generated: '2026-10-07' method: searched source: https://docs.mrscraper.com/docs/api/authentication docs: https://docs.mrscraper.com/docs/api/authentication summary: types: [apiKey, oauth2] api_key_in: [header, query] note: Every REST endpoint takes a MrScraper API token in the x-api-token header; Marketplace endpoints take the same token as an RFC 6750 Bearer; the Scraper API also accepts the token as a `token` query parameter. The hosted MCP server is OAuth 2.1 (authorization code + PKCE) with an API-key Bearer fallback. schemes: - name: ApiKeyAuth type: apiKey in: header parameter: x-api-token description: MrScraper API token created at https://app.mrscraper.com/api-tokens (name + expiration date). Required on every Platform API and Scraper API request. Analytics endpoints accept an `apiTokenName` query filter. docs: https://docs.mrscraper.com/docs/getting-started/api-token sources: - https://docs.mrscraper.com/docs/api/authentication - openapi/mrscraper-scraper-service-gateway-openapi.yml - name: BearerAuth type: http scheme: bearer description: '"Authorization: Bearer " - the same MrScraper API token for Marketplace endpoints (RFC 6750), or an OAuth 2.1 access token issued by the platform for the MCP connector.' sources: - https://docs.mrscraper.com/docs/api/authentication - openapi/mrscraper-scraper-service-gateway-openapi.yml - name: TokenQuery type: apiKey in: query parameter: token description: The Scraper API (GET https://api.mrscraper.com/?url=...) also accepts the API token as a `token` query parameter, as shown on the Response Headers page. sources: - https://docs.mrscraper.com/docs/api/response-headers - openapi/mrscraper-scraper-service-gateway-openapi.yml - name: McpOAuth type: oauth2 description: OAuth 2.1 for the hosted MCP endpoint https://mcp.mrscraper.com/mcp - RFC 9728 protected-resource metadata, RFC 8414 authorization-server metadata, PKCE S256, dynamic client registration, refresh tokens. A tool called without its scope returns 403 insufficient_scope. flows: authorizationCode: authorizationUrl: https://api.app.mrscraper.com/oauth/authorize tokenUrl: https://api.app.mrscraper.com/oauth/token refreshUrl: https://api.app.mrscraper.com/oauth/token scopes: scrape:read: fetch, serp, results, result scrape:write: scrape, rerun account:read: status offline_access: refresh token sources: - https://mcp.mrscraper.com/.well-known/oauth-protected-resource/mcp - https://api.app.mrscraper.com/.well-known/oauth-authorization-server - https://docs.mrscraper.com/docs/getting-started/mcp-server