Skip to content
MeherMankarPublic

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Repository files navigation

GrabX API

GitHub License

A self-hosted Flask API that extracts direct download/stream links from multiple video platforms — no third-party services, deployable on Render in minutes.

Maintained by: MeherMankar · Telegram
Terabox base by: genxnano


Deploy

Platform Free Card needed Cold start Speed
Koyeb ✅ ❌ ❌ (always warm) ⚡⚡⚡
Render ✅ ❌ ✅ (sleeps after 15m) ⚡⚡
Heroku ✅ (eco dynos) ✅ ✅ ⚡⚡

Deploy to Koyeb

Deploy to Render

Deploy to Heroku


Supported Platforms

Platform Endpoint Notes
Terabox POST /download Requires TERABOX_COOKIE. Supports folders, 20+ mirror domains
PornHub POST /ph/download All qualities, yt-dlp fallback, auto-refresh on CDN expiry
Xvideos POST /xv/download 360p/480p MP4 + HLS variants
XNXX POST /xnxx/download Same extractor as Xvideos
XHamster POST /xh/download 144p–720p MP4, PRNG URL decryption
JAVtiful POST /jav/download Free 720p MP4 stream
Any site POST /yt/download yt-dlp — Twitter/X, Reddit, Twitch, Dailymotion, Vimeo, 1000+ sites
RedTube POST /redtube/download yt-dlp adapter
YouPorn POST /youporn/download yt-dlp adapter
Eporner POST /eporner/download yt-dlp adapter
SpankBang POST /spankbang/download yt-dlp adapter
PornTrex POST /porntrex/download yt-dlp adapter; extractor availability depends on yt-dlp

All platforms have a /watch page for browser playback.


Features

  • API key auth — required for protected API routes, with signed proxy tokens for streaming
  • yt-dlp fallback — when datacenter IPs are blocked, yt-dlp extracts MP4 DDLs via residential proxy
  • Rotating proxy pool — PROXY_URL accepts 10+ proxies, picks randomly per request
  • Redis-backed caching — shared extraction cache with configurable TTL and authenticated cache clearing
  • Background extraction — Redis/RQ jobs for slow sites, with polling endpoints
  • Abuse controls — Redis-backed per-key/IP request limits and bounded violation logs
  • Cloudflare Worker — route all CDN streams through CF edge, zero server bandwidth
  • DPI bypass — curl_cffi Chrome TLS + HTTP/3/QUIC + Cloudflare DoH
  • Terabox — recursive folder support, video quality/resolution metadata, 20+ mirror domains
  • XHamster — proprietary PRNG URL decryption (matches yt-dlp extractor)
  • Adaptive streaming — HLS/live manifests and DASH manifest/segment proxying
  • Player controls — quality switching, download/copy links, live marker, and playback speed
  • Auto-refresh — expired PH CDN links are re-resolved automatically using the embedded viewkey
  • Adapter-based site registry in api/extractors/, Docker-ready, single .env setup

Quick Start

1. Get a stream link

curl -X POST https://grabx-api.onrender.com/ph/download \
  -H "X-API-Key: YOUR_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "https://www.pornhub.com/view_video.php?viewkey=abc123"}'

2. Open the player in any browser (no key needed)

https://grabx-api.onrender.com/ph/watch/abc123

3. Stream or download (no key needed — URL is pre-signed)

# The proxy_url from the response works directly:
import requests
r = requests.get(response_json["data"]["best_proxy_url"], stream=True)

Setup

Prerequisites

  • Python 3.11+
  • A free Terabox account (only needed for Terabox endpoints)
  • A free Render account (for deployment)

Get your Terabox ndus cookie

  1. Open 1024terabox.com in Chrome and log in
  2. Press F12 → Application → Cookies → https://www.1024terabox.com
  3. Copy the value of the ndus cookie

Local development

git clone https://github.com/MeherMankar/grabx-api
cd grabx-api
pip install -r requirements.txt

Create .env:

# Terabox — one account
TERABOX_COOKIE=ndus=YOUR_NDUS_VALUE

# Multiple Terabox accounts (picked randomly per request)
TERABOX_COOKIE=ndus=VALUE1,ndus=VALUE2

# Required in production for protected download/proxy routes
API_KEY=your_secret_key
# Optional locally; required in production and for background jobs
# REDIS_URL=redis://localhost:6379/0

Run:

python api/index.py

API available at http://localhost:5000. With Redis running and REDIS_URL configured, run rq worker grabx in a second terminal to process async extraction jobs.


