Free tools Windows power users keep installed
One-click scans. No signup required.
Start with authorization, not code. AliExpress’s Terms of Use, updated August 26, 2026 and effective September 26, 2026, prohibit systematic retrieval of site content to create collections, databases, or directories without written permission. The Open Platform/API agreement is narrower still: access is purpose-bound, redistribution and circumvention are prohibited, and AliExpress can restrict user or operational data. If you have written permission or an approved API use case, collect the smallest public field set you need, throttle requests, cache results, and keep an audit trail. If you do not have authorization, do not automate AliExpress pages.
What “scraping AliExpress” can mean
People use the word scraping for several different activities. They have different permissions and risks:
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Amazon eGift Card - Amazon Logo | $50.00 | Buy on Amazon |
| 2 |
|
Visa Physical Gift Card $200 (plus $6.95 Purchase Fee) | $206.95 | Buy on Amazon |
| 3 |
|
$500 Apple Gift Card—Email Delivery - Season's greetings | $500.00 | Buy on Amazon |
| 4 |
|
Visa Physical Gift Card $100 (plus $5.95 Purchase Fee) | $105.95 | Buy on Amazon |
| 5 |
|
Visa Virtual eGift Card | $54.95 | Buy on Amazon |
- Official API access: an application uses fields and methods allowed by the Open Platform agreement.
- Permitted public-product collection: you have written permission for a defined set of pages and fields.
- Researcher access: a qualifying researcher uses the European Commission-described route for systemic-risk analysis.
- Unauthorised automation: a bot copies pages, searches, reviews, or account data without a contractual basis. This is the route to avoid.
A page being visible without logging in does not make systematic copying lawful. Terms of use, privacy obligations, intellectual-property rights, database rights where applicable, and local laws still apply.
Can you scrape AliExpress legally?
Read the current Terms of Use first
AliExpress’s current Terms of Use say: “Systematic retrieval of Site Content from the Sites to create or compile, directly or indirectly, a collection, compilation, database or directory … without written permission from AliExpress.com is prohibited.” The same terms require compliance with applicable law and allow action when automated or bot-like activity is detected.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- Amazon.com Gift Cards never expire and carry no fees.
- Multiple gift card designs and denominations to choose from.
- Redeemable towards millions of items store-wide at Amazon.com or certain affiliated websites.
- Available for immediate delivery. Gift cards sent by email can be scheduled up to a year in advance.
- No returns and no refunds on Gift Cards.
That language matters for price trackers and catalog projects: a script that repeatedly gathers product pages into a database is systematic retrieval. Before collecting anything, obtain written permission that identifies the domains, request volume, fields, retention period, and permitted uses.
Understand the API agreement’s limits
The Open Platform/API agreement is an authorized path, not a blanket copying license. It prohibits reverse engineering, redistribution, circumvention, and using user data outside the stated application purpose. It also says AliExpress may restrict or prevent a developer or end user from obtaining user data and operation data. Design your application so it still behaves correctly when a field is unavailable or access is withdrawn.
Keep private and public data separate
Do not collect buyer contact details, private orders, authentication cookies, payment information, or other account data for a public-product project. Seller terms state that Platform Data remains AliExpress or an affiliate’s property and prohibit copying, scraping, extracting, compiling, storing beyond permitted seller purposes, selling, transferring, disclosing, publishing, or distributing it except where required by law.
Know the researcher exception
The European Commission reports that AliExpress committed to enable qualifying researchers to independently access and use public data for systemic-risk analysis through automated means such as data scraping. This is a specific researcher-access commitment, not a general license for commercial monitoring or an unrestricted public API.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Choose an authorized access route
| Route | Use it when | Important limitation |
|---|---|---|
| Open Platform/API | Your application fits the documented purpose and fields. | AliExpress can restrict user and operation data; redistribution and circumvention are not allowed. |
| Written permission | You need a defined public-page collection outside the API. | Permission should specify pages, fields, volume, retention, and downstream use. |
| Researcher access | You are a qualifying researcher analyzing systemic risk. | It is not a general scraping entitlement. |
| Managed scraper API | Your authorization permits a vendor to collect the agreed public data. | You add vendor, cost, retention, and compliance dependencies. |
Ask the platform or your legal adviser to confirm the route for your country, business model, and intended fields. Do not treat a vendor’s technical capability as proof that your use is permitted.
Rank #2
- Gift Cards are shipped active and ready for use.
- This card is non-reloadable. No cash or ATM access. Funds do not expire. If available funds remain on your card after the valid thru date has passed, please call customer service for a replacement card. A one-time purchase fee applies at the time of checkout. No fees after purchase.
