ScreenshotNeo

BlogHow-to

How to Scrape Talabat Data with an API

Use Talabat’s authorized Partner API with OAuth, sandbox testing, pagination, webhooks, retries, and privacy controls instead of consumer-site scraping.

By the ScreenshotNeo team1 October 20267 min read

Short answer: use Talabat’s authorized Partner API rather than scraping the consumer website. Request partner credentials, authenticate with OAuth 2.0 client credentials, develop against the sandbox, then use the documented catalog, order, promotion, outlet, export, and webhook workflows. Talabat’s country terms prohibit unauthorized robots, crawlers, extraction software, and systematic retrieval.

What Talabat data access looks like

Talabat does not provide an anonymous public scraping endpoint for its consumer site. The official route is a partner integration managed through the Partner Portal or a Talabat account manager. The Partner API is described as a gateway for catalog management, order processing, promotions, outlet operations, and insights.

Requirement Official approach
Authorization Partner relationship and issued client credentials
Authentication OAuth 2.0 client-credentials grant
Testing Separate sandbox host and sandbox credentials
Resources Catalogs, orders, promotions, outlets, exports, and webhooks
Pagination page and page_size; documented page size is 1–500
Token limit 50 token requests per minute per client ID

Before you write code

  1. Identify the Talabat country and the partner relationship that applies to your business.
  2. Request a client_id and client_secret through the Partner Portal or your Talabat account manager.
  3. Read the Partner API documentation and the terms for the relevant country. Saudi Arabia and Egypt terms prohibit unauthorized automated extraction and systematic retrieval.
  4. Obtain written authorization for your intended data scope, retention period, and redistribution model.
  5. Create separate configuration for production and the sandbox at https://sandbox.partner.deliveryhero.io.

Authenticate with OAuth 2.0

The documented token endpoint is https://talabat.partner.deliveryhero.io/v2/oauth/token. Use the client-credentials grant and send the resulting access token as Authorization: Bearer <access_token>. Cache the token until its documented expiry; requesting one for every API call wastes rate-limit capacity.

cURL

curl -X POST "https://talabat.partner.deliveryhero.io/v2/oauth/token" \
  -u "$TALABAT_CLIENT_ID:$TALABAT_CLIENT_SECRET" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  --data-urlencode "grant_type=client_credentials"

Python

import os
import requests

response = requests.post(
    "https://talabat.partner.deliveryhero.io/v2/oauth/token",
    auth=(os.environ["TALABAT_CLIENT_ID"], os.environ["TALABAT_CLIENT_SECRET"]),
    data={"grant_type": "client_credentials"},
    timeout=30,
)
response.raise_for_status()
token = response.json()["access_token"]
print(token)

Node.js

const clientId = process.env.TALABAT_CLIENT_ID;
const clientSecret = process.env.TALABAT_CLIENT_SECRET;
const basic = Buffer.from(`${clientId}:${clientSecret}`).toString('base64');

const res = await fetch('https://talabat.partner.deliveryhero.io/v2/oauth/token', {
  method: 'POST',
  headers: {
    Authorization: `Basic ${basic}`,
    'Content-Type': 'application/x-www-form-urlencoded'
  },
  body: new URLSearchParams({ grant_type: 'client_credentials' })
});
if (!res.ok) throw new Error(`${res.status}: ${await res.text()}`);
const { access_token: token } = await res.json();
console.log(token);

Keep client secrets in a secret manager or environment variables. Never commit them to source control or send them to browser code.

Retrieve catalog data

Use the catalog endpoint and resource path assigned in your Partner API documentation. The exact resource URL and required identifiers depend on your country, account, and integration type, so do not copy an endpoint from an unrelated country or partner account. Catalog listing supports page and page_size; use a page size between 1 and 500.

Generic paginated request

curl -G "$TALABAT_CATALOG_ENDPOINT" \
  -H "Authorization: Bearer $TALABAT_ACCESS_TOKEN" \
  -d page=1 \
  -d page_size=500
import os
import requests

endpoint = os.environ["TALABAT_CATALOG_ENDPOINT"]
token = os.environ["TALABAT_ACCESS_TOKEN"]
page = 1
page_size = 500

while True:
    r = requests.get(
        endpoint,
        headers={"Authorization": f"Bearer {token}"},
        params={"page": page, "page_size": page_size},
        timeout=60,
    )
    r.raise_for_status()
    payload = r.json()
    print(payload)
    # Follow the next-page field or link defined by your assigned schema.
    if not payload.get("next"):
        break
    page += 1
const endpoint = process.env.TALABAT_CATALOG_ENDPOINT;
const token = process.env.TALABAT_ACCESS_TOKEN;

for (let page = 1; ; page++) {
  const url = new URL(endpoint);
  url.searchParams.set('page', page);
  url.searchParams.set('page_size', '500');
  const res = await fetch(url, {
    headers: { Authorization: `Bearer ${token}` }
  });
  if (!res.ok) throw new Error(`${res.status}: ${await res.text()}`);
  const payload = await res.json();
  console.log(payload);
  if (!payload.next) break; // Use the next-page field in your assigned schema.
}

