API documentation · 2 of 9

Authentication

Every request carries an API key. Keys belong to your account and reach only your own projects.

Create a key

  1. Sign in and open Account → API keys.
  2. Give the key a name you will recognise later, such as the script that uses it.
  3. Tick Allow this key to modify data if it will create projects, change settings or start crawls.
  4. Copy the key when it appears. It is shown once: only a hash is stored, so it cannot be shown again. If it is lost, revoke it and create another.

Scopes

ScopeAllows
readEvery GET: projects, crawls and results. Every key has it.
writeCreating projects, changing their settings, and starting and stopping crawls.

Send it

As a bearer token in the Authorization header:

curl -H "Authorization: Bearer sk_live_..." http://localhost:9000/api/v1/projects

When it is refused

StatusCodeWhy
401missing_credentialsNo bearer token was sent.
401invalid_credentialsThe key is unknown, malformed or revoked. All three answer alike.
403insufficient_scopeA read-only key called an endpoint that needs write.
404project_not_foundThe project is not yours. It is not found rather than forbidden, so the API never confirms an id exists.

Revoking a key in Account → API keys takes effect at once. The page also shows when each key was last used.