Deploy to Render

  1. Click the Deploy to Render button above, or go to render.com → New → Web Service → connect repo

  2. Render auto-detects the Dockerfile:

    Setting Value
    Environment Docker
    Port 8000
  3. Add environment variables:

    Name Value
    TERABOX_COOKIE ndus=VALUE1,ndus=VALUE2
    API_KEY your_secret_key (required in production)
    REDIS_URL Redis connection URL (required)
    APP_ENV production
    CF_WORKER_URL https://grabx-api.yourname.workers.dev (optional)
  4. Click Deploy

For async jobs, run a separate background worker with the same environment:

rq worker grabx

Note: Render free tier sleeps after 15 min of inactivity (30s cold start). Use UptimeRobot to ping /health every 5 min to keep it warm.


Deploy to Koyeb (recommended — no cold starts)

  1. Click the Deploy to Koyeb button above

  2. Set these env vars in the Koyeb dashboard:

    Name Value
    TERABOX_COOKIE ndus=VALUE1,ndus=VALUE2
    API_KEY your_secret_key (required in production)
    REDIS_URL Redis connection URL (required)
    APP_ENV production
    CF_WORKER_URL https://grabx-api.yourname.workers.dev (optional)
    PROXY_URL host:port:user:pass,... (optional — for PH/XV/XH MP4 DDLs)
  3. Click Deploy → you get grabx-api-xxx.koyeb.app

The Koyeb manifest also defines a grabx-worker service. Configure its API_KEY and REDIS_URL with the same values as the web service; copy PROXY_URL too if the API relies on the proxy pool for yt-dlp extractions. The worker runs rq worker grabx to process async jobs. Make sure the worker service itself is created and running; deploying only the web service does not start it. The API returns HTTP 503 from POST /jobs with a worker setup message when no worker is registered for the grabx queue. Queued job status responses include queue depth and worker states to help diagnose a worker that is registered but not consuming jobs. The XHamster stream proxy retries HTTP 403 responses through PROXY_URL when configured, and refreshed extraction URLs are cached for five minutes.


Deploy to Heroku

  1. Click the Deploy to Heroku button above
  2. Fill in the config vars on the Heroku deploy page
  3. Click Deploy app

Requires a Heroku account with eco dyno credits ($5/month or free with student pack).


Cloudflare Worker (optional — zero Render bandwidth)

By default all streams go through Render. The CF Worker routes PH, Xvideos, XNXX, XHamster, and JAVtiful CDN streams through Cloudflare's edge instead — Render only handles API logic and Terabox.

cd worker
npm install
npx wrangler login          # pick your CF account
npx wrangler secret put API_KEY   # same value as on Render
npx wrangler deploy
# → https://grabx-api.yourname.workers.dev

Then add CF_WORKER_URL=https://grabx-api.yourname.workers.dev to Render env vars and redeploy.


API Reference

Full docs at /docs or see docs.md.

