Received activity.
Ready for your application.
Request the layers you need, receive approval, then create a key in your ordinary Layer400 account.
Quick start
Use HTTPS and a server-side Bearer key. Never put a key in the URL, a browser application or a public repository.
curl --get 'https://layer400.com/business/api/v1/live/adsb' \ --header "Authorization: Bearer $LAYER400_API_KEY" \ --user-agent 'YourOrganisation-YourIntegration/1.0' \ --data-urlencode 'bbox=-5,49,2,56' \ --data-urlencode 'limit=250'
Endpoints & permissions
All data endpoints use GET. The base URL is https://layer400.com/business/api/v1.
| Endpoint | Required permission |
|---|---|
/live/rid | rid.live |
/live/adsb | adsb.live |
/history/rid | rid.history |
/history/adsb | adsb.history |
Each layer is approved independently. A website subscription, contributor status or a history grant does not automatically unlock any other API layer.
Live queries
bbox is required: west,south,east,north, in WGS84 decimal degrees. Each side may span at most 30°. Split queries crossing the antimeridian.
limit: 1–1000, default 250. When next_cursor is non-null, repeat the same query with cursor set to that value. Start the next refresh without a cursor. Records are ordered by public track reference.
Live results change as reports arrive or expire; paged responses are not an immutable snapshot. De-duplicate public track references within a refresh. Receiver coverage determines what is available—not a hidden 100-aircraft cap.
History queries
GET /business/api/v1/history/rid ?bbox=-2.3,50.7,-2.0,50.9 &start=2026-09-27T09:00:00Z &end=2026-09-27T09:10:00Z &limit=1000
start and end are required RFC3339 timestamps. Windows are half-open: start is included, end is excluded. Each query covers at most one hour, with bounds no larger than 5° per side. Your administrator-approved lookback is between 1 and 30 days.
Always inspect truncated. If true, do not treat the returned points as the complete recording. Split the time window, query each half and repeat as needed; subdivide the area if one timestamp is still too dense. History does not use the live cursor. The flag also detects an overfull source window before filtering the requested layer.
A query only returns retained received positions. Empty results do not prove that no aircraft or drone was present. Missing reception is not filled with invented positions.
Response contract
{
"version": "1",
"request_id": "…",
"generated_at": "2026-09-27T12:00:00Z",
"layer": "rid",
"mode": "live",
"data": [],
"next_cursor": null,
"truncated": false
}Each record includes public_track_id, observed_at, longitude/latitude, altitude_m, height_agl_m, speed_mps, heading_deg, confidence, receiver count, track kind, simulated, test_broadcast and emergency_state. Live records also include stale_after.
Altitude is reported/normalised altitude in metres; AGL is estimated height above ground where available. These are not interchangeable. Unknown values are null or explicitly labelled unknown; do not treat them as zero. Heading is degrees clockwise from north, speed is metres/second and times are RFC3339.
Public track references rotate. They are not permanent aircraft serial numbers. Version 1 excludes raw ICAO/Remote ID identifiers, pilot/controller locations, private receiver coordinates and private owner information. TEST and simulated records remain clearly flagged—filter them explicitly if your application should exclude them.
Limits, keys & errors
Your portal shows account-level limits shared by every key. Successful authorisation consumes one request, including empty results and later query failures. Invalid credentials and denied scopes do not consume that account’s quota. Minute counters reset at the next minute; daily counters reset at midnight UTC.
X-RateLimit-Remaining and X-DailyLimit-Remaining describe remaining allowance. Follow Retry-After and use exponential backoff with jitter on 429 or 503. Avoid synchronising all integrations to the same second.
| 400 | Invalid bounds, window, cursor or parameters. |
|---|---|
| 401 | Missing, invalid, expired or revoked key. |
| 403 | Unapproved layer, inactive grant or history outside the approved lookback. |
| 429 | Account or edge request limit reached. |
| 503 | Service busy, dependency unavailable or query timed out. |
Errors include a request reference where the API handled the request. Never send your key when contacting support. Keys expire no later than their grant and at most 365 days after creation. Rotate by creating a replacement, updating your integration, then revoking the old key.
Use & availability
Access is reviewed for your declared use case. Commercial terms, redistribution and any service commitments must be agreed separately. This API is not a certified collision-avoidance or emergency service and does not guarantee complete detection or uninterrupted coverage.
Additional JSON fields may be introduced without changing v1. Breaking changes require a new API version. Contact Layer400 for integration support.