Skip to main content
Every Zenrows API request is authenticated with your account’s API key. The key is the credential itself: there is no separate token exchange for the Fetch (formerly, Universal Scraper API), Extract, Batch or Crawl APIs.

Get your API key

Create a free account at app.zenrows.com/register, then copy your key from the API keys page (Settings > API keys). An account can have up to 10 API keys, each with its own credit caps. See API Keys and Credit Caps. An agent with no human present can create its own account and key with one unauthenticated request: POST https://app.zenrows.com/api/agent/signup with an empty body. The account stays unclaimed until a human opens the claimUrl returned with the key to take ownership, and the same key keeps working after the claim. The full flow is described in www.zenrows.com/auth.md.
Store your key in an environment variable or a secrets manager, and never commit it or share it publicly.

How to send the key

A Fetch request with the key in the query string:
cURL
A Batch request with the key in the header:
cURL
The SDKs and the CLI take the same key and send it for you.

MCP server: OAuth 2.1

The remote Zenrows MCP server accepts OAuth 2.1 with PKCE (S256), or your API key as a Bearer token. With OAuth, the user signs in at app.zenrows.com and approves access, and the access token issued is the account’s API key, so every tool runs with that key’s permissions. Discovery, dynamic client registration and the single api scope are described in MCP authentication and permissions.

In the OpenAPI spec

The Zenrows OpenAPI spec declares two API key security schemes: apiKeyQuery (the apikey query parameter, used by Fetch and Extract) and apiKeyHeader (the X-API-Key header, used by Batch). A generated client reads them from there.

Authentication errors

A missing or invalid key returns 401 Unauthorized. The code in the body depends on the surface:
  • Fetch, including extract=auto: AUTH001 (key missing), AUTH002 (key malformed) or AUTH003 (key not found). Each one, and the fix for it, is listed under 401 Unauthorized.
  • Batch and the Extract prepared-domains endpoints: unauthenticated. See Batch and Extract error codes.