How to Get Your Music Credentials: sp_dc, media-user-token, Deezer ARL & Qobuz Auth Token
If you’re connecting a downloader or API tool to your own music account, you’ll need a private session credential that the service hides inside your browser. This guide walks you through grabbing each one — Spotify sp_dc, Apple Music media-user-token, Deezer arl, and Qobuz x-user-auth-token — in a couple of minutes, with troubleshooting tables for the common snags.
A quick word on safety. These credentials are the keys to your account. Treat them exactly like a password: keep them on your machine, never share them, and never commit them to Git.
Before you start
You’ll need:
- A desktop browser — Chrome, Edge, or Firefox. (Mobile browsers don’t expose developer tools, so this has to be done on a computer.)
- An active login to the account you want to use.
- About two minutes per service, and the patience to click through DevTools once.
Nothing gets installed, and nothing leaves your machine. You’re simply reading a value your own browser already has.
Spotify sp_dc Cookie
What it is, and why you need it
sp_dc is the login cookie set by the Spotify web player. It’s what tools like SpotiFLAC use to authenticate against Spotify’s internal endpoints — the ones that aren’t part of the public API. It’s tied to your session, so it only exists once you’re logged in. If you’d rather not touch cookies at all, an online Spotify downloader handles authentication for you.
Step by step
Works the same way in Chrome, Edge, and Firefox.
- Open and log in. Go to open.spotify.com and sign in. Finish any CAPTCHA or two-factor prompt.
- Open Developer Tools. Press
F12, then:- Chrome / Edge: open the Application tab.
- Firefox: open the Storage tab.
- Find your cookies. In the left sidebar, expand Cookies → https://open.spotify.com.
- Copy the value. Find the row named
sp_dcand copy its Value column. It starts withAQBor similar.
That’s your credential. Keep it somewhere safe until you’ve pasted it into your tool.
If it doesn’t work
| What you’re seeing | What to try |
|---|---|
| The cookie isn’t listed | Double-check you’re actually logged in (your avatar should be top-right), then refresh with DevTools already open. |
| The value is empty or expired | Log out and back in — 2FA sessions sometimes rotate the cookie. |
| You signed in with Facebook or Google | Use Log in with password instead. OAuth logins don’t always set sp_dc the same way. |
| You hit “rate limited” errors later | Don’t run several tools against the same account at once. Give it a few hours and try again. |
Apple Music media-user-token
What it is, and why you need it
When your browser talks to Apple Music’s web API (amp-api.music.apple.com), it attaches a long JWT-style token in a header called media-user-token. Apple’s official Web API requires this header for personal endpoints like /v1/me/library. It is also needed in our AM Ripper shortcut, which is available in our Premium Plan.
There’s no page in Apple’s settings that shows you this value — the only way to get it is to copy it out of your own logged-in browser session. Here’s how.
Step by step
- Open and log in. Go to music.apple.com in Chrome or Edge, and sign in to your account.
- Open Developer Tools. Press
F12, or right-click anywhere on the page and choose Inspect. - Switch to the Network tab. This is where your browser lists every request it makes.
- Tick Preserve log — otherwise the list clears every time the page reloads.
- In the filter box, type
buy, or simply play a track to generate some API traffic.
- Find a request to Apple’s API. Look for entries pointing at
amp-api.music.apple.com(URLs beginninghttps://amp-api.music.apple.com/v1/...). Click any one of them. - Read the request headers. In the panel that opens, scroll to Request Headers and look for
media-user-token:. - Copy the value. Select everything after the colon — it’s long, and it always starts with
eyJ. That whole string is your token.
If it doesn’t work
| What you’re seeing | What to try |
|---|---|
| The header isn’t in the list | Force a fresh API call — reload the page, or click into a playlist or artist. Some requests only fire when you interact. |
| The value looks like a placeholder | Make sure you’re on Headers → Request Headers, not the Preview pane. Filtering by Fetch/XHR can also make the right request easier to spot. |
| The token stops working later | It expires. Just repeat these steps for a fresh one. |
Deezer arl Cookie
What it is, and why you need it
arl is Deezer’s session cookie. Downloaders and tools that fetch FLAC or high-quality streams from Deezer — see our guide on how to download Deezer playlists — use it to authenticate as you. There’s no public API for personal downloads, so the cookie is the only way in. It lasts a long time (typically months), so you won’t need to refresh it often.
Step by step
- Open and log in. Go to www.deezer.com and sign in to your account.
- Open Developer Tools. Press
F12, then:- Chrome / Edge: open the Application tab.
