FAQ

Australian address API questions, answered

Everything about scope, data residency, integration, billing and licensing. Can’t find it? Email support@wattleaddr.com.au.

Choosing a provider

What is the best Australian address autocomplete API?

It depends on one thing: whether you need to know an address exists, or that Australia Post will deliver to it. For web forms, checkouts, sign-ups and CRM data, the right category is a G-NAF-based API such as WattleAddr — G-NAF is the authoritative national address file and essentially every Australian provider builds on it, so coverage rarely separates them. For bulk mail lodgement you need an Australia Post AMAS/PAF-certified provider instead, which WattleAddr is not — AMAS certifies against Australia Post’s PAF, a separately licensed dataset that G-NAF does not include. Within the G-NAF category, the differences that change the outcome are where the lookup is processed, whether you are billed per keystroke or per completed address, and whether you can get a data-residency attestation, DPA and purchase-order billing.

What is the cheapest Australian address API?

Look at the billing unit before the rate, because that is where the order-of-magnitude difference lives: autocomplete fires a request on roughly every keystroke, so per-request billing charges eight to twelve times per address found compared with per-session billing. WattleAddr bills one lookup per completed address search regardless of how many characters were typed, bills nothing for a search the customer abandons, and starts at $0 for 5,000 lookups a month with no card required. Paid plans are $53.90/month for 50,000 lookups and $163.90/month for 250,000 — $0.66 per 1,000 at the Growth tier — in Australian dollars including GST ($49 and $149 ex-GST).

Is there a free Australian address autocomplete API?

Yes. WattleAddr’s Free tier is ongoing rather than a time-limited trial: 5,000 lookups a month, no card required, on the same G-NAF data and the same Australian infrastructure as the paid plans, with the search-log privacy controls included. The underlying dataset, G-NAF, is itself open data published by Geoscape Australia — what you pay for is having it indexed, matched and served fast from Australia.

Is there an Australian alternative to Google Places Autocomplete?

Yes — WattleAddr. It replaces Places Autocomplete plus Place Details for the address field on a form: Australian-owned, served entirely from Australian infrastructure, billed in Australian dollars per completed address search rather than per keystroke. The trade-off is coverage. WattleAddr returns Australian physical addresses only, and does not return businesses, landmarks or points of interest. Migration is usually under an hour for a single field (the field mapping is here); the main change is that street name and street type come back as separate fields where Google returns a combined route.

Does my address API have to be hosted in Australia?

Rarely by law, often by contract. Australian Privacy Principle 8 leaves you accountable for what an overseas recipient does with personal information you disclose to them, and government and regulated buyers routinely require onshore processing outright. The trap specific to autocomplete is that it transmits your end-users’ raw keystrokes to the provider before anyone presses submit — so an offshore autocomplete can quietly break a residency promise you have already made. WattleAddr serves every request from Sydney with an Australian backup and no foreign CDN or offshore edge, and publishes a data-residency attestation for procurement.

When is WattleAddr the wrong choice?

Five cases, and we would rather say so up front. If you lodge bulk mail and want Australia Post discounts, you need an AMAS-certified provider — G-NAF alone cannot get you there, because AMAS certifies against Australia Post’s PAF, a separately licensed dataset. If you need PO Boxes validated, no G-NAF provider can help — that data lives in PAF too; we detect those queries and return an explicit postal_address_unsupported notice rather than an empty dropdown, and do not bill for them. If you have customers outside Australia, we return Australian addresses only. If you need reverse geocoding or a bulk-cleansing endpoint today, the API is four endpoints and has neither. And if you need businesses or landmarks to resolve, you want a places index rather than an address file.

When is WattleAddr the right choice?

When you need to know an Australian address exists, is correctly formatted and where it is, answered onshore. That covers a data-residency promise you have made to a customer, auditor or tender, since autocomplete sends raw keystrokes before anyone presses submit; selling to government, health or finance, where a DPA, data-residency attestation, SLA and purchase-order billing are available on Enterprise; a busy form where per-keystroke billing hurts, since one completed search is one lookup and an abandoned one is free; and wanting the address parsed into fields with a per-field verdict so a checkout can re-prompt for the one field that disagreed.

Product & scope

What is WattleAddr?

WattleAddr is an Australian address API: autocomplete, verification, standardisation and geocoding, built on the open Geocoded National Address File (G-NAF) and hosted entirely in Australia. You add it to any form so people can type a few characters and pick a real, correctly formatted Australian address.

What can the API do?

