Authentication
DataFuel uses two kinds of API key. Which one you send depends on the API.
| API | Key | Header |
|---|---|---|
| User API, Proxy API | df_live_…, created in the dashboard under Settings → API keys, with scopes | Authorization: Bearer <key> |
| Scraping API | Your scraping plan’s key, df_key_… | X-API-Key: df_key_… |
| Proxy gateway | Proxy username and password | Proxy authentication |
Keep every key server-side. Never call the APIs from a browser or an app you ship to users.
User API and Proxy API
Send a dashboard API key as a Bearer token:
curl https://api.datafuel.ai/api/v1/account \
--header 'Authorization: Bearer df_live_your_key_here'
Each key has scopes, and every operation names the scope it needs (api.residential.read, api.static.purchase, …). A key without it answers 403 with the missing scope in meta.required. A missing, expired or revoked key answers 401. See Errors & limits for every error code.
Scraping API
Send your scraping key in the X-API-Key header. Keys look like df_key_… (32 characters after the prefix).
curl https://scraping-api.datafuel.ai/api/v1/users/@me/balance \
--header 'X-API-Key: df_key_your_key_here'
Authorization: Bearer df_key_… is accepted too; X-API-Key wins when both are sent. A missing or unknown key answers 401, a deactivated account 403.
Credits are charged per task when it is queued and refunded if it fails. Check remaining credits with GET /users/@me/balance; concurrency and monthly limits are on GET /users/@me. Your scraping key itself is managed through the User API, under Web scraping.
Proxies authenticate on the gateway with a username and password. See Proxies.