A self-hosted Flask API that extracts direct download/stream links from multiple video platforms — no third-party services, deployable on Render in minutes.
Maintained by: MeherMankar · Telegram
Terabox base by: genxnano
| Platform | Free | Card needed | Cold start | Speed |
|---|---|---|---|---|
| Koyeb | ✅ | ❌ | ❌ (always warm) | ⚡⚡⚡ |
| Render | ✅ | ❌ | ✅ (sleeps after 15m) | ⚡⚡ |
| Heroku | ✅ (eco dynos) | ✅ | ✅ | ⚡⚡ |
| Platform | Endpoint | Notes |
|---|---|---|
| Terabox | POST /download |
Requires TERABOX_COOKIE. Supports folders, 20+ mirror domains |
| PornHub | POST /ph/download |
All qualities, yt-dlp fallback, auto-refresh on CDN expiry |
| Xvideos | POST /xv/download |
360p/480p MP4 + HLS variants |
| XNXX | POST /xnxx/download |
Same extractor as Xvideos |
| XHamster | POST /xh/download |
144p–720p MP4, PRNG URL decryption |
| JAVtiful | POST /jav/download |
Free 720p MP4 stream |
| Any site | POST /yt/download |
yt-dlp — Twitter/X, Reddit, Twitch, Dailymotion, Vimeo, 1000+ sites |
| RedTube | POST /redtube/download |
yt-dlp adapter |
| YouPorn | POST /youporn/download |
yt-dlp adapter |
| Eporner | POST /eporner/download |
yt-dlp adapter |
| SpankBang | POST /spankbang/download |
yt-dlp adapter |
| PornTrex | POST /porntrex/download |
yt-dlp adapter; extractor availability depends on yt-dlp |
All platforms have a /watch page for browser playback.
- API key auth — required for protected API routes, with signed proxy tokens for streaming
- yt-dlp fallback — when datacenter IPs are blocked, yt-dlp extracts MP4 DDLs via residential proxy
- Rotating proxy pool —
PROXY_URLaccepts 10+ proxies, picks randomly per request - Redis-backed caching — shared extraction cache with configurable TTL and authenticated cache clearing
- Background extraction — Redis/RQ jobs for slow sites, with polling endpoints
- Abuse controls — Redis-backed per-key/IP request limits and bounded violation logs
- Cloudflare Worker — route all CDN streams through CF edge, zero server bandwidth
- DPI bypass —
curl_cffiChrome TLS + HTTP/3/QUIC + Cloudflare DoH - Terabox — recursive folder support, video quality/resolution metadata, 20+ mirror domains
- XHamster — proprietary PRNG URL decryption (matches yt-dlp extractor)
- Adaptive streaming — HLS/live manifests and DASH manifest/segment proxying
- Player controls — quality switching, download/copy links, live marker, and playback speed
- Auto-refresh — expired PH CDN links are re-resolved automatically using the embedded viewkey
- Adapter-based site registry in
api/extractors/, Docker-ready, single.envsetup
curl -X POST https://grabx-api.onrender.com/ph/download \
-H "X-API-Key: YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"url": "https://www.pornhub.com/view_video.php?viewkey=abc123"}'https://grabx-api.onrender.com/ph/watch/abc123
# The proxy_url from the response works directly:
import requests
r = requests.get(response_json["data"]["best_proxy_url"], stream=True)- Python 3.11+
- A free Terabox account (only needed for Terabox endpoints)
- A free Render account (for deployment)
- Open 1024terabox.com in Chrome and log in
- Press
F12→ Application → Cookies →https://www.1024terabox.com - Copy the value of the
nduscookie
git clone https://github.com/MeherMankar/grabx-api
cd grabx-api
pip install -r requirements.txtCreate .env:
# Terabox — one account
TERABOX_COOKIE=ndus=YOUR_NDUS_VALUE
# Multiple Terabox accounts (picked randomly per request)
TERABOX_COOKIE=ndus=VALUE1,ndus=VALUE2
# Required in production for protected download/proxy routes
API_KEY=your_secret_key
# Optional locally; required in production and for background jobs
# REDIS_URL=redis://localhost:6379/0Run:
python api/index.pyAPI available at http://localhost:5000.