Orders, promotions, outlets, and exports

  • Orders: retrieve order details and status according to your assigned integration. Payloads include status, fulfillment, items, pricing and payment fields, delivery details, and masked customer information.
  • Order events: implement webhook handling for statuses such as RECEIVED, READY_FOR_PICKUP, DISPATCHED, and CANCELLED. Allowed transitions depend on transport and integration type.
  • Promotions and outlets: use the documented resources for your partner scope rather than inferring consumer-site URLs.
  • Exports: catalog export is asynchronous. Wait for the webhook notification, then download from the webhook-provided URL.

Pagination, rate limits, and reliability

  • Cache access tokens until expiry. The token endpoint is limited to 50 requests per minute per client ID; excess requests can return HTTP 429.
  • Use bounded exponential backoff with jitter for transient 5xx responses and network timeouts.
  • Do not retry blindly. A 401 usually means an expired, malformed, or wrong-environment token; refresh credentials and retry once. A 403 indicates missing authorization or scope. A 404 commonly means an incorrect resource identifier or country host. A 429 requires backoff and respect for the server’s rate limit.
  • Persist the last successful page or cursor so a worker can resume after interruption.
  • Deduplicate webhook events using an event or order identifier when supplied by the schema.
  • Use idempotency controls for order operations where the assigned documentation provides them.

Compliance and privacy checklist

  • Confirm that your Talabat partner authorization covers every endpoint and country you use.
  • Do not reverse engineer private consumer endpoints, imitate mobile clients, bypass bot controls, or publish copied menus and reviews without permission.
  • Store only fields needed for the business purpose. Customer details are documented as masked in order payloads.
  • Encrypt secrets and personal data, restrict employee access, and define deletion and retention rules.
  • Review Talabat’s privacy policy, which discusses API-related service providers and personal-data handling.
  • Document webhook verification, audit logs, and incident-response ownership before production.

Common errors and fixes

Symptom Likely cause Fix
401 Unauthorized Expired token, wrong credentials, or missing Bearer header Request a token from the correct host and send Authorization: Bearer ....
403 Forbidden Account lacks the resource or country scope Ask the account manager to confirm permissions.
404 Not Found Wrong resource path, outlet ID, or environment Use the path and identifiers in your assigned specification; verify sandbox versus production.
429 Too Many Requests Token or API rate limit exceeded Stop rapid retries, cache tokens, and back off with jitter.
Empty catalog page Wrong page parameters, outlet scope, or no published items Check page_size, account scope, and catalog status in the Partner Portal.
Webhook download fails Export is not complete or URL handling is incorrect Wait for the completion webhook and retrieve the supplied download URL as documented.
Duplicate orders or events Retries without deduplication Store processed event/order IDs and make handlers idempotent.

Performance and cost planning

Choose the largest permitted page size when bandwidth and memory allow it, then process records incrementally instead of loading a full catalog into memory. Prefer webhooks for order changes so you do not poll aggressively. Exports are useful for bulk synchronization because they complete asynchronously and provide a download URL. Your Talabat commercial terms, infrastructure, storage, and partner agreement determine total cost; the public specification does not provide a universal per-request price.

Or skip the browser setup

If your project also needs visual snapshots of Talabat pages for QA, documentation, or an internal review, ScreenshotNeo provides a website screenshot API and MCP server. It is separate from Talabat’s Partner API and does not grant permission to extract Talabat data. One request returns a PNG, JPEG, WebP, or PDF.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' }); const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Cookie banners, newsletter popups, and chat widgets are removed before the shot. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server lets AI agents use take_screenshot, get_page_info, and capture_pdf. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. See the ScreenshotNeo API documentation and create a free account.

FAQ

Does Talabat have an API?

Yes. The authorized Partner API is available to approved partners with issued credentials and documented scopes.

Can I use the consumer website with a scraper?

Talabat country terms prohibit unauthorized automated extraction and systematic retrieval. Obtain authorization and use the Partner API.

How often should I request OAuth tokens?

Once per token lifetime. Cache the token and refresh it after expiry or an authentication failure.

Are customer details exposed in order data?

The order documentation describes customer information as masked. Minimize storage and follow your agreement and applicable privacy law.

What if I only need a one-time menu snapshot?

Ask Talabat for permission and the appropriate export or catalog access. Do not assume a one-time scrape is exempt from the terms.