Autopass API

Autopass returns a valid Search Guard SG_SS token for your requests. Send us the challenge page, get a token back, attach it to your request. This page explains how to set it up, what it returns, & what each returned value is.

Quick start

Every request needs your API key. Grab it from your dashboard after signing up. The flow is: request a token from Autopass, then attach it as the SG_SS cookie on your own request.

curl -X POST "https://solve.autopia.top/token" \
  -H "x-api-key: AUT_abc..." \
  -H "content-type: application/json" \
  -d '{ 
    "html": "<base64 of the challenge page>", 
    "took": "how long it took to fetch challenge page (ms)", 
    "zone": "The timezone of your IP" 
  }'

Authentication

Authenticate every request with your API key in the x-api-key header. Requests without a valid key return 401 Unauthorized.

x-api-key: AUT_abc...

Get a solution

POST /token

Submits a challenge page & returns a valid token. Send a JSON body:

Field Type Description
html required string The challenge page, Base64-encoded.
took number Optional. Milliseconds your first request took, used to tune timing.
zone string Optional. Your exit timezone (e.g. America/New_York) when routing through a proxy.
POST /token
Content-Type: application/json
x-api-key: AUT_abc...

{
  "html": "PGh0bWw+…"
}

Response

A 200 OK returns the token plus metadata to pair with your next request:

Field Type Description
token string The value to set as the SG_SS cookie.
sei string The sei parameter for the second request.
connection object { downlink, rtt } hints for your client.
accept-language string The accept-language header in your request
{
  "accept-language": "en-US,en;q=0.9",
  "connection": {
        "downlink": 1.4,
        "effectiveType": "4g",
        "rtt": 100
  },
  "sei": QtLCar30FavRkPIPz...
  "token": *mKSapMDyAAbOW0Se7lt9EjKjJ7vFj...
}

Errors

Errors return a non-200 status and a JSON body with an error message.

Status Description
400 Missing required fields such as html.
401 Missing or invalid API key.
402 Plan has ended, check dashboard to renew.
429 Exceeded 10,000 RPM.
5xx Server issue, contact support if persistent.
{ "error": "quota exceeded" }

Rate limits & RPM

Autopass sustains 10,000+ tokens per minute (TPM, inline with RPM). There is no maximum requests; only a maximum RPM (unless you require more). If you hit 429, simply tone down the concurrency.

Quota & billing

The free trial includes 50 solutions. Each successful token is one solution; failed tokens don't count. Autopass Unlimited is a flat $2,500/week with no per-request metering and no overage fees. Manage your plan and get your key in the dashboard.

Best practices

  • Capture the NID cookie of a successful request, you can re-use it for a few searches before requiring a new token.
  • Send the challenge page exactly as received, Base64-encoded, without modifying it.
  • Retry 5xx and 429 with lowered concurrency; don't retry 400/401.
  • Don't leak your API key, your RPM will be affected, slowing your productivity.

Support

Questions or higher volume needs? Contact us on Telegram or Discord.