Are API Keys Required for Data Layers in God's Eye View? Complete Credential Guide

Yes—several live-data layers in God's Eye View require API keys or client credentials, while free-to-use sources like OpenStreetMap and Open-Meteo work without authentication.

God's Eye View is an open-source geospatial visualization application by bilawalsidhu that aggregates multiple real-time data streams—satellite imagery, traffic, flights, vessels, and fires—into a unified 3D interface. While some layers draw from public APIs, others connect to commercial or authenticated services that demand valid credentials. This guide maps which layers need keys, where to configure them, and how the system behaves when credentials are absent.


Which Data Layers Require API Keys

The application isolates all credentials in environment variables, typically via a .env file or the Pinokio launcher's environment configuration. Below is the complete breakdown of authenticated versus open layers.

Data Layer Required Credential Read Location Fallback Behavior Without Key
Google Map Tiles / Places / Street View GOOGLE_MAPS_API_KEY (client-exposed) src/main.js, src/mapStackController.js, src/voice/gevActions.js Switches to Esri World Imagery basemap; Google attribution removed
Cesium Ion (Google 3D Tiles) CESIUM_ION_TOKEN (client-exposed) src/main.js, src/mapStackController.js Same Esri fallback; no 3D photogrammetry
TomTom Traffic Flow TOMTOM_API_KEY (server-side only) vite.config.js (proxy to /api/tomtom) Built-in traffic simulation; no TomTom attribution
NASA FIRMS (Active Fires) FIRMS_MAP_KEY (server-side only) vite.config.js (proxy /api/firms) Empty layer with "KEY REQUIRED" message
OpenSky Network (Flights) OPENSKY_CLIENT_ID & OPENSKY_CLIENT_SECRET (or OPENSKY_AUTH_MODE=anon) src/keySetup.js Anonymous mode: limited, rate-restricted access
OpenAI Realtime Voice OPENAI_API_KEY (server-side only) src/voice/voiceCost.js Voice control disabled; UI shows unavailable
AISStream (Vessel Tracking) AISSTREAM_API_KEY (server-side only) src/data/aisStream.js (proxy) No vessels displayed
Open-Meteo, OpenStreetMap, CelesTrak, USGS None N/A Full functionality always available

The definitive reference for all required variables appears in lines 13-96 of .env.example in the repository.


How Credentials Are Injected

God's Eye View uses a two-tier strategy: client-exposed keys for browser-side APIs and server-side proxies for backends that must hide credentials.

Client-Exposed Keys

Google Maps and Cesium Ion tokens must reach the browser bundle. In src/main.js, the build process injects these into a global:

// src/main.js lines 81-82
window.__GOOGLE_MAPS_API_KEY__ = import.meta.env.GOOGLE_MAPS_API_KEY;
window.__CESIUM_ION_TOKEN__ = import.meta.env.CESIUM_ION_TOKEN;

These variables are then consumed by src/mapStackController.js to initialize the Cesium viewer and tile providers.

Server-Side Proxies

For APIs that charge by request or require secret authentication, vite.config.js sets up Vite dev server proxies. Lines 1784-1948 define routes like /api/tomtom and /api/firms that append the key server-side:

// vite.config.js (simplified excerpt)
server: {
  proxy: {
    '/api/tomtom': {
      target: 'https://api.tomtom.com',
      changeOrigin: true,
      rewrite: (path) => {
        const apiKey = process.env.TOMTOM_API_KEY;
        return path.replace(/^\/api\/tomtom/, '') + `?key=${apiKey}`;
      }
    }
  }
}

This architecture prevents keys from appearing in browser network requests.


OpenSky Authentication Modes

The flight data layer offers flexibility through src/keySetup.js. Set OPENSKY_AUTH_MODE=anon to operate without credentials, or supply OPENSKY_CLIENT_ID and OPENSKY_CLIENT_SECRET for full access:

// src/keySetup.js line 277 and surrounding logic
const authMode = import.meta.env.OPENSKY_AUTH_MODE || 'credentials';
const clientId = import.meta.env.OPENSKY_CLIENT_ID;
const clientSecret = import.meta.env.OPENSKY_CLIENT_SECRET;

if (authMode === 'anon') {
  // Rate-limited, restricted endpoint access
} else if (clientId && clientSecret) {
  // OAuth token exchange for full access
}

Anonymous mode suits demonstration; production deployments should register for credentials at opensky-network.org.


