Most people who reach this page are developers searching for filter.locationId in the Kroger Products API. This page explains that parameter and the location ID behind it, the daily limits, and what the Kroger rules allow. It also shows what kroger.com did to our server. The short answer: for Kroger data, use the API the way Kroger intends, and a proxy plays no part in it.
What filter.locationId does
Without a location, a product search returns everything Kroger sells nationwide that matches your term. It returns no price. The documentation is direct: "To return the following data from the /products endpoint, you must include a location Id in the request."
With filter.locationId set, each product gains these fields for that store:
| field | what it holds |
|---|---|
| price | the regular and the promo price at that store |
| nationalPrice | the regular and the promo national price |
| fulfillment | instore, shiptohome, delivery and curbside, each true or false |
| aisleLocations | where the item sits in that store |
| inventory | a stockLevel, when known |
The stockLevel reads HIGH, LOW or TEMPORARILY_OUT_OF_STOCK. Two notes from the same page matter. The instore flag only means the store sells the item, not that it is in stock. And seasonal products return a price only while they are available.
Finding a location ID
A location ID is eight characters, a combination of the division and the store number. You get it from the Locations API, and the usual starting point is filter.zipCode.near. By default, a search from a starting point returns 10 locations within a 10-mile radius. Widen it with filter.radiusInMiles.
The example in the Kroger documentation writes the address as /v1/locations&filter.zipCode.near=45140. The query needs a question mark instead: /v1/locations?filter.zipCode.near=45140.
A location ID of the wrong length fails with a clear error: code PRODUCT-2011-400, reason "Field 'locationId' must have a length of 8 characters".
A working call
The public APIs use an OAuth2 token made from your client ID and secret. Three calls cover the whole path:
# 1. A token for your application (curl builds the Basic header from -u)
curl -X POST 'https://api.kroger.com/v1/connect/oauth2/token' \
-u "$CLIENT_ID:$CLIENT_SECRET" \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d 'grant_type=client_credentials&scope=product.compact'
# 2. Stores near a ZIP code, with their locationId
curl 'https://api.kroger.com/v1/locations?filter.zipCode.near=45140' \
-H "Authorization: Bearer $TOKEN"
# 3. Products at one store, with prices
curl 'https://api.kroger.com/v1/products?filter.term=milk&filter.locationId=YOUR8CHARID' \
-H "Authorization: Bearer $TOKEN"
Let curl build the Basic header with -u. A header built by hand with GNU base64 breaks for long credentials, because that tool wraps its output every 76 characters.
We sent the third call from our own server on 27 September 2026 without a token. The API answered 401 with "The access_token is missing". A missing scope gives 403, and an expired token gives 401 with "The access token is invalid or has expired".
The daily limits
| API | limit |
|---|---|
| Products | 10,000 calls a day |
| Locations | 1,600 calls a day, for each of its three endpoints |
Kroger counts calls to an endpoint, whatever the operation. Each limit resets 24 hours after the first call to that endpoint. The documentation also says the limits are "applied equally across all clients", with no individual limits by client. Search results come 10 to a page by default, and filter.limit and filter.start page through them.
What the Kroger rules allow
The acceptable use rules for the Products API allow two things. You may show product data exactly as the server returns it, and leave out the parts your use case does not need. They prohibit four things:
- "Comparing products/prices among other retailers."
- Tracking, sharing or storing data derived from customer searches or frequently viewed products.
- Changing any product value, such as the name, description or price.
- "Systematically scraping or gathering response data to create a database. This includes using bots or crawlers to retrieve data from our APIs."
The website has its own terms, last updated on 9 September 2026. Those terms forbid users to "Use any automated means, including bots, crawlers, scrapers, or data-mining tools, to access, collect, extract, or monitor information from the Kroger Sites".
So the API is for showing Kroger products inside an app, such as a shopping list. Price tracking is ruled out on both the API and the website.
What kroger.com did to our server
We opened kroger.com twice from our server in St. Louis on 27 September 2026, as plain requests with a browser user agent. Both times the connection and the TLS handshake completed. Then the server reset the stream without sending any response. The address belongs to Akamai. We read the website terms from an Internet Archive copy of 24 September 2026 for that reason.
Where a proxy fits
It does not fit the API, which checks your application and counts your calls, not your address. It does not fit the website either, whose terms forbid automated collection and monitoring. A proxy changes neither rule. If you need price data, our price monitoring page covers the work on sites that allow it.
For other work, where a proxy is allowed, our guides compare datacenter and residential proxies, rotating and static residential proxies, and sticky and rotating sessions. A scripted browser takes a proxy as our Playwright guide shows, and our study of headless browser proxy bandwidth cost measures what it downloads. Our free proxy list and proxy checker cost nothing. We sell residential and ISP proxies. Residential traffic starts at $0.44/GB, and every plan is on our pricing page.
The limits of this page
We did not register an application, so we did not make a successful call or see a live price. The documentation text comes from the search index of the Kroger developer site, because its pages render with a script. The rules and limits can change, and this page is due for a check by 27 December 2026.
Sources
We read every source below on 27 September 2026.
- Kroger Developers, the Products API overview and product search guide, the Locations API location search guide, API Basics, Common Errors, Quick Start and Acceptable Use of Public APIs, from the developer site.
- Kroger, Website and App Terms, last updated 9 September 2026, in an Internet Archive copy of 24 September 2026.
- Our requests from our own server to kroger.com and to api.kroger.com, 27 September 2026.
More pages in this series: proxies for Walmart, proxies for Costco and proxies for Instacart.