Three things: autocomplete (type-ahead suggestions as a user types), verify & standardise (match free-text input to a canonical address with clean components, plus a verdict telling you whether to accept it and a per-field status telling you which field disagreed), and geocode (return latitude and longitude for a matched address).

What can it not do?

WattleAddr confirms that an address exists and where it is. It is not a postal deliverability or mail-house service. It does not provide Australia Post AMAS/PAF certification, DPIDs or barcodes, and must not be relied on to decide whether mail can be delivered. We are deliberately upfront about this so you buy the right tool.

Do you provide planning, zoning or flood data for an address?

Not through this API. WattleAddr tells you an Australian address exists, standardises it and gives you the coordinates; it holds no planning, zoning, flood, bushfire, heritage or land-value information. A separate product from the same company does: WattleAddr Property reads the published government registers for one address and returns a PDF report, $9.90 including GST, paid once — every New South Wales address and some Queensland councils today. The distinction it is built around is worth knowing even if you never buy one: a hazard question has three answers, not two, because land can be inside a mapped hazard area, outside one, or in a council that has never mapped that hazard at all. Only 10 of New South Wales’ 128 councils publish a flood planning map, so for most of the state an empty flood result means nobody has looked. That distinction is explained at property.wattleaddr.com.au/learn/unmapped.

Which addresses are covered?

Every current, geocoded physical address in Australia that appears in G-NAF, the authoritative national address file. It is refreshed quarterly, and each API response tells you which G-NAF release it came from.

Do you support PO Boxes?

No. G-NAF is a register of physical addresses and contains no PO Boxes, GPO Boxes, Locked Bags or Private Bags, so we cannot match them. Rather than showing an empty dropdown, the API detects these and returns a clear postal_address_unsupported notice, does not bill for them, and the widget shows a short message explaining it — so your form can prompt for a street address or accept the PO Box in a separate field. We could confirm the suburb exists, but we have no source telling us a particular box number does, and we would rather return nothing than something we cannot stand behind.

How accurate and current is the data?

The data is sourced from Geoscape Australia’s G-NAF and updated each quarter. We re-ingest each release and swap it in with zero downtime. Because it reflects the national dataset, coverage and formatting are consistent across the country.

How accurate is the matching?

On our own benchmark of randomly sampled G-NAF addresses, a complete Australian address returns the correct record as the top suggestion about 94% of the time, and within the top six about 98% of the time. Partial or misspelt input scores lower. The method is described in the accuracy guide, and the saved runs are available on request.

How does it handle typos and misspelt addresses?

Matching tolerates one wrong, missing or extra character in a word of three to five letters and two in a longer word, in the street name and the suburb alike, so “589 Beems Rd Carseldine” finds 589 Beams Rd. It is not phonetic: “Beems” works because it is one letter from “Beams”, not because it sounds the same. The last word typed gets no tolerance, so a suburb misspelt at the end of the query matches nothing; it is then dropped and the search retried on the street alone, and verify reports it in dropped_tokens with a lower score. Verify never corrects a street number; a number that disagrees is reported as changed. In autocomplete a one- or two-digit number is matched exactly, so if no premise carries it the suggestions are units that do, while a longer number gets the same one-character tolerance as a word. Verify tells you exactly what it corrected: the elements field marks each part verified, changed or missing, and changed_elements lists the corrected ones. A corrected street name lowers the score and the verdict is never “verified” (usually “unverified”), so review it rather than auto-accept. Details in typos, misspellings and units.

Do you support international addresses?

No. WattleAddr is Australia-only by design. That focus is part of what lets us keep everything onshore and fast.

What’s the difference between autocomplete, verify and geocode?

Autocomplete is for interactive forms (suggestions as someone types). Verify takes a full free-text address and finds the best canonical match, useful for cleaning data you already hold. Geocode returns coordinates for a matched address, for maps, routing or catchment logic.

What is the difference between address validation and address verification?

In practice they are used interchangeably, and in WattleAddr both mean the verify endpoint: you send free text, and it returns the best matching G-NAF record with a verdict saying whether to accept it and a per-field status saying which part disagreed. Neither word means mail deliverability; that is a separate Australia Post service that WattleAddr does not provide.

What is a locality in an Australian address?

Locality is G-NAF’s word for the suburb or town, and it is the field name WattleAddr returns in every address record. The same address can carry a well-known name and an official locality that differ; the API returns the official G-NAF one.

What is a DPID, and do you provide one?

A Delivery Point Identifier is Australia Post’s eight-digit number for a mail delivery point, issued from its PAF dataset and used for barcoding and bulk-mail discounts. WattleAddr does not provide DPIDs, because G-NAF does not contain them; if you need them, you need an AMAS-certified provider.

