Does ApiFlash Support Websites Behind Cloudflare?
ApiFlash can capture some Cloudflare-protected sites, but strict bot protection may block it. Learn what its proxy option can do and how to diagnose failures.
Short answer: ApiFlash can capture some websites that use Cloudflare, but it does not guarantee access to every Cloudflare-protected site. ApiFlash says bot protection may block its screenshot API. Its documented troubleshooting option is the proxy parameter; the proxy type needed depends on the target’s protection, and using one does not guarantee success. ApiFlash FAQ
That means the useful question is not simply whether a site “uses Cloudflare.” Find out what the capture actually receives: a challenge, a login page, a normal page that loads incorrectly, or no usable response. Those problems have different causes and fixes.
1. What Cloudflare support means in practice
Cloudflare is not a single on/off barrier. A site’s security rules and the request it receives determine whether a capture can proceed. ApiFlash says it attempts to bypass bot protection, but stricter protections can still block its request. Its FAQ recommends trying the proxy parameter when needed, with the appropriate proxy level varying by target. It describes residential proxies as sometimes sufficient and specialized web-unlocker proxies as potentially necessary for stricter defenses. These are suggestions, not a promise that a particular site will work. ApiFlash FAQ
| What you see | Likely issue | What to check |
|---|---|---|
| A Cloudflare challenge or block page | Bot protection is preventing the capture request from reaching the intended page. | Try ApiFlash’s documented proxy option if you are authorized to access the site; the needed proxy level depends on the site. |
| A login page or access denied after login is expected | The page requires authentication, or the supplied session is invalid. | Check whether the page needs cookies or authorization headers. