Autopass API
Autopass returns a valid Search Guard SG_SS token for your
requests. Send us the challenge page, get a token back, attach it to your request. This
page explains how to set it up, what it returns, & what each returned value is.
Quick start
Every request needs your API key. Grab it from your
dashboard after signing up. The flow is: request a token
from Autopass, then attach it as the SG_SS cookie on your
own request.
curl -X POST "https://solve.autopia.top/token" \ -H "x-api-key: AUT_abc..." \ -H "content-type: application/json" \ -d '{ "html": "<base64 of the challenge page>", "took": "how long it took to fetch challenge page (ms)", "zone": "The timezone of your IP" }'
Authentication
Authenticate every request with your API key in the
x-api-key header. Requests without a valid key return
401 Unauthorized.
x-api-key: AUT_abc...
Get a solution
Submits a challenge page & returns a valid token. Send a JSON body:
| Field | Type | Description |
|---|---|---|
| html required | string | The challenge page, Base64-encoded. |
| took | number | Optional. Milliseconds your first request took, used to tune timing. |
| zone | string |
Optional. Your exit timezone (e.g. America/New_York)
when routing through a proxy.
|
POST /token Content-Type: application/json x-api-key: AUT_abc... { "html": "PGh0bWw+…" }
Response
A 200 OK returns the token plus metadata to pair with your
next request:
| Field | Type | Description |
|---|---|---|
| token | string | The value to set as the SG_SS cookie. |
| sei | string | The sei parameter for the second request. |
| connection | object | { downlink, rtt } hints for your client. |
| accept-language | string | The accept-language header in your request |
{
"accept-language": "en-US,en;q=0.9",
"connection": {
"downlink": 1.4,
"effectiveType": "4g",
"rtt": 100
},
"sei": QtLCar30FavRkPIPz...
"token": *mKSapMDyAAbOW0Se7lt9EjKjJ7vFj...
}
Errors
Errors return a non-200 status and a JSON body with an
error message.
| Status | Description |
|---|---|
| 400 | Missing required fields such as html. |
| 401 | Missing or invalid API key. |
| 402 | Plan has ended, check dashboard to renew. |
| 429 | Exceeded 10,000 RPM. |
| 5xx | Server issue, contact support if persistent. |
{ "error": "quota exceeded" }
Rate limits & RPM
Autopass sustains 10,000+ tokens per minute (TPM, inline with RPM).
There is no maximum requests; only a maximum RPM (unless you require more). If you hit
429, simply tone down the concurrency.
Quota & billing
The free trial includes 50 solutions. Each successful token is one solution; failed tokens don't count. Autopass Unlimited is a flat $2,500/week with no per-request metering and no overage fees. Manage your plan and get your key in the dashboard.
Best practices
- Capture the NID cookie of a successful request, you can re-use it for a few searches before requiring a new token.
- Send the challenge page exactly as received, Base64-encoded, without modifying it.
-
Retry
5xxand429with lowered concurrency; don't retry400/401. - Don't leak your API key, your RPM will be affected, slowing your productivity.
Support
Questions or higher volume needs? Contact us on Telegram or Discord.
Autopia