DouK-Downloader: a data collector for Douyin and TikTok with the encryption work deliberately left to you
抖音 / TikTok 平台作品下载/数据采集工具
At a glance
- What is it?
- A Python tool for bulk downloading and scraping two short-video platforms, now Apache-free GPL-3.0 with a planned rewrite for version 6.0 and an encryption layer it refuses to maintain.
- Who is it for?
- What makes DouK-Downloader worth reading about is the decision at its centre. The project states it will no longer maintain its encryption parameter algorithm, to keep itself legally compliant, and tells users that if a platform update breaks a feature they should bring their own parameter generator.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 20 days ago.
- What is it written in?
- Mainly JavaScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 21, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The project is named DouK-Downloader but the repository is not
The repository URL, the GitHub description and the homepage all still point at TikTokDownloader, and the README carries a note that the project's historical name was TikTokDownloader. The 5.7 release announcement states the name changed to DouK-Downloader. Inside the code, `pyproject.toml` and `setup.py` both use DouK-Downloader as the distribution name, and the Docker image is built as `joeanamier/tiktok-downloader`.
So the rename is complete in the package metadata and incomplete in the URLs, which is normal for a rename of this kind but creates a genuine search problem. If you are looking for this tool, searching the current name is more likely to find a mirror than the canonical repository.
The README also carries two warnings above the feature list. The project plans a complete overhaul at version 6.0, with the expectation that GUI or WebUI support arrives afterwards. And the encryption parameter algorithm will no longer be maintained, for legal and compliance reasons, with the note that if a platform update causes some features to stop working you should supply your own parameter generation code and follow the linked documentation.
Those two warnings together tell you where the project is. The current code works, the author intends to rebuild it, and a specific capability has been handed back to users rather than dropped.
A feature list that covers collection, download and live streams
The README hides its feature list inside a collapsed details block, which is a reasonable choice given there are around forty entries. Reading them as groups rather than one list gives a clearer picture.
Downloading covers Douyin videos and image sets, Douyin live photos and animated images, the highest quality video file, TikTok videos and image sets, and batch downloads from a list of links. Collection walks accounts by published, liked, favorited and collection-folder works on Douyin, and by published and liked works on TikTok, with the same for Douyin collections and TikTok playlists. There is also comment data collection, search data, hot list data, and incremental downloads for account works.
Storage is the part with the most concrete engineering. Collected data persists, and the supported formats are CSV, XLSX and SQLite, which is a broader choice than most scrapers offer. Downloads skip files already present, record the IDs of works already downloaded, and archive files into folders per work, with a configurable filename length limit and a configurable maximum file size. There is a file integrity mechanism and resumable downloads with buffering.
Live streaming is supported on both platforms, including fetching the pull stream address and invoking ffmpeg to record it, with a configurable default clarity. Operational features include multi-account batch downloads, multi-threaded downloads, custom rule filtering, filtering by publish time, automatic nickname and identifier updates, proxy support, LAN remote access, deployment to private or public servers, a clipboard link watcher, and custom account or collection identifiers.
The one item worth reading twice is browser cookie reading. The README lists it, but release 5.8 removed it and then restored manual cookie input as a separate item in the same release.
Three interaction modes, and one of them is currently closed
The tool exposes terminal, Web UI and Web API modes, and their current states differ in a way the README makes clear.
Terminal mode is the recommended default, and the README suggests managing accounts through a configuration file rather than interactively, pointing at the wiki documentation for more. Screenshots are included for several stages of the terminal flow.
Web UI mode carries an explicit note that its code has not been updated and it will reopen after the planned refactor. So it is not currently a usable option, which is a larger caveat than the feature list suggests, since the feature list includes a Web UI entry.
