First request
Authentication
Section titled “Authentication”Send credentials only in Authorization: Bearer …. Never put keys in URLs, Git, client-side JavaScript or agent messages. Keep the key in the server-side CSFOLDER_API_KEY environment variable.
curl --fail-with-body \ -H "Authorization: Bearer $CSFOLDER_API_KEY" \ "http://127.0.0.1:3100/v1/items?q=AK-47&limit=10"Search → prices → history
Section titled “Search → prices → history”On Free, search the catalog and call GET /v1/items/{item_id}/history without dates: it returns available Steam daily observations for the last 30 completed UTC days. Current quote fields in the catalog are null. The multi-market example below requires Builder or Trader; see plans and limits.
- Search with
GET /v1/items?q=…. - Use a returned
item_id; never guess IDs or merge paint phases. - Read
GET /v1/items/{item_id}/markets. - Draw a chart from
GET /v1/items/{item_id}/history?provider=buff163&from=2026-08-01&to=2026-08-31.
History contains available daily observations, not a guarantee of every day for every item since release. Items, marketplaces and periods can have gaps.
Server-side JavaScript
Section titled “Server-side JavaScript”const key = process.env.CSFOLDER_API_KEY;if (!key) throw new Error('Set CSFOLDER_API_KEY on the server');const response = await fetch('http://127.0.0.1:3100/v1/items?limit=10', { headers: { Authorization: `Bearer ${key}` }, signal: AbortSignal.timeout(10_000),});if (!response.ok) throw new Error(`CSFolder returned ${response.status}`);const { data, meta } = await response.json();console.log(data, meta.request_id);Responses wrap method output in data. meta.request_id is a diagnostic identifier. meta.generated_at is the response timestamp, not the price timestamp. Errors use application/problem+json.