With Redis running and REDIS_URL configured, run rq worker grabx in a
second terminal to process async extraction jobs.
-
Click the Deploy to Render button above, or go to render.com → New → Web Service → connect repo
-
Render auto-detects the
Dockerfile:Setting Value Environment Docker Port 8000 -
Add environment variables:
Name Value TERABOX_COOKIEndus=VALUE1,ndus=VALUE2API_KEYyour_secret_key(required in production)REDIS_URLRedis connection URL (required) APP_ENVproductionCF_WORKER_URLhttps://grabx-api.yourname.workers.dev(optional) -
Click Deploy
For async jobs, run a separate background worker with the same environment:
rq worker grabxNote: Render free tier sleeps after 15 min of inactivity (30s cold start). Use UptimeRobot to ping
/healthevery 5 min to keep it warm.
-
Click the Deploy to Koyeb button above
-
Set these env vars in the Koyeb dashboard:
Name Value TERABOX_COOKIEndus=VALUE1,ndus=VALUE2API_KEYyour_secret_key(required in production)REDIS_URLRedis connection URL (required) APP_ENVproductionCF_WORKER_URLhttps://grabx-api.yourname.workers.dev(optional)PROXY_URLhost:port:user:pass,...(optional — for PH/XV/XH MP4 DDLs) -
Click Deploy → you get
grabx-api-xxx.koyeb.app
The Koyeb manifest also defines a grabx-worker service. Configure its API_KEY
and REDIS_URL with the same values as the web service; copy PROXY_URL too if
the API relies on the proxy pool for yt-dlp extractions. The worker runs
rq worker grabx to process async jobs. Make sure the worker service itself is
created and running; deploying only the web service does not start it. The API
returns HTTP 503 from POST /jobs with a worker setup message when no worker is
registered for the grabx queue. Queued job status responses include queue
depth and worker states to help diagnose a worker that is registered but not
consuming jobs. The XHamster stream proxy retries HTTP 403 responses through
PROXY_URL when configured, and refreshed extraction URLs are cached for five
minutes.
- Click the Deploy to Heroku button above
- Fill in the config vars on the Heroku deploy page
- Click Deploy app
Requires a Heroku account with eco dyno credits ($5/month or free with student pack).
By default all streams go through Render. The CF Worker routes PH, Xvideos, XNXX, XHamster, and JAVtiful CDN streams through Cloudflare's edge instead — Render only handles API logic and Terabox.
cd worker
npm install
npx wrangler login # pick your CF account
npx wrangler secret put API_KEY # same value as on Render
npx wrangler deploy
# → https://grabx-api.yourname.workers.devThen add CF_WORKER_URL=https://grabx-api.yourname.workers.dev to Render env vars and redeploy.
Full docs at /docs or see docs.md.
