Short answer: Vinted does not document a public, anonymous catalog-search API. Its official Pro Integrations API is an allowlisted, signed API for managing a seller’s own inventory and orders. If you need marketplace search data, you must either build a browser/session-based collector (subject to Vinted’s controls and terms) or use a managed Vinted data provider. Keep those two jobs separate: the official API is for your inventory; catalog scraping is a different integration.
First decide what “scrape Vinted listings” means
There are two materially different use cases. Choosing the wrong API path is the most common source of wasted implementation work.
Manage your own inventory
Vinted’s Pro Integrations API is designed for seller operations: creating and validating items, importing inventory, deleting or checking item status, handling orders, reading ontologies, and receiving webhooks. Access is allowlisted. You sign in to the Pro Integrations Portal, create a token, split the token into an access key and signing key, and authenticate every request with both values.
Search the public marketplace
The official documentation does not describe a public catalog-search operation. It identifies marketplace_item_id as the integer ID used in website URLs, while integration endpoints use an integration-item UUID; that distinction does not create a public search API.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
Internal web or app endpoints can expose catalog results, but they are implementation details rather than a contractual API. A provider article reports a catalog URL such as https://www.vinted.fr/api/v2/catalog/items?search_text=nike&per_page=20. The same report says requests need a session token minted by a real browser homepage session and may encounter DataDome and Cloudflare controls. Treat that URL, its parameters, and its authentication as volatile. Do not build a production dependency on it without checking Vinted’s current terms and obtaining permission where required.
Choose an access path
| Goal | Best-fit path | What you must operate |
|---|---|---|
| Publish and maintain your own Pro inventory | Official Pro Integrations API | Allowlist approval, environment-specific token, HMAC signing, item and order workflows |
| Research public listings at small scale | Self-managed browser/session extraction, only where permitted | Browser automation, session lifecycle, pagination, rate controls, anti-bot responses, schema changes |
| Run recurring marketplace data collection | Managed Vinted data API | Provider contract, coverage and field validation, quotas, retention and licensing review |
Managed services can remove browser, proxy, session and normalization work, but current prices, limits and coverage change. Verify them directly before committing.
Using Vinted’s official Pro Integrations API
Access and environments
- Confirm that your account is allowlisted for Pro Integrations.
- Log in to the Pro Integrations Portal and generate an access token.
- Split the generated value into the access key and signing key exactly as the portal specifies. Never put either key in client-side code or logs.
- Use the production host https://pro.svc.vinted.com or the sandbox host https://pro-public-sandbox.svc.vinted.com.
- Create a separate token for each environment. A sandbox token is not a production credential.
Vinted states that each API user initially receives 500 active-item slots. That is an inventory capacity allocation, not a catalog-search quota.
How request signing works
For each request, build one exact signing string by joining these five components with periods:
- Current Unix timestamp in seconds.
- Uppercase HTTP method, such as
GETorPOST. - Request path including its exact query string.
- Access key.
- The exact request body sent on the wire (an empty string for a bodyless request).
Compute HMAC-SHA256 over that string with the signing key. Send the access key in X-Vpi-Access-Key and send t={timestamp},v1={hash} in X-Vpi-Hmac-Sha256. Vinted rejects timestamps that are too old or too far in the future, so synchronize your host clock with UTC.
Reusable Python signer
The script below signs the operation path you provide through VPI_PATH. Set that path to the specific item, order or other operation documented for your account; do not change the path after calculating the signature.
import os, time, hmac, hashlib, requests
base = os.getenv("VPI_BASE", "https://pro.svc.vinted.com")
path = os.environ["VPI_PATH"] # include ?query=... when present
method = os.getenv("VPI_METHOD", "GET").upper()
body = os.getenv("VPI_BODY", "") # exact bytes represented as text
access_key = os.environ["VPI_ACCESS_KEY"]
signing_key = os.environ["VPI_SIGNING_KEY"]
timestamp = str(int(time.time()))
payload = ".".join([timestamp, method, path, access_key, body])
signature = hmac.new(
signing_key.encode("utf-8"),
payload.encode("utf-8"),
hashlib.sha256,
).hexdigest()
headers = {
"X-Vpi-Access-Key": access_key,
"X-Vpi-Hmac-Sha256": f"t={timestamp},v1={signature}",
}
if body:
headers["Content-Type"] = "application/json"
response = requests.request(
method, base + path, headers=headers,
data=body.encode("utf-8"), timeout=30
)
print(response.status_code)
print(response.text)
For a JSON body, serialize it once, retain that exact string in body, and send the same bytes. Re-serializing with different whitespace or key order after signing can invalidate the request. Include the exact encoded query string in VPI_PATH.
