OK this is a bit ridiculous. The FAQ does not specify how to use the API beyond listing a json parameter. If you send a curl command with that parameter the first search just returns "Logged In", and run another search and then you're temporarily IP banned site wide.
Having hair trigger sensitive security around API while not telling the user what the request should look like to not trigger that is just silly.
Still not entirely sure what about the original request trigger it. Think it was something around the Sec-Fetch-* headers that copying a request from browser via copy cURL included
Sorry! You can use the incognito token (from the incognito URL) in order to not have to send the cookie over. If you were trying too aggressively to search, you could've been rate-limited for a few minutes.
Can't even get to the homepage in private browse anymore so must be IP level. Just says "Forbidden".
Must have tripped some sort of safeguard while trying to figure out how to use the API via curl