ScrapingBee
ScrapingBee is a web scraping API that handles proxies, headless browsers and anti-bot defences for you, returning raw HTML, Markdown, structured JSON or screenshots. Built for developers, founders and product teams collecting public web data at scale.
What is ScrapingBee?
ScrapingBee is a web scraping API published by VostokInc, a French SAS incorporated on 23 October 2018. The product first shipped as ScrapingNinja before being renamed, and the domain scrapingbee.com was registered on 18 September 2019. Co-founders Pierre de Wulf and Kevin Sahin, the latter the author of the Java Web Scraping Handbook, still run it after the product joined the Oxylabs group, where it keeps operating as a separate product and entity. The promise is narrow and explicit: collect public web data without managing proxies, browsers or anti-bot defences yourself. You send a URL to a single endpoint and receive raw HTML, a rendered page, clean Markdown, structured JSON or a screenshot. JavaScript rendering runs in headless Chrome by default and costs 5 credits per request; a JavaScript scenario can click, scroll and fill forms before extraction. Proxies rotate automatically, with premium residential and stealth options and country-level geotargeting. Extraction works either through CSS and XPath rules or through AI Query, where you describe the fields you want in plain English. On top of the generic API sit pre-parsed vertical endpoints for Amazon, Walmart, Google Search, Fast Search (under one second), YouTube, ChatGPT, Gemini and Employee Search. Access paths include Python and Node.js SDKs, a CLI, a remote MCP server, LangChain and no-code connectors for n8n, Make and Zapier, which makes the tool usable well beyond engineering teams. The homepage advertises 4,000+ developers, a 99% success rate and a 2.5-second median on the e-commerce API, while its structured data declares a 4.9 rating over 118 reviews. Commercially it is a monthly credit subscription from 49 USD excluding VAT, with no permanent free tier: a single request costs between 1 and 75 credits depending on the options you enable, which is the real variable in the bill. On compliance, the publisher holds SOC 2 Type II, publishes a detailed DPA with named sub-processors, and serves its APIs mainly from the EU, while the marketing site sits on Netlify in the United States. The terms restrict the service to professional activity only.
What it does
- Fetch the raw HTML of any public page with a single API call
- Render JavaScript in a headless Chrome, wait for a selector, then click, scroll or fill forms before extracting
- Extract fields as JSON through CSS and XPath rules or through a plain-English AI query
- Convert any page into clean Markdown or text ready for an LLM
- Rotate proxies automatically, switch to premium or stealth proxies and geotarget by country
- Query dedicated endpoints for Amazon, Google Search, Fast Search, YouTube, Walmart, ChatGPT and Gemini
- Plug scraping into n8n, Make or Zapier, or into a coding agent through the MCP server
When to use ScrapingBee / When not to
A quick filter to help you decide if ScrapingBee is the right fit.
When to use ScrapingBee
- Back-end and full-stack developers who need public web data at scale without maintaining proxies, headless browsers or anti-bot workarounds
- AI and LLM teams building RAG or agent pipelines, using sub-second Fast Search results, clean Markdown output and structured JSON
- E-commerce and market intelligence teams tracking prices, catalogues and reviews through the dedicated Amazon, Walmart and Google Search endpoints
- Growth, SEO and GEO specialists monitoring search visibility and enriching leads, including from n8n, Make or Zapier without writing code
- Fintech and cybersecurity analysts collecting alternative data, regulatory news, leaked credentials and attack-surface signals
When not to use ScrapingBee
- Individuals scraping for personal projects: the terms state that use of the API or the Services for personal purposes is strictly forbidden
- Anyone under 18, the contractual minimum age set by both the terms and the privacy policy
- Teams that need data sitting behind a login, since the acceptable use policy forbids collecting non-public data
- Anyone chasing SEO manipulation, fake engagement, ticket bots, paid surveys, click fraud, lotteries or crypto and NFT schemes, all banned by the acceptable use policy
- Occasional and mobile-first users: there is no permanent free tier, no mobile app, no browser extension, and entry starts at 49 USD per month excluding VAT
How to use ScrapingBee
A typical end-to-end flow, from setup to results.
