ScreenshotNeo

BlogHow-to

How to Build a Zillow Scraper

Zillow’s Terms of Use prohibit automated scraping. Here’s how to pursue property data through an approved API or a separately licensed source.

By the ScreenshotNeo team4 October 20269 min read

Direct answer: Do not build a bot that automatically collects listing or property information from Zillow pages. Zillow’s Terms of Use prohibit automated queries for obtaining information from its services, including screen or database scraping, spiders, robots, crawlers, and CAPTCHA bypass. They also prohibit bypassing measures used to restrict access. The responsible way to pursue Zillow data is to request approval for the relevant Zillow API component or choose a separate source whose written license covers your intended use. Read Zillow’s Terms of Use.

This is a summary of Zillow’s published terms, not legal advice or a claim that a particular act violates a law in every jurisdiction. The terms and API conditions can change; review the current documents before implementation.

Why this guide does not provide a Zillow page scraper

A conventional Zillow scraper would automate page requests or browser actions to extract Zillow information. Zillow’s terms expressly prohibit that type of automated collection and attempts to bypass access restrictions. This guide therefore does not include Zillow selectors, hidden endpoints, browser automation, CAPTCHA handling, proxy rotation, stealth settings, or code for extracting Zillow pages.

Checking a site’s robots.txt does not replace the applicable terms or grant permission. Nor does the fact that a browser can display a page establish permission to collect its contents automatically.

Choose an authorized data route

Need Route to investigate Verify before building
Zillow valuations, property attributes, mortgage data, postings, or real estate professional information Request approval for the relevant Zillow API component Approval, credential, approved site or application, fields, display, retention, quota, and current version
Listing or property data outside the approved Zillow API scope Find a separately licensed data provider or authorized MLS/IDX relationship Written rights for the data, geography, audience, commercial use, retention, redistribution, and refresh cadence
Aggregate market trends Check whether a published public dataset fits the use case Terms for storage, manipulation, attribution, and redistribution
Listings you or your organization are authorized to submit Use the applicable feed or listing submission workflow Feed requirements, completeness, update cadence, and the specific agreement

Zillow describes its API as serving preapproved licensees, with access limited to the components for which Zillow approved the licensee. A general account or publicly discoverable credential should not be treated as approval. Review Zillow Group’s Data & APIs Terms of Use.

Plan the data request before writing code

  1. List the required fields. Separate active listings, property attributes, valuations, mortgage information, professional information, and market aggregates. “Property data” is too broad to determine the right authorization.
  2. Define the use. Record the geographic coverage, intended users, display context, commercial purpose, refresh needs, and whether records will be stored, transformed, or shared.
  3. Ask Zillow about approval. Identify the API component and application, then obtain the required approval and issued credential. Do not assume approval for one component covers another.
  4. Read the component terms. Confirm limits on display, bulk access, retention, attribution, audience, and call volume. Property Details has additional terms, including a limit of 20 properties displayed to a user at a time and requirements intended to prevent bulk downloading or scraping.
  5. Check the quota and API version. The reviewed terms list 1,000 daily calls for Home Valuations and Property Details APIs, with a higher limit potentially available after review. Zillow may release new API versions and require the latest version; check the current terms and technical documentation when access is granted.
  6. If the scope does not fit, evaluate another licensed source. Get written confirmation that its rights cover the exact fields, use, audience, territory, storage, redistribution, and update frequency you need.
  7. Only then design ingestion. Keep source provenance and timestamps, define deduplication and stale-record handling, restrict access, and document deletion and error handling. These are general engineering practices; the governing agreement determines the actual obligations.

Build a client only after receiving approved API details

Zillow’s API requires an issued credential for approved use, but the reviewed public terms do not provide a universal endpoint, request schema, or credential that readers can use to access every component. Do not copy an endpoint from an unrelated example or guess the response format. Use the technical documentation and credentials supplied for your approved component.

The following small clients are runnable against an API endpoint and schema that your provider has authorized and documented. Set the endpoint and parameter names to those exact specifications. They intentionally do not point at Zillow or implement Zillow page extraction.

cURL

export AUTHORIZED_API_URL='https://api.example.com/v1/authorized-properties'
export AUTHORIZED_API_TOKEN='YOUR_APPROVED_TOKEN'
curl --fail-with-body --silent --show-error \
  --get "$AUTHORIZED_API_URL" \
  --header "Authorization: Bearer $AUTHORIZED_API_TOKEN" \
  --data-urlencode 'postal_code=10001' \
  --data-urlencode 'limit=20' \
  --output properties.json

Replace the example host and parameters with the authorized provider’s documented values. Do not put a real token in source control or shared shell history.

Python

import json
import os
import requests

api_url = os.environ["AUTHORIZED_API_URL"]
token = os.environ["AUTHORIZED_API_TOKEN"]

response = requests.get(
    api_url,
    headers={"Authorization": f"Bearer {token}"},
    params={"postal_code": "10001", "limit": 20},
    timeout=(5, 30),
)
response.raise_for_status()

payload = response.json()
with open("properties.json", "w", encoding="utf-8") as output:
    json.dump(payload, output, ensure_ascii=False, indent=2)

Install the dependency with python -m pip install requests. Match the parameters and expected response structure to your approved API documentation. Add pagination only if the API documents it and your license permits the requested access.

