Access-Control-Allow-Origin: *) — call them straight from the browser. Basic use is free with a link back to the source (map.megainet.art).Endpoints
| Endpoint | Returns |
|---|---|
GET /api/alerts.php | Alert state per oblast + district-level alerts |
GET /api/threats.php | Active threats (drones, missiles, KABs) with coordinates and heading |
GET /api/feed.php | Monitor message feed + carriers (MiG-31K etc.) |
GET /api/stats.php | 24-hour statistics by type + hourly histogram |
GET /api/history.php | Alert history: daily aggregate (?hours=24) or one oblast’s transitions (?region=UA-XX) |
GET /api/analytics.php | Aggregated analytics for 24/48/168 h: rhythm, types, oblast heat map, directions, monitors |
GET /api/keyinfo.php | Tier, limit and usage of YOUR key (key required; CORS closed) |
GET /api/fires.php | NASA FIRMS thermal points, last 24h (Ukraine bbox) |
GET /api/occupied.php | Front line and gray zone (GeoJSON) |
Example
curl -s https://map.megainet.art/api/alerts.phpResponse (truncated)
{
"source": "siren/districts",
"updated": "2026-07-23 20:15:02",
"regions": {
"UA-63": { "alert": true, "changed_ts": 1784500000 },
"UA-12": { "alert": false, "partial": [ { "name": "Нікопольський район", "ts": 1784499000 } ] }
},
"local": [ { "name": "Нікопольський район", "oblast": "Дніпропетровська область", "lat": 47.57, "lon": 34.4 } ]
}Limits & pricing
Without a key it is 60 requests per minute per IP address, with a free key 120. Need more, or no attribution? See pricing.
Event subscriptions (webhooks)
Instead of polling /api/alerts.php every 15 seconds — 5,760 requests a day for a dozen events — you can receive the event the moment it happens. We send a POST to your https:// address with the body {event, region, alert, ts, source}; the event is alert.start or alert.end, and you can narrow it to selected oblasts. Every delivery is signed: the X-Map-Signature header is HMAC-SHA256 over «X-Map-Timestamp \n body» with your secret — recompute it on your side and compare, and a forged call becomes impossible. No 2xx answer — we retry after 1, 5, 30 minutes, 2 and 6 hours; a subscription that fails twenty times in a row is switched off, and the reason is visible in the cabinet. Management: GET/POST/DELETE /api/hooks.php with your key. The feature is paid (Pro, Business); the free tier does not get worse because of it.
Authentication & keys
Basic endpoints work without a key — the limit is then counted per IP. A Free-tier key (120 req/min) is issued in one click on the key page, no sign-up. Send it as the ?key=ak_… parameter or the X-API-Key header. Every response carries X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Tier; over the limit the API returns 429 with Retry-After.
Endpoints
All GET, JSON responses, CORS open. A key is optional: without one the limit is 60 requests per minute per address.
/api/alerts.phpGETAlert state for every oblast plus local alerts.
/api/threats.phpGETTargets from the last 45 minutes: type, coordinates, heading, target.
/api/feed.phpGETMonitor message feed and the carrier bar.
/api/stats.phpGETDaily totals: by target type and by hour.
/api/history.phpGETAlert history: daily aggregate or one oblast’s transitions.
/api/analytics.phpGETAggregated analytics: rhythm, types, heat map, directions.
/api/occupied.phpGETFront line and gray zone (GeoJSON, DeepStateMap).
/api/fires.phpGETNASA FIRMS thermal points over the last day.