- To access your card information safely, type the complete website address shown on your Gift Card (MyGift.GiftCardMall.com) directly into your browser's address bar. Don't use search engines or shortened versions of the website address, as these may lead you to fake or fraudulent sites. Do not provide any Gift Card details (example: Card Number) to someone you do not know or trust. If you believe you've reached an illegitimate website, contact cardholder service at 1-888-524-1283. Be cautious of phishing sites, there are a variety of scams in which fraudsters try to trick others into paying with gift cards.
- To report your Lost or Stolen Physical Visa Card, call Customer Service 24/7 at 1 (888) 524-1283 to cancel your Gift Card as soon as you can. You will be asked to provide the Gift Card number and other identifying information.
- Use your Visa Gift Card in the U.S. everywhere Visa debit cards are accepted, including online.
Define a minimal, defensible data set
Write a data specification before sending requests. A small schema is cheaper, easier to delete, and less likely to include personal information.
| Field | Why collect it | Implementation note |
|---|---|---|
| Product URL and platform ID | Stable reference for a record. | Store the canonical URL and collection timestamp. |
| Displayed price and currency | Price tracking or catalog work. | Keep the currency and any “from” or variant qualifier. |
| Title | Catalog matching. | Preserve the captured text; do not infer specifications. |
| Rating and review count | Research or ranking. | Record the value and timestamp because it changes. |
| Shipping estimate | Delivery comparison. | Store destination and capture time; estimates are regional. |
| Seller name | Seller-level analysis. | Do not append private seller or buyer information. |
Set a deletion schedule, restrict access to raw responses, encrypt stored data, and log who exported or shared it. Honor takedown or access-restriction requests promptly. Keep only fields required for the stated application purpose.
Self-managed collection: a compliant workflow
Use the following workflow only after you have API authorization or written permission. It deliberately avoids login automation, CAPTCHA circumvention, stealth techniques, and private account data.
Recommended Free Tools
- Document the scope. Record the approved domains, URLs, fields, destinations, request ceiling, retention period, and contact for restrictions.
- Prefer an API response. Use the documented endpoint and credentials rather than rendering pages. Request only the fields your specification needs.
- Set a conservative schedule. Use a queue, per-host rate limit, exponential backoff, and a maximum retry count. Cache unchanged URLs and use conditional requests when the authorized interface supports them.
- Validate every record. Reject malformed prices, missing currencies, impossible timestamps, and HTML error pages before they enter your database.
- Monitor change. Alert on schema changes, unusual error rates, access-denied responses, or a sudden increase in page challenges. Pause the job while you confirm permission and update the parser.
- Delete on schedule. Remove raw HTML and fields that are no longer necessary; retain only derived data your agreement permits.
Python example for an authorized endpoint
This example expects an endpoint supplied by your agreement. Replace the URL and parameter names with the documented API values; do not point it at AliExpress pages without permission.
import os, time, random, csv, requests
from datetime import datetime, timezone
ENDPOINT = os.environ["AUTHORIZED_ALIEXPRESS_ENDPOINT"]
TOKEN = os.environ["AUTHORIZED_API_TOKEN"]
PRODUCT_IDS = ["approved-id-1", "approved-id-2"]
session = requests.Session()
session.headers.update({"Authorization": f"Bearer {TOKEN}", "Accept": "application/json"})
rows = []
for product_id in PRODUCT_IDS:
for attempt in range(4):
try:
response = session.get(
ENDPOINT,
params={"product_id": product_id, "fields": "title,url,price,currency,rating,review_count,shipping,seller"},
timeout=30,
)
if response.status_code in (429, 500, 502, 503, 504):
if attempt == 3:
raise RuntimeError(f"temporary failure {response.status_code}")
time.sleep((2 ** attempt) + random.random())
continue
response.raise_for_status()
item = response.json()
required = ("title", "url", "price", "currency")
if not all(item.get(k) not in (None, "") for k in required):
raise ValueError("schema validation failed")
rows.append({
"captured_at": datetime.now(timezone.utc).isoformat(),
"title": item["title"], "url": item["url"],
"price": item["price"], "currency": item["currency"],
"rating": item.get("rating"), "review_count": item.get("review_count"),
"shipping": item.get("shipping"), "seller": item.get("seller"),
})
break
except (requests.RequestException, ValueError, RuntimeError):
if attempt == 3:
print(f"paused after failure for {product_id}")
time.sleep(2) # apply the interval required by your authorization
with open("aliexpress-authorized.csv", "w", newline="", encoding="utf-8") as f:
writer = csv.DictWriter(f, fieldnames=rows[0].keys() if rows else ["captured_at", "url"])
writer.writeheader()
writer.writerows(rows)
The retry loop is for transient service failures, not for defeating a block. A 403, CAPTCHA, or bot-check response should pause collection and trigger a permission review.
