Authentication
Authenticate every request with your API key in the x-api-key header.
Send your key
Every request needs your API key. Send it in the x-api-key header:
curl "https://api.scrapercompany.com/v1/usage?period=30d" \
-H "x-api-key: $SCRAPERCOMPANY_API_KEY"Two alternatives are accepted, for clients that cannot set custom headers:
| Method | Example | Use it for |
|---|---|---|
Header (recommended) | x-api-key: sk_… | Everything. |
Bearer token | Authorization: Bearer sk_… | HTTP clients with built-in bearer auth. |
Query parameter | ?api_key=sk_… | SearchApi-style GET integrations only; URLs end up in logs and browser history. |
Get a key
During the beta, accounts are issued by the ScraperCompany team; there is no self-serve signup. Request access and we will send you a dashboard sign-in (with a temporary password you change the first time you sign in). Your signed-in session is all the dashboard needs: open the API access page and choose Create API key. The key itself is only for calls to /v1/*.
Key format
Keys are sk_ followed by 32 random URL-safe characters. There is one kind of key (no separate live and test keys), and each account currently has one key. Requests with a key cost credits only when they succeed.
Keep it secret
- Call the API from your servers, never from browser or mobile code.
- Read the key from an environment variable or secrets manager, for example
SCRAPERCOMPANY_API_KEY. - Never commit it, paste it into tickets, or send it to support — we never need it.
SCRAPERCOMPANY_API_KEY=sk_your_key_hereRotate or revoke
Rotate the key yourself from the dashboard (API access page): rotating mints a replacement with the same name and rate limit, moves your account to it, and stops the old key immediately. The full new key is shown once — store it before you leave the page. If you would rather we handle it, or want a key revoked without a replacement, email support@scrapercompany.com.
Auth errors
A missing, malformed or revoked key returns 401. Requests over your key's per-minute limit return 429 (see Rate limits).
{
"detail": "missing or invalid API key"
}