Skip to content

Authentication

Authenticate every request with your API key in the x-api-key header.

Send your key

Every request needs your API key. Send it in the x-api-key header:

curl "https://api.scrapercompany.com/v1/usage?period=30d" \
  -H "x-api-key: $SCRAPERCOMPANY_API_KEY"

Two alternatives are accepted, for clients that cannot set custom headers:

MethodExampleUse it for
Header (recommended)
x-api-key: sk_…
Everything.
Bearer token
Authorization: Bearer sk_…
HTTP clients with built-in bearer auth.
Query parameter
?api_key=sk_…
SearchApi-style GET integrations only; URLs end up in logs and browser history.

Get a key

During the beta, accounts are issued by the ScraperCompany team; there is no self-serve signup. Request access and we will send you a dashboard sign-in (with a temporary password you change the first time you sign in). Your signed-in session is all the dashboard needs: open the API access page and choose Create API key. The key itself is only for calls to /v1/*.

The key is shown once

Store it in a secrets manager when you create it. The dashboard shows only the key's name, prefix, rate limit and created date afterwards, never the full key.

Key format

Keys are sk_ followed by 32 random URL-safe characters. There is one kind of key (no separate live and test keys), and each account currently has one key. Requests with a key cost credits only when they succeed.

Keep it secret

  • Call the API from your servers, never from browser or mobile code.
  • Read the key from an environment variable or secrets manager, for example SCRAPERCOMPANY_API_KEY.
  • Never commit it, paste it into tickets, or send it to support — we never need it.
.env
SCRAPERCOMPANY_API_KEY=sk_your_key_here

Rotate or revoke

Rotate the key yourself from the dashboard (API access page): rotating mints a replacement with the same name and rate limit, moves your account to it, and stops the old key immediately. The full new key is shown once — store it before you leave the page. If you would rather we handle it, or want a key revoked without a replacement, email support@scrapercompany.com.

Auth errors

A missing, malformed or revoked key returns 401. Requests over your key's per-minute limit return 429 (see Rate limits).

401 response
{
  "detail": "missing or invalid API key"
}