DEVELOPING

Connect with the credential you already have

If your application publishes properties on portals through PropertyAPI, each of your clients needs to have their own account on the portal connected. These endpoints manage those connections.

MethodPathWhat it does
POST/connectionsRegisters a client's connection with a portal
GET/connectionsLists a client's connections
GET/connections/{portal}Returns one connection
DELETE/connections/{portal}Disconnects the connection

These endpoints are under development. Write to us at dev@mapaprop.com if your integration requires them.

Before you start

You are the one who obtains the portal account token. These endpoints do not log in against the portal: they store the credential your client already authorized you to use. Each portal has its own connection mechanism.

You need one scope per portal. Scopes are granted when you register your application; write to us stating which portals you are going to work with.

portal values

PortalValueRequired scope
ArgenpropArgenpropApiargenpropapi:connect
CabapropCabapropApicabapropapi:connect
MercadoLibreMercadolibreApimercadolibreapi:connect

It is case-insensitive: ArgenpropApi, argenpropapi and ARGENPROPAPI are the same portal and the same connection. Responses always return the value in lowercase (argenpropapi), so do not be surprised if it comes back different from the way you sent it.

The Api suffix matters: some portals also have an XML feed, and these endpoints are only for the API integration.

Zonaprop does not connect here. These endpoints store a credential you already have, and Zonaprop does not issue one: the agency authorizes in the portal and the authorization stays on their side.

To connect Zonaprop, request a link and send it to your client: Connect with a link. If you try it here, you get 409.

Identifying your client: clientRef

clientRef is the identifier that you choose for each of your end clients. It is opaque to us: it can be your internal id, a UUID or whatever you use. You send it in the x-client-ref header (or in the query, or in the body of the POST).

Your connections live in a space of their own: no other application can read them or touch them, and you cannot reach another application's either. That is determined by your token, not by what you send in the request.

One portal account = one owner

The same portal account cannot be connected by two applications at the same time. If you try to register an account that is already connected by another one, you get a 409. This is what makes it possible to route the inquiries coming from the portal without ambiguity.

POST /connections

Registers the connection. If you call it again for the same client and portal, it updates the existing connection (this is how you rotate the token).

FieldTypeRequiredDescription
portalstringyesSee portal values
portalAccountIdstring or numberyesId of the account on the portal. Case-sensitive
accountTokenstringyesCredential of the account. Maximum 4096 bytes
clientRefstringyes*Your client id. *Can be sent in a header
tokenExpiresAtnumber or nullnoExpiration in epoch, if the portal reports it
scopesGrantedarray of stringnoPermissions your client granted you. Up to 32
appMetaobjectnoData of your own. Maximum 8192 bytes serialized
curl -X POST https://property-api.mapaprop.com/connections \
  -H "Authorization: Bearer <TU_TOKEN>" \
  -H "Content-Type: application/json" \
  -d '{
    "portal": "ArgenpropApi",
    "portalAccountId": "310578",
    "accountToken": "<credencial de la cuenta>",
    "clientRef": "cliente-42"
  }'

201 response:

{
  "connection": {
    "portal": "argenpropapi",
    "portalAccountId": "310578",
    "status": "active",
    "scopesGranted": [],
    "createdAt": "2026-09-04T13:40:00.000Z",
    "lastActivityAt": "2026-09-04T13:40:00.000Z",
    "tokenExpiresAt": null,
    "appMeta": {}
  }
}

The accountToken never comes back out. It is stored encrypted and no endpoint returns it, not even encrypted. Store it yourself if you need it for anything else.

After connecting

To check the status or disconnect, see Check and disconnect — it works both for accounts connected this way and for those connected with a link.

Errors

CodeerrorWhat happened
400portal is required / portal must be a non-empty stringThe portal is missing or is not text
400Invalid JSON bodyThe body is not valid JSON
400clientRef is required (header x-client-ref, query or body)The client is not identified
400(several, with field)A field does not meet the format or exceeds a maximum
401UnauthorizedThe token is missing or is not valid
403Missing required scope: argenpropapi:connectYour application does not have the scope for that portal
404Connection not foundThat client has no connection with that portal
409portal account already connectedThat portal account is already connected by another application
503Connection storage is temporarily unavailable (encryption backend)A temporary problem on our side. Retry

A 403 tells you exactly which scope is missing, and that text includes the portal just as you sent it. If you see Missing required scope: argenprop:connect instead of argenpropapi:connect, the problem is the portal value, not your permissions.