Node.js equivalent
import crypto from 'node:crypto';
const base = process.env.VPI_BASE || 'https://pro.svc.vinted.com';
const path = process.env.VPI_PATH; // include the exact query string
const method = (process.env.VPI_METHOD || 'GET').toUpperCase();
const body = process.env.VPI_BODY || '';
const accessKey = process.env.VPI_ACCESS_KEY;
const signingKey = process.env.VPI_SIGNING_KEY;
const timestamp = Math.floor(Date.now() / 1000).toString();
const payload = [timestamp, method, path, accessKey, body].join('.');
const signature = crypto.createHmac('sha256', signingKey)
.update(payload, 'utf8').digest('hex');
const headers = {
'X-Vpi-Access-Key': accessKey,
'X-Vpi-Hmac-Sha256': `t=${timestamp},v1=${signature}`
};
if (body) headers['Content-Type'] = 'application/json';
const res = await fetch(base + path, {
method, headers, body: body || undefined
});
console.log(res.status, await res.text());
cURL once you have a signature
Generate the timestamp and HMAC in your application, then pass the resulting values to cURL. The URL must use the same path and query string that were signed.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
curl --request GET "https://pro.svc.vinted.com${VPI_PATH}"
--header "X-Vpi-Access-Key: ${VPI_ACCESS_KEY}"
--header "X-Vpi-Hmac-Sha256: t=${VPI_TIMESTAMP},v1=${VPI_SIGNATURE}"
Building a marketplace collector responsibly
If your target is public catalog data, isolate the unstable browser layer from the rest of your system.
- Define the query contract. Record the market domain, keyword, category, condition, price range, page size, sort order and fields you actually need.
- Acquire a session through a normal browser flow. Internal endpoints reported by third parties may require a browser-minted token. Do not attempt to defeat CAPTCHA, DataDome or Cloudflare challenges; stop, slow down or obtain an authorized data source.
- Extract and normalize. Preserve the original item URL and marketplace ID, then map title, price, currency, shipping, seller, condition, brand, size, image URLs and timestamps into your schema. A field absent from a response should remain null, not be guessed.
- Paginate with checkpoints. Save the query and cursor/page before processing each page. On restart, resume from the last successful checkpoint rather than requesting the entire result set again.
- Deduplicate. Prefer a stable item URL or ID. Keep a first-seen and last-seen timestamp so relisted or changed items can be distinguished from duplicate responses.
- Throttle and retry. Use bounded concurrency, exponential backoff and a maximum retry count. A challenge response is not a transient 500 error; record it separately and reduce request pressure.
- Store raw evidence. Keep the raw response, retrieval time, request parameters and parser version. You can reprocess historical data when Vinted changes field names.
- Monitor drift. Alert on rising challenge rates, HTTP status changes, missing images or seller fields, duplicate spikes and sudden page-size changes.
Review Vinted’s terms, account permissions, privacy obligations and country-specific restrictions before collecting or redistributing listing data.
Managed Vinted data APIs
A managed provider may handle session creation, proxies, anti-bot responses and field normalization. Evaluate the service against your actual market and refresh rate rather than choosing on an endpoint list alone.
| Provider | Documented coverage | What to verify before purchase |
|---|---|---|
| Sessemi | Catalog, seller-item, item and profile data; documents handling session-token and anti-bot hurdles. | Current countries, freshness, pagination, challenge handling, retention, licensing and price. |
| ScrapeAtlas | Search, item, profile, wardrobe, feedback, brand and category endpoints. | Field completeness, rate limits, latency, data rights, support and total cost. |
| Scrappa | Advertises structured search and item details across 19 countries, including price, shipping, seller, condition, brand, size, category, favorites and view counts. | Country/domain availability, accuracy, update cadence, quotas and contract terms. |
Comparable live pricing, scrape-success benchmarks and affiliate terms are not established here. Ask each vendor for a current plan sheet and a representative response for your target country before integrating.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Commercial and account rules
Vinted distinguishes casual resale from operating a business. Its Trust & Safety guidance says everyday members may not run a business through a personal account; only Vinted Pro members may sell for profit as a business. On September 24, 2026, Vinted listed Pro availability in France, Italy, the Netherlands, Luxembourg, Belgium, Portugal, Spain and the UK. Availability can change, so check the rule for your account’s market before automating inventory or resale workflows.
Reliability, cost and data-quality controls
- Separate quotas. The official 500 active-item allocation concerns managed inventory. Provider request limits and catalog freshness are separate commercial terms.
- Measure what matters. Track successful pages, challenged pages, empty results, duplicate rate, missing-field rate and time from listing publication to detection.
- Control retention. Listing data can contain personal information. Define deletion windows, access controls and encryption before storing seller or profile fields.
- Design for replacement. Keep your parser behind an interface so you can change from a self-managed endpoint to a provider without rewriting downstream pricing, alerting or storage logic.
- Budget for volatility. Internal endpoints, tokens and anti-bot behavior can change without notice. A managed API moves some operational cost into a vendor bill; it does not remove the need to validate coverage and licensing.
Common failures and fixes
401 or 403 from the Pro API
Check that the account is allowlisted, the token belongs to the same environment as the host, and the access key is sent in X-Vpi-Access-Key. Recompute the signature using the exact path, query string and body.
“Invalid signature” after a code change
Log a hash of the serialized body, not the secret itself. Confirm that the bytes signed are the bytes transmitted, that the method is uppercase, and that the timestamp is current UTC time.
Requests work in the browser but fail in a script
The browser may hold a session token and pass device or challenge signals that a plain HTTP client lacks. Do not copy a short-lived token into a long-running service; use an authorized provider or redesign the collection flow.
Recommended Free Tools
Best Value
Empty pages or sudden challenge responses
Stop retrying aggressively. Record the status and challenge rate, lower concurrency, verify the market domain and query, and check whether the endpoint or terms have changed.
Duplicate or disappearing listings
Deduplicate by stable URL or item ID, store retrieval timestamps, and treat a missing item as “not observed” until your retention policy or a second observation supports deletion.
Or skip the browser setup
For visual records of listing or search pages, ScreenshotNeo provides a one-request website screenshot API. It is not a replacement for a structured Vinted data feed, but it can accompany your collector with a reproducible page image. Before capture it accepts the cookie/consent banner and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response reports the page verdict and billing status in X-Page-Verdict and X-Billed.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://www.vinted.fr -o shot.webp
See the ScreenshotNeo API documentation for options such as full-page capture, CSS-selector element capture, device presets, retina scale, dark mode, custom headers and cookies, waits, request blocking, JavaScript, PDFs, resizing, caching, signed links, asynchronous webhooks and bulk capture. It also has an MCP server with take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.
The Free plan includes 1,000 screenshots per month with no card. Paid plans are Starter $5 for 3,000, Growth $15 for 15,000, Pro $39 for 60,000, Scale $99 for 250,000 and Business $249 for 1,000,000; yearly billing gives two months free, and every feature is on every plan. Create a free ScreenshotNeo account to start.
Frequently Asked Questions
Can a provider’s “19 countries” claim be treated as permanent coverage?
No. Country and domain coverage is a vendor-published capability and can change. Confirm the exact market, language, currency and fields in a current response before signing a contract.
Should I keep screenshots as proof of listing state?
They can be useful as a visual audit trail, but retain the raw structured response and retrieval timestamp as well; an image alone is difficult to query or reconcile.
Is the 500-item figure a limit on how many listings I may search?
No. It is the initial active-item slot allocation for a Vinted Pro Integrations API user, not a catalog-search allowance.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

