# Are API Keys Required for Data Layers in God's Eye View? Complete Credential Guide

> Discover which God's Eye View data layers need API keys and which are free to use. Understand credential requirements for live data access in this comprehensive guide.

- Repository: [Bilawal Sidhu/gods-eye-view](https://github.com/bilawalsidhu/gods-eye-view)
- Tags: how-to-guide
- Published: 2026-09-06

---

**Yes—several live-data layers in God's Eye View require API keys or client credentials, while free-to-use sources like OpenStreetMap and Open-Meteo work without authentication.**

God's Eye View is an open-source geospatial visualization application by **bilawalsidhu** that aggregates multiple real-time data streams—satellite imagery, traffic, flights, vessels, and fires—into a unified 3D interface. While some layers draw from public APIs, others connect to commercial or authenticated services that demand valid credentials. This guide maps which layers need keys, where to configure them, and how the system behaves when credentials are absent.

---

## Which Data Layers Require API Keys

The application isolates all credentials in environment variables, typically via a `.env` file or the Pinokio launcher's environment configuration. Below is the complete breakdown of authenticated versus open layers.

| Data Layer | Required Credential | Read Location | Fallback Behavior Without Key |
|------------|---------------------|-------------|-------------------------------|
| **Google Map Tiles / Places / Street View** | `GOOGLE_MAPS_API_KEY` (client-exposed) | [`src/main.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/main.js), [`src/mapStackController.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/mapStackController.js), [`src/voice/gevActions.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/voice/gevActions.js) | Switches to Esri World Imagery basemap; Google attribution removed |
| **Cesium Ion (Google 3D Tiles)** | `CESIUM_ION_TOKEN` (client-exposed) | [`src/main.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/main.js), [`src/mapStackController.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/mapStackController.js) | Same Esri fallback; no 3D photogrammetry |
| **TomTom Traffic Flow** | `TOMTOM_API_KEY` (server-side only) | [`vite.config.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/vite.config.js) (proxy to `/api/tomtom`) | Built-in traffic simulation; no TomTom attribution |
| **NASA FIRMS (Active Fires)** | `FIRMS_MAP_KEY` (server-side only) | [`vite.config.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/vite.config.js) (proxy `/api/firms`) | Empty layer with "KEY REQUIRED" message |
| **OpenSky Network (Flights)** | `OPENSKY_CLIENT_ID` & `OPENSKY_CLIENT_SECRET` (or `OPENSKY_AUTH_MODE=anon`) | [`src/keySetup.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/keySetup.js) | Anonymous mode: limited, rate-restricted access |
| **OpenAI Realtime Voice** | `OPENAI_API_KEY` (server-side only) | [`src/voice/voiceCost.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/voice/voiceCost.js) | Voice control disabled; UI shows unavailable |
| **AISStream (Vessel Tracking)** | `AISSTREAM_API_KEY` (server-side only) | [`src/data/aisStream.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/data/aisStream.js) (proxy) | No vessels displayed |
| **Open-Meteo, OpenStreetMap, CelesTrak, USGS** | None | N/A | Full functionality always available |

The definitive reference for all required variables appears in lines 13-96 of `.env.example` in the repository.

---

## How Credentials Are Injected

God's Eye View uses a two-tier strategy: **client-exposed keys** for browser-side APIs and **server-side proxies** for backends that must hide credentials.

### Client-Exposed Keys

Google Maps and Cesium Ion tokens must reach the browser bundle. In [`src/main.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/main.js), the build process injects these into a global:

```javascript
// src/main.js lines 81-82
window.__GOOGLE_MAPS_API_KEY__ = import.meta.env.GOOGLE_MAPS_API_KEY;
window.__CESIUM_ION_TOKEN__ = import.meta.env.CESIUM_ION_TOKEN;

```

These variables are then consumed by [`src/mapStackController.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/mapStackController.js) to initialize the Cesium viewer and tile providers.

### Server-Side Proxies

For APIs that charge by request or require secret authentication, [`vite.config.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/vite.config.js) sets up Vite dev server proxies. Lines 1784-1948 define routes like `/api/tomtom` and `/api/firms` that append the key server-side:

```javascript
// vite.config.js (simplified excerpt)
server: {
  proxy: {
    '/api/tomtom': {
      target: 'https://api.tomtom.com',
      changeOrigin: true,
      rewrite: (path) => {
        const apiKey = process.env.TOMTOM_API_KEY;
        return path.replace(/^\/api\/tomtom/, '') + `?key=${apiKey}`;
      }
    }
  }
}

```

This architecture prevents keys from appearing in browser network requests.

---

## OpenSky Authentication Modes

The flight data layer offers flexibility through [`src/keySetup.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/keySetup.js). Set `OPENSKY_AUTH_MODE=anon` to operate without credentials, or supply `OPENSKY_CLIENT_ID` and `OPENSKY_CLIENT_SECRET` for full access:

```javascript
// src/keySetup.js line 277 and surrounding logic
const authMode = import.meta.env.OPENSKY_AUTH_MODE || 'credentials';
const clientId = import.meta.env.OPENSKY_CLIENT_ID;
const clientSecret = import.meta.env.OPENSKY_CLIENT_SECRET;

if (authMode === 'anon') {
  // Rate-limited, restricted endpoint access
} else if (clientId && clientSecret) {
  // OAuth token exchange for full access
}

```

Anonymous mode suits demonstration; production deployments should register for credentials at opensky-network.org.

