Skip to main content
Every request to the AdsCrawl API must carry a credential. For nearly all workflows, that credential is your API key — a long-lived secret you send in the x-api-key request header. Two narrower token types exist for specific scenarios: a session JWT for cloud browser lifecycle operations initiated from a dashboard session, and a data token embedded in CDP session URLs for WebSocket access. Understanding which credential goes where prevents authentication errors and keeps your key secure.

Getting your API key

Open the AdsCrawl dashboard after signing in, and copy your API key from the keys section. Store it in an environment variable or a secrets manager — never hard-code it in your application source.

Sending your API key

Pass your API key in the x-api-key header on every request. The header name is lowercase; the value is the full key string.
Never expose your API key in client-side JavaScript, browser extensions, mobile apps, public repositories, or request URLs. Your key authorizes charges against your account. If a key is compromised, rotate it immediately from the dashboard.

Session JWT (cloud browser lifecycle)

Cloud browser list, create, launch, start, and stop endpoints also accept a session JWT in the Authorization: Bearer <SESSION_JWT> header. This is a login session token — it represents a signed-in dashboard user, not an API key. Session authentication is narrower than API key authentication in one important way: it requires apiKeyId on start requests. You must supply the UUID of an active, unexpired API key that belongs to the same account. API key authentication selects the current key automatically.
Session cookies are also accepted in place of the Bearer token for dashboard-initiated requests. Use API key authentication for all server-side and automated workflows.

Data tokens (CDP WebSocket access)

When you create a CDP session, the 201 response includes a cdpBaseUrl that already contains an embedded data token:
Pass cdpBaseUrl directly to Playwright’s connectOverCDP. The data token in this URL authorizes both the CDP discovery endpoint (GET /cdp/sessions/:id/json/version) and the CDP WebSocket (WSS /cdp/sessions/:id/devtools/browser/:browserId).
Do not replace the data token in cdpBaseUrl with your API key. The data token is a separate, session-scoped credential. Substituting your API key will result in a 401 error.
For live browser control, use POST /cdp/live-token (authenticated with your API key) to obtain a short-lived controlToken. This single-use token expires after 30 seconds and authorizes one WebSocket connection to WSS /cdp/live/:sessionId.

Error reference

API key limits by plan

The number of API keys you can create depends on your plan. Each key is independent and can be scoped to different servers or services.
You can view and manage your API keys, credit balance, and plan from the dashboard. To create a new account, visit app.adscrawl.net/register.