WebCrawlerAPI · Authentication Profile

Webcrawlerapi Com Authentication

Authentication

WebCrawlerAPI secures its APIs with apiKey across 1 declared security scheme, as derived from its OpenAPI definitions.

Web ScrapingWeb CrawlingData ExtractionMarkdownAI AgentsLLMRAGWeb FeedsChange DetectionStructured DataMCPA2AAgent-Native
Methods: apiKey Schemes: 1 OAuth flows: API key in: header

Security Schemes

ApiKeyAuth apiKey
· in: header (Authorization)

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: https://webcrawlerapi.com/docs/access-key + openapi/_original/webcrawlerapi-com-swagger.json (securityDefinitions.ApiKeyAuth)
  + live unauthenticated 401 from api.webcrawlerapi.com observed 2026-09-19 + changelog 2026-03-29 (multiple API
  keys)
docs: https://webcrawlerapi.com/docs/access-key
summary:
  types:
  - apiKey
  api_key_in:
  - header
  style: Bearer token carrying a static API key
  oauth2: false
  openid_connect: false
  mutual_tls: false
schemes:
- name: ApiKeyAuth
  type: apiKey
  in: header
  parameter: Authorization
  format: Bearer {api_key}
  description: 'Docs: "Webcrawler API uses Bearer Token authentication scheme. You need to include the API key in
    the Authorization header" - Authorization: Bearer <API key>. The Swagger document models this as an apiKey scheme
    named Authorization with description "API key for authentication. Format: Bearer {api_key}" rather than as http/bearer;
    the wire format is identical. Applied per operation on 23 of 24 operations; GET /ping is anonymous.'
  obtain: Sign up at https://dash.webcrawlerapi.com/sign-up (no credit card), then copy a key from https://dash.webcrawlerapi.com/access.
  key_management:
    keys_per_organization: 20
    named_keys: true
    default_key: true
    individual_revocation: true
    regenerate: at any time from the dashboard
    source: https://webcrawlerapi.com/changelog/2026-03-29-multiple-api-keys
  admin_key:
    required_for:
    - GET /v2/organization/usage
    source: https://webcrawlerapi.com/docs/api/organization/usage
    note: The usage endpoint docs call for an "admin API key"; the spec declares the same ApiKeyAuth scheme with
      no scope distinction.
  failure:
    status: 401
    body: '{"error":"Unauthorized","message":"No Authorization header. Read the docs: https://webcrawlerapi.com/docs/access-key"}'
    observed: 2026-09-19 on POST /v1/crawl without a header
    docs_example: '{"error": "Unauthorized"}'
  sdk_env_vars:
    mcp_server: WEBCRAWLER_API_KEY
    claude_code_skill: WEBCRAWLERAPI_API_KEY
    cli: stored via `webcr auth set`
  sources:
  - https://webcrawlerapi.com/docs/access-key
  - openapi/webcrawlerapi-com-openapi.yml
scopes: null
scopes_note: No OAuth, no scopes; the only privilege distinction documented is the admin key for usage statistics.
guidance: Keep the key server-side (docs warn against client-side code and public repos). Content URLs on data.webcrawlerapi.com
  returned inside job items are fetched WITHOUT the key.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/webcrawlerapi-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.