Keep credentials on the server
Store keys in a secret manager and give each integration the permissions it needs. Keep source-site credentials out of application logs.Choose outputs and validate results
Combine the Scrape formats you need in one request. Check each output’ssuccess; handle empty lists, missing Brand fields, and low-confidence People matches explicitly. Preserve user corrections outside refreshed API data.
Set cache freshness
Choose freshness by workload. UsemaxAgeMs: 0 when a Scrape result must reflect a new visit; accept older data for infrequently changing pages. See Scrape caching and Brand options.
Bound work and retries
Set API and client timeouts, restrict crawl scope, and cap concurrent work. HonorRetry-After after 429. Retry transient failures with bounded exponential backoff and jitter; fix invalid inputs before retrying.
Use an idempotency key for batch submission. Monitor webhook deliveries and deduplicate events before applying changes.
Reduce transfer size
Request only needed outputs and apply content filters. Avoid preserving base64 images in Markdown unless needed. UseAccept-Encoding: gzip or your client’s compression support; SDKs generally decompress responses automatically.
Observe the integration
Recordrequest_id, latency, response status, and stable error codes. Use tags and logs to locate regressions without retaining unnecessary page content. Test ZDR confirmation when using retention controls.
Pin SDK versions, review the changelog, and follow the API stability policy when upgrading.