How do I know whether to trust a verify result?

Branch on the verdict field of the verify endpoint. verified means everything you supplied agrees and no other candidate fits, so accept it. corrected means it agrees as far as it goes but you abbreviated or left something out, so accept the canonical form or re-prompt for the missing fields. ambiguous means an element was contradicted, part of your input was discarded to get a match, or a runner-up fits equally well, so review it rather than auto-accepting. unverified means nothing usable matched. A verdict says an address exists in G-NAF and where it is; it is not a statement about mail delivery.

Should I use match_score or the elements field?

Use elements to find which field disagreed: every component of the address gets its own status of verified, changed or missing, so a checkout can re-prompt for the one field that is wrong rather than the whole address. match_score (0 to 100) and match_level (subpremise, premise, thoroughfare or locality) describe how precisely the match was made and are useful for logging and review queues, but we publish no accept or reject threshold, because the right line depends on what a wrong address costs you. The older top-level confidence field is deprecated; do not branch on it.

Data residency & privacy

Where is my data hosted?

Entirely in Australia. Primary infrastructure is in Sydney, with backups held in Australia, on Australian cloud infrastructure (Binary Lane). Nothing is processed or stored offshore today, and the data-residency attestation records that arrangement as at its effective date — ask us for a current copy if you are relying on it for procurement.

Does any data leave Australia?

No, for address data. Address queries are served from Australian infrastructure and are not routed or cached overseas, and there is no foreign CDN or offshore edge in the request path. That is a statement about how the service runs today rather than a promise about every future version of it: if we ever process data outside Australia we will update the data-residency attestation and give notice under the DPA before it happens.

Do you send my customers’ keystrokes to any third party?

No. Unlike some popular autocompletes, your end-users’ input never touches a third-party ad platform. Their addresses stay with us, in Australia.

Do you store the addresses my users type?

By default, queries and matched results are recorded in a per-workspace search log for debugging, usage and support, with configurable retention (for example 7, 30, 90 or 365 days) after which entries are purged. You can also choose, per workspace, to store queries as a salted keyed hash instead of plain text, or to store no query or matched-address text at all.

Can I reduce what’s stored?

Yes, three ways in Settings. You can shorten your search-log retention (query text is purged once that window passes). You can switch the search-log to a keyed-hash mode, where each query is stored as a salted HMAC and the matched address text is not kept — this is pseudonymisation (we hold the key), not anonymisation. Or you can turn off storing query and matched-address text entirely, keeping only counts, timing and billing. Any of these can also be applied to logs already stored.

Are you IRAP assessed or ISO 27001 certified?

No. Our infrastructure is architected to support IRAP-aligned workloads, but we do not hold an IRAP assessment, ISO 27001 certification or equivalent, and we do not claim one. The Data Residency Attestation says so plainly so a reviewer does not have to infer it.

Are you compliant with the Privacy Act and the APPs?

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. See our Privacy Policy for detail.

Can I get a Data Processing Agreement?

Yes. Our DPA covers our processing of end-user address data on your behalf, all within Australia. It is published on our website and applies to every workspace from the moment it is created; Enterprise & Government customers may sign a negotiated version instead.

Is it suitable for government and regulated industries?

That is exactly who we built it for. All-Australian hosting, configurable retention, a DPA, data-residency attestation and manual/PO billing make WattleAddr a fit where offshore address autocomplete is not allowed. The procurement checklist is answered row by row on the government and regulated industries page, including what we do not hold: no IRAP assessment or ISO 27001 certification.

Getting started & integration

How do I get started?

Create a free account in the console, create a workspace, and grab a publishable key (for the browser) and a secret key (for your backend). Then call the API or drop in the widget; the quickstart walks a first-timer through it in five minutes.

What’s the difference between secret and publishable keys?

Secret keys authenticate server-side calls and must be kept private (use an Authorization: Bearer header). Publishable keys run in the browser and are locked to the domains you allow, so they can’t be misused elsewhere. Publishable keys can call autocomplete and retrieve only; verify needs a secret key. Rule of thumb: if the key would show up in “view source”, it must be publishable.

Is there a drop-in widget?

Yes, and three ways to add it. A lightweight JavaScript autocomplete widget attaches type-ahead to any input with a publishable key and handles session tokens for you. Add it with a single <script> tag, install it from npm as @wattleaddr/js, or use the @wattleaddr/react component. You can also call the REST API directly.

Do you have an npm package or a React component?