- Create an account with an email and password or Google SSO; no credit card is required
- Copy your API key from the dashboard at dashboard.scrapingbee.com
- Send a first request to https://app.scrapingbee.com/api/v1 with the api_key and url parameters; one line of curl is enough
- Or build the call visually in the dashboard request builder: pick the endpoint, set the parameters, run a test and read the response
- Move to the official Python or Node.js SDK, or copy the Java, Ruby, PHP, Go or JavaScript snippets from the documentation; a Postman collection covers every feature
- Tune the rendering: JavaScript is on by default, add a wait for a selector, or pass a js_scenario for clicks, scrolls and form filling
- Choose an extraction mode: extract_rules for CSS and XPath, or ai_query and ai_extract_rules to describe the fields in plain English
- Add advanced options as needed: premium_proxy, stealth_proxy, country_code, screenshot, and max_cost to cap what Auto-Mode may spend
- For no-code or agent use, wire the n8n node, the Make module, the Zapier zap, the MCP server or the CLI instead of calling the API directly
- Track consumption on the /usage endpoint, capped at six calls per minute, and quote the Spb-request-id returned with each response when contacting support
Pros & Cons
Pros
- Complete public pricing with no sales gate, and billing limited to successful requests returning HTTP 200, 404 or 410
- Auto-Mode charges nothing when no configuration succeeds, and cancellation takes under thirty seconds from the dashboard, with no justification required
- European publisher under French law and CNIL oversight, with APIs served mainly from the EU: Google Cloud Paris and Datapacket in the Netherlands, France and the Czech Republic
- Public and detailed DPA listing every sub-processor by name, country and transfer mechanism, backed by a SOC 2 Type II audit whose report, or an ISO 27001 certificate, is supplied on request
- Scraped response content is never logged and API logs are deleted after fourteen days
- Solid developer material: full documentation, a Postman collection, Python and Node.js SDKs, snippets in eight or more languages, and integrations with n8n, Make, Zapier, MCP, LangChain, IDEs and coding agents
- 1,000 trial credits without a credit card, a Capterra rating of 4.9 out of 5 over 118 reviews, and a post-acquisition price cut taking Google API calls from 25 to 15 credits
Cons
- No permanent free tier: the 1,000 credits are a one-off trial, and entry starts at 49 USD per month excluding VAT, which is steep for occasional use
- Credits never roll over: whatever is left at the end of a cycle expires, and everything remaining is forfeited when the account is closed
- The real cost of a request swings from 1 to 75 credits depending on the options, so the headline price says nothing about the usable volume
- The terms formally forbid personal use, reserving the service to professional activity, and set a minimum age of 18
- Liability is capped at 50% of the amounts collected over the previous six months, claims lapse after one year, no availability or result is guaranteed, and the service may be interrupted without notice
- Legal responsibility for what is scraped rests entirely with the customer, and the publisher may block content at its sole discretion without notification
- No mobile app and no browser extension, an English-only interface and documentation, a Trust Center readable only with a JavaScript browser, and a SIREN number in the DPA that does not exist in the French register
Pricing & Plans
There is no permanent free plan. Access starts with a one-off trial of 1,000 API credits granted at sign-up, without a credit card. Beyond that trial, the lowest paid entry point is the Freelance plan at 49.00 USD per month, exclusive of VAT, which includes 250,000 credits and 50 concurrent requests. Three further tiers follow at 99, 249 and 599 USD per month, plus a Custom plan priced on request. Billing is monthly or annual, payable in advance and renewed automatically, and all amounts are stated in United States dollars, exclusive of tax. Buyers should note that a single request consumes between 1 and 75 credits depending on the options enabled: 1 credit for a plain request, 5 by default with JavaScript rendering, 10 or 25 with a premium proxy, 75 with a stealth proxy, and 5 more for AI extraction. Google Search API and HTML API calls have cost 15 credits since the acquisition, down from 25. Mid-cycle upgrades, early renewals and one-off add-ons are available.
