Every scrape request must be authenticated with an API key. Create and manage keys in your
dashboard under API keys.
Sending your key
Send the key in the x-api-key header:
A Bearer token is also accepted, if that fits your HTTP client better:
A missing, invalid, or revoked key returns 401 UNAUTHORIZED.
Keys are a 28-character random string of letters and digits — there is no live/test split and no
prefix. The full secret is shown once, when the key is created; store it securely (an environment
variable or a secret manager). If you lose it, revoke the key and create a new one.
Treat your API key like a password. Never commit it to source control or expose it in client-side code
(browser or mobile apps). Call the API from your server.
Managing keys
From the dashboard you can create multiple keys, name them, see each key’s last-used time, and revoke any
key immediately. Revoking takes effect right away.