---

## Setting Up Your Environment File

Create a `.env` file from the provided template:

```bash

# Copy the example

cp .env.example .env

# Edit with your keys

nano .env

```

Populate all required values:

```dotenv

# .env — API keys for God's Eye View data layers

GOOGLE_MAPS_API_KEY=AIza...your_key...
CESIUM_ION_TOKEN=eyJ...your_token...
TOMTOM_API_KEY=your_tomtom_key
FIRMS_MAP_KEY=your_firms_key
OPENSKY_CLIENT_ID=your_opensky_id
OPENSKY_CLIENT_SECRET=your_opensky_secret
OPENAI_API_KEY=sk-...your_key...
AISSTREAM_API_KEY=your_aisstream_key

# Optional: force anonymous OpenSky

# OPENSKY_AUTH_MODE=anon

```

Launch the development server:

```bash
npm install
npm run dev

```

The UI displays a "Provider Settings" chip indicating which services are authenticated.

---

## Programmatic Key Detection

Layer controllers check for credential presence before attempting API calls. The attribution system in [`src/data/dataCredits.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/data/dataCredits.js) demonstrates this pattern:

```javascript
import { registerDynamicCredit } from './src/data/dataCredits.js';

// TomTom credit only appears when key is present
const TOMTOM_CREDIT = {
  text: 'Traffic flow data © TomTom',
  link: 'https://www.tomtom.com'
};

function initTrafficLayer(viewer) {
  const hasKey = Boolean(import.meta.env.TOMTOM_API_KEY);
  
  if (hasKey) {
    registerDynamicCredit(viewer, TOMTOM_CREDIT);
    loadRealTrafficTiles(viewer);
  } else {
    loadSimulatedTraffic(viewer);
  }
}

```

This conditional approach ensures graceful degradation when credentials are missing.

---

## Layer Attribution and Key Visibility

According to [`src/data/dataCredits.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/data/dataCredits.js), dynamic credits are registered only for authenticated layers. The TomTom credit (lines 88-93) exemplifies this:

```javascript
// src/data/dataCredits.js
export const TOMTOM_CREDIT = {
  id: 'tomtom-traffic',
  text: 'Traffic flow data © <a href="https://www.tomtom.com">TomTom</a>'
  // Only added to viewer credits when real API is active
};

```

When running without keys, the attribution line disappears—an immediate visual indicator of which data source is active.

---

## Summary

- **Seven data layers require API keys**: Google Maps, Cesium Ion, TomTom Traffic, NASA FIRMS, OpenSky, OpenAI, and AISStream
- **Credentials reside in `.env`** and are documented in `.env.example` lines 13-96
- **Two injection patterns**: client-exposed globals for browser APIs, server proxies for protected backends
- **Graceful fallbacks**: missing keys trigger simulations, alternative basemaps, or disabled features rather than crashes
- **Attribution reflects authentication**: credits like TomTom's only appear when real data is fetched

Configuring these keys unlocks the full real-time capabilities of God's Eye View according to the bilawalsidhu/gods-eye-view source code implementation.

---

## Frequently Asked Questions

### What happens if I run God's Eye View without any API keys?

The application launches successfully but with degraded functionality. You'll see Esri World Imagery instead of Google 3D tiles, simulated rather than real traffic, empty fire and vessel layers, and disabled voice control. Free layers—weather, street maps, satellite TLEs—operate normally.

### Where should I get API keys for the commercial data sources?

- **Google Maps & Cesium Ion**: Google Cloud Console and Cesium ion dashboard respectively
- **TomTom**: Developer portal at developer.tomtom.com
- **NASA FIRMS**: Registration at earthdata.nasa.gov for FIRMS API access
- **OpenSky**: Account creation at opensky-network.org
- **AISStream**: Free tier at aisstream.io
- **OpenAI**: Platform account at platform.openai.com

### Are API keys exposed to end users in production?

No—server-side keys in [`vite.config.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/vite.config.js) proxies never reach the browser. Only `GOOGLE_MAPS_API_KEY` and `CESIUM_ION_TOKEN` are client-exposed by design, as these services require browser-side authentication. For production deployments, implement additional origin restrictions and HTTP referer locks at the provider dashboard level.

### Can I contribute a new data layer without requiring API keys?

Yes—the architecture supports keyless sources. Follow the pattern in `src/data/` for layers like Open-Meteo: implement direct fetch to public endpoints, skip proxy configuration in [`vite.config.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/vite.config.js), and register static attribution in [`src/data/dataCredits.js`](https://github.com/bilawalsidhu/gods-eye-view/blob/main/src/data/dataCredits.js). If your source requires authentication, mirror the TomTom proxy pattern and add variables to `.env.example`.