Web API mode is the most interesting for anyone automating this, because it runs a local server with generated documentation. Once started, visiting `http://127.0.0.1:5555/docs` or `http://127.0.0.1:5555/redoc` shows the auto-generated docs. The README supplies a working example that posts to the comment endpoint:
from curl_cffi.requests import post
from rich import printThe example passes a token in the headers and a body containing a work identifier and a page count, against the local comment endpoint, then prints the JSON response. The choice of `curl_cffi` here is not incidental: release 5.8 replaced `httpx` with `curl_cffi`, which is a library that impersonates browser TLS and HTTP fingerprints. That change is consistent with a tool whose hardest problem is not parsing responses but getting past the request layer.
Underneath, the API is FastAPI served by uvicorn, both of which appear in the dependency list, and `pydantic` is used for models.
The release notes read as a record of features being reversed
The three most recent releases are more interesting for what they removed than what they added.
Release 5.6, from 2025-05-10, is the outlier that makes the pattern visible. It removed the server deployment mode entirely, disabled the QR code login feature, disabled request parameter updates, removed the built-in delay mechanism, removed a resolution field from collected data, and renamed a configuration parameter from `original_cover` to `static_cover`. In the same release it reopened Web API mode, refactored it, and added TikTok live download.
Release 5.7, from 2025-08-19, added clipboard link watching and a configurable default live clarity, and restored the data request delay mechanism. It also announces the project rename. It fixed a 404 when downloading private account works and stopped saving a cookie to the configuration file when reading it from a browser failed.
Release 5.8, from 2026-09-13, is the largest list at twenty-five items. It added offset and count parameters to the search endpoint, highest quality video downloads, a new request parameter for TikTok, a download buffering mechanism, and dynamic loading of external Python code. It replaced `httpx` with `curl_cffi`, removed browser cookie reading, restored manual cookie input, enabled LAN access by default in server mode, and rebuilt the built-in request delay mechanism.
The same release carries an upgrade note that does not appear in the others: copy the `_internal/Volume` folder from the old program folder into the new one. For a tool that also reverses its own decisions between versions, that kind of manual step is expected, and the README's warning to read the disclaimer and follow the prompts at first launch reflects the same reality.
The repository is not archived, its last push was on 2026-09-16, and it carries around 16,209 stars with 2,763 forks under a GPL-3.0 license.
Installing from an executable, from pip, or from uv
There are three routes in, and the README is clear that the first two are alternatives rather than steps.
The compiled route points macOS and Windows 10 or later users at the Releases page or at GitHub Actions artifacts. The Actions route matters because the repository contains workflows that build executables automatically, so a build of the latest source can always be produced even when no release is cut. The Mac caveat is stated in bold: the `main` executable on macOS is not code signed, so Gatekeeper blocks the first run, and you need to clear the quarantine attribute from the project folder before it will start.
The source route requires Python 3.12 or newer. There is a pip path that creates a virtual environment, activates it, installs from `requirements.txt` using a Tsinghua mirror index, and starts `main.py`. The recommended path uses uv instead:
uv sync --no-dev
uv run main.pyThe dependency set is worth noting because it explains the architecture. `curl_cffi` for impersonated requests, `fastapi` and `uvicorn` for the API mode, `aiosqlite` for async SQLite, `aiofiles` for async file writes, `openpyxl` for XLSX output, `lxml` for parsing, `pydantic` for validation, `rich` for terminal rendering, `pyperclip` for the clipboard watcher, and `emoji` for output formatting.
The `javascript` package with the unusual version specifier `1!1.2.6` is there because some features execute JavaScript, which is why the README lists Node.js 18 or newer as an optional dependency. That same Node.js requirement is why the Dockerfile installs `nodejs` in the final image even though the application itself is Python, and it is worth noticing that the repository's language metadata reads as JavaScript rather than Python, presumably because of that dependency.
A Dockerfile with the right shape and one unusual instruction
The Dockerfile is a two-stage build and reads the way it should. The builder stage uses a full `python:3.12-bookworm` image, installs build-essential so that the compiled parts of the dependency tree can build, installs `requirements.txt` into a separate prefix directory, and the final stage copies that directory into the system paths of a slim image.
