Dataset: I wish to give a journalist my scrapes of Hinge profiles of SF and London
Disclaimer
Quick Note
Main
Hinge's API has been reverse engineered and there exist alternate clients for it.
You can pull various unofficial client repos off of github, and ask gpt-6-astra to figure out the latest endpoints.
Make sure to pass all traffic through IProyal residential proxies.
You can complete phone registration using hero-sms and email registration using a temporary email provider.
Hoewever, completing 100% profile still did not enable Discover for me.
The only step that I needed to run on a real mobile device was Hinge Face Check powered by FaceTec.
I was able to pass this step simply using my own face for multiple different accounts, which was surprising to me. I combed my hair differently, wore different clothes and used different lighting angle, although I don't know if any of this made a difference.
I was prepared for the worst case option which would to be find somebody of lower class, and pay them to pass it for me. But I didn't end up having to do even this.
FaceTec runs a $600k bounty program which makes me confused how this even worked. Maybe Hinge has disabled or used a relaxed threshold for multiple accounts using the same face?
You can use the same account back and forth on cloud + residential proxy, and then real mobile device + real residential IP. You can even use the same device for multiple accounts, just logout of app and google playstore, and clear app storage and cache. Only the Face Check step seems to check the device as far as I understand.
The image CDN has no authentication.
Once you have obtained all the image urls, you can just run a simple bulk curl to get all the images. No proxy and no login required for this step.
I used two accounts ofcourse, one male then one female. You can further use short-term, long-term, non-binary etc if you are particular about 100% coverage.
Main 2
As always, I think I am not the ideal person to sit and DM all these people and get interviews and so on. If you are a journalist and want to work with me on this, contact me.
As always, I decided not to post the dataset publicly because it might be usable for doxxing random people. I am okay doxxing people personally but wanted to be more selective about what gets leaked to the public.
I could post the repo if anyone wants, although to be honest these types of endpoints tend to change formats every few months. You're probably better off just asking gpt-6-astra medium (or higher) to look through existing github repos to scrape Hinge, and figure out the latest endpoints.
Scraping summary, written with help of gpt-6-astra medium, may contain hallucins
Hinge scraping - compact, standalone recipe
Transport: https://prod-api.hingeaws.net; JSON requests through IPRoyal (geo.iproyal.com), one pooled connection, 5-second spacing. (Samuel - 5s is optimal to avoid ratelimit)
If 412: POST /auth/device/validate with {"installId":I,"deviceId":D,"caseId":"RETURNED_ID","code":"EMAIL_CODE"}. Retain token/identityId from the direct response or hingeAuthToken wrapper. Use Authorization: Bearer <token>.
Settings: Complete the profile; set city, Everyone, ages 18-85, distance 100 + dealbreaker in the app. Verify via GET /user/v3 and /preference/v2/selected.
Collection loop:
POST /rec/v2 {"playerId":"IDENTITY_ID","newHere":false,"activeToday":false}
For each feed: IDs = subjects[].subjectId; V = feed.viewToken.
POST /user/v3/public {"ids":IDs,"viewToken":V}
POST /content/v2/public {"ids":IDs,"viewToken":V}
Key: bulk POSTs with feed viewToken, not ratingToken; no swipes. Save JSON, deduplicate IDs, checkpoint, honor Retry-After. Fetch returned image URLs without auth. Stop after 30 zero-new batches. Historical success: ~2000 SF / ~2000 London IDs, followed by an account ban.
Subscribe
To subscribe, enter "Subscribe " followed by Signal username, email address or whatsapp phone number. You will receive atmost one update per month.
Alternatively, you can subscribe via RSS, or a third-party service like blogtrottr