Updated September 2026. I wrote this in 2020, when Heroku's free tier was still the obvious place to put a hobby project. That is gone, and there is now a much simpler answer than the one I originally described — so the easy option is first, and my original approach follows it.
Almost everyone using the official Supercell games API has shown disagreement with the fact that the official API limits keys to IP addresses. Lots of the people using the API are using it personally for hobby projects and thus use free services. But that limitation of the Supercell API — which applies to Clash of Clans, Clash Royale and Brawl Stars alike — is causing lots of problem to the free users using the service.
There are two ways around it. One is a proxy, which is about five minutes of work. The other is the service I built, which re-issues your key whenever your IP changes.
The easy way: use a proxy
If all you need is for the API to answer your requests, you do not need to solve the dynamic-IP problem at all — you can point at a proxy that already has a fixed IP and let it forward your calls.
RoyaleAPI runs one for free, and it covers Clash of Clans, Clash Royale and Brawl Stars:
- Create a key on the official developer portal as usual
- Whitelist
45.79.218.79— the proxy's IP — instead of your own - Send your requests to
https://proxy.royaleapi.dev, keeping the same paths
So a Clash of Clans call becomes:
https://proxy.royaleapi.dev/v1/clans/%232ABC123
Your key never leaves your own control, and there is nothing to host. If this covers your use case, stop here — the rest of this article is the harder path, and it only makes sense if you specifically want to keep talking to the official endpoint directly.
The other way: re-issue the key yourself
To overcome that issue without a proxy, I thought of this work around.
How does it actually work?
- It logs in to the developer portal using the mail and password provided through the config.
- It then fetches the available API keys and checks if any key has the current IP whitelisted.
- If found returns the token, otherwise generate a new one for the current IP and return it.
- All the requests to the Official API are made then using the generated key
That sounds risky!!
It is a fair question. This is not a documented use of the developer portal, so you should go in aware of these things:
- You are using your mail and password to login to the developer site so you should always make sure they are not publicly posted anywhere!
Important - This is not how supercell wants you to access the developer site and create a token, and supercell might take action against you, so make sure to use an alternative mail for this purpose.
- Use this method only until you can get yourself a static IP, or move to the proxy above. If you get one, opt out of this method as soon as you can.
What extra can I do with it?
You can customize the service as per your needs. If you need to save the responses in some database for analytics purposes then you can simply edit the route files i.e. {game}/routes/{file} and customize it as per the need. You can even add custom routes, remove the routes available or modify the available routes as per the requirements.
Heard enough! How do I use it?
Yeah I have talked enough as well. The service is built using express and contains an index.js file to be started with, so locally all you got to do is run node index.js. But you are not going to want this running on your own machine, so it needs somewhere to live.
This is the part that has aged. The original version of this article walked through Heroku's free tier, which ended in November 2022; Fly.io's free allowance went the same way in 2024. As of 2026 the free tiers worth looking at are Render and Koyeb — either gives you a small web service, which is all this needs. The shape of the setup is the same on both:
- Fork this repo bsantosh909/supercell-api
- Update the config.js to enable the API you want to use
- Create a new web service on your platform of choice and point it at your fork
- Deploy from
master, and set the start command tonode index.js(theherokubranch is still there from the original setup, but it is only useful on Heroku itself) - Add the environment variables
GLOBAL_MAIL,GLOBAL_PASS,CLASH_MAIL,CLASH_PASS,ROYALE_MAIL,ROYALE_PASS,BRAWL_MAIL,BRAWL_PASS- Set
GLOBAL_MAILandGLOBAL_PASSif you have the mail and password same over all the developer portals - Otherwise set the other variables with the individual values of mail and password over the respective developer portals
- NOTE:
GLOBAL_MAILandGLOBAL_PASSwill supersede values of other relative variables
- Set
That gets you a working service that returns data from the official API and behaves just like it. One thing has carried over from the Heroku days: free tiers still spin down after a stretch of inactivity, so the first request after a quiet spell is slow. Worth knowing, but not worth papering over with a keep-alive pinger — platforms now generally read that as abusing the free tier.
// Enabling the games
exports.games = {
clash: false,
royale: false,
brawl: true
};
// Set mail and pass are same across all dev platforms
exports.global = {
mail: 'shared-mail@gmail.com',
password: 'shared-secret-key'
};
// Set mail and pass for single platform
exports.brawl = {
mail: 'your-mail@gmail.com',
password: 'secret-password-here'
};How to use with full control?
Technically it is possible by extracting the core of the project i.e. util/tokener.js in the github repository. This file is the reason behind the success of this concept. So if you want to have completely control over how you do stuffs while having this awesome feature, you can simply get the file from the github repo and use as your requirements.
Anything else?
Thats all from me. But if you got anything you can contact me through my contact mail. But if it is some Bug or feature idea, simply report it over at the original Repository. I will be more than happy to hear feedback from you guys.
If you play the games rather than build against them, my other Supercell write-up covers creator codes and how to use them.

