API Developer Guide

QNA-Locator is a REST API. Every request must include your API key as a Bearer token. Free accounts get 500 requests per calendar month. Pro Monthly gets 5,000 requests in its 30 days; Pro Annual gets 10,000 requests in each month of its 365 days.

Authentication

Pass your API key in the Authorization header as a Bearer token on every request.

Authorization: Bearer qna_live_xxxxxxxxxxxxxxxxxxxxxxxx

Endpoints

GET/api/v1/locate?zone=&street=&building=

Returns the coordinates for a specific zone/street/building number.

curl "https://qna.louis-innovations.com/api/v1/locate?zone=55&street=950&building=234" \
  -H "Authorization: Bearer qna_live_..."

{
  "zone": "55",
  "street": "950",
  "building": "234",
  "latitude": "25.25244752",
  "longitude": "51.41655439",
  "googleMapsUrl": "https://www.google.com/maps/search/?api=1&query=25.25244752,51.41655439",
  "wazeUrl": "https://waze.com/ul?q=25.25244752,51.41655439"
}
GET/api/v1/zones

Returns every zone number in the database.

curl "https://qna.louis-innovations.com/api/v1/zones" \
  -H "Authorization: Bearer qna_live_..."

{ "zones": [{ "zoneNumber": "1" }, { "zoneNumber": "2" }, ...] }
GET/api/v1/streets?zone=

Returns every street number within a zone.

curl "https://qna.louis-innovations.com/api/v1/streets?zone=55" \
  -H "Authorization: Bearer qna_live_..."

{ "zone": "55", "streets": [{ "streetNumber": "1" }, ...] }
GET/api/v1/buildings?zone=&street=

Returns every building number (with coordinates) on a street.

curl "https://qna.louis-innovations.com/api/v1/buildings?zone=55&street=950" \
  -H "Authorization: Bearer qna_live_..."

{ "zone": "55", "street": "950", "buildings": [{ "buildingNumber": "8" }, { "buildingNumber": "10" }] }

Errors

Rate limits

The Free allowance resets on the first day of each month at 00:00 UTC (03:00 Qatar time); a Pro plan month starts at the date and time of payment and renews every month after it, until the paid period ends. The resetsAt field of a 429 answer gives the exact time. Limits are counted per account, so replacing your key does not reset them. A 429 response includes your tier and limit, for example:

{ "error": "Free monthly limit reached. Upgrade to Pro in your dashboard, or wait for the 1st of next month.", "limit": 500, "period": "month", "resetsAt": "2026-11-01T00:00:00.000Z" }

Refused requests are not counted and nothing is charged automatically. Under heavy load requests are queued briefly; if the queue is full you receive 503 with a Retry-After header, and that request is not counted.

Calling from a browser

Call the API from your server whenever you can and keep the key there. If you must call it from a web page, register each website domain (up to 10, for example shop.example.qa) under Allowed websites in your dashboard. Registering example.qa also covers www.example.qa; a subdomain such as shop.example.qa is registered on its own. Browsers send an Origin header; the API answers with CORS headers only for registered domains and refuses other origins with 403. Every call is logged with its time, endpoint, result, IP address, origin and user agent, and you can review your own requests and usage statistics in your dashboard. To protect the address data, each account may make up to 120 calls a minute and locate up to 20,000 different addresses a month (looking up the same address again does not count towards this). The buildings endpoint lists building numbers only; coordinates come from /locate one address at a time. The list controls which websites a browser may call from; it does not protect a key that has leaked. If your key is exposed, create a new one in your dashboard (your usage is counted per account, so this does not reset your limit).