PartyScape Public API

Last updated: 28 September 2026 · read-only, no account required for the open layer

PartyScape has a small, read-only public API for websites, Discord bots and spreadsheets. It serves the same profile, skills, leaderboard and clan data the game already shows to other players - nothing more, and never anything private (gold, bag, bank, chat, email, or any other player's Discord/Steam id). There are two layers, both under https://partyscape.club/api/v1/:

The open layer - no token. Anyone's public profile, the leaderboards, and the clan directory. Cached, and rate-limited per IP address.

The token layer - your own token. Your own live account (gold, bag, bank, current action), and your own clan's roster, bank, log and boss fight. Read-only: a token can never play, spend, trade or change anything.

The full machine-readable contract (every route, every field, every error) is /api/v1/openapi.json, an OpenAPI 3.1 document generated straight from the server's own response types. This page is the human-readable tour of the same thing; if the two ever disagree, the OpenAPI document is right.

The open layer

No Authorization header, no cookie, nothing to sign up for. Every response is cached for a little while (see Caching) and every route sends Access-Control-Allow-Origin: *, so a browser can call these directly from any site.

RouteWhat
GET /public/players/{username}A player's public profile: levels, feats, pets, capes, diaries, rare drops, relics. Case-insensitive username.
GET /public/players/{username}/skillsThe cheap subset for polling: skills, totalLevel, totalXp, featPoints, combatLevel.
GET /public/leaderboards/{board}Up to the top 100 rows of one leaderboard. ?scope=iron or ?scope=hardcore restricts to that account type.
GET /public/clansEvery clan: name, tag, kills, fort levels, member count. No rosters.
GET /public/clans/{id}One clan, with its member roster (username, rank, joined date).
GET /public/game/requirementsClan track costs, tribute costs, the clan boss's stats - static content, already in the game's client bundle.
GET /public/game/eventsActive and upcoming weekly events, and when the next world boss spawns.
GET /public/game/versionThe running build's commit sha and the current online player count.

Every path above is relative to https://partyscape.club/api/v1.

Example: a player's profile

GET /api/v1/public/players/YourName

{
  "username": "YourName",
  "combatLevel": 87,
  "totalLevel": 1142,
  "featPoints": 214,
  "highestPerk": { "name": "Spoils I", "description": "+1% drop rate, always" },
  "topSkills": [{ "skill": "Melee", "level": 82 }, ...],
  "skills": [{ "skill": "Woodcutting", "level": 76, "xp": 1521543 }, ...],
  "totalKills": 8123,
  "questsDone": 14,
  "cosmetics": { "hat": null, "cape": null, "face": null, "aura": null, "shirt": null },
  "pets": [{ "id": "pet_beaver", "name": "Beaver" }],
  "petTotal": 14,
  "rareDrops": [{ "id": "draconic_visage", "name": "Draconic Visage" }],
  "relics": [{ "id": "midas_coin", "name": "Midas Coin", "count": 1 }],
  "capes": ["Woodcutting Cape"],
  "diaries": ["Moonbridge Diary (Easy)"],
  "latest": [{ "kind": "pet", "name": "Beaver", "at": 1758999999000 }],
  "accountType": "normal",
  "clan": { "id": "cl_abc123", "name": "Example Clan", "tag": "EXMP" },
  "joined": "2026-01-15T09:02:11.000Z"
}

This is an illustrative example, not a live response. There is deliberately no online or location field on this layer - the open profile never reveals real-time presence, even for a signed-in viewer looking at the same account in-game.

Example: a leaderboard row

GET /api/v1/public/leaderboards/overall

[
  { "rank": 1, "username": "YourName", "totalXp": 88213321, "totalLevel": 1142, "combatLevel": 87, "featPoints": 214 },
  { "rank": 2, "username": null, "hidden": true },
  ...
]

A row for a player who has hidden themselves (see below) keeps its rank but loses everything else. On a per-skill board (see the board list below) each row also carries skillLevel and skillXp for that one skill; the overall board does not, since there is no single skill for it to report.

Leaderboard board ids

The {board} path segment must be exactly one of:

overall, Woodcutting, Mining, Smithing, Fishing, Cooking, Fletching, Thieving, Crafting, Farming, Runecrafting, Tailoring, Herblore, Melee, Ranged, Magic, Defence, Hitpoints, MonsterHunting, Prayer, Enchanting.

One name is not what it looks like in the game: the skill the game displays as "Slayer" is MonsterHunting everywhere in this API - in the board id above, and as the id the server actually checks. A skill field inside a profile or skills response still prints the display name, "Slayer", because that is what a player reads on their own card. Ask for the board with the wrong name (/leaderboards/Slayer) and you get 400 err.api.badboard, not a Slayer board.

Getting a token

Tokens are for YOUR OWN account and are created inside the game, not through the API: sign in, open Account › API, and press New token. Pick a label and which scopes it needs (see below), and the token is shown to you once.