- 49 USD per month
- 250
- 000 credits
- 50 concurrent requests
- 99 USD per month
- 1
- 000
- 000 credits
- 100 concurrent requests
- flagged Recommended on the pricing page
- 249 USD per month
- 3
- 000
- 000 credits
- 200 concurrent requests
- 599 USD per month
- 8
- 000
- 000 credits
- 400 concurrent requests
- credits and concurrency quoted on request
- through a Let’s talk contact form
- new accounts get a one-off trial of 1
- 000 credits without a credit card
- Every tier includes JavaScript rendering
- rotating and premium proxies
- geotargeting
- screenshots
- extraction rules and the Google Search API
- while dedicated scraping APIs
- priority email support
- a dedicated account manager and team management are reserved for the higher tiers
Data, GDPR & hosting
A consolidated view of how ScrapingBee handles your data.
GDPR overview
GDPR implementation is documented and concrete. A dedicated GDPR notice took effect on 22 July 2024, alongside a privacy policy and terms effective 15 July 2024 and a data processing agreement revised on 23 March 2026, published openly and accepted when an account is opened. As a French SAS, the publisher applies the GDPR and French law 78-17, and names the CNIL as supervisory authority. Legal bases invoked are consent, contract, legitimate interest and legal obligation. Access, rectification, erasure, restriction, portability and objection are covered, exercised at contact@scrapingbee.com or by post to Paris, with proof of identity requested. Transfers outside the EEA rely on the 2021 standard contractual clauses, module 2, plus the ICO’s IDTA for the United Kingdom. No article 27 representative is designated, the publisher being EU-established. A SOC 2 Type II report or an ISO 27001 certificate is supplied on request.
Who owns the data?
Two roles coexist. For account, billing and support data, the publisher VostokInc acts as data controller under its privacy policy. For the personal data contained in the pages you scrape it is only a processor, and you are the controller: the DPA states that the scope of scraped content is “determined solely by the Customer”. You therefore keep your extractions, and you carry the warranty that you hold every right and consent they require. When the contract ends, the DPA offers a full machine-readable copy and/or secure deletion within thirty days, with a deletion certificate on request; the terms add that closing an account permanently erases your data and forfeits any remaining credits, without compensation.
Reuse rights
What you extract is yours to reuse: the publisher claims no licence over scraped content. The counterpart is that the terms make you responsible for reading each target site’s own terms and privacy policy, for checking whether it prohibits scraping before every extraction, for holding the rights and consents your operations require, and for indemnifying the publisher if you do not. On its own side, article 6.2 of the DPA forbids processing personal data for any purpose other than providing the Services under your documented instructions, while article 6.1 limits the publisher to aggregated and anonymised technical data — response times, error rates, load, usage patterns — used for service health and platform improvement. The GDPR page adds that response content is not logged, only requests. No clause in the terms, the privacy policy, the DPA or the GDPR page mentions training AI models on customer data. Business contacts are processed under a separate independent-controller role for invoicing, account management, support and compliance checks, and marketing emails sent through Customer.io can be unsubscribed from at any time.
Data retention & training
Hosting summary
Exhibit 1 of the data processing agreement states that processing locations are “primarily EU”. The version revised in March 2026 names Google Cloud Platform in Paris as the main host, with multi-datacentre EU backup, Datapacket dedicated servers in the Netherlands, France and the Czech Republic, and Crisp IM SAS in France for live chat and support. Four United States sub-processors operate under the 2021 standard contractual clauses, module 2: Customer.io for email, Datadog for logs and monitoring, Chargebee for invoicing and Stripe for payment. Transfers outside the EEA rely only on chapter V mechanisms, with the ICO’s IDTA covering the United Kingdom. Two of the publisher own documents disagree, however: the GDPR page and the legal notices, both from July 2024, declare Netlify Inc in San Francisco for the marketing site and Clever Cloud SAS in Nantes for the API servers. The domain itself resolves to a United States address, 3.131.150.69, on Amazon AS16509 in Columbus. Jurisdiction remains French throughout.
Things to keep in mind
Risks and trade-offs to weigh before adopting ScrapingBee.
- Contradictory terms of use: article 6 strictly forbids personal use of the API, yet the same list also forbids using the Services in a commercial manner, and the acquisition blog post claims customers using ScrapingBee for both personal and professional projects. Establish which clause actually binds you before committing budget.
