Get started

Authentication

Every request is authenticated with a bearer token.

API keys

Pass your key in the Authorization header as a bearer token. Keys come in two flavours: sf_live_* for production and sf_test_* for staging and local development.

bash
Authorization: Bearer sf_live_9x2a...
⚠
Never expose keys in client-side code. Call ScrapeFlow from your backend or a serverless function. If a key leaks, revoke it in Dashboard → API Keys — the request that leaked it keeps working only until you revoke.

Per-key budgets & scopes

Each key can carry its own monthly budget cap and rate limit, so you can give staging a small budget and production a larger one. When a key hits its cap, its requests pause automatically instead of overflowing your bill.

Rotation

Create a new key, deploy it, then revoke the old one — zero downtime. We recommend rotating production keys every 90 days.