API Providers Guide
TokGrab does not scrape TikTok directly. It calls a data provider API that returns TikTok profile and video data as JSON. You choose the provider and supply your own keys.
This keeps the script flexible: if one provider changes, is slow, or gets expensive, you can switch to another without touching code.
Where to configure
Admin → Settings → API Providers
TokGrab supports five provider modes. The active one is selected in the dropdown:
| Provider | Best for | Key field |
|---|---|---|
| RapidAPI (default) | Most buyers; a ready-made TikTok scraper on RapidAPI | RAPIDAPI_KEY |
| TikWM API | Simple setup with a direct TikWM key | TIKWM_API_KEY |
| TikAPI | Advanced/higher-limit direct API | TIKAPI_API_KEY |
| Custom API | Any API that follows TokGrab's request paths (incl. your own) | your own header |
| Apify (advanced) | Apify users who also have a compatible API service | APIFY_API_TOKEN |
Each provider keeps its own saved profile — base URL, host, keys, and auth settings. Switching the active provider does not delete the others, so you can switch back anytime.
Always click Test Connection
After entering credentials, use Test Connection to confirm the provider works before you send traffic to your live site.
What TokGrab calls
The provider must answer three request paths:
| Purpose | Path | Example parameters |
|---|---|---|
| Profile info | /user/info |
unique_id=username |
| User's videos | /user/posts |
unique_id=username, count=15, cursor=... |
| Single video | / |
url=https://www.tiktok.com/... |
Responses are read flexibly — both the common flat format (tiktok-scraper7 style) and the
nested aweme_list format are supported, so many providers work out of the box.
Provider 1: RapidAPI (Default)
Recommended starting point. Default host: tiktok-scraper7.p.rapidapi.com.
- Create a RapidAPI account and subscribe to a TikTok scraper API.
- Copy your API key.
- In Admin → Settings → API Providers, choose RapidAPI (default).
- Enter the Base URL and Host from the provider's endpoint (see the note below).
- Paste the key into Primary Key (and optionally Secondary Key).
- Click Test Connection.
RapidAPI auth defaults are preset for you: header x-rapidapi-key plus x-rapidapi-host.
Request URL vs endpoint domain
The “Request URL” shown in the RapidAPI dashboard is not the base endpoint the app
calls. Use the provider's endpoint domain for the Base URL
(e.g. https://tiktok-scraper7.p.rapidapi.com) and the same host for Host.
Provider 2: TikWM API
A direct TikWM key. Default base URL: https://api.tikwmapi.com.
- Get your TikWM API key.
- In Admin → Settings → API Providers, choose TikWM API.
- Paste the key into Primary Key (and optionally Secondary Key).
- Leave the service URL unchanged unless TikWM gives you a different one.
- Click Test Connection.
Provider 3: TikAPI
A direct TikAPI key. Default base URL: https://api.tikapi.io.
- Get your TikAPI key.
- In Admin → Settings → API Providers, choose TikAPI.
- Paste the key into Primary Key (and optionally Secondary Key).
- Leave the service URL unchanged unless TikAPI gives you a different one.
- Click Test Connection.
Provider 4: Custom Endpoint (Bring Your Own API)
Use this to connect any API that follows the three paths above — including your own hosted service.
- In Admin → Settings → API Providers, choose Custom API.
- Enter the Base URL of your API.
- Set the auth header and scheme your API expects, for example:
Authorization+Bearer(a token in the request header), or- a custom header name with no scheme.
- Optionally set a host header if your API expects one.
- Add your key and click Test Connection.
If your API returns a different JSON shape, the normalizer in
app/Services/TikTokService.php (normalizePost()) can be extended to map your fields.
Provider 5: Apify (advanced)
- Create an Apify account and get an API token.
- In Admin → Settings → API Providers, choose Apify (advanced).
- Enter the Base URL for your actor's run API and your token.
- Auth defaults to the
Authorization: Bearerheader. - Click Test Connection.
Apify is more robust but slower and usually costs more per request than RapidAPI. It also generally needs an extra compatible API service for live lookups.
Automatic fallback (reliability)
When enabled, TokGrab can try more than one provider if the active one fails. Fallback order:
Enable or disable this in Admin → Settings → API Providers (fallback toggle). Leave it off if you only configure one provider.
API key rotation (reliability)
TokGrab can rotate across multiple keys automatically:
- Primary Key + Secondary Key, or
- a comma-separated list of keys.
If a key returns 401, 403, 429 (rate limit), or a server error, the app tries the next
key. The last key that works is used for that request. This reduces downtime when one key hits
its quota.
Caching (save quota)
Profile and video responses are cached to lower API usage and speed up pages. TokGrab caches per content type:
| Cache | Default | Where |
|---|---|---|
| Profile | 300 s | Settings → API Providers (advanced) |
| Posts | 300 s | Settings → API Providers (advanced) |
| Video | 300 s | Settings → API Providers (advanced) |
Increase the TTLs to save API quota; decrease them for fresher data.
Rate limits (protect your quota)
TokGrab throttles abusive traffic per IP before it reaches your provider:
| Action | Default (per minute) |
|---|---|
| Search | 20 |
| Download | 30 |
| Stream | 30 |
| Image proxy | 60 |
These are configurable in Admin → Settings → API Providers (advanced).
Troubleshooting
"All API keys have failed"
- Check the Base URL and Host match the provider's endpoint (not the dashboard “Request URL”).
- Confirm the key is active and has remaining quota.
- Verify your hosting allows outbound HTTP/cURL.
Connection test fails with an SSL error (common on local Windows)
PHP needs a valid CA bundle. Point curl.cainfo / openssl.cafile to a cacert.pem file, or
let the app use the system bundle. This is a local/server SSL issue, not an API credential
issue.
Videos have a watermark
TokGrab prefers no-watermark URLs, but the watermark depends entirely on what the provider returns. Choose a provider that offers no-watermark links.
Switching providers
Switching the active provider never deletes the other provider's saved settings. If a lookup starts failing after a switch, re-run Test Connection for the newly active provider.
Legal note
TokGrab is provider-agnostic and ships with no API keys. You are responsible for choosing a provider and using it within its terms of service and applicable law, including TikTok's terms and copyright rules. Keeping the buyer responsible for their own provider and keys is the recommended, lower-risk setup.