11 ms·
Youtube.js – full-featured wrapper around YouTube's private API
- trinovantes 4y agoI'm always nervous about 3rd party API wrappers. It's basically saying "Here's the keys to my (users) Google account, please don't do anything bad". Even if it's open source, there's no guarantee there's no malicious change in version x.x.N+1
- sieabahlpark 4y agoYou could just pin to a version like a good dev and rid yourself of the problem. Just do a quick diff check when you upgrade. If you're too lazy to do that then you never really cared about security all that much in the first place.
- Firmwarrior 4y agoWHAT? How am I supposed to make a social media calculator flashlight app without pulling in 200 random libraries and their 5000 dependencies?
- Aachen 4y ago> just pin to a version like a good dev Good devs don't keep up with dependencies' security updates or was this meant ironically? Also, you'd have to pin to a hash, I imagine. Changing the version tag and pushing with -f doesn't sound like rocket science for someone with malice in mind. Next time you deploy it, you'll still get that code.
- chmod775 4y agoAny software you use might steal your YouTube credentials. It might be this API wrapper or it might be any other dependency. It might even be the scientific calculator you installed that had nothing to do with that project. What makes this especially scary?
- trinovantes 4y agoTechnically nothing can be trusted e.g. can anyone trust their silicon, wires, device drivers, compilers, OS, routers, SSL CAs, etc.? Trust has to happen at some point. The difference is that it's trivial for this developer to insert a backdoor to steal Google credentials since they know exactly how and where the oauth tokens are located. It's significantly harder for e.g. a webpack developer to insert a backdoor to steal Google credentials since they would have to first determine the code it's processing is handling oauth tokens and then figure out where they are stored. The barrier to entry is the key in assessing your threat model. 3 letter agencies may not care about the cost if the target is valuable but a bored kid on the other side of the world will give up pretty quickly.
- cmeacham98 4y ago> The difference is that it's trivial for this developer to insert a backdoor to steal Google credentials since they know exactly how and where the oauth tokens are located So does all the malware: your browser's cookie store
- trinovantes 4y agoNot every application runs in the browser i.e. not SPA and any injected frontend js would have to bypass browser's sandboxing to steal another domain's cookies i.e. a zero day which is beyond your threat model
- cmeacham98 4y ago> Not every application runs in the browser We're talking about YouTube in this thread. > any injected frontend js would have to bypass browser's sandboxing to steal another domain's cookies i.e. a zero day which is beyond your threat model Where did this random unrelated attack vector come from? We're going talking about running untrusted software on your computer, remember? That's the attack vector we're discussing. Your point was "malware in random unrelated software won't know where to look for my YouTube session key", my response was "it will".
- deleted 4y ago[deleted]
- timoteostewart 4y agoLove this Q&A: Do I need an API key to use this? No, YouTube.js does not use any official API so no API keys are required.
- deleted 4y ago[deleted]
- RobertRoberts 4y agoThe reason I stopped integrating any API based system (FB, Twitter, etc...) into my code bases for services I don't pay for (or my customers) is because they all changed willy-nilly and broke on a regular basis. This is more likely to break (be broken by google) than an official API, and those are bad enough. (hard pass on even trying this out, especially if it's good/nice I'll want to use it and kick myself later for being an idiot.)
- stingraycharles 4y agoUnfortunately it’s rarely that these kind of decisions are based on technical merit, but instead because they’re part of the business proposition, or requested by other parts of the business (sales/marketing). Other than that, I fully agree that you should try to minimize your dependence on them, it’s not good a good position to be in; what’s in the best interest for YouTube today may not be the case in one year.
- cromwellian 4y agoIn my experience, private APIs are expected to be refactored, and you should not depend on them. I don't think sales/marketing are involved at all. For a public API, sure, but don't expect private, undocumented APIs not to break you, in fact, you SHOULD expect them to change, especially in any codebase that is actively being maintained.
- matheusmoreira 4y agoAwesome!! A custom client for YouTube that bypasses all their front end code. I wish there was something like this for every single web site!
- foreigner 4y agoI wish there was one for Facebook
- endisneigh 4y agoIf you’re YouTube or any site, and want to stop these sort of wrappers - what’s the easiest way to do so without breaking your own site? I find this task to be an interesting engineering problem. A related question is if there’s an unspoofable way to detect a client.
- sschueller 4y agoProvide a public API (charge for it if you have too). The videos on YouTube are the property of the creators, not YouTube.
