
YandexMapsLocator
Store locator on Yandex Maps for MODX 3. Free: map and search. Pro: open now, MiniShop3, CSV, and REST
- MODX 3
- PHP 8.2


Free installs yandexmapslocator_api_* keys. The endpoint and kill switch activate after Pro. List rate limits also apply to Free search.php.
Request → ApiSecurityMiddleware (enabled, Bearer, rate limit, CORS) → parser → parent validation → controller → serializers → JSON + security headers.
| Key | Production recommendation |
|---|---|
yandexmapslocator_api_enabled | Yes. Disable during an incident |
yandexmapslocator_api_token | Long secret for server-side clients. Never written into locator HTML |
yandexmapslocator_api_cors_origins | Exact frontend origins, not * |
yandexmapslocator_api_allowed_parents | Restrict location containers |
yandexmapslocator_api_resource_tvs | TV whitelist for include=tv |
yandexmapslocator_api_trust_proxy | Yes only behind a trusted reverse proxy |
yandexmapslocator_api_list_rate_limit | Tune for network load |
yandexmapslocator_api_geocode_rate_limit | Geocoding costs Yandex quota |
Full list: System settings.
Content-Type: application/json; charset=utf-8X-Content-Type-Options: nosniffCache-Control: public, max-age=60 only if the token is empty, there is no Authorization header, and fields stay in the short public set. Otherwise private, max-age=60Cache-Control: private, max-age=60Cache-Control: no-store429 + Retry-After: 60 when limit exceededSample error bodies:
{
"success": false,
"error": "Unauthorized",
"code": "unauthorized"
}{
"success": false,
"error": "Rate limit exceeded",
"code": "rate_limit_exceeded"
}{
"success": false,
"error": "API is disabled",
"code": "api_disabled"
}REST does not include the Yandex Maps apiKey in JSON. On the snippet page the key only appears in the browser map script URL.
where is forbidden in REST and search.php.
Without Pro, product_id is cleared even if passed in the request.