ScreenshotNeo

BlogHow-to

How to Screenshot a Website with Authentication Using Abstract Screenshot API

Abstract announced support for capturing password-protected websites, but its reviewed API reference does not explain how to authenticate to the target site.

By the ScreenshotNeo team4 October 20267 min read

Direct answer: Abstract’s Website Screenshot API announced expanded support for capturing password-protected websites, but the API reference reviewed for this guide does not document how to provide credentials for the target site. It documents an Abstract API key and a target URL; those authenticate the caller to Abstract, not necessarily to the protected website. Do not guess a credential parameter or treat Abstract’s API key as the target site’s login.

Abstract’s changelog says it “Expanded support to allow content capture of password-protected websites” on May 20, 2024. That announcement does not specify whether the current method uses cookies, Basic Auth, authorization headers, or another mechanism. Confirm the current method, parameter names, credential scope, and restrictions in Abstract’s current API reference or with its support team before sending a protected-page capture request.

1. What the API documents

Abstract describes its Website Screenshot API as a REST API that returns an image of a given URL. Version 1 uses the endpoint https://screenshot.abstractapi.com/v1. The documented example request includes api_key and url. Abstract says each API has a unique key. The documented key is for accessing the screenshot API; the reference does not establish that it logs into the target site.

The reference lists rendering and output controls, but these do not explain how to authenticate to the target:

Parameter Documented use
capture_full_page Boolean controlling full-page capture; default is true.
width, height Viewport dimensions in pixels.
delay Seconds between loading and capture.
css_injection Inject CSS for rendering.
user_agent Set the browser user agent.
export_format JPEG or PNG; JPEG is the documented default.

Abstract’s documentation also states that communications must use TLS 1.2 or greater. See the API reference for current parameter details.

2. Make a documented public-page request

This runnable example demonstrates the documented request shape for a public URL. It does not demonstrate authenticated target access. Use your own Abstract API key and save the returned image. The example uses the documented endpoint and parameters.

curl -G "https://screenshot.abstractapi.com/v1" \
  --data-urlencode "api_key=YOUR_ABSTRACT_API_KEY" \
  --data-urlencode "url=https://example.com" \
  --data-urlencode "capture_full_page=true" \
  --data-urlencode "width=1366" \
  --data-urlencode "height=900" \
  --data-urlencode "export_format=png" \
  -o screenshot.png

Keep the API key private. The URL above is a public page; adding a protected URL does not supply its login credentials.

Python

import requests

response = requests.get(
    "https://screenshot.abstractapi.com/v1",
    params={
        "api_key": "YOUR_ABSTRACT_API_KEY",
        "url": "https://example.com",
        "capture_full_page": "true",
        "width": 1366,
        "height": 900,
        "export_format": "png",
    },
    timeout=90,
)
response.raise_for_status()
with open("screenshot.png", "wb") as image_file:
    image_file.write(response.content)

Node.js

const params = new URLSearchParams({
  api_key: 'YOUR_ABSTRACT_API_KEY',
  url: 'https://example.com',
  capture_full_page: 'true',
  width: '1366',
  height: '900',
  export_format: 'png',
});

const response = await fetch(
  `https://screenshot.abstractapi.com/v1?${params}`
);
if (!response.ok) {
  throw new Error(`Screenshot request failed: ${response.status}`);
}
const bytes = new Uint8Array(await response.arrayBuffer());
await import('node:fs/promises').then(fs => fs.writeFile('screenshot.png', bytes));

3. How to proceed with a protected page

  1. Check Abstract’s current reference and product guidance for an explicit target-authentication procedure.
  2. Confirm which authentication types are supported and the exact parameter or request mechanism. Do not infer these from the password-protected-content changelog entry.
  3. Confirm credential scope: which hosts and redirects can receive credentials, how long credentials are retained, and whether they appear in logs or URLs.
  4. Use a test account with minimal access and a non-sensitive page first. Verify the resulting image actually shows the authenticated content.
  5. Store secrets in a server-side secret store or environment configuration. Avoid committing them to source control or exposing them in browser-side code. This is prudent handling advice, not a claim about Abstract’s implementation.
  6. After Abstract confirms the method, add its exact documented fields to the request and test login redirects, session expiration, and any multi-factor or bot-check behavior relevant to your target.

