Guide

Usenet indexers and API keys explained

Direct answer

API keys are the quiet glue between NZB indexers and your automation apps. Without them, Sonarr and Radarr would need a human in a browser every time a new episode airs. With them, Prowlarr searches on a schedule, grabs an NZB, and hands work to SABnzbd while you sleep. Most provider-only review sites skip this layer; keys are indexer credentials, not NNTP passwords.

Updated 2026-10-01

API keys are the quiet glue between NZB indexers and your automation apps. Without them, Sonarr and Radarr would need a human in a browser every time a new episode airs. With them, Prowlarr searches on a schedule, grabs an NZB, and hands work to SABnzbd while you sleep. Most provider-only review sites skip this layer; keys are indexer credentials, not NNTP passwords.

Treat keys like passwords because they gate your paid indexer quotas and identify your account in logs. Leaked keys show up in paste sites and get revoked without warning. A few minutes of tidy setup prevents weekend outages that look like “Usenet is down” when only the indexer API locked out.

Why indexer APIs exist

Indexers expose HTTP endpoints that return search results and NZB links in machine-readable form. Newznab-compatible schemas dominate, so Prowlarr can reuse the same connector shape across many sites with per-site URLs and keys. Caps endpoints advertise categories and limits so *arr apps do not hammer impossible queries.

APIs replace scraping, which breaks whenever a site redesigns HTML. Stable keys let operators rate-limit fairly and revoke abusers. Your side of the bargain is storing keys securely and rotating them after migrations or exposed backups.

Where keys live and how to copy them

After you create an indexer account, open profile or API settings. You will see a random string, sometimes labeled API key, API ID plus key pair, or RSS key variants. Copy once into Prowlarr’s indexer form; avoid posting screenshots in Discord support threads.

Some indexers issue separate keys for RSS and API; use the API key path for Prowlarr unless the site documentation says otherwise. If an indexer offers multiple apps or keys, dedicate one key to your homelab so you can revoke it without breaking a phone RSS reader.

Prowlarr setup flow

Add each indexer as a Newznab-compatible app inside Prowlarr, paste base URL and key, test connectivity, then sync to Sonarr, Radarr, Lidarr, and Readarr from the Apps section. Sync propagates indexer definitions so you are not manually retyping keys in four UIs.

Watch Prowlarr health for 401 and 429 errors. Unauthorized usually means a typo or expired membership; too many requests means you need fewer apps, slower RSS sync, or a higher tier. Deeper client pairing notes live in best Usenet for Prowlarr.

Security and rotation habits

Store keys in Prowlarr’s config backup encrypted if you export settings. After cloning a VM or sharing a compose file, assume keys leaked and regenerate on the indexer site. Do not commit keys to git; use environment variables or secret stores for container stacks documented in homelab guides.

Indexer keys are unrelated to your Usenet provider password on port 563. Compromising one does not automatically compromise the other, but reuse across services makes incident response harder. Revoke old keys when you decommission an old Prowlarr host.

Rate limits and multiple apps

Each indexer sets its own hourly or daily API caps by membership tier. Running Sonarr, Radarr, and a manual search tool against one key can exhaust quotas before prime time releases land. Stagger RSS intervals and avoid redundant full-library searches after initial import.

Multiple keys on one account are uncommon; multiple indexers with one key each is normal. If searches fail only on one show, check indexer maintenance pages before blaming NZB quality or provider completion. Downloader basics remain in SABnzbd setup guide.

Document which key belongs to which homelab VM before you clone disks. Regenerate keys after restoring old backups to production so two Prowlarr instances never share one quota unknowingly.

FAQ

Is an API key the same as my Usenet provider password?
No. Provider credentials authenticate NNTP; indexer keys authenticate HTTP search APIs.
Do indexers rate limit API keys?
Yes. Limits vary by tier; exceed them and searches fail until the window resets.
Should I create multiple keys per indexer?
Only when the site offers per-app keys. Otherwise one homelab key is typical.
Do I need keys if I only use Easynews web search?
Browser search skips Prowlarr. Automation without indexers is impractical for Sonarr-grade libraries.

Related

Read next

Ecosystem and tools