非浏览器方式调用Blur未公开API返回403问题求助
解决Blur未公开API调用403问题
出现403是因为该API有反爬验证,只允许浏览器环境的请求,你需要完全模拟浏览器的请求参数才能通过验证,具体操作如下:
复制浏览器完整请求头
打开浏览器开发者工具(F12),切换到「Network」标签,访问https://core-api.prod.blur.io/v1/prices,找到对应的请求,右键选择「复制」→「复制为cURL(bash)」,再把cURL转换成Python requests代码,就能完整还原浏览器的所有请求头和Cookies。修正代码URL错误
你代码里写了response = requests.get(url+endpoint, headers=headers),但url已经是完整的目标接口地址,拼接endpoint会导致URL无效,直接使用url即可。补充关键验证头
除了你现有的头,通常还需要添加这些浏览器专属头(以实际请求为准):Referer:https://blur.io/(API可能验证请求来自官网)Origin:https://blur.ioSec-Fetch-Dest:emptySec-Fetch-Mode:corsSec-Fetch-Site:same-site
另外必须带上浏览器请求中的Cookie头,很多反爬会验证会话Cookie。
修改后的示例代码(需替换实际Cookie值):
import requests url = "https://core-api.prod.blur.io/v1/prices" headers = { "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36", "Accept-Language": "zh-CN,zh;q=0.9", "Accept-Encoding": "gzip, deflate, br", "Connection": "keep-alive", "Referer": "https://blur.io/", "Origin": "https://blur.io", "Sec-Fetch-Dest": "empty", "Sec-Fetch-Mode": "cors", "Sec-Fetch-Site": "same-site", # 替换成你浏览器中实际的Cookie内容 "Cookie": "这里粘贴浏览器请求中的Cookie值" } response = requests.get(url, headers=headers) print("Status:", response.status_code) print("Content-type:", response.headers['content-type']) if response.status_code == 200: print("Data:", response.json())
- 注意事项
- Cookie可能会过期,过期后需要重新从浏览器复制
- 不要频繁请求,避免被封禁IP
- 该API是未公开的,Blur随时可能修改验证规则或关闭接口,使用需谨慎
内容的提问来源于stack exchange,提问作者Joseph
相关产品推荐
相关产品推荐