- charcircuit 4y agoYouTube already has a public API
- samisupset 4y agoKeep changing the implementation, keep changing names, keep changing the API formats. I'm definitely curious if there's a way to do a rotation that resists easy automatic code analysis.
- FrenchDevRemote 4y agoyou don't even have to look at the script, just at the network requests you'd basically have to make your own stealthy video format, otherwise you can just catch network requests
- comprev 4y agoFacebook does something similar to combat adblockers. They mangle the names of div elements to make sponsored posts indistinguishable from friends/group posts. I'm not aware of any browser plugins which are effective at blocking FB ads. Anyone know if other websites put as much effort into anti-adblock engineering?
- lostmsu 4y ago
- imiric 4y agoIt would be great if this had a CLI tool, so that it could be used as an alternative to yt-dlp. Or a web frontend as an alternative to Invidious, which breaks more often than not. That said, I wouldn't be surprised if Google issues a C&D, or just inevitably breaks it, especially if it uses undocumented APIs.
- skanga 4y agoIts VERY easy to make one. 1. Install NodeJS and NPM (if you don't already have it) 2. Create a new folder 3. Run "npm install youtubei.js@latest" in that folder 4. Create a new file in this folder called ytdl.js (or whatever you like) 5. See section "Downloading videos:" on the github page. Make the contents of the file exactly like that. i.e. just cut/paste that example. 6. Replace line 'Looking for life on Mars - documentary' with the name of the youtube video you want to download (ideally this should come from args) 7. Run "node ytdl.js" and it should download
- imiric 4y agoWell, sure, but I'd rather have this as part of the official project, instead of me messing with the JS ecosystem, or trusting a 3rd party to do it. It should be trivial for the project maintainers to do this, as you say.
- bragr 4y agoCool project but I wonder if the name will catch flak from the lawyers. Trademarks and all that. At they very least a big "This is not affiliated with Google/Youtube" seems like a wise precaution.
- wvenable 4y agoThey should immediately rename it so as not to be caught the way YouTube Vanced was. A disclaimer is not a sufficient response to trademark issues.
- ______-_-______ 4y agoOr do this: 1. Release it as youtube.js for the name recognition 2. Wait for the certified letter 3. Announce you're renaming your project and get another 24 hours of exposure in the news This guy is playing the game.
- kadoban 4y agoSomething like this lives or dies based on how much you annoy the people with lawyers to spare. Doesn't seem like the best plan.
- actually_a_dog 4y agoIs there any better plan in an era where the real currency is attention?
- kadoban 4y agoI doubt having the project named after youtube is that important for attention.
- actually_a_dog 4y agoThe attention comes from the stories that happen after they leak the C&D that Alphabet is going to send them for naming it after youtube, then quickly roll out a rename.
- grammers 4y agoNice, thanks for sharing!
- freedomben 4y agoI've been wanting to use the Youtube Music API to automate some personal chores (like building/cleaning playlists, etc) and was very discouraged. I actually switched to Spotify (trial) partially over it but there were a couple of other (off-topic) reasons I didn't want to stay with Spotify. This looks like a wonderful tool! And it's not in Python :-D (sorry python people). Like others I'm a little concerned about breakage as youtube APIs churn. Does anyone know what Youtube's approach to backwards compatibility is for internal APIs? Some companies just wait until 98% of user's are on the new clients and then rip stuff out, but others I've worked with basically don't allow breaking the API except in important circumstances and they stick around deprecated for a while.
- qzx_pierri 4y ago+1 Social Credit Points for posting "SPOTIFY BAD" in a public forum /s
- deleted 4y ago[deleted]
- heavyset_go 4y agoThs drove me nuts because Google Music had an actual public API. The service was deprecated in favor of YT Music, which has less features and no equivalent API. That deprecation was a catalyst to move my music collection elsewhere, so it's not threatened by the whims of Google anymore.
- freedomben 4y agoMakes a ton of sense. I almost bailed for the same reason. It was such a ridiculous downgrade. I just barely (today actually) got back a super important feature to me that Play Music had years ago: Save a queue as a playlist. If this private API gets a C&D or gets aggressively broken, I absolutely will bail too.
- Aachen 4y agoFwiw I've played with the Spotify api before for managing playlists in my account and that was not complicated. The GDPR export is also computer-readable (json) though it takes a literal month (sleep(rand(10,20)*days) for the initial set, then contact support to also get the "diagnostic" data associated with your account and wait some more). But it's probably more work for you to switch than it's worth.