Rank #3
- For all things Apple - products, accessories, apps, games, music, movies, TV shows, iCloud+, and more.
- Perfect for App Store purchases and subscriptions—get apps, games, music, movies, TV shows, and more.
- The perfect gift to say happy birthday, thank you, congratulations, and more.
- Available in $15 - 500, Card delivered via email or SMS
- Use it for purchases at any Apple Store location, on the Apple Store app, apple.com, the App Store, iTunes, Apple Music, Apple TV, Apple News+, Apple Books, Apple Arcade, iCloud+, Fitness+, Apple One, and other Apple properties in US only
cURL and Node.js patterns
For an authorized JSON endpoint, the same principle can be expressed with cURL:
curl --fail --retry 2 --retry-delay 3
-H "Authorization: Bearer $AUTHORIZED_API_TOKEN"
--get "$AUTHORIZED_ALIEXPRESS_ENDPOINT"
--data-urlencode "product_id=approved-id-1"
--data-urlencode "fields=title,url,price,currency,rating,review_count,shipping,seller"
Node.js:
const endpoint = process.env.AUTHORIZED_ALIEXPRESS_ENDPOINT;
const token = process.env.AUTHORIZED_API_TOKEN;
const params = new URLSearchParams({
product_id: 'approved-id-1',
fields: 'title,url,price,currency,rating,review_count,shipping,seller'
});
const res = await fetch(`${endpoint}?${params}`, {
headers: { Authorization: `Bearer ${token}`, Accept: 'application/json' }
});
if (!res.ok) throw new Error(`authorized endpoint returned ${res.status}`);
const item = await res.json();
console.log(item);
Managed scraper APIs: when they fit
A managed service can provide browser rendering, regional execution, structured output, and storage integrations, reducing the infrastructure you maintain. It does not transfer your legal responsibility: confirm that your authorization permits the vendor, target pages, fields, and retention model.
Bright Data
Bright Data advertises an AliExpress Scraper API for publicly available data, compliance review, structured outputs, and multiple storage integrations. Its page states that new accounts receive 5,000 free credits per month. Credits, pricing, and availability can change, so verify the current offer before budgeting.
Oxylabs
Oxylabs documents AliExpress product-page, search-result, and arbitrary-URL targets. Its stated use cases include price tracking, competitor-price benchmarking, product research, catalog enrichment, and review or ratings analysis. Confirm current target availability, delivery formats, and retention terms directly with the provider.
Comparison checklist
- Authorization: Is your permission explicit about a vendor and automated collection?
- Coverage: Do you need product pages, search results, or arbitrary URLs?
- Rendering: Can the service execute the JavaScript required for the authorized fields?
- Regional behavior: Can it collect the destination-specific price and shipping estimate you are allowed to use?
- Parsing: Are fields structured, and how are markup changes communicated?
- Delivery: Do you need JSON, files, a webhook, or direct storage?
- Governance: Where are requests and responses retained, and how can you delete them?
- Observability: Can you see status, retries, timestamps, and partial failures?
- Total cost: Include requests, browser time, storage, support, and compliance review.
Or skip the browser setup
For authorized visual capture of a page, ScreenshotNeo is the first option to try: it removes consent banners, newsletter popups, and chat widgets before capture, bills only clean shots, and has a $5 paid plan for 3,000 shots.
ScreenshotNeo is a screenshot API and MCP server, not a permission bypass. Use it only for pages you are authorized to capture. The API supports PNG, JPEG, WebP, and PDF output, full-page shots with lazy images loaded, CSS-selector element capture, device presets, custom headers and cookies, waits, request blocking, caching, signed links, asynchronous jobs, bulk capture, and usage reporting. Its MCP tools—take_screenshot, get_page_info, and capture_pdf—work with Claude, Cursor, and other MCP clients.
Rank #4
- Gift Cards are shipped active and ready for use.
- This card is non-reloadable. No cash or ATM access. Funds do not expire. If available funds remain on your card after the valid thru date has passed, please call customer service for a replacement card. A one-time purchase fee applies at the time of checkout. No fees after purchase.
- To access your card information safely, type the complete website address shown on your Gift Card (MyGift.GiftCardMall.com) directly into your browser's address bar. Don't use search engines or shortened versions of the website address, as these may lead you to fake or fraudulent sites. Do not provide any Gift Card details (example: Card Number) to someone you do not know or trust. If you believe you've reached an illegitimate website, contact cardholder service at 1-888-524-1283. Be cautious of phishing sites, there are a variety of scams in which fraudsters try to trick others into paying with gift cards.
- To report your Lost or Stolen Physical Visa Card, call Customer Service 24/7 at 1 (888) 524-1283 to cancel your Gift Card as soon as you can. You will be asked to provide the Gift Card number and other identifying information.
