PartyScape Public API
Last updated: 28 September 2026 · read-only, no account required for the open layer
PartyScape has a small, read-only public API for websites, Discord bots and spreadsheets. It
serves the same profile, skills, leaderboard and clan data the game already shows to other
players - nothing more, and never anything private (gold, bag, bank, chat, email, or any
other player's Discord/Steam id). There are two layers, both under
https://partyscape.club/api/v1/:
The open layer - no token. Anyone's public profile, the leaderboards, and the clan directory. Cached, and rate-limited per IP address.
The token layer - your own token. Your own live account (gold, bag, bank, current action), and your own clan's roster, bank, log and boss fight. Read-only: a token can never play, spend, trade or change anything.
The full machine-readable contract (every route, every field, every error) is /api/v1/openapi.json, an OpenAPI 3.1 document generated straight from the server's own response types. This page is the human-readable tour of the same thing; if the two ever disagree, the OpenAPI document is right.
The open layer
No Authorization header, no cookie, nothing to sign up for. Every response is
cached for a little while (see Caching) and every route sends
Access-Control-Allow-Origin: *, so a browser can call these directly from any site.
| Route | What |
|---|---|
GET /public/players/{username} | A player's public profile: levels, feats, pets, capes, diaries, rare drops, relics. Case-insensitive username. |
GET /public/players/{username}/skills | The cheap subset for polling: skills, totalLevel, totalXp, featPoints, combatLevel. |
GET /public/leaderboards/{board} | Up to the top 100 rows of one leaderboard. ?scope=iron or ?scope=hardcore restricts to that account type. |
GET /public/clans | Every clan: name, tag, kills, fort levels, member count. No rosters. |
GET /public/clans/{id} | One clan, with its member roster (username, rank, joined date). |
GET /public/game/requirements | Clan track costs, tribute costs, the clan boss's stats - static content, already in the game's client bundle. |
GET /public/game/events | Active and upcoming weekly events, and when the next world boss spawns. |
GET /public/game/version | The running build's commit sha and the current online player count. |
Every path above is relative to https://partyscape.club/api/v1.
Example: a player's profile
GET /api/v1/public/players/YourName
{
"username": "YourName",
"combatLevel": 87,
"totalLevel": 1142,
"featPoints": 214,
"highestPerk": { "name": "Spoils I", "description": "+1% drop rate, always" },
"topSkills": [{ "skill": "Melee", "level": 82 }, ...],
"skills": [{ "skill": "Woodcutting", "level": 76, "xp": 1521543 }, ...],
"totalKills": 8123,
"questsDone": 14,
"cosmetics": { "hat": null, "cape": null, "face": null, "aura": null, "shirt": null },
"pets": [{ "id": "pet_beaver", "name": "Beaver" }],
"petTotal": 14,
"rareDrops": [{ "id": "draconic_visage", "name": "Draconic Visage" }],
"relics": [{ "id": "midas_coin", "name": "Midas Coin", "count": 1 }],
"capes": ["Woodcutting Cape"],
"diaries": ["Moonbridge Diary (Easy)"],
"latest": [{ "kind": "pet", "name": "Beaver", "at": 1758999999000 }],
"accountType": "normal",
"clan": { "id": "cl_abc123", "name": "Example Clan", "tag": "EXMP" },
"joined": "2026-01-15T09:02:11.000Z"
}
This is an illustrative example, not a live response. There is deliberately no
online or location field on this layer - the open profile never
reveals real-time presence, even for a signed-in viewer looking at the same account in-game.
Example: a leaderboard row
GET /api/v1/public/leaderboards/overall
[
{ "rank": 1, "username": "YourName", "totalXp": 88213321, "totalLevel": 1142, "combatLevel": 87, "featPoints": 214 },
{ "rank": 2, "username": null, "hidden": true },
...
]
A row for a player who has hidden themselves (see below)
keeps its rank but loses everything else. On a per-skill board (see the board list below) each row
also carries skillLevel and skillXp for that one skill; the
overall board does not, since there is no single skill for it to report.
Leaderboard board ids
The {board} path segment must be exactly one of:
overall, Woodcutting, Mining, Smithing,
Fishing, Cooking, Fletching, Thieving,
Crafting, Farming, Runecrafting, Tailoring,
Herblore, Melee, Ranged, Magic,
Defence, Hitpoints, MonsterHunting, Prayer,
Enchanting.
One name is not what it looks like in the game: the skill
the game displays as "Slayer" is MonsterHunting everywhere in this API - in
the board id above, and as the id the server actually checks. A skill field inside
a profile or skills response still prints the display name, "Slayer", because that
is what a player reads on their own card. Ask for the board with the wrong name
(/leaderboards/Slayer) and you get 400 err.api.badboard, not a Slayer
board.
Getting a token
Tokens are for YOUR OWN account and are created inside the game, not through the API: sign in, open Account › API, and press New token. Pick a label and which scopes it needs (see below), and the token is shown to you once.
- Up to 3 live tokens per account at a time. Revoke one to make room for another.
- A token lasts 365 days. The same tab has a Renew button per token that mints a fresh one and retires the old one in the same action.
- Read-only, always: no token, however it is scoped, can play the game, spend gold, trade, or change any setting.
- Revoke a token any time from the same tab. A revoked or expired token answers exactly like one that never existed.
Authorization
Send the token as a bearer token on every token-layer request:
Authorization: Bearer psk_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
The open layer needs no Authorization header at all - sending a token there
changes nothing, since that layer never looks at it.