| Method | Path | Auth | Description |
|---|---|---|---|
| GET | / |
— | API info |
| GET | /health |
— | Health check |
| GET | /docs |
— | Full documentation |
| POST | /download |
✓ | Terabox → download links |
| GET | /proxy |
token | Terabox CDN proxy |
| POST | /ph/download |
✓ | PornHub → stream links |
| GET | /ph/watch/<viewkey> |
— | PH video player |
| GET | /ph/proxy |
token | PH CDN proxy |
| POST | /jobs |
✓ | Queue an asynchronous extraction |
| GET | /jobs/<job_id> |
✓ | Poll job status/result |
| POST | /redtube/download |
✓ | RedTube extraction via yt-dlp |
| POST | /youporn/download |
✓ | YouPorn extraction via yt-dlp |
| POST | /eporner/download |
✓ | Eporner extraction via yt-dlp |
| POST | /spankbang/download |
✓ | SpankBang extraction via yt-dlp |
| POST | /porntrex/download |
✓ | PornTrex extraction via yt-dlp (if supported) |
| POST | /xv/download |
✓ | Xvideos → stream links |
| GET | /xv/watch |
— | Xvideos player |
| POST | /xnxx/download |
✓ | XNXX → stream links |
| GET | /xnxx/watch |
— | XNXX player |
| POST | /xh/download |
✓ | XHamster → stream links |
| GET | /xh/watch |
— | XHamster player |
| POST | /jav/download |
✓ | JAVtiful → stream links |
| GET | /jav/watch |
— | JAVtiful player |
| GET | /adult/proxy |
token | Xvideos/XNXX/XHamster CDN proxy |
| GET | /jav/proxy |
token | JAVtiful CDN proxy |
Auth column: ✓ = API key required · token = signed URL token (no key needed) · — = always public
import requests
BASE = "https://grabx-api.onrender.com"
HEADERS = {"X-API-Key": "your_key", "Content-Type": "application/json"}
# PornHub
r = requests.post(f"{BASE}/ph/download",
json={"url": "https://www.pornhub.com/view_video.php?viewkey=abc123"},
headers=HEADERS)
data = r.json()["data"]
print(data["watch_url"]) # open in browser
print(data["best_proxy_url"]) # stream directly
print(data["best_download_url"]) # download
# Terabox
r = requests.post(f"{BASE}/download",
json={"url": "https://1024terabox.com/s/YOUR_SHARE_ID"},
headers=HEADERS)
files = r.json()["data"]["files"]
for f in files:
print(f["filename"], f["size"], f["proxy_url"])
# XHamster
r = requests.post(f"{BASE}/xh/download",
json={"url": "https://xhamster.com/videos/some-video-xhABCDEF"},
headers=HEADERS)
data = r.json()["data"]
print(f"{len(data['qualities'])} qualities:", [q['quality']+'p' for q in data['qualities']])const BASE = "https://grabx-api.onrender.com";
const KEY = "your_key";
const res = await fetch(`${BASE}/ph/download`, {
method: "POST",
headers: { "Content-Type": "application/json", "X-API-Key": KEY },
body: JSON.stringify({ url: "https://www.pornhub.com/view_video.php?viewkey=abc123" })
});
const { data } = await res.json();
// Open player in Telegram bot
bot.sendMessage(chatId, `Watch: ${data.watch_url}`);
// Or send download link (pre-signed, no key needed)
bot.sendMessage(chatId, `Download: ${data.best_download_url}`);grabx-api/
├── api/
│ ├── index.py # Flask app entry point (~165 lines)
│ ├── utils.py # Shared utilities (tokens, proxy builder, watch page)
│ └── extractors/
│ ├── terabox.py # Terabox extractor + routes
│ ├── pornhub.py # PornHub extractor + routes
│ ├── javtiful.py # JAVtiful extractor + routes
│ ├── xvideos.py # Xvideos + XNXX + /adult/proxy
│ └── xhamster.py # XHamster (with PRNG decryption) + routes
├── worker/
│ ├── worker.js # Cloudflare Worker
│ └── wrangler.toml
├── Dockerfile
├── render.yaml
├── requirements.txt
└── docs.md # Full API documentation
All variants of: terabox.com · 1024terabox.com · teraboxapp.com · nephobox.com · 4funbox.co · mirrobox.com · momerybox.com · tibibox.com · freeterabox.com · dubox.com · teraboxlink.com · terafileshare.com · teraboxshare.com · terasharefile.com · terasharelink.com · terabox1.com · terabox2.com · 1024tera.com · terabox.app
| Role | Credit |
|---|---|
| Maintainer | MeherMankar · Telegram |
| Terabox base | genxnano |
| WAP bypass | FZBypassBot |
| XHamster decryption | yt-dlp XHamster extractor |