Skip to content

API Providers Guide

TokGrab does not scrape TikTok directly. It calls a data provider API that returns TikTok profile and video data as JSON. You choose the provider and supply your own keys.

This keeps the script flexible: if one provider changes, is slow, or gets expensive, you can switch to another without touching code.


Where to configure

Admin → Settings → API Providers

TokGrab supports five provider modes. The active one is selected in the dropdown:

Provider Best for Key field
RapidAPI (default) Most buyers; a ready-made TikTok scraper on RapidAPI RAPIDAPI_KEY
TikWM API Simple setup with a direct TikWM key TIKWM_API_KEY
TikAPI Advanced/higher-limit direct API TIKAPI_API_KEY
Custom API Any API that follows TokGrab's request paths (incl. your own) your own header
Apify (advanced) Apify users who also have a compatible API service APIFY_API_TOKEN

Each provider keeps its own saved profile — base URL, host, keys, and auth settings. Switching the active provider does not delete the others, so you can switch back anytime.

Always click Test Connection

After entering credentials, use Test Connection to confirm the provider works before you send traffic to your live site.


What TokGrab calls

The provider must answer three request paths:

Purpose Path Example parameters
Profile info /user/info unique_id=username
User's videos /user/posts unique_id=username, count=15, cursor=...
Single video / url=https://www.tiktok.com/...

Responses are read flexibly — both the common flat format (tiktok-scraper7 style) and the nested aweme_list format are supported, so many providers work out of the box.


Provider 1: RapidAPI (Default)

Recommended starting point. Default host: tiktok-scraper7.p.rapidapi.com.

  1. Create a RapidAPI account and subscribe to a TikTok scraper API.
  2. Copy your API key.
  3. In Admin → Settings → API Providers, choose RapidAPI (default).
  4. Enter the Base URL and Host from the provider's endpoint (see the note below).
  5. Paste the key into Primary Key (and optionally Secondary Key).
  6. Click Test Connection.

RapidAPI auth defaults are preset for you: header x-rapidapi-key plus x-rapidapi-host.

Request URL vs endpoint domain

The “Request URL” shown in the RapidAPI dashboard is not the base endpoint the app calls. Use the provider's endpoint domain for the Base URL (e.g. https://tiktok-scraper7.p.rapidapi.com) and the same host for Host.


Provider 2: TikWM API

A direct TikWM key. Default base URL: https://api.tikwmapi.com.

  1. Get your TikWM API key.
  2. In Admin → Settings → API Providers, choose TikWM API.
  3. Paste the key into Primary Key (and optionally Secondary Key).
  4. Leave the service URL unchanged unless TikWM gives you a different one.
  5. Click Test Connection.

Provider 3: TikAPI

A direct TikAPI key. Default base URL: https://api.tikapi.io.

  1. Get your TikAPI key.
  2. In Admin → Settings → API Providers, choose TikAPI.
  3. Paste the key into Primary Key (and optionally Secondary Key).
  4. Leave the service URL unchanged unless TikAPI gives you a different one.
  5. Click Test Connection.

Provider 4: Custom Endpoint (Bring Your Own API)

Use this to connect any API that follows the three paths above — including your own hosted service.

  1. In Admin → Settings → API Providers, choose Custom API.
  2. Enter the Base URL of your API.
  3. Set the auth header and scheme your API expects, for example:
    • Authorization + Bearer (a token in the request header), or
    • a custom header name with no scheme.
  4. Optionally set a host header if your API expects one.
  5. Add your key and click Test Connection.

If your API returns a different JSON shape, the normalizer in app/Services/TikTokService.php (normalizePost()) can be extended to map your fields.


Provider 5: Apify (advanced)

  1. Create an Apify account and get an API token.
  2. In Admin → Settings → API Providers, choose Apify (advanced).
  3. Enter the Base URL for your actor's run API and your token.
  4. Auth defaults to the Authorization: Bearer header.
  5. Click Test Connection.

Apify is more robust but slower and usually costs more per request than RapidAPI. It also generally needs an extra compatible API service for live lookups.


Automatic fallback (reliability)

When enabled, TokGrab can try more than one provider if the active one fails. Fallback order:

TikWM → RapidAPI → TikAPI → Custom → Apify

Enable or disable this in Admin → Settings → API Providers (fallback toggle). Leave it off if you only configure one provider.


API key rotation (reliability)

TokGrab can rotate across multiple keys automatically:

  • Primary Key + Secondary Key, or
  • a comma-separated list of keys.

If a key returns 401, 403, 429 (rate limit), or a server error, the app tries the next key. The last key that works is used for that request. This reduces downtime when one key hits its quota.


Caching (save quota)

Profile and video responses are cached to lower API usage and speed up pages. TokGrab caches per content type:

Cache Default Where
Profile 300 s Settings → API Providers (advanced)
Posts 300 s Settings → API Providers (advanced)
Video 300 s Settings → API Providers (advanced)

Increase the TTLs to save API quota; decrease them for fresher data.


Rate limits (protect your quota)

TokGrab throttles abusive traffic per IP before it reaches your provider:

Action Default (per minute)
Search 20
Download 30
Stream 30
Image proxy 60

These are configurable in Admin → Settings → API Providers (advanced).


Troubleshooting

"All API keys have failed"

  • Check the Base URL and Host match the provider's endpoint (not the dashboard “Request URL”).
  • Confirm the key is active and has remaining quota.
  • Verify your hosting allows outbound HTTP/cURL.

Connection test fails with an SSL error (common on local Windows)

PHP needs a valid CA bundle. Point curl.cainfo / openssl.cafile to a cacert.pem file, or let the app use the system bundle. This is a local/server SSL issue, not an API credential issue.

Videos have a watermark

TokGrab prefers no-watermark URLs, but the watermark depends entirely on what the provider returns. Choose a provider that offers no-watermark links.

Switching providers

Switching the active provider never deletes the other provider's saved settings. If a lookup starts failing after a switch, re-run Test Connection for the newly active provider.


TokGrab is provider-agnostic and ships with no API keys. You are responsible for choosing a provider and using it within its terms of service and applicable law, including TikTok's terms and copyright rules. Keeping the buyer responsible for their own provider and keys is the recommended, lower-risk setup.