Skip to main content
Every Simkl API request needs three URL parameters that identify your app, plus a User-Agent header. Endpoints that read or write user data also need an Authorization: Bearer token — and the cached catalog endpoints want you to leave that header off.

Required URL parameters

Append these to every request URL — both public catalog calls and authenticated user calls:
These three parameters help us see which apps are using the API, debug issues you report, and route around outages. They’re cheap to send — please always include them.

Required HTTP headers

Do not send Authorization on the Cloudflare-cached endpoints. An Authorization header makes Cloudflare treat the request as private and stop serving it from the edge, so the call goes to Simkl’s origin instead — slower for your user, and heavier for everyone else, for a response that is identical either way.Send it on nothing in this list:These carry no per-user state, so a token changes nothing about the response. They are the same endpoints that need no user token at all, including on AUTH V2, and that do not count against your quota.The three URL parameters and the User-Agent header are still required on these calls. Only Authorization comes off.
As an alternative to the client_id query parameter, you may pass it as a simkl-api-key header. Either works; query-param form is preferred because it makes the request fully self-describing in URL form.

Putting it together

A typical authenticated call looks like:
A cached catalog call looks like — note the absence of Authorization, even if your app is holding a perfectly good token:
In the API Reference playground these values are auto-filled — paste your client_id, app-name, app-version, and access_token once and they’ll be reused.

HTTP verbs

The full list of status codes Simkl returns lives on the Errors page.