Yes — two official, typed, MIT-licensed packages. @wattleaddr/js is a zero-dependency SDK with a headless client (works in the browser and in Node 18+) and a drop-in autocomplete widget. @wattleaddr/react adds a useAddressAutocomplete hook and an accessible <AddressAutocomplete> component built on it. Install with "npm install @wattleaddr/react" (or @wattleaddr/js for vanilla JS or your backend); both are documented in the docs.

What platforms and frameworks are supported?

Anything that can make an HTTPS request. The REST API works with any language or framework; the browser widget works with any front-end. We publish official npm packages for JavaScript/TypeScript (@wattleaddr/js) and React (@wattleaddr/react), and an OpenAPI 3.1 spec you can use to generate a client in your own language. For Shopify there is a listed app that needs no code; see wattleaddr.com.au/integrations/shopify. Any other front end can use the script-tag widget, and any language can call the REST API.

What are the rate limits?

Each API key may make a set number of requests per second, decided by the plan: Free 5, Starter 15, Growth 40, Enterprise 200. It works as a token bucket per key: a key can send that many requests at once, then keeps going at that rate. Over the limit the API returns 429 with a Retry-After header saying how many seconds to wait; nothing is queued, and a refused request is not counted or charged. Monthly usage is governed separately by the plan’s quota. The numbers and how they behave are in limits and performance.

Is there a concurrency limit?

No separate one. Parallel requests are fine as long as they fit within the key’s per-second rate. Every key has its own bucket, and the right setup is one key per system, each with its own limit (Free allows 2 live keys, Starter 10, Growth 25, plus a smaller separate allowance of test keys). If one system needs more than its plan’s rate, talk to us rather than fanning out across keys; per-key limits above the published ones are set by agreement.

Is there a test mode?

Yes. Test-mode keys hit the real engine and the real address data, and they are never billed. They are free for the first 15 days of an account so you can build and evaluate, then you switch to a live key.

Can my team sign in with SSO?

Yes, on Enterprise plans. The console can be pointed at your own identity provider over OpenID Connect — Okta, Microsoft Entra ID, Google Workspace, Auth0 or similar. Accounts are created on first sign-in with a role you choose, your identity provider can never change an existing member’s role or create owners, and you can require SSO so a password cannot be used instead. You verify each email domain by DNS first. This covers console access; your application still authenticates to the API with keys. See the setup guide at /docs/sso.

What happens if a key is leaked?

Rotate or revoke it instantly in the console. Revocation takes effect immediately. We only ever store a prefix and a hash of each key, never the raw value.

Billing & plans

What plans are available?

Four: Free (5,000 lookups/month to try and build), Starter ($53.90/month incl. GST, 50,000 lookups), Growth ($163.90/month incl. GST, 250,000 lookups), both paid plans scale with usage-based overage, and Enterprise/Government (custom volume, residency attestation, DPA, SLA and PO billing).

What counts as a billable lookup?

One address-search session. All the autocomplete keystrokes a person types while finding one address, plus the final selection, collapse into a single billable lookup.

Are autocomplete keystrokes billed?

No. Autocomplete keystrokes are treated as fair-use. You’re only billed for completed lookups, so a busy checkout stays affordable.

What happens if I exceed my quota?

On the Free tier, billable requests stop once you reach the cap (until the next period or an upgrade). On the paid plans (Starter and Growth), you keep going and pay overage. There is one safety ceiling: once a period’s usage reaches five times the plan’s included lookups, overage is paused and the API returns 402 until the next period or until you ask us to lift it, so a leaked key or a runaway integration cannot run up a bill nobody expects. We email you at twice the allowance, well before that. You can also ask us to set a lower spending cap for your workspace.

How does overage work?

Starter and Growth each include a monthly allowance of lookups, then bill any extra per 1,000 at the rate shown on the pricing page ($2.75 on Starter, $1.65 on Growth, both including GST). No forced upgrade. Overage pauses at five times the included allowance in a period unless you ask us to lift the ceiling; see the quota question above.

What payment methods do you accept?

Every paid plan is invoiced — we don’t store your card and nothing is ever automatically debited. When you pick a paid plan we email you a tax invoice, and you pay it either by bank transfer or PayID using the invoice number as the reference, or by a one-off card payment in the console. Card details are handled by our Australian payment processor and are not saved, so paying one invoice does not authorise any further payment. Enterprise and Government accounts can also pay against a purchase order.

Can I pay by invoice or purchase order?

Yes — invoicing is the only way we bill. Every paid account gets a valid Australian tax invoice showing our ABN and the GST, payable by EFT or PayID. Enterprise and Government accounts can additionally pay against a purchase order; email billing@wattleaddr.com.au to set that up.

