Skip to main content
All API requests require authentication using an API key. Learn how to create and manage your keys securely.

Getting an API Key

1

Sign in

Sign in to your ScrapeBadger account. Your first API key is created automatically and shown on the dashboard, where you can copy or regenerate it anytime.
2

Create more keys (optional)

Open the API Keys page and click Create key. Give it a name, optional notes, the APIs it may call and an optional expiry date.
3

Copy your key

Copy the key and store it as a secret (for example in an environment variable).

Using Your API Key

Include your API key in every request using one of these methods: Pass your API key in the x-api-key header. This is the recommended method as it keeps your key out of URLs and logs.

Query Parameter

Alternatively, pass your API key as a query parameter. Note that this method may expose your key in logs and browser history.

Error Responses

If authentication fails, the API returns one of these status codes:
Error Response Format

API Key Permissions

Every key either has access to all APIs (the default, including APIs added in the future) or is restricted to the APIs you pick — for example a key that may only call Google and Amazon. Set this when you create the key or later with Edit on the API Keys page; changes apply to the key’s very next request. Permissions are per API, matching the first path segment after /v1/: twitter, google, amazon, web, youtube, and so on. Everything under that API — including Twitter stream monitors, filter rules and the stream WebSocket — is covered by its permission. /v1/account is always allowed. A request to an API the key isn’t permitted to call is rejected before any credits are charged, with 403 and error: "insufficient_scope":
403 insufficient_scope
The official SDKs raise PermissionDeniedError for this response, with required_scope and allowed_scopes attached.
Give each application its own key restricted to the APIs it uses. A leaked key then exposes only those APIs, and you can revoke it without touching anything else.

IP Restrictions

Limit a key to the IP addresses your servers use, so a leaked key is useless anywhere else. On the API Keys page, open Edit → IP restrictions, choose Only these addresses and add:
  • single addresses: 203.0.113.7, 2001:db8::1
  • CIDR ranges: 203.0.113.0/24, 2001:db8::/48
Add my current IP fills in the address of the browser you’re using — your servers may use a different one. Up to 100 entries per key; IPv4 and IPv6 are both supported. Changes apply on the key’s next request. A request from any other address is rejected before any credits are charged, with 403 and error: "ip_not_allowed". The response names the address we saw, so you can tell a misconfigured server from someone else using your key:
403 ip_not_allowed
The official SDKs (0.53.0+) raise IPNotAllowedError, a subclass of PermissionDeniedError, with client_ip.
The address is taken from the network connection as it reaches Cloudflare — it can’t be set with headers such as X-Forwarded-For. Keys with IP restrictions don’t work through the hosted MCP server: its requests come from your AI assistant’s provider, not your servers. Use a separate, unrestricted key there.

Security Best Practices

Never expose keys in client-side code

API keys should only be used in server-side code. Never include them in frontend JavaScript, mobile apps, or public repositories.

Use separate keys for different environments

Create separate API keys for development, staging, and production. This makes it easier to rotate keys and track usage.

Rotate keys regularly

Periodically create new API keys and deactivate old ones. If a key is compromised, you can disable it without affecting other keys.

Managing API Keys

From the API Keys page you can:
  • Create multiple API keys for different projects and environments
  • Add notes describing what uses each key
  • Restrict each key to specific APIs, or allow all APIs
  • Limit each key to specific IP addresses or CIDR ranges
  • Set an expiry date after which the key stops working
  • Rename keys and enable or disable them without deleting them
  • View and copy a key again later, and see usage per key
  • Delete keys that are no longer needed
Working with colleagues? Teams let several accounts share one balance, with member keys and service keys managed by team admins.