- Use your Visa Gift Card in the U.S. everywhere Visa debit cards are accepted, including online.
See the ScreenshotNeo documentation for parameters. A one-call capture looks like this:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://www.aliexpress.com -o shot.webp
Cookie banners, popups, and chat widgets are removed before the shot. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers report the page verdict and billing status. Free accounts include 1,000 shots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Reliability, regional data, and cost controls
Prices are contextual
Store currency, destination, variant, seller, and capture time with every price. A displayed “from” price or a selected variant is not interchangeable with the price another visitor sees. Compare normalized values only after recording these qualifiers.
Use caching and change detection
Set a cache TTL that matches your use case. Daily catalog enrichment does not justify minute-by-minute requests. Hash the normalized fields and write a new version only when the authorized response changes. This reduces load, spend, and duplicate records.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsPlan for partial failure
Keep a job state for queued, fetched, validated, rejected, and paused records. A run that returns 98% of URLs should not silently publish as complete. Expose the failed URL list and the reason so an operator can decide whether to retry, delete, or request access clarification.
Budget the whole system
Self-managed collection shifts cost to browser infrastructure, proxies or regional execution where permitted, parser maintenance, storage, monitoring, and engineering time. A managed API converts much of that into usage charges but adds vendor dependency and a separate data-processing relationship. Compare total cost per validated record, not just the advertised request price.
Best Value
- Visa Virtual eGift Cards are designed for online use only. Gift Cards are subject to Terms and Conditions: a.co/5bw3qXJ
- When you access your Visa Virtual eGift Card for the first time, you’ll need to register your name, address, phone number, and email address via activationspot.com. These details should also be used as your billing address for online purchases, as many merchants require address verification for purchase authorization.
- This Visa Virtual eGift Card is non-reloadable. No cash or ATM access. Visa Virtual eGift Cards are emailed active.
- Funds do not expire but your Visa Virtual eGift Card has a ‘valid thru’ date (9 years from date of purchase). If funds remain after this date has passed, please call the Toll Free number found on your Visa Virtual eGift Card for a replacement card. A one-time purchase fee applies at the time of checkout.
- This item is not eligible for refund, resale, or return. Available for sale within the United States only. Not available to residents of Puerto Rico, Hawaii, New Mexico, South Dakota, West Virginia and the US Virgin Islands.
Troubleshooting common failures
| Symptom | Likely cause | Safe response |
|---|---|---|
| 403 or access denied | Permission, endpoint, or policy restriction. | Stop retries; verify the agreement and contact the platform or vendor. |
| 429 too many requests | Rate limit exceeded. | Honor the stated limit, lengthen backoff, reduce concurrency, and use caching. |
| CAPTCHA or bot-check page | Automated activity was detected. | Do not circumvent it. Pause and obtain an approved route or written clarification. |
| Empty or partial product fields | Variant, region, JavaScript, or schema change. | Record destination and variant, validate the schema, and update the authorized integration. |
| Prices differ between runs | Currency, destination, seller, promotion, or variant changed. | Store all qualifiers and timestamps; do not overwrite the prior observation. |
| Vendor output contains unexpected personal data | Overbroad target or parser. | Quarantine the response, delete unnecessary fields, and narrow the request. |
| Parser suddenly returns zero rows | Markup or API response changed. | Fail closed, alert an operator, and inspect a permitted sample before deploying a fix. |
FAQ
Can I use scraped prices to create an affiliate site?
Only if both your data collection and affiliate activity are authorized. AliExpress’s affiliate agreement identifies robots, frames, iframes, scripts, or manual refreshes used solely to create commissions as fraud. Automation must never be used to manufacture conversions.
May I sell or publish the collected catalog?
Not by default. Publication, transfer, resale, and redistribution depend on the API agreement or written permission and on applicable intellectual-property and privacy law. Treat permission to access as separate from permission to redistribute.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What should happen when AliExpress withdraws an API field?
Fail closed for that field, mark affected records as incomplete, and notify users of the limitation. Do not substitute an unauthorized page scrape merely to keep the pipeline green.
Frequently Asked Questions
Does a robots.txt entry grant permission to build a database?
No. A robots.txt file is not a substitute for the Terms of Use, an API agreement, written permission, or applicable law.
Is a managed scraper automatically compliant?
No. You must verify that your authorization covers the vendor, targets, fields, request volume, retention, and intended use.
The Bottom Line
In 2026, the defensible way to collect AliExpress data is an approved API or explicit written permission, a minimal public-field schema, conservative scheduling, and strict deletion and audit controls. Treat bot checks and access restrictions as stop signals—not obstacles to bypass.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