Scopes and the token layer
| Scope | Lets a token |
|---|---|
self:read | Read your own gold, bag, bank, skills and what you are currently doing. |
clan:read | Read the clan you belong to right now: roster, bank, log and boss fight. Stops working the moment you leave the clan. |
| Route | Scope | What |
|---|---|---|
GET /tokens/self | any | This token's own label, scopes, lifetime and usage. |
GET /me | self:read | Your live profile plus gold, bag, bank, pouches, active action, queue, buffs. |
GET /me/skills | self:read | Your skills, xp and per-action mastery. |
GET /clan | clan:read | Your clan's roster, level and fort. |
GET /clan/bank | clan:read | Your clan bank's items and gold. |
GET /clan/log?limit= | clan:read | Your clan's activity log. limit defaults to 60, max 200. |
GET /clan/boss | clan:read | The live clan boss fight, personalised to you (your volleys, cooldown, whether you can call or join). |
/tokens/self is at /api/v1/tokens/self;
everything else in this table is at /api/v1/me... or /api/v1/clan...
directly - there is no /public in a token-layer path. The clan is always
whichever one the TOKEN'S OWNER belongs to right now; there is no way to ask for a clan by id on
this layer.
Example
curl -H "Authorization: Bearer psk_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \ https://partyscape.club/api/v1/me
Rate limits
| Layer | Limit |
|---|---|
| Open layer | 60 requests/minute per IP address. |
| Token layer | 60 requests/minute per token, and 100/minute combined across all of one account's tokens. |
Going over either limit answers 429 with a Retry-After header (in
seconds). The open layer also has one shared safety valve across every caller at once: if the
whole layer gets too busy in a given minute, it briefly answers 503
(err.api.busy) to new requests rather than letting one surge slow everyone down. That
is not something a well-behaved integration should ever see; it exists for the rare case, not the
normal one.
Caching
| Route(s) | Cache lifetime |
|---|---|
| A player's profile / skills | up to 60 seconds |
| Leaderboards, the clan directory, one clan | up to 300 seconds (5 minutes) |
game/requirements | forever between deploys - served with an ETag; send If-None-Match and expect 304 |
game/events, game/version | up to 20 seconds |
Any /api/v1/clan... token route | up to 30 seconds |
/api/v1/me, /api/v1/me/skills | none - always your current saved state |
Because of that cache, a player who just turned hide-me on can still read as visible on the open layer for up to that route's cache lifetime afterwards. That is the cache doing its job, not a bug.
Hiding yourself
Every player can go to Account › API and turn on "Hide me from the public API." Turning it on:
- Makes
GET /public/players/{username}and its/skillsanswer404, identically to an unknown username. - Replaces the player's row on any leaderboard, and their entry in a clan roster, with
{ "hidden": true }in place - on a leaderboard only the rank stays, on a roster only the clan role, so the numbers around them stay honest.
It changes nothing inside the game itself: other players still see the normal profile card, and clanmates still see a hidden member's real name and stats in the Clan tab. It is only about what an unauthenticated URL can say. It also has no effect on the player's own tokens, which read the player's own data regardless.
Calling it from a browser
The token layer allows cross-origin browser requests (Authorization header,
GET only, no cookies involved) - you can call it straight from client-side
JavaScript on your own site, not only from a backend.
But do not paste a token into a public web page, a browser extension you did not write, or any shared/online tool. Anyone who loads that page or installs that tool gets to read everything your token allows, until you notice and revoke it. If you are building something other people will load in their own browser, keep the token on a backend you control and have YOUR server call the API - never ship the token itself to other people's browsers.
Errors
| Status | Code | Meaning |
|---|---|---|
| 400 | err.api.badboard | The {board} in a leaderboard URL is not one of the ids listed above. |
| 401 | err.api.token | Missing, malformed, unknown, revoked or expired token, or its owner is banned. The body is just {"code": "err.api.token"}. |
| 403 | err.api.scope | The token does not carry the scope this route needs. The body names the missing scope in args.scope. |
| 403 | err.api.notmember | A clan:read token was used, but its owner is not in a clan right now. |
| 404 | err.api.notfound | Unknown username or clan id - or a real one that is banned, a guest, or has hidden themselves. |
| 429 | err.api.ratelimit | Rate limit hit. See Retry-After. |
| 503 | err.api.busy | The open layer's shared ceiling was hit this minute. Try again shortly. |
| 503 | (no code) | The public API is switched off right now. The body is just {"error": "public api disabled"}, with no code field at all. |
Every response body also has an error field with a short English
sentence, EXCEPT the plain 401, whose body is code only. Treat
code as the stable thing to branch on in your own code - the English text can
change.
Versioning
Everything here lives under /api/v1/. That prefix will keep meaning exactly what
it means today for as long as it exists; a change that would break an existing integration ships
as /api/v2/ instead, side by side with /api/v1/, rather than changing
/api/v1/ under you.
More curl examples
# Open layer - no token needed curl https://partyscape.club/api/v1/public/players/YourName curl https://partyscape.club/api/v1/public/leaderboards/overall curl https://partyscape.club/api/v1/public/clans # Token layer - your own token curl -H "Authorization: Bearer psk_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \ https://partyscape.club/api/v1/me curl -H "Authorization: Bearer psk_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \ https://partyscape.club/api/v1/clan/log?limit=100
API terms
- This API, and PartyScape, are not affiliated with or endorsed by any other game, company, or trademark holder.
- Tokens are personal. Do not share, publish, or sell one, or use one that is not yours.
- We may rate-limit, throttle, or revoke any token, or block any client, at any time and without notice, for any reason including suspected abuse.
- This API is provided as-is, free of charge, with no uptime or availability promise.
- If you obtained data about a player while they were visible on this API, you may not keep using it to show that player once they have turned on hide-me. Delete or stop displaying anything about them from that point on.
See also: Privacy Policy, Terms of Service, and the machine-readable OpenAPI document.