Do prices include GST?

Yes. The headline price on every plan is the total you pay in Australian dollars, GST included: Starter is $53.90/month and Growth $163.90/month. RR Sols Pty Ltd is GST-registered, so the 10% is itemised separately on every invoice rather than added on top of the advertised figure, and each plan also shows its ex-GST price ($49 and $149) for anyone claiming the credit back. Every invoice is a valid Australian tax invoice with the GST itemised and our ABN on it.

Is there a free tier or trial?

Yes. The Free tier is ongoing (not a time-limited trial), with a monthly lookup allowance and no card required.

How do I cancel, and are fees refundable?

You can cancel any time in the console. If you cancel within 7 days of your first payment, that payment is eligible for a refund, less the value of any heavy use in those days — we confirm it against the payment received, then send it by bank transfer — and we cancel any invoice still unpaid. After that window, cancellation takes effect at the end of the period you have already paid for — you are not invoiced again, but that period is not refunded, except where the Australian Consumer Law requires it. See the Refund & Cancellation Policy for the detail.

What is the difference between cancelling and deleting a workspace?

Cancelling stops the billing and drops the workspace to Free — your API keys keep working on the Free allowance, so nothing on your site breaks. Deleting removes the workspace and revokes its API keys immediately, so anything still calling us with those keys stops working straight away. If you only want to stop paying, cancel. Deleting within 7 days of your first payment makes it eligible for the same refund as cancelling does.

Data, licensing & ownership

Where does the address data come from?

From G-NAF (the Geocoded National Address File), © Geoscape Australia, provided as open data. WattleAddr ingests, indexes and serves it through our API.

Do I need to attribute G-NAF?

Yes. The open G-NAF licence requires a short attribution to Geoscape Australia wherever you surface address data. We provide the exact wording in our docs, and it also appears in our own site footer.

Can I store or cache the addresses I retrieve?

Yes, you can cache a result for your own operational use (for example, saving the address a customer selected). Because G-NAF is refreshed quarterly and identifiers can change between releases, store the returned formatted address and components too, not just the identifier.

Who owns the data?

G-NAF remains the property of Geoscape Australia and its licensors, used under the open licence. You own your application and your data; we don’t claim ownership of the addresses you process.

Reliability, security & support

How fast is the API?

Measured inside our API in September 2026: autocomplete answers in about 65 ms at the median and about 225 ms at the 95th percentile; verify in 35 to 100 ms once a query is warm, and up to about 600 ms on the first call for a large block of units. Add your network round trip: a fresh HTTPS connection from within Australia adds roughly 50 to 90 ms, a reused one about 45 ms. Repeated prefixes are served from an in-memory cache. Live availability is on the status page.

What is the API built on?

The full G-NAF release is loaded into OpenSearch by the open-source Addressr loader, which we host ourselves, and our own API queries that index directly: the exact query first, and a spelling-tolerant one only when the exact one finds nothing. The same API handles keys, metering, scoring and the corrections that make results useful (suburb fallback, building before units). Keys, usage and billing live in Postgres. Everything runs on Australian infrastructure: Sydney is primary, Melbourne is a warm standby. Quarterly G-NAF releases are loaded in place with no downtime.

What’s your uptime and do you offer an SLA?

Live status, the G-NAF release we are serving and a daily availability history are at wattleaddr.com.au/status, measured from outside our own infrastructure and excluding nothing, not even announced maintenance, so it is harsher than the contractual figure. A formal SLA with a 99.5% monthly uptime commitment and service credits is available on Enterprise plans. The published maintenance window is Sundays 01:00 to 05:00 Australian Eastern time.

Is there a status page?

Yes: the status page shows live availability, the G-NAF release currently being served and a daily history. The API also exposes an unauthenticated /v1/status endpoint that is safe to poll.

How do I get support?

Free tier has community/email support; Starter and Growth include email support (priority on Growth); Enterprise adds dedicated support. Reach us at support@wattleaddr.com.au.

How do I delete my data or account?

You can delete workspaces and rotate/revoke keys in the console, and adjust search-log retention. To delete your account or request erasure, contact us and we’ll action it subject to any legal retention requirements.

How do you secure API keys and data?

Keys are shown once and stored only as a prefix plus a hash; data is encrypted in transit and hosted on access-controlled Australian infrastructure with least-privilege access, logging and backups. See our Privacy Policy and DPA (Annex B) for detail.

Still have a question?

Start free and see it working, or talk to us about Enterprise and Government needs.