Node.js

const apiUrl = process.env.AUTHORIZED_API_URL;
const token = process.env.AUTHORIZED_API_TOKEN;

if (!apiUrl || !token) {
  throw new Error('Set AUTHORIZED_API_URL and AUTHORIZED_API_TOKEN');
}

const url = new URL(apiUrl);
url.search = new URLSearchParams({ postal_code: '10001', limit: '20' });

const response = await fetch(url, {
  headers: { Authorization: `Bearer ${token}` },
  signal: AbortSignal.timeout(30000),
});

if (!response.ok) {
  const body = await response.text();
  throw new Error(`API returned ${response.status}: ${body}`);
}

const payload = await response.json();
const { writeFile } = await import('node:fs/promises');
await writeFile('properties.json', JSON.stringify(payload, null, 2));

This uses the built-in fetch available in current Node.js releases. Configure the endpoint, authentication scheme, and query fields from the approved provider’s documentation.

Ingestion design for an authorized source

Keep a source and permission record

For each feed or API, store its provider name, contract or license reference, allowed fields, permitted purpose, geography, refresh interval, retention rule, and the person responsible for access. Make this record available to the engineers maintaining the ingestion job.

Make updates repeatable

  • Use stable provider IDs where available; avoid using mutable display fields as identifiers.
  • Store the provider’s update timestamp and your ingestion timestamp separately.
  • Make an import idempotent so retrying a page or batch does not create duplicate records.
  • Track deletions and status changes according to the provider’s documented semantics.
  • Keep raw responses only if the agreement permits retaining them; otherwise process and discard them as required.
  • Log request IDs, time, status, and record counts without logging credentials or unnecessary personal information.

Respect documented rate and display limits

Read the limit for the approved component and design for it. Do not treat the reviewed 1,000 calls per day figure as a universal limit for every Zillow API component or as permission to make those calls. The terms say a higher limit may be approved after review. Zillow API data is subject to restrictions on bulk access and retention; the Property Details terms also limit the number of properties displayed per user at a time. Confirm the current applicable language for your approval before choosing batch size, caching, or display behavior.

Listings feeds are a separate workflow

Zillow’s Listings Quality Policy concerns authorized listing submissions, not permission to collect Zillow pages. The policy, updated September 2024, says feed data must be complete and feeds must be updated at least daily. Apply those rules only when the feed arrangement and current policy apply to your organization. Check Zillow’s current policy and feed documentation before implementation.

Or skip the browser setup

If your task is to take a screenshot of a website you own or are authorized to capture, ScreenshotNeo provides a screenshot API and MCP server. It is not a method for collecting Zillow listing data, and it does not override Zillow’s terms. The one-call example below captures ScreenshotNeo’s own site; use an authorized target for your project. See the ScreenshotNeo API documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://screenshotneo.com -o shot.webp

ScreenshotNeo accepts cookie or consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing, and the response identifies the page verdict and billing status in headers. Its MCP server gives AI agents tools for screenshots, page information, and PDF capture. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for 1,000 free screenshots a month with no card.

Troubleshooting

Symptom Likely cause Next step
No approved Zillow API credential The API is limited to preapproved licensees and approved components. Request approval for the relevant component. Do not use a page scraper or a credential intended for another purpose.
401 or 403 from an authorized API Missing, invalid, expired, or incorrectly scoped credential; the requested component or site may not be approved. Check the issued credential and approval scope, then contact the provider through its documented support route.
429 or quota error Call limit reached, or requests are being made more quickly than the approved limit. Honor any documented reset or retry instructions, reduce request frequency, and ask whether a higher limit can be approved.
Fields are missing or a response changed Wrong component, schema assumption, or API version change. Compare against the current approved component documentation and version notice; validate fields before writing records.
Duplicate or stale records Imports are not idempotent, provider updates are not tracked, or deletion semantics were assumed. Use documented stable IDs and timestamps; implement the provider’s update and deletion rules.
Retention or display review fails The implementation exceeds the agreement’s limits on copies, audience, bulk access, or display. Pause the affected use and compare the implementation with the applicable component terms; change the design or obtain written approval.
Authorized feed is incomplete or out of date Source feed omissions or refresh job failures. Check feed validation and job history. Zillow’s Listings Quality Policy says applicable feeds must be complete and updated at least daily.

Performance, reliability, and cost

  • Performance: Estimate calls from the documented page size, field selection, and refresh cadence. Avoid polling for changes more often than the API or license permits. Use batching or incremental updates only when documented and authorized.
  • Reliability: Set connection and read timeouts, check HTTP status codes, validate response schemas, and record failures for review. Retry transient errors only with bounded backoff and within the allowed request rate. Do not retry authorization failures as if they were transient.
  • Freshness: A successful fetch does not prove that a listing is current. Preserve source timestamps and display freshness honestly. For Zillow listing submissions, the separate quality policy specifies at least daily feed updates; that does not promise the freshness of scraped or third-party records.
  • Cost: The reviewed sources do not establish a price for your approved API access or a third-party provider. Ask for the applicable commercial terms, usage charges, and overage rules before estimating cost. Include engineering, storage, monitoring, and compliance work in the operating estimate.
  • Compatibility: Zillow may require a newer API version, and a new version may not be compatible with an existing implementation. Monitor official notices and budget time to validate changes.

FAQ

Is scraping Zillow illegal?

This article does not make a universal legal determination. Zillow’s published Terms of Use prohibit automated scraping and related automated queries. Whether a specific activity has legal consequences depends on facts and applicable law.

Does an API key mean I can download all matching properties?

No. Zillow’s API access is approval-based and limited by component-specific terms. The reviewed terms restrict bulk access and retention, and Property Details has additional display and anti-bulk-download conditions.

Can I use a screenshot tool to collect listing data?

A screenshot is an image, not an authorization to collect or reuse Zillow information. Use screenshot tools only for targets you are authorized to capture and for a permitted purpose.

Possibly, if its terms cover your intended storage, analysis, display, and redistribution. Verify the dataset’s current terms and scope before relying on it.

Sources and scope

The policy summary and quota details above reflect the supplied research dossier, accessed October 3, 2026. API terms and technical requirements can change, so verify the current component documents before building.