Amazon Scraper API · Authentication Profile

Amazon Scraper Api Authentication

Authentication

Amazon Scraper API secures its APIs with apiKey and http across 3 declared security schemes, as derived from its OpenAPI definitions.

Web ScrapingData ExtractionE-Commerce DataAmazonmarketplace dataProduct IntelligencePrice MonitoringCompetitor ResearchMCPAgent Tooling
Methods: apiKey, http Schemes: 3 OAuth flows: API key in: query, header

Security Schemes

apiKeyQuery apiKey
· in: query (api_key)
apiKeyHeader apiKey
· in: header (X-API-Key)
bearerAuth http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-09-03'
method: searched
source: openapi/amazon-scraper-api-openapi-original.json
docs: https://amazonscraperapi.com/docs/guides/authentication
summary:
  types:
  - apiKey
  - http
  api_key_in:
  - query
  - header
schemes:
- name: apiKeyQuery
  type: apiKey
  in: query
  parameter: api_key
  sources:
  - openapi/amazon-scraper-api-openapi-original.json
  - https://amazonscraperapi.com/docs/guides/authentication
- name: apiKeyHeader
  type: apiKey
  in: header
  parameter: X-API-Key
  note: Documented in the provider's ai-plugin.json and published Claude Skills; not declared in the OpenAPI securitySchemes.
  sources:
  - well-known/amazon-scraper-api-ai-plugin.json
  - skills/amazon-scraper-api-scrape-amazon-product.md
- name: bearerAuth
  type: http
  scheme: bearer
  note: Authorization Bearer with the same API key, per ai-plugin.json and the OpenAPI.
  sources:
  - openapi/amazon-scraper-api-openapi-original.json
key_format:
  prefixes:
  - prefix: asa_live_
    meaning: Production traffic
  - prefix: asa_test_
    meaning: Sandbox keys (roadmap only - not yet live; would return deterministic fixtures and never bill)
  shortprefix: 12 characters after the prefix identify a key in the dashboard and logs without revealing the secret
management:
  console: https://app.amazonscraperapi.com
  max_active_keys_per_workspace: 20
  rotation: Generate a second key, deploy, revoke the old one; revocation is global within ~30 seconds and revoked keys return 401 {"error":"revoked"}
  usage_retention_after_revoke: 90 days
notes:
- Unauthorized (401) requests are never billed.
- Keys are workspace-scoped; the monthly credit allowance is per workspace, not per key.
- IP allow-lists are on the roadmap for Pro and Custom plans.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/amazon-scraper-api-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.