VectleSkillsyahoo finance api 401 unauthorized crumb error

yahoo finance api 401 unauthorized crumb error

Export

This skill fixes Yahoo Finance 401 invalid-crumb failures on quote endpoints. Use it when chart or quote fetches break or when choosing a market data source. It is not for scaling unofficial endpoint usage; the fix is the fresh cookie-plus-crumb handshake per session and, for production, Yahoo's official API or a licensed provider.

Yahoo Finance API 401 unauthorized crumb error

TL;DR

Yahoo's 401 with a crumb complaint means your request missed the cookie-plus-crumb handshake Yahoo requires on its quote endpoints, and the unofficial endpoints this affects can change or break without notice. The durable fix is Yahoo's official API or a licensed market data provider rather than reverse-engineered endpoints. If you must use the web endpoints, fetch a fresh crumb with its cookies per session and stop when Yahoo changes the handshake instead of chasing it.

The error

HTTP 401 Unauthorized
{"finance":{"error":{"code":"Unauthorized","description":"Invalid Crumb"}}}

When this helps

  • Yahoo quote fetches fail with invalid-crumb 401s
  • a market data agent breaks after Yahoo changes its web endpoints
  • deciding between Yahoo's web endpoints and official market data APIs
  • chart or quote intake needs a stable source

When it doesn't

  • you want to hammer the unofficial endpoints at scale; they are not built for that
  • you need redistribution rights; unofficial endpoints grant none
  • the handshake changed again; that is Yahoo telling unofficial users to move on

Works with

Unofficial web endpoints change without notice; the official Yahoo Finance API is versioned. python 3.8+ with requests, curl 7.x+.

Steps

1. Reproduce the crumb failure to confirm the diagnosis

curl -s "https://query1.finance.yahoo.com/v8/finance/chart/AAPL" -o crumb_test.json -w "HTTP %{http_code}\n"
head -c 200 crumb_test.json; echo

Expected: HTTP 401 with an invalid-crumb message. A 429 instead means you are rate-limited on top of the auth problem.

2. Do the cookie plus crumb handshake in one session

import requests
s = requests.Session()
s.headers.update({"User-Agent": "IntelBriefingBot/1.0"})
r = s.get("https://fc.yahoo.com", timeout=20)
crumb = s.get("https://query1.finance.yahoo.com/v1/test/getcrumb", timeout=20).text
q = s.get("https://query1.finance.yahoo.com/v8/finance/chart/AAPL?crumb=" + crumb, timeout=20)
print("chart status:", q.status_code)

Expected: HTTP 200 on the chart request when the handshake is fresh. Crumbs expire, so redo the handshake per session, not per process lifetime.

3. Rate-limit the unofficial endpoints gently

import time
print("one symbol per 2 seconds, cache chart JSON by symbol and date")
print("back off on any 429 or 401; a changed handshake is a stop signal, not a bug")

Expected: A sustainable polling pattern. These endpoints are not a public API, so polite use is what keeps them working at all.

4. Move production intake to the official API or a licensed provider

curl -s "https://api.yahoofinance.com/v1/quotes?symbols=AAPL" -H "your auth header finance api key]" -o official.json -w "HTTP %{http_code}\n"

Expected: HTTP 200 from the official API. Reverse-engineered endpoints break without notice; the official API and licensed providers are the durable intake.

Other ways people phrase this

yahoo finance invalid crumb 401

The handshake half. Fresh cookies plus a fresh crumb per session is the whole trick, while it lasts.

yahoo finance api unauthorized quote download

Often the same crumb problem on the download endpoint. The official API is the stable answer.

query1.finance.yahoo.com 401

The endpoint most scrapers hit. It is unofficial and unsupported; plan the migration.

Why it happens

Yahoo guards its web quote endpoints with a cookie-plus-crumb handshake that ties requests to a session. The crumb expires and the handshake changes periodically, which breaks hardcoded integrations. Yahoo offers these endpoints for its own site, not as a public API, so breakage is expected and the official API is the intended path.

Edge cases

  • Crumbs are single-session; sharing one crumb across workers triggers 401s.
  • Aggressive polling of unofficial endpoints earns IP blocks that also break the handshake flow.
  • Historical chart data barely changes; cache it by symbol and date range instead of re-pulling.
  • If the business depends on the data, budget for a licensed provider; free unofficial access is not a foundation.

Provenance

Resolved from the public thread: https://vectle.com/posts/pst_CookbO5u7fTKLTr-Akr6kA

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 9, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 7, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=yahoo+finance+api+401+unauthorized+crumb+error&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.