Authorization

Send the token as a bearer token on every token-layer request:

Authorization: Bearer psk_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

The open layer needs no Authorization header at all - sending a token there changes nothing, since that layer never looks at it.

Scopes and the token layer

ScopeLets a token
self:readRead your own gold, bag, bank, skills and what you are currently doing.
clan:readRead the clan you belong to right now: roster, bank, log and boss fight. Stops working the moment you leave the clan.
RouteScopeWhat
GET /tokens/selfanyThis token's own label, scopes, lifetime and usage.
GET /meself:readYour live profile plus gold, bag, bank, pouches, active action, queue, buffs.
GET /me/skillsself:readYour skills, xp and per-action mastery.
GET /clanclan:readYour clan's roster, level and fort.
GET /clan/bankclan:readYour clan bank's items and gold.
GET /clan/log?limit=clan:readYour clan's activity log. limit defaults to 60, max 200.
GET /clan/bossclan:readThe live clan boss fight, personalised to you (your volleys, cooldown, whether you can call or join).

/tokens/self is at /api/v1/tokens/self; everything else in this table is at /api/v1/me... or /api/v1/clan... directly - there is no /public in a token-layer path. The clan is always whichever one the TOKEN'S OWNER belongs to right now; there is no way to ask for a clan by id on this layer.

Example

curl -H "Authorization: Bearer psk_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
  https://partyscape.club/api/v1/me

Rate limits

LayerLimit
Open layer60 requests/minute per IP address.
Token layer60 requests/minute per token, and 100/minute combined across all of one account's tokens.

Going over either limit answers 429 with a Retry-After header (in seconds). The open layer also has one shared safety valve across every caller at once: if the whole layer gets too busy in a given minute, it briefly answers 503 (err.api.busy) to new requests rather than letting one surge slow everyone down. That is not something a well-behaved integration should ever see; it exists for the rare case, not the normal one.

Caching

Route(s)Cache lifetime
A player's profile / skillsup to 60 seconds
Leaderboards, the clan directory, one clanup to 300 seconds (5 minutes)
game/requirementsforever between deploys - served with an ETag; send If-None-Match and expect 304
game/events, game/versionup to 20 seconds
Any /api/v1/clan... token routeup to 30 seconds
/api/v1/me, /api/v1/me/skillsnone - always your current saved state

Because of that cache, a player who just turned hide-me on can still read as visible on the open layer for up to that route's cache lifetime afterwards. That is the cache doing its job, not a bug.

Hiding yourself

Every player can go to Account › API and turn on "Hide me from the public API." Turning it on:

It changes nothing inside the game itself: other players still see the normal profile card, and clanmates still see a hidden member's real name and stats in the Clan tab. It is only about what an unauthenticated URL can say. It also has no effect on the player's own tokens, which read the player's own data regardless.

Calling it from a browser

The token layer allows cross-origin browser requests (Authorization header, GET only, no cookies involved) - you can call it straight from client-side JavaScript on your own site, not only from a backend.

But do not paste a token into a public web page, a browser extension you did not write, or any shared/online tool. Anyone who loads that page or installs that tool gets to read everything your token allows, until you notice and revoke it. If you are building something other people will load in their own browser, keep the token on a backend you control and have YOUR server call the API - never ship the token itself to other people's browsers.

Errors

StatusCodeMeaning
400err.api.badboardThe {board} in a leaderboard URL is not one of the ids listed above.
401err.api.tokenMissing, malformed, unknown, revoked or expired token, or its owner is banned. The body is just {"code": "err.api.token"}.
403err.api.scopeThe token does not carry the scope this route needs. The body names the missing scope in args.scope.
403err.api.notmemberA clan:read token was used, but its owner is not in a clan right now.
404err.api.notfoundUnknown username or clan id - or a real one that is banned, a guest, or has hidden themselves.
429err.api.ratelimitRate limit hit. See Retry-After.
503err.api.busyThe open layer's shared ceiling was hit this minute. Try again shortly.
503(no code)The public API is switched off right now. The body is just {"error": "public api disabled"}, with no code field at all.

Every response body also has an error field with a short English sentence, EXCEPT the plain 401, whose body is code only. Treat code as the stable thing to branch on in your own code - the English text can change.

Versioning

Everything here lives under /api/v1/. That prefix will keep meaning exactly what it means today for as long as it exists; a change that would break an existing integration ships as /api/v2/ instead, side by side with /api/v1/, rather than changing /api/v1/ under you.

More curl examples

# Open layer - no token needed
curl https://partyscape.club/api/v1/public/players/YourName
curl https://partyscape.club/api/v1/public/leaderboards/overall
curl https://partyscape.club/api/v1/public/clans

# Token layer - your own token
curl -H "Authorization: Bearer psk_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
  https://partyscape.club/api/v1/me
curl -H "Authorization: Bearer psk_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
  https://partyscape.club/api/v1/clan/log?limit=100

API terms

See also: Privacy Policy, Terms of Service, and the machine-readable OpenAPI document.