- cphoover 4y agoI'm surprised they still support video dislike via API, but have removed it from the user interface... I understand they are likely worried about backwards compatibility with the abundance of client-devices, and not inadvertently breaking some app somewhere, but why not just make it a noop... Unrelated: My treadmill has the absolute worst YT client I've ever used.
- freedomben 4y agoMy understanding was that they still want to hoover up that sweet sweet preferences data (of which dislike is a useful metric). It's just not going to be exposed externally.
- tshaddox 4y agoYouTube hasn’t removed the dislike button. They have removed the dislike count.
- cphoover 4y agoMy mistake
- Tenoke 4y agoThey do and you can install extensions to see the dislike count though sadly they slow down my experience every time Ive tried them (at least on Windows Chrome).
- etra0 4y agoYou cannot longer see the true like/dislike ratio. They removed the dislike count even from the API since December 13th [0]. The extension does some guesswork to calculate that for you [1]. This library also doesn't give you the dislikes anymore (just tested it). [0] https://support.google.com/youtube/thread/134791097/update-to-youtube-dislike-counts https://support.google.com/youtube/thread/134791097/update-t... [1] https://github.com/Anarios/return-youtube-dislike#what-it-does https://github.com/Anarios/return-youtube-dislike#what-it-do...
- jokoon 4y agoSadly, I don't think it will let users view video that require login. For example, some 6min show that goes on live french TV everyday got flagged and requires login to be viewed, for age reason. Maybe there was curse words, or some butt-shaped thing in it?
- Quentak 4y agohttps://github.com/zerodytrash/Simple-YouTube-Age-Restriction-Bypass https://github.com/zerodytrash/Simple-YouTube-Age-Restrictio...
- lpgauth 4y agoVery interesting. Does anyone know how stable the InnerTube API is?
- krick 4y agoI suppose it will break more often than youtube-dl.
- judge2020 4y agouse yt-dlp - seems to be more actively maintained, at least for the youtube downloader which runs at full speed for me, while youtube-dl downloads videos at <50kbps.
- binarynate 4y agoThis is really cool, but maybe the README's disclaimer should also warn that using YouTube's private APIs is against their Terms of Service[0], specifically this section: The following restrictions apply to your use of the Service. You are not allowed to: (...) 3. access the Service using any automated means (such as robots, botnets or scrapers) except (a) in the case of public search engines, in accordance with YouTube’s robots.txt file; or (b) with YouTube’s prior written permission; It would be great if YouTube updated their ToS to permit this because that could unlock some really interesting innovation. Until then, devs should at least be aware that building a product with these APIs is risky. [0]: https://www.youtube.com/static?template=terms https://www.youtube.com/static?template=terms
- judge2020 4y agoI don't see why YouTube would want to allow any of this; the APIs probably changes regularly, have documentation only available internally, and they can't attribute the use of these APIs to specific Client IDs for abuse (ie. bypassing rate limits by using these); this is not mentioning how there's $0 to gain from doing this, and it could actively cause them to lose money since the RIAA has DMCA'd even the mention of downloading music videos from YT[0]. If they wanted to introduce any more functionality to the API, they'll simply add it to the official API and extend the docs[1]. 0: https://news.ycombinator.com/item?id=24872911 https://news.ycombinator.com/item?id=24872911 1: https://developers.google.com/youtube/v3/docs https://developers.google.com/youtube/v3/docs
- Grimburger 4y ago> the APIs probably changes regularly I'd go as far to say routinely. A massive pain point for third party youtube apps like newpipe which break every few months due to it.
- arcbyte 4y agoAs a regular user of NewPipe, I disagree that it's a "massive" pain point. NewPipe works very well almost all the time. Coincidentally today is maybe the third time I've went to watch something and it's been broken. It's annoying yes, but soooo much less annoying that constant ads. It's a minor pain point that is easily solved by temporarily switching back to regular youtube.. by the time I've seen a few ads I'm more annoyed at the regular experience and NewPipe probably has a fix out by then anyway.
- Aulig 4y agoDoes the OAuth login give you full access like a cookie login? Personally I'm using Firebase's private API because the public API is missing a couple of features. Currently I just regularly extract my Google cookies from Firefox and use those. But an easy login that grants access to the private API would be cleaner of course.
- londons_explore 4y agoWorth noting that if you automate too much with this API, you'd be smart to not do it with a Google account you care about, or it'll get banned. And they ban any accounts with matching recovery or verification phone numbers and email addresses too, or part of the same gsuite domain.