Developers and AI agents
wcway has a free HTTP API and a free MCP server. Both find public toilets. You need no account and no API key.
Quickstart
Ask for the toilets near a place. The answer is JSON. The field results lists the toilets by distance. The field attribution holds the credit that you must show.
curl "https://wcway.com/api/v1/toilets/nearest?place=Luisenplatz%20Darmstadt&limit=3"The answer, shortened:
{
"status": "ok",
"origin": {
"lat": 49.8731921,
"lon": 8.6506765,
"label": "Luisenplatz, Stadtzentrum, Darmstadt-Mitte, Darmstadt, Hessen, 64283, Deutschland",
"source": "place"
},
"results": [
{
"id": "lt_6a0bfcab63bd23128f7e",
"name": null,
"distance_m": 117,
"walk_min": 1,
"access_rule": "fee",
"open_now": "unknown",
"wheelchair": "yes",
"url": "https://wcway.com/toilets/lt_6a0bfcab63bd23128f7e"
}
],
"attribution": {
"text": "© OpenStreetMap contributors",
"license": "ODbL-1.0",
"url": "https://www.openstreetmap.org/copyright"
}
}Add the MCP server to Claude Code:
claude mcp add --transport http wcway https://wcway.com/mcpHTTP API
Every endpoint answers GET. The version is part of the path.
GET /api/v1/toilets/nearest: Toilets near a place or a position, sorted by distance. Filters: open_now, wheelchair, changing_table, free, no_purchase_needed.GET /api/v1/toilets: Toilets in a map box. The parameter bbox is west,south,east,north in degrees.GET /api/v1/toilets/{id}: One toilet by id.
The OpenAPI document also lists operations for the web pages of this site and for Stripe. They need a human check, a signed-in account or a Stripe signature. Agents do not call them.
MCP server
The server uses Streamable HTTP and needs no authentication. It has two read-only tools: find_toilets_near and get_toilet. The server card lists their input and output schemas.
Authentication
Public toilet search needs no account or API key. Send no Authorization header to /mcp. Account access at /mcp/account uses OAuth and your existing wcway passkey login. After approval, an app can read your own partner listings and subscribe to claim-status and profile changes. Revoke access under Connected apps.
Limits
Each IP address may send 60 requests a minute to the API and the MCP server. The map area endpoint allows 300. Answers of the API carry RateLimit headers. On status 429, wait for the time in Retry-After.
There is no separate test environment. The read endpoints change no data, so you can test against the live API.
Do not copy the whole data set through the API. Download the open data dumps instead.
Errors
Errors use application/problem+json (RFC 9457). The field detail tells you what to change.
{
"type": "https://wcway.com/problems/invalid-parameters",
"title": "Invalid parameters",
"status": 400,
"detail": "Fix the listed parameters and send the request again. The OpenAPI document lists the allowed values.",
"invalid_params": [{ "name": "bbox", "reason": "Required" }]
}Versions and deprecation
The version is part of the path, for example /api/v1. A change that removes a field or changes its meaning gets a new path, such as /api/v2.
Before wcway removes an operation, it marks the operation as deprecated in the OpenAPI document. The answers of that operation then carry the Deprecation and Sunset headers. No operation is deprecated today.
Credit the data
Show “© OpenStreetMap contributors”, ODbL 1.0, next to the toilet data. Every answer holds the text and the links in the field attribution.