The final stage is `python:3.12-slim-bookworm`, installs Node.js, and copies `src`, `locale`, `static`, `license` and `main.py` into place. It exposes port 5555, which matches the port in the Web API documentation URLs, and declares a volume at `/app/Volume`, which corresponds to the Volume folder the 5.8 upgrade note tells Windows users to copy over.
The command is `python main.py`, meaning the same entry point serves all modes, with configuration deciding whether terminal, API or Web UI behaviour applies.
Alongside the Dockerfile, `setup.py` shows how the Windows executable is produced. It uses cx_Freeze rather than PyInstaller, which is worth flagging because the repository topics include `pyinstaller`, suggesting the packaging approach changed at some point. The cx_Freeze configuration bundles only the `rich` and `uvicorn` packages explicitly, includes the `locale` and `static` directories as files, and sets `include_msvcr` to true so the Microsoft Visual C runtime ships with the build.
The executable itself is defined with the icon from the project's own images directory and a target name of DouK-Downloader.
Editorial conclusion
What makes DouK-Downloader worth reading about is the decision at its centre. The project states it will no longer maintain its encryption parameter algorithm, to keep itself legally compliant, and tells users that if a platform update breaks a feature they should bring their own parameter generator. Very few tools make that trade explicitly, and it explains a lot of the otherwise puzzling churn in the release notes, where features are added, removed and later restored across versions. The tool itself is capable: three storage formats, account and collection traversal, incremental downloads, live stream addresses, a FastAPI server with generated docs, and a Docker image. The counterweight is that the 6.0 rewrite is planned and the Web UI is currently closed. Start from the Web API mode if you want something scriptable and stable, and read the encryption parameter documentation before assuming any feature will work out of the box.
Frequently asked questions
What can DouK-Downloader download?
Douyin videos and image sets, Douyin live photos and animated images, TikTok videos and image sets, and the highest quality video file available. It also traverses accounts by published, liked and favorited works, downloads Douyin collections and TikTok playlists, batch downloads from link lists, and captures live stream addresses on both platforms using ffmpeg to record them.
What formats can the collected data be saved in?
CSV, XLSX and SQLite. Data is persisted between runs, downloaded files are skipped if already present, and the IDs of downloaded works are recorded. The dependency set includes openpyxl for spreadsheet output and aiosqlite for the SQLite backend, and 5.8 added a download buffering mechanism and fixed a case where an error could corrupt an XLSX file.
Why does the project say it no longer maintains the encryption parameters?
The README states it stops maintaining the encryption parameter algorithm to keep the project legally compliant, and that if a platform update breaks some functionality you should prepare your own parameter generation code. The configuration method is documented in the project wiki. Several release notes also show request parameters being adjusted as platforms change.
Can I use it as an API instead of a terminal program?
Yes, there is a Web API mode built on FastAPI and uvicorn. After starting it, visiting `http://127.0.0.1:5555/docs` or `http://127.0.0.1:5555/redoc` shows the auto-generated API documentation, and the README includes a Python example posting to the comment endpoint. The Web UI mode is not currently available, since its code has not been updated and it will reopen after a planned rewrite.
How do I install and run it?
macOS and Windows 10 or later users can download a compiled executable from Releases or from GitHub Actions artifacts, while source users need Python 3.12 or newer. With uv the sequence is `uv sync --no-dev` followed by `uv run main.py`; a pip route using a virtual environment and `requirements.txt` is also documented. macOS executables are unsigned, so the quarantine attribute must be cleared before the first run.
Is there a Docker image?
The repository includes a two-stage Dockerfile that builds dependencies in a full Python image and copies them into a slim one, with Node.js added for the JavaScript execution some features need. It exposes port 5555, mounts a volume at `/app/Volume`, and starts the same `main.py` entry point that serves every mode.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/joeanamier-tiktokdownloader)