API included on every paid plan

Automate everything with the Bulldog API

Profile management over HTTPS, a desktop loopback API, and signed event notifications. Available within your paid plan limits.

REST API

Create profiles, attach proxies, start sessions and manage your team — all over HTTPS with bearer-token auth.

# Generate an API key in Dashboard → API & Automation.
curl https://bulldogbrowser.com/api/profiles \
  -H "Authorization: Bearer $BULLDOG_API_KEY"

curl -X POST https://bulldogbrowser.com/api/profiles \
  -H "Authorization: Bearer $BULLDOG_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name":"work-profile","os":"windows","proxy":"socks5://USER:PASS@HOST:1080"}'

# Profile IDs are numeric. Recover a deleted profile within 30 days:
curl -X POST https://bulldogbrowser.com/api/profiles/123/restore \
  -H "Authorization: Bearer $BULLDOG_API_KEY"

Core endpoints

GET/api/profilesList accessible profiles; view-only data is redacted
POST/api/profilesCreate a profile within your paid plan limit
PATCH/api/profiles/:idUpdate settings, proxy or cookies (edit access)
DELETE/api/profiles/:idMove profile to Recently deleted (manage access)
GET/api/profiles/trashList your recoverable profiles
POST/api/profiles/:id/restoreRestore your profile within 30 days and plan capacity
POST/api/profiles/:id/sharesGrant an active teammate profile access
POST/api/profiles/:id/cloud-launchLaunch configured cloud browser; returns view URL
GET/api/webhooksList receivers and recent delivery results
POST/api/webhooksRegister approved HTTPS receiver; secret shown once
POST/api/webhooks/deliverRetry due pending deliveries

Desktop automation

Use the local API to list, start and stop profiles. It binds to loopback and requires a local bearer key. CDP framework attachment and headless operation are not verified in this release.

# Enable Local API in the desktop app's settings.
# Use the LOCAL automation key, not your website API key.
curl http://127.0.0.1:3999/profiles \
  -H "Authorization: Bearer $BULLDOG_LOCAL_KEY"

curl -X POST http://127.0.0.1:3999/profiles/start \
  -H "Authorization: Bearer $BULLDOG_LOCAL_KEY" \
  -H "Content-Type: application/json" -d '{"id":123}'

curl -X POST http://127.0.0.1:3999/profiles/stop \
  -H "Authorization: Bearer $BULLDOG_LOCAL_KEY" \
  -H "Content-Type: application/json" -d '{"id":123}'

# The current release does NOT return a CDP browser endpoint.
# Puppeteer/Playwright/Selenium attach and headless mode are not
# verified supported interfaces in this release.

Webhooks

Subscribe to supported profile and team events. HMAC-signed payloads use stable event IDs. Failed deliveries retry on later event activity or on demand, with backoff and an eight-attempt limit.

import { createHmac, timingSafeEqual } from 'node:crypto';
// Keep the raw request body. Do not re-serialize parsed JSON.
const parts = Object.fromEntries(signatureHeader.split(',').map(x => x.split('=')));
const timestamp = Number(parts.t);
if (!Number.isFinite(timestamp) || Math.abs(Date.now()/1000 - timestamp) > 300)
  throw new Error('Expired webhook');
const expected = createHmac('sha256', process.env.BULLDOG_WEBHOOK_SECRET)
  .update(parts.t + '.' + rawBody).digest();
const received = Buffer.from(parts.v1 || '', 'hex');
if (received.length !== expected.length || !timingSafeEqual(received, expected))
  throw new Error('Invalid signature');
// Deduplicate by payload.id. Return 2xx after accepting the event.
// Events: profile_create, profile_update, profile_delete, profile_restore,
// profile_launch, team_invite, team_update, team_remove, profile_share.
// Payload contains event ID, type, timestamp and actor ID; no cookies.
// Configure receivers and view deliveries in API & Automation.
// Admin must approve receiver hostnames using BB_WEBHOOK_ALLOWED_HOSTS.

Ship your automation this week

API access is available on paid plans, starting at US$10/month for Starter. Profile and seat limits still apply.

7-day free trial, 1 profile · No credit card required · Plans from US$10/month