Automate everything with the Bulldog API
Profile management over HTTPS, a desktop loopback API, and signed event notifications. Available within your paid plan limits.
REST API
Create profiles, attach proxies, start sessions and manage your team — all over HTTPS with bearer-token auth.
# Generate an API key in Dashboard → API & Automation.
curl https://bulldogbrowser.com/api/profiles \
-H "Authorization: Bearer $BULLDOG_API_KEY"
curl -X POST https://bulldogbrowser.com/api/profiles \
-H "Authorization: Bearer $BULLDOG_API_KEY" \
-H "Content-Type: application/json" \
-d '{"name":"work-profile","os":"windows","proxy":"socks5://USER:PASS@HOST:1080"}'
# Profile IDs are numeric. Recover a deleted profile within 30 days:
curl -X POST https://bulldogbrowser.com/api/profiles/123/restore \
-H "Authorization: Bearer $BULLDOG_API_KEY"Core endpoints
/api/profilesList accessible profiles; view-only data is redacted/api/profilesCreate a profile within your paid plan limit/api/profiles/:idUpdate settings, proxy or cookies (edit access)/api/profiles/:idMove profile to Recently deleted (manage access)/api/profiles/trashList your recoverable profiles/api/profiles/:id/restoreRestore your profile within 30 days and plan capacity/api/profiles/:id/sharesGrant an active teammate profile access/api/profiles/:id/cloud-launchLaunch configured cloud browser; returns view URL/api/webhooksList receivers and recent delivery results/api/webhooksRegister approved HTTPS receiver; secret shown once/api/webhooks/deliverRetry due pending deliveriesDesktop automation
Use the local API to list, start and stop profiles. It binds to loopback and requires a local bearer key. CDP framework attachment and headless operation are not verified in this release.
# Enable Local API in the desktop app's settings.
# Use the LOCAL automation key, not your website API key.
curl http://127.0.0.1:3999/profiles \
-H "Authorization: Bearer $BULLDOG_LOCAL_KEY"
curl -X POST http://127.0.0.1:3999/profiles/start \
-H "Authorization: Bearer $BULLDOG_LOCAL_KEY" \
-H "Content-Type: application/json" -d '{"id":123}'
curl -X POST http://127.0.0.1:3999/profiles/stop \
-H "Authorization: Bearer $BULLDOG_LOCAL_KEY" \
-H "Content-Type: application/json" -d '{"id":123}'
# The current release does NOT return a CDP browser endpoint.
# Puppeteer/Playwright/Selenium attach and headless mode are not
# verified supported interfaces in this release.Webhooks
Subscribe to supported profile and team events. HMAC-signed payloads use stable event IDs. Failed deliveries retry on later event activity or on demand, with backoff and an eight-attempt limit.
import { createHmac, timingSafeEqual } from 'node:crypto';
// Keep the raw request body. Do not re-serialize parsed JSON.
const parts = Object.fromEntries(signatureHeader.split(',').map(x => x.split('=')));
const timestamp = Number(parts.t);
if (!Number.isFinite(timestamp) || Math.abs(Date.now()/1000 - timestamp) > 300)
throw new Error('Expired webhook');
const expected = createHmac('sha256', process.env.BULLDOG_WEBHOOK_SECRET)
.update(parts.t + '.' + rawBody).digest();
const received = Buffer.from(parts.v1 || '', 'hex');
if (received.length !== expected.length || !timingSafeEqual(received, expected))
throw new Error('Invalid signature');
// Deduplicate by payload.id. Return 2xx after accepting the event.
// Events: profile_create, profile_update, profile_delete, profile_restore,
// profile_launch, team_invite, team_update, team_remove, profile_share.
// Payload contains event ID, type, timestamp and actor ID; no cookies.
// Configure receivers and view deliveries in API & Automation.
// Admin must approve receiver hostnames using BB_WEBHOOK_ALLOWED_HOSTS.Ship your automation this week
API access is available on paid plans, starting at US$10/month for Starter. Profile and seat limits still apply.
7-day free trial, 1 profile · No credit card required · Plans from US$10/month