Food & drink / API GUIDE

Open Food Facts.

Barcode-based food product information, ingredients, and nutrition data.

Documentation reviewed · 16 Sep 2026
Official resource ↗
AUTHENTICATIONNo key
ACCESS / PRICINGFree access
EXAMPLE REQUESTIncluded below
REVIEW STATUSDocs reviewed
THE OVERVIEW

A building block for your next idea.

Build a barcode product lookup showing available ingredients, source links, and missing-data states.

Know before you build

Public reads require an identifying User-Agent; writes need authentication. Follow endpoint rate limits, attribution, and share-alike conditions. Data is community-contributed and may be incomplete. Use staging for testing.

Check current provider documentation ↗

Your first request

Start with this documented example. Replace credential placeholders with your own test credentials. Browser execution depends on the provider’s CORS policy.

cURL REQUEST EXAMPLE
curl --request GET 'https://world.openfoodfacts.org/api/v3.6/product/3274080005003.json'

This provider requests an identifying User-Agent in server integrations. Browsers control that header; the browser playground omits it. Consult provider requirements before using a browser-only integration in production.

Practical questions

What can I build with Open Food Facts?+

Build a barcode product lookup showing available ingredients, source links, and missing-data states.

Does Open Food Facts need authentication?+

The reviewed example is listed as “No key”. Public reads require an identifying User-Agent; writes need authentication. Follow endpoint rate limits, attribution, and share-alike conditions. Data is community-contributed and may be incomplete. Use staging for testing.

Can I call Open Food Facts from a browser?+

Browser access depends on the provider’s CORS policy for your origin, method, and headers. The playground makes a direct request and cannot bypass those restrictions.

Sources & confidence

Provider documentation was reviewed on 16 September 2026. This is not a live availability test or an endorsement.

Source catalogs can become outdated. Read our review and attribution policy. Plain-text guide ↗

THE REQUEST WORKBENCH

Meet the data.

Runs in your browser

Edit a request and see what comes back. Your credentials stay in page memory and go directly to the selected API provider.

01 / REQUEST
Provider docs ↗

Choose an HTTPS endpoint.

Query parameters

Authentication

Custom headers +

The browser manages Cookie, Origin, User-Agent, and other restricted headers.

CORS support is required. No proxy. No saved credentials. 30-second timeout · 2 MB response limit.

02 / RESPONSE
Ready when you are
{ }

A little curiosity.
A real response.

Send a request to explore the response.
Nothing runs automatically.

Response bodies are displayed as data. Remote HTML and scripts are never executed.

Take the request with you cURL / JavaScript

Authentication, query values, custom header values, and body content are hidden by default. Check any URL path before sharing.