# Hometrack > Hometrack is a UK property data, valuation and risk-decisioning company (founded 1999, part of Houseful alongside Zoopla). It runs the AVM used by 18 of the top 20 UK mortgage lenders, and sells valuation, climate/property risk, surveyor allocation and case management to lenders, surveyors, brokers, housing associations and investors. Its API contracts are public; its data is not — every call requires a key issued under a commercial agreement. Generated by API Evangelist (https://apievangelist.com) on 2026-07-26 from https://developer.hometrack.com/ and the six OpenAPI documents harvested from its Azure API Management developer portal. Hometrack publishes no llms.txt of its own (https://developer.hometrack.com/llms.txt and https://www.hometrack.com/llms.txt both return 404). ## Access reality - Developer portal is anonymous: https://developer.hometrack.com/ (also served at https://api.docs.hometrack.com/). No login wall, full API catalogue, OpenAPI export. - Data plane is closed: https://api.hometrack.com/ returns HTTP 401 {"statusCode": 401, "message": "Unauthorized. Access token is missing or invalid."} to any anonymous caller. - Exactly one operation answers anonymously: GET https://api.hometrack.com/valuation-api/v1/status (HTTP 200, zero-byte body). - Getting a key: "To interact with any of our APIs you will need to have a valid API Key for that respective product. If you do not yet have an API Key, please contact us." — https://www.hometrack.com/uk/#contactus. No self-serve signup, no trial, no sandbox, no published pricing. - Auth: OAuth 2.0 client credentials via Auth0. POST https://hometrack-prod.eu.auth0.com/oauth/token with client_id, client_secret, audience=https://api.hometrack.com, grant_type=client_credentials. Bearer token, expires_in 86400 (24h). Documented scopes: read:valuations, write:valuations. ## APIs - [Hometrack Valuation API](https://developer.hometrack.com/apis): real-time AVM. 3 operations. Base https://api.hometrack.com/valuation-api/v1 - [Hometrack Broker AVM API](https://developer.hometrack.com/apis): broker valuation orders, with a v2 variant that adds climate data. 12 operations. Base https://api.hometrack.com/valuation/v2 - [Hometrack PRH Core External Client API v2.0](https://developer.hometrack.com/apis): Property Risk Hub — instructions, cases, case documents, valuation reports, data-provider statuses, property repository search. 19 operations, 257 schemas. Base https://api.hometrack.com/prh - [Hometrack Climate API (v2)](https://developer.hometrack.com/apis): EPC, flood, ground, subsidence and coastal-erosion risk per property, keyed on UPRN. 5 operations. Base https://api.hometrack.com/climate - [Hometrack Climate GraphQL API](https://developer.hometrack.com/apis): registered GraphQL surface over the same climate backend; schema auth-gated (introspection returns 401). Base https://api.hometrack.com/climate/graphql - [Hometrack API Public](https://developer.hometrack.com/apis): account, licensing, branding, partner and Property Valuation Report plumbing, plus the embedded PVR plugin. 20 operations. Base https://api.hometrack.com ## Specs - openapi/hometrack-valuation-api-v1-openapi.yml — OpenAPI 3.0.1 - openapi/hometrack-broker-avm-api-openapi.yml — OpenAPI 3.0.1 - openapi/hometrack-prh-core-external-client-api-v2-openapi.yml — OpenAPI 3.0.1 - openapi/hometrack-climate-api-v2-openapi.yml — OpenAPI 3.0.1 - openapi/hometrack-climate-graphql-api-openapi.yml — OpenAPI 3.0.1 (stub: servers + security schemes, no paths) - openapi/hometrack-api-public-openapi.yml — OpenAPI 3.0.1 ## Artifacts - authentication/hometrack-authentication.yml — the three credential layers (OAuth2/Auth0, APIM subscription keys, legacy exchange tokens) - scopes/hometrack-scopes.yml — read:valuations, write:valuations (the only scopes Hometrack publishes) - well-known/hometrack-well-known.yml — no security.txt anywhere; Auth0 OIDC + RFC 8414 + JWKS captured - conventions/hometrack-conventions.yml — pagination (PRH only), correlation headers (Climate only), error envelopes, 202-and-poll, NO idempotency, NO webhooks - errors/hometrack-problem-types.yml — full status catalogue including 402 licence exhausted and 499 confidence-threshold failure - lifecycle/hometrack-lifecycle.yml — published three-version support window with two deprecation warning stages - changelog/hometrack-changelog.yml — the portal changelog page exists and is empty (0 releases across all 6 APIs) - conformance/hometrack-conformance.yml — OAuth2/OIDC/OpenAPI yes, ISO 27001 certified, RESO/OData no (no MLS in the UK) - data-model/hometrack-data-model.yml — four disjoint identifier domains with no published join key - components/hometrack-components.yml — the PVR plugin, an embeddable widget authorised by host domain - sandbox/hometrack-sandbox.yml — a try-it console against production; no sandbox, no test data - mcp/hometrack-mcp.yml + mcp/hometrack-tool-crosswalk.yml — candidate agent tool surface derived from the specs (Hometrack publishes no MCP server) - agentic-access/hometrack-agentic-access.yml — recommended x-agentic-access contracts for all 59 operations - skills/ — packaged agent skills for the marquee flows - security/hometrack-domain-security.yml — TLS 1.3 + HSTS on all hosts, SPF + DMARC (quarantine), no DNSSEC, no CAA ## Docs - [Developer portal](https://developer.hometrack.com/) - [API list and console](https://developer.hometrack.com/apis) - [API authentication](https://developer.hometrack.com/api-authentication) - [API changelog](https://developer.hometrack.com/api-changelog) - [ISO 27001 certification](https://www.hometrack.com/iso-27001/) - [Company website](https://www.hometrack.com/) - [UK House Price Index newsroom](https://www.hometrack.com/newsroom/uk-house-price-index/) ## Notes for agents - Nothing here is callable without a Hometrack commercial agreement. Do not attempt to obtain a key programmatically; the path is a sales contact form. - There is NO idempotency contract. POST /broker/order, POST /broker/v2/order and POST /organisation/{orgId}/instruction create billable, real-world work (a valuation, a surveyor instruction). Retrying them is not safe. Use the client-supplied order.orderReference / InstructionReference as a business key and check before re-sending. - Long-running work is 202-then-poll. There are no webhooks or events anywhere in Hometrack's surface. - The Climate API is UPRN-only. A postcode will not address it; resolve the UPRN first. - A Climate 404 usually means no data exists for that UPRN, not a bad request.