Endpoints at a glance

Method Path Auth Description
GET / — API info
GET /health — Health check
GET /docs — Full documentation
POST /download ✓ Terabox → download links
GET /proxy token Terabox CDN proxy
POST /ph/download ✓ PornHub → stream links
GET /ph/watch/<viewkey> — PH video player
GET /ph/proxy token PH CDN proxy
POST /jobs ✓ Queue an asynchronous extraction
GET /jobs/<job_id> ✓ Poll job status/result
POST /redtube/download ✓ RedTube extraction via yt-dlp
POST /youporn/download ✓ YouPorn extraction via yt-dlp
POST /eporner/download ✓ Eporner extraction via yt-dlp
POST /spankbang/download ✓ SpankBang extraction via yt-dlp
POST /porntrex/download ✓ PornTrex extraction via yt-dlp (if supported)
POST /xv/download ✓ Xvideos → stream links
GET /xv/watch — Xvideos player
POST /xnxx/download ✓ XNXX → stream links
GET /xnxx/watch — XNXX player
POST /xh/download ✓ XHamster → stream links
GET /xh/watch — XHamster player
POST /jav/download ✓ JAVtiful → stream links
GET /jav/watch — JAVtiful player
GET /adult/proxy token Xvideos/XNXX/XHamster CDN proxy
GET /jav/proxy token JAVtiful CDN proxy

Auth column: ✓ = API key required · token = signed URL token (no key needed) · — = always public


Usage Examples

Python

import requests

BASE    = "https://grabx-api.onrender.com"
HEADERS = {"X-API-Key": "your_key", "Content-Type": "application/json"}

# PornHub
r = requests.post(f"{BASE}/ph/download",
    json={"url": "https://www.pornhub.com/view_video.php?viewkey=abc123"},
    headers=HEADERS)
data = r.json()["data"]
print(data["watch_url"])           # open in browser
print(data["best_proxy_url"])      # stream directly
print(data["best_download_url"])   # download

# Terabox
r = requests.post(f"{BASE}/download",
    json={"url": "https://1024terabox.com/s/YOUR_SHARE_ID"},
    headers=HEADERS)
files = r.json()["data"]["files"]
for f in files:
    print(f["filename"], f["size"], f["proxy_url"])

# XHamster
r = requests.post(f"{BASE}/xh/download",
    json={"url": "https://xhamster.com/videos/some-video-xhABCDEF"},
    headers=HEADERS)
data = r.json()["data"]
print(f"{len(data['qualities'])} qualities:", [q['quality']+'p' for q in data['qualities']])

JavaScript / Bot

const BASE = "https://grabx-api.onrender.com";
const KEY  = "your_key";

const res = await fetch(`${BASE}/ph/download`, {
  method: "POST",
  headers: { "Content-Type": "application/json", "X-API-Key": KEY },
  body: JSON.stringify({ url: "https://www.pornhub.com/view_video.php?viewkey=abc123" })
});
const { data } = await res.json();

// Open player in Telegram bot
bot.sendMessage(chatId, `Watch: ${data.watch_url}`);

// Or send download link (pre-signed, no key needed)
bot.sendMessage(chatId, `Download: ${data.best_download_url}`);

Project Structure

grabx-api/
├── api/
│   ├── index.py              # Flask app entry point (~165 lines)
│   ├── utils.py              # Shared utilities (tokens, proxy builder, watch page)
│   └── extractors/
│       ├── terabox.py        # Terabox extractor + routes
│       ├── pornhub.py        # PornHub extractor + routes
│       ├── javtiful.py       # JAVtiful extractor + routes
│       ├── xvideos.py        # Xvideos + XNXX + /adult/proxy
│       └── xhamster.py       # XHamster (with PRNG decryption) + routes
├── worker/
│   ├── worker.js             # Cloudflare Worker
│   └── wrangler.toml
├── Dockerfile
├── render.yaml
├── requirements.txt
└── docs.md                   # Full API documentation

Supported Terabox Domains

All variants of: terabox.com · 1024terabox.com · teraboxapp.com · nephobox.com · 4funbox.co · mirrobox.com · momerybox.com · tibibox.com · freeterabox.com · dubox.com · teraboxlink.com · terafileshare.com · teraboxshare.com · terasharefile.com · terasharelink.com · terabox1.com · terabox2.com · 1024tera.com · terabox.app


License

MIT


Credits

Role Credit
Maintainer MeherMankar · Telegram
Terabox base genxnano
WAP bypass FZBypassBot
XHamster decryption yt-dlp XHamster extractor

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages