I built a tool that extracted client tokens from Spotify's web player. Spotify's lawyers sent me a cease and desist letter.
The repository is gone now. But let's talk about what actually happened and why this is complete bullshit.
The tool was called
spotify-secrets. It was a scraper that monitored Spotify's web player for authentication secrets. Here's the entire thing:typescript
The core functionality was literally hooking
Object.prototype.secret in a headless browser, letting Spotify's own web player run, and capturing the TOTP secrets it uses client-side.I wasn't "hacking their infrastructure." I was watching their JavaScript set properties on objects. Properties they expose in every user's browser when you open
open.spotify.com.The tool would:
- Open Spotify's web player in Puppeteer
- Inject a property hook
- Wait for Spotify's code to set
.secret - Save the values to JSON files
- That's it
No server exploitation. No credential theft. No network interception. Just reading values that Spotify's own code creates in the browser.
On October 10, 2025, I got a message on Telegram from Perkins Coie LLP, Spotify's legal team.
The letter claimed:
- I violated Spotify's User Guidelines by "scraping"
- I was enabling "illicit tools" to rip content
- The repository name "Spotify Secrets" infringed their trademark
- I was committing tortious interference with a contract
They demanded I:
- Stop developing and distributing the tool
- Stop infringing their intellectual property
- Stop helping anyone else do the same
The tone was threatening. "Serious penalties." "Federal trademark infringement." "Spotify reserves all rights and remedies."
I got a legal threat from a multi-billion dollar company over a 100-line script that reads JavaScript variables.
Here's what makes this fucking ridiculous:
Spotify aggressively defends against a scraper while actively licensing their entire catalog to AI companies that redistribute music for profit.
AI companies scrape Spotify's metadata, lyrics, and audio features to train models. Some of them build competing products. Spotify's response? Cut licensing deals.
An random indie developer builds a tool that helps open-source projects authenticate with Spotify's API? Send the lawyers.
The double standard is insane. Billion-dollar AI companies get partnerships. Indie developers get cease and desists.
spotify-secrets wasn't enabling piracy. It was helping open-source projects access metadata.Projects that depended on it:
Votify (588 stars)
A tool for downloading songs. Uses the secrets for authentication.
A tool for downloading songs. Uses the secrets for authentication.
SimpMusic (5,200 stars)
"A simple music app using YouTube Music for backend" - uses Spotify for metadata enrichment.
"A simple music app using YouTube Music for backend" - uses Spotify for metadata enrichment.
librespot community
I worked with the librespot community to crack how Spotify's TOTP authentication works. They didn't depend on my tool, but we collaborated on reverse engineering the obfuscation.
I worked with the librespot community to crack how Spotify's TOTP authentication works. They didn't depend on my tool, but we collaborated on reverse engineering the obfuscation.
Most apps just use it for metadata. Song titles, artist info, album art, popularity metrics, recommendations.
Not piracy. Not ripping content. Just data that should be accessible through official APIs but isn't.
Spotify already has DRM. You can't just download audio even with valid tokens. These are authentication helpers, not piracy tools.
These projects exist because Spotify's official APIs are deliberately limited. You can't get recommendation metrics without a user token. You can't access certain endpoints without premium. Rate limits are absurdly low for hobbyists.
I tried to apply for better API access five times. Rejected every time. No explanation.
So the community reverse engineers solutions. Then Spotify acts shocked when people work around their restrictions.
Spotify doesn't want developers they can't control.
If you're a big company with an official partnership, you get:
- Advanced API access
- Higher rate limits
- Dedicated support
- Advance notice of changes
If you're an indie developer building cool shit for free, you get:
- Rejected API applications
- Broken endpoints with no warning
- Hostile Terms of Service
- Legal threats when you find workarounds
Don't forget, this is the same company that:
- Killed libspotify SDK in 2020 with no replacement
- Randomly requires premium for certain endpoints
- Breaks the recommendations API without notice
- Ships a desktop client that uses more RAM than Chrome (Literally bundles Chrome as the Desktop Client)
But instead of improving their platform, they spend resources building legal cases against developers who make their platform more useful.
When I took down the repo, people immediately noticed.
Projects broke. Developers scrambled for alternatives. The ecosystem got a little bit smaller.
And for what? What did Spotify actually gain here?
They didn't stop reverse engineering.
Someone else will build the same tool with a different name. They just made it harder for people who were already dealing with their hostile API policies.
The letter isn't a lawsuit. It's a demand to stop. I stopped.
Could Spotify actually sue me? Maybe. But I don't have lawyer money. Fighting this would be stupid even if I'd probably win.
So I took the loss. Deleted the repo. Moved on.
The frustrating part is that I tried to do this the right way first, not the C&D.
I applied for official API access. Multiple times. Rejected.
I built a tool that helped the community. Got threatened.
Spotify's message is clear:
If you're not making them money, they don't want you building on their platform.
This hits OSS projects the hardest.
Commercial apps can pivot. Pay for official APIs. Find alternatives. Open-source maintainers are doing this for free. They don't have resources to constantly rewrite authentication when Spotify breaks things.
Projects die because maintainers get tired of fighting. The ecosystem shrinks. Innovation stops.
Spotify benefits from these projects. They drive engagement. They solve problems Spotify won't solve. They keep power users on the platform.
But instead of supporting this ecosystem, Spotify destroys it. Then wonders why their platform feels stagnant.
It's a pattern in tech:
- Twitter killed third-party clients
- Reddit broke API access with pricing (But bots are still so common)
- YouTube constantly breaks downloaders
- Instagram kills scraping tools
Platforms want total control. They want to be the only way to access their data. Innovation they can't monetize gets crushed.
And the people hurt most are:
- Users - Fewer tools, fewer alternatives, less control
- Developers - Years of work destroyed with no warning
- The ecosystem - Less innovation, more monopolistic control
If you're building something that depends on scraping or unofficial APIs:
Don't use company trademarks in the name
I called it "Spotify Secrets." That made the trademark claim easy. Call it something generic.
Keep descriptions vague
"Extracting secrets from Spotify's infrastructure" sounds worse than "authentication helper for open-source projects."
Have a backup plan
The repo getting nuked shouldn't break your projects. Keep local copies.
The repo is only in my local directory now. The functionality still works for my personal projects.
Is this what the C&D wanted? Probably not. But they said stop distributing, not stop using.
Also, I do the same thing with Apple Music. Extract their JWT from bundle files. Get way better data. Apple hasn't sent any lawyers for my ass.
typescript
Same concept. Different company. No legal threats.
Make of that what you will.
I built a tool that helped the community. Spotify sent lawyers instead of saying thanks.
They pay artists $0.003 per stream while making billions. They license content to AI companies for profit. But a developer scraping client tokens for metadata access? That's where they draw the line.
The irony is not lost on me.
OSS devs make platforms better. We solve problems companies won't solve. We build tools that users actually want.
The least companies could do is not actively destroy our work.
But here we are.
Note: The repo is no longer available in remote. If you depended on
spotify-secrets, you'll need to find alternative approaches. I can't help you directly due to the C&D terms.The community will figure it out. We always do.
text