- Firefox: open the Storage tab.
- Find your cookies. In the left sidebar, expand Cookies → https://www.deezer.com.
- Copy the value. Find the row named
arland copy its Value column — it’s a 192-character hexadecimal string.
That’s the entire credential. Paste it wherever your tool asks for a Deezer ARL.
If it doesn’t work
| What you’re seeing | What to try |
|---|---|
| The cookie isn’t listed | Make sure you’re logged in and refresh the page with DevTools open. The arl only appears after a successful login. |
| The tool rejects the ARL | Check for stray spaces or line breaks when you copied it — the value must be exactly 192 characters. |
| Downloads fail in low quality | Your account tier matters. A free account’s arl won’t unlock HiFi/FLAC streams; you need Deezer Premium or HiFi. |
| It suddenly stops working | Log out of Deezer everywhere (Settings → Devices) and log back in for a fresh arl. |
Qobuz x-user-auth-token
What it is, and why you need it
Qobuz authenticates personal API calls with a token sent in the x-user-auth-token header. Tools that download Qobuz music or stream in hi-res use this header alongside the app’s public app_id to act on your account.
Step by step
- Open and log in. Go to play.qobuz.com in Chrome or Edge, and sign in.
- Open Developer Tools. Press
F12and switch to the Network tab. - Generate some traffic. Play a track, or click into an album or your favorites — this fires API requests.
- Find a Qobuz API request. In the filter box, type
qobuz.comor look for requests towww.qobuz.com/api.json/0.2/.... Click one. - Read the request headers. Scroll to Request Headers and find:
x-user-auth-token:— the long alphanumeric string after the colon is your token.
- Copy the value. While you’re here, also note the
x-app-idheader value — most tools need both.
If it doesn’t work
| What you’re seeing | What to try |
|---|---|
| No API requests appear | Filter by Fetch/XHR and interact with the page — play a song or open your library. |
| The header isn’t there | Scroll carefully through Request Headers — it’s near the bottom. Try a different api.json request. |
| The tool says the token is invalid | Copy the entire value with no spaces, and make sure you’re passing the matching x-app-id too. |
| It expires | Log out and back in at play.qobuz.com, then repeat the steps for a fresh token. |
Security notes (please read)
All four of these values are effectively account passwords — media-user-token grants read access to your Apple Music library, sp_dc is close to full Spotify account access, and the Deezer arl and Qobuz token are equivalent to being logged in as you. A few habits will keep you safe:
- Never paste them into untrusted tools or websites. If you didn’t build it and don’t trust it, it shouldn’t see your credentials.
- Never commit them to version control. Keep them out of your repos, and add
.envto.gitignore. - Store them in environment variables or a
.envfile, not hard-coded in scripts:
# .env
SPOTIFY_SP_DC=AQBcX9...
APPLE_MEDIA_USER_TOKEN=eyJhbGciOi...
DEEZER_ARL=9a8b7c6d...
QOBUZ_AUTH_TOKEN=Ab1Cd2Ef...- Rotate if leaked. Logging out of all sessions in each account’s settings invalidates the old credentials.
Quick reference
| Credential | Where it lives | Where to find it | What it unlocks |
|---|---|---|---|
sp_dc |
Cookie on open.spotify.com |
DevTools → Application/Storage → Cookies | Spotify internal endpoints (playlists, downloads) |
media-user-token |
Request header to amp-api.music.apple.com |
DevTools → Network → Request Headers | Apple Music library endpoints (/v1/me/library) |
arl |
Cookie on www.deezer.com |
DevTools → Application/Storage → Cookies | Deezer streams and downloads (quality depends on your plan) |
x-user-auth-token |
Request header to www.qobuz.com/api.json |
DevTools → Network → Request Headers | Qobuz purchases and hi-res streaming |
FAQ
How long do these last?
Most are session-bound and expire eventually — the Deezer arl is the exception and often lasts months. When a tool suddenly reports an auth error, grabbing a fresh value is almost always the fix.
Can I use a friend’s or a shared account? Please don’t. These credentials are personal, and sharing them risks both your account and theirs.
Do I need a paid subscription?
The credential itself is set on any logged-in account, but what it unlocks depends on your plan — for example, a free Deezer account’s arl won’t fetch FLAC, and Spotify download tools generally need Premium. If cost is the blocker, some Spotify alternatives are cheaper or include hi-res audio in the base plan.
I’m stuck. Re-read the troubleshooting table for your service — nine times out of ten the answer is there. If not, an expired token or a non-standard login method (OAuth via Google/Facebook) is usually to blame.
Chrunos