Setting Up Your Environment File

Create a .env file from the provided template:


# Copy the example

cp .env.example .env

# Edit with your keys

nano .env

Populate all required values:


# .env — API keys for God's Eye View data layers

GOOGLE_MAPS_API_KEY=AIza...your_key...
CESIUM_ION_TOKEN=eyJ...your_token...
TOMTOM_API_KEY=your_tomtom_key
FIRMS_MAP_KEY=your_firms_key
OPENSKY_CLIENT_ID=your_opensky_id
OPENSKY_CLIENT_SECRET=your_opensky_secret
OPENAI_API_KEY=sk-...your_key...
AISSTREAM_API_KEY=your_aisstream_key

# Optional: force anonymous OpenSky

# OPENSKY_AUTH_MODE=anon

Launch the development server:

npm install
npm run dev

The UI displays a "Provider Settings" chip indicating which services are authenticated.


Programmatic Key Detection

Layer controllers check for credential presence before attempting API calls. The attribution system in src/data/dataCredits.js demonstrates this pattern:

import { registerDynamicCredit } from './src/data/dataCredits.js';

// TomTom credit only appears when key is present
const TOMTOM_CREDIT = {
  text: 'Traffic flow data © TomTom',
  link: 'https://www.tomtom.com'
};

function initTrafficLayer(viewer) {
  const hasKey = Boolean(import.meta.env.TOMTOM_API_KEY);
  
  if (hasKey) {
    registerDynamicCredit(viewer, TOMTOM_CREDIT);
    loadRealTrafficTiles(viewer);
  } else {
    loadSimulatedTraffic(viewer);
  }
}

This conditional approach ensures graceful degradation when credentials are missing.


Layer Attribution and Key Visibility

According to src/data/dataCredits.js, dynamic credits are registered only for authenticated layers. The TomTom credit (lines 88-93) exemplifies this:

// src/data/dataCredits.js
export const TOMTOM_CREDIT = {
  id: 'tomtom-traffic',
  text: 'Traffic flow data © <a href="https://www.tomtom.com">TomTom</a>'
  // Only added to viewer credits when real API is active
};

When running without keys, the attribution line disappears—an immediate visual indicator of which data source is active.


Summary

  • Seven data layers require API keys: Google Maps, Cesium Ion, TomTom Traffic, NASA FIRMS, OpenSky, OpenAI, and AISStream
  • Credentials reside in .env and are documented in .env.example lines 13-96
  • Two injection patterns: client-exposed globals for browser APIs, server proxies for protected backends
  • Graceful fallbacks: missing keys trigger simulations, alternative basemaps, or disabled features rather than crashes
  • Attribution reflects authentication: credits like TomTom's only appear when real data is fetched

Configuring these keys unlocks the full real-time capabilities of God's Eye View according to the bilawalsidhu/gods-eye-view source code implementation.


Frequently Asked Questions

What happens if I run God's Eye View without any API keys?

The application launches successfully but with degraded functionality. You'll see Esri World Imagery instead of Google 3D tiles, simulated rather than real traffic, empty fire and vessel layers, and disabled voice control. Free layers—weather, street maps, satellite TLEs—operate normally.

Where should I get API keys for the commercial data sources?

  • Google Maps & Cesium Ion: Google Cloud Console and Cesium ion dashboard respectively
  • TomTom: Developer portal at developer.tomtom.com
  • NASA FIRMS: Registration at earthdata.nasa.gov for FIRMS API access
  • OpenSky: Account creation at opensky-network.org
  • AISStream: Free tier at aisstream.io
  • OpenAI: Platform account at platform.openai.com

Are API keys exposed to end users in production?

No—server-side keys in vite.config.js proxies never reach the browser. Only GOOGLE_MAPS_API_KEY and CESIUM_ION_TOKEN are client-exposed by design, as these services require browser-side authentication. For production deployments, implement additional origin restrictions and HTTP referer locks at the provider dashboard level.

Can I contribute a new data layer without requiring API keys?

Yes—the architecture supports keyless sources. Follow the pattern in src/data/ for layers like Open-Meteo: implement direct fetch to public endpoints, skip proxy configuration in vite.config.js, and register static attribution in src/data/dataCredits.js. If your source requires authentication, mirror the TomTom proxy pattern and add variables to .env.example.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →