Deck Help Center

Get started with the local API

Turn on LoginDeck's local API, copy your token, and open profiles or run Flows from your own scripts.

Updated Β· 5 min read

On this page

LoginDeck can serve a small HTTP API on this computer. Your script asks it to open a profile, and gets back a DevTools endpoint it can hand straight to Playwright, Puppeteer or Selenium. The browser it gets is a real LoginDeck session β€” same fingerprint, same proxy, same timezone as pressing Run β€” so your script inherits the identity instead of building a worse one with puppeteer.launch().

Part of Pro, Team and Custom.

πŸ”Œ Turn it on#

  1. Open Settings (at the bottom of the left sidebar), then API & MCP.
  2. Tick Serve the API on this machine. The status next to the API & MCP heading reads listening on 19222.
  3. Leave Port at 19222 unless something else on the machine has it. To change it, type a new port (1024–65535) and click Apply.
  4. Copy the Token with the Copy button.
Switching the API on in Settings and copying the token.

It is off until you turn it on, and it only ever listens on 127.0.0.1 β€” nothing on your network can reach it.

πŸ“‹ Copy a working snippet#

The Connect panel next to the switch prints ready-to-run code with your port and your token already in it. Pick a tab β€” curl, Puppeteer, Playwright, Python or AI agent (MCP) β€” and click Copy.

The shortest possible check, from a terminal:

curl -s http://127.0.0.1:19222/api/v1/status \
  -H "Authorization: Bearer YOUR_TOKEN"
{"ok":true,"data":{"app":"antiorbit","api":1,"version":"0.1.209",
 "engine":{"path":"…","patched":true},"profiles":42,"running":1}}

Every reply has that shape: {"ok":true,"data":{…}}, or {"ok":false,"error":"…"} with an HTTP status to match.

πŸ” The rules every request follows#

  • Authorization: Bearer <token> on every request. Without it you get 401 missing or wrong token β€” send Authorization: Bearer &lt;token&gt;.
  • Anything that changes something is a POST with a JSON body, and the Content-Type: application/json header. A POST without it is refused with 415.
  • Requests from a web page are refused. Anything carrying an Origin header gets 403 this API does not serve browser origins, and no CORS headers are ever sent. This is deliberate: it means a page you happen to visit cannot drive your profiles, which is not true of every antidetect browser's local API.
  • The Host header must be 127.0.0.1, localhost or [::1] with your port, or you get 403 bad Host header.
  • Bodies are capped at 64 KB.

Your token is a key to every logged-in profile on this computer

Anything on this machine that has the token can open your accounts. Keep it out of screenshots, out of repositories and out of shell history. Click Regenerate if it leaks β€” every script holding the old token stops working at once, which is the point of the button.

▢️ Open a profile from a script#

curl -s http://127.0.0.1:19222/api/v1/browser/start \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "My profile"}'

You get back the session, including the two forms of its DevTools endpoint:

{"ok":true,"data":{"profile_id":"…","name":"My profile","pid":12345,
 "debug_port":54321,"ws":"ws://127.0.0.1:54321/devtools/browser/…",
 "http":"http://127.0.0.1:54321","headless":false,
 "proxy":"http://gate.example.com:8000","timezone":"Europe/London",
 "exit":{"ip":"…","country":"United Kingdom","city":"London","isp":"…"},
 "engine":{"path":"…","patched":true,"version":"Chrome/155.0.0.0"}}}

Hand ws to your automation library β€” Connect Playwright, Puppeteer or Selenium. Close it again with POST /api/v1/browser/stop.

Profiles can be named or identified by id. A name that two profiles share is refused rather than guessed: 2 profiles are named "Facebook 3" β€” use profile_id.

Windowed beats headless

{"headless": true} works, and the reply tells you why you should think twice: headless is more detectable than a windowed session. Use a window for anything logged in.

πŸ€– Or run a Flow instead of driving the browser yourself#

If the job already exists as a Flow, you do not need to write the clicking at all:

curl -s http://127.0.0.1:19222/api/v1/flows/run \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"flow": "My flow", "name": "My profile", "inputs": {}, "wait": true}'

With "wait": true the call returns when the run finishes, with the phase, the step it stopped on, the log and the variables the Flow produced. GET /api/v1/flows lists your Flows and the inputs each one asks for. Every route is in the Local API reference.

πŸ‘€ What the API has open#

Settings β†’ API & MCP shows Open automation sessions: the profile, its port, its endpoint and where it exits, with a Stop button each. Sessions you started by pressing Run are deliberately not listed β€” they have no debugging port, on purpose.

πŸ›Ÿ If it will not work#

What you seeWhat it means
port {n} is already in use β€” something else on this machine has itPick another port and click Apply. The switch stays on so you can see the reason.
401 missing or wrong tokenThe header is missing, or the token was regenerated since your script last read it.
403 this API does not serve browser originsYou are calling it from a web page or a browser console. Run the code in Node, Python or a terminal.
415 POST bodies must be application/jsonAdd -H "Content-Type: application/json".
automation (API/MCP) is not supported for Firefox profiles yetThe API drives Chromium profiles. See Chrome or Firefox.
this profile is already running without an automation port β€” stop it first, then start it through the APIThe profile is open from the app. Close that window first.
This profile is locked…You are over your plan's profile count: Plan limit messages.

ℹ️ Good to know#

  • LoginDeck has to be open. The API is served by the app, so quitting it closes the API and the browsers it opened.
  • The API is per computer, and so is the token β€” a second computer has its own.
  • POST /api/v1/profiles/create counts against your plan's profile limit exactly as the + New Profile button does.
  • Proxies come back from the API with their passwords stripped. Your script does not need them: the browser it was handed is already going out through that proxy.
  • Want an AI agent to do this instead of a script? See Let AI agents drive LoginDeck (MCP).