> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zenrows.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> The Zenrows API (Fetch, Extract via extract=auto, and Batch) is described in OpenAPI 3.1 at https://www.zenrows.com/openapi.json and listed in the RFC 9727 API catalog at https://www.zenrows.com/.well-known/api-catalog. Use the spec for exact parameter names and types.

# Zenrows API Authentication

> How to authenticate Zenrows API requests: where to find your API key, how to send it to Fetch, Extract, Batch and Crawl, and how the Zenrows MCP server signs in with OAuth.

Every Zenrows API request is authenticated with your account's API key. The key is the credential itself: there is no separate token exchange for the Fetch (formerly, Universal Scraper API), Extract, Batch or Crawl APIs.

## Get your API key

Create a free account at [app.zenrows.com/register](https://app.zenrows.com/register?p=free), then copy your key from the [API keys page](https://app.zenrows.com/settings/api-keys) (**Settings** > **API keys**). An account can have up to 10 API keys, each with its own credit caps. See [API Keys and Credit Caps](/first-steps/api-key-credit-caps).

An agent with no human present can create its own account and key with one unauthenticated request: `POST https://app.zenrows.com/api/agent/signup` with an empty body. The account stays unclaimed until a human opens the `claimUrl` returned with the key to take ownership, and the same key keeps working after the claim. The full flow is described in [www.zenrows.com/auth.md](https://www.zenrows.com/auth.md).

<Tip>Store your key in an environment variable or a secrets manager, and never commit it or share it publicly.</Tip>

## How to send the key

| Surface | Base URL | How the key is sent |
| - | - | - |
| [Fetch](/fetch/api-reference), including `extract=auto` | `https://api.zenrows.com/v1/` | `apikey` query parameter |
| [Extract endpoints](/extract/endpoints) | `https://api.zenrows.com/v1/extract/` | `apikey` query parameter or `X-API-Key` header |
| [Crawl](/crawl/endpoints) | `https://api.zenrows.com/v1/crawls` | `X-API-Key` header or `apikey` query parameter |
| [Batch](/batch/developer-guide-restapi) | `https://async.api.zenrows.com/v1` | `X-API-Key` header only, never in the URL |
| [Plan usage](/fetch/features/other#plan-usage) | `https://api.zenrows.com/v1/subscriptions/self/details` | `X-API-Key` header |
| [MCP server](/mcp/overview) | `https://mcp.zenrows.com/mcp` | OAuth 2.1 sign-in, or `Authorization: Bearer YOUR_ZENROWS_API_KEY` |

A Fetch request with the key in the query string:

```bash cURL theme={"dark"}
curl "https://api.zenrows.com/v1/?apikey=YOUR_ZENROWS_API_KEY&url=https%3A%2F%2Fhttpbin.io%2Fanything"
```

A Batch request with the key in the header:

```bash cURL theme={"dark"}
curl "https://async.api.zenrows.com/v1/jobs" \
  -H "X-API-Key: YOUR_ZENROWS_API_KEY"
```

The [SDKs](/sdk/overview) and the [CLI](/cli/introduction) take the same key and send it for you.

## MCP server: OAuth 2.1

The remote Zenrows MCP server accepts OAuth 2.1 with PKCE (S256), or your API key as a Bearer token. With OAuth, the user signs in at `app.zenrows.com` and approves access, and the access token issued is the account's API key, so every tool runs with that key's permissions. Discovery, dynamic client registration and the single `api` scope are described in [MCP authentication and permissions](/mcp/tool-reference#authentication-and-permissions).

## In the OpenAPI spec

The [Zenrows OpenAPI spec](https://www.zenrows.com/openapi.json) declares two API key security schemes: `apiKeyQuery` (the `apikey` query parameter, used by Fetch and Extract) and `apiKeyHeader` (the `X-API-Key` header, used by Batch). A generated client reads them from there.

## Authentication errors

A missing or invalid key returns `401 Unauthorized`. The `code` in the body depends on the surface:

* **Fetch, including `extract=auto`:** `AUTH001` (key missing), `AUTH002` (key malformed) or `AUTH003` (key not found). Each one, and the fix for it, is listed under [401 Unauthorized](/api-error-codes#401).
* **Batch and the Extract prepared-domains endpoints:** `unauthenticated`. See [Batch and Extract error codes](/api-error-codes#unauthenticated).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.