If Abstract does not currently document a supported way to pass target credentials, ask its support team before sending credentials or automating a login. Do not send passwords, cookies, or authorization headers under guessed parameter names.

4. Rendering options and practical choices

  • Full page: capture_full_page defaults to true in the reference. Set it deliberately when consistent output dimensions matter.
  • Viewport: set width and height to reproduce the layout you need. Responsive pages can render differently at different widths.
  • Delay: use delay when a page needs additional time after loading to render. A delay does not guarantee that a login flow or asynchronous content has completed.
  • CSS injection: use css_injection for presentation adjustments, not to bypass access controls or establish a session.
  • User agent: user_agent changes the browser identity presented to the site; it does not provide authentication.
  • Export format: choose PNG for lossless output or JPEG when that format suits your downstream use. The documented default is JPEG.

5. Troubleshooting

Symptom Likely cause What to check
Screenshot shows a login page No target-site session was established, credentials were not passed by a documented method, or the session expired. Verify Abstract’s current supported authentication procedure and confirm the test account can open the target page.
Abstract rejects the request The API key, endpoint, URL, or parameter values may be invalid. Check the key for the Website Screenshot API, endpoint version, URL encoding, and current reference.
Image is the wrong size Viewport dimensions or full-page behavior differ from the intended capture. Set the documented width, height, and full-page option explicitly.
Content is missing or still loading The page may render asynchronously or require more time after initial load. Try an appropriate documented delay and inspect whether the content appears in a normal browser session. A delay alone cannot complete an unconfigured login.
Redirect returns to sign-in The session may be absent, expired, or not valid for the redirected host. Ask Abstract how authentication is scoped across redirects; do not forward credentials based on assumptions.
Image file cannot be opened The response may be an API error rather than image bytes. Inspect the HTTP status and response body before saving it as an image; use your client library’s error handling.

6. Reliability, latency, and cost considerations

Screenshot requests depend on the target site loading and rendering successfully. Authentication adds dependencies such as session validity, redirects, and any additional sign-in steps. Test the complete path with a low-privilege account and handle request timeouts and non-success responses in your application. The reviewed dossier does not establish Abstract rate limits, pricing, capture-time guarantees, or retry semantics; check the current product terms for those details.

For production use, avoid logging secrets, make retries bounded, and distinguish an API transport failure from a successful capture of the wrong page. A successful HTTP response alone may not prove that the expected authenticated content appeared, so validate captures where the workflow requires it.

Or skip the browser setup

If the goal is a clean capture and you do not need Abstract specifically, ScreenshotNeo is a website screenshot API and MCP server. It can accept cookie and consent banners and remove more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and responses include X-Page-Verdict and X-Billed headers. AI agents can use its MCP tools, including take_screenshot, get_page_info, and capture_pdf. The service does not establish from these facts that it can log into an arbitrary protected target; check its documentation for the target access method you need.

See the ScreenshotNeo API documentation. One GET request returns a capture; this example uses the documented public-page pattern:

curl -G "https://api.screenshotneo.com/v1/shot" \
  -d access_key=YOUR_API_KEY \
  --data-urlencode url=https://stripe.com \
  -o shot.webp

Python:

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
const fs = await import('node:fs/promises');
await fs.writeFile('shot.webp', new Uint8Array(await res.arrayBuffer()));

Cookie banners, popups, and chat widgets are removed before the shot; bot checks, blank pages, and failed loads are never billed. An MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card, and paid plans start at $5 for 3,000. Sign up for free.

FAQ

Does Abstract’s API key sign in to the website being captured?

The reviewed reference describes it as the key for accessing Abstract’s API. It does not say that it authenticates to the target site.

Does the May 2024 announcement explain how to send target credentials?

No. It announces expanded support for password-protected content but does not identify the authentication mechanism.

Can I use a longer delay to get past a login?

No. A delay can allow rendering time; it does not by itself create an authenticated session.

What should I confirm before using real credentials?

Confirm the supported authentication scheme, exact request fields, credential scope across hosts and redirects, and applicable security restrictions with Abstract’s current documentation or support.