer's authentication story does not: OpenStreetMap-derived fields, provenance, and the ID scheme stay keyless, matching the licensing commitment in licensing and attribution.
Next
- Rate limits and errors for what actually gates a client without a key.
- Quickstart to make your first request.
Updated 1 day ago