- Legal responsibility for scraping is transferred to you in full. The terms require you to read the terms and privacy policies of the targeted websites, to check for a scraping prohibition before every extraction, to hold all rights and consents, and to indemnify the publisher. Scraping is lawful or not depending on the target and the jurisdiction, and the publisher does not check what you do.
- Identity mismatch in the paperwork: the DPA revised on 23 March 2026 quotes SIREN 882 964 115, which returns no result in the French company register, while the legal notices, the terms, the privacy policy and the GDPR page all quote 843 352 683, matching VOSTOKINC. That is a contractual defect worth raising with the publisher.
- Hosting is described differently in two of the publisher own documents: the 2024 GDPR page names Clever Cloud for the API servers and Netlify for the site, whereas the 2026 DPA names Google Cloud Platform in Paris and Datapacket. If your compliance file depends on the answer, ask for written confirmation.
- Stale or inconsistent published material: the terms describe scraping configurations uploaded and shared by other users, a feature that does not exist in the product; they link pricing to a homepage anchor while the grid lives on a separate page; the site still publishes an Oxylabs alternative page against what is now its parent company; the homepage shows a 5.0 rating over 100+ reviews while its structured data declares 4.9 over 118; and the acquisition post is dated 19 January 2026 although the press dates the announcement to June 2025.
- Cost drift is easy: a request costs 1 to 75 credits, credits never roll over, and the balance is forfeited when the account closes. Without a max_cost ceiling and monitoring on the /usage endpoint, one misconfigured job can burn a monthly quota.
- Discretionary blocking and thin guarantees: the publisher may proactively block adult, governmental or harmful domains at its sole discretion and without notice, guarantees neither availability nor result, caps liability at 50% of six months of fees and closes claims after one year. There is also no contact, about or demo page, since all three URLs return 404.
Setup & Integrations
Technical difficulty
Low to moderate, and developer-oriented by design. The main path is a single authenticated HTTP call: once the API key is copied from the dashboard, one line of curl returns a page. Official Python and Node.js SDKs, snippets in Java, Ruby, PHP, Go and JavaScript, a Postman collection and a visual request builder shorten the first mile, and a genuine no-code route exists through n8n, Make, Zapier, the MCP server and the CLI. Nothing has to be installed: no proxies, no browsers, no containers. The real difficulty lies further on, in tuning options and controlling their credit cost.
Deployment
Integrations
Supported languages
Behind ScrapingBee
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement ScrapingBee.
Frequently asked questions
What exactly is a web scraping API?
Is there a free trial or a free plan?
How much does a single request cost?
What happens when a request fails?
Do unused credits roll over to the next month?
Can I cancel at any time?
Do I need to know how to code?
Are there age or usage restrictions?
Where is the data hosted?
Is my data used to train AI models?
Should you pick ScrapingBee?
ScrapingBee is infrastructure, not a content tool: it does not create anything, it gives you reliable access to public web data. The positioning is unambiguously aimed at developers and technical teams, with genuine no-code bridges through n8n, Make, Zapier, an MCP server and a CLI for anyone who does not want to write requests by hand. Pricing is public and readable, from 49 USD per month excluding VAT, but its readability stops at the tiers: what a plan actually buys depends entirely on the credit cost of the options you enable, from 1 to 75 per request. Budget on your real configuration, not on the credit count advertised, and remember there is no permanent free plan, only a one-off trial of 1,000 credits. The legal framing is among the strongest points: French law, the CNIL as supervisory authority, a public and detailed DPA with named sub-processors, standard contractual clauses for transfers, SOC 2 Type II, response content never logged and logs deleted after fourteen days. The counterpart is blunt: legal responsibility for what you scrape sits entirely with you, and you must check each target site’s terms, hold the rights and consents your extractions require, and indemnify the publisher. Three reservations remain open. The DPA quotes a SIREN number that returns no result in the French register, while four other legal pages quote the valid one. The announced hosting differs between the 2024 GDPR page, which names Clever Cloud and Netlify, and the 2026 DPA, which names Google Cloud Paris and Datapacket. And the terms forbid personal use outright, which contradicts the publisher own acquisition post. The product is now backed by the Oxylabs group, run separately, and still actively developed.
- Choosing a selection results in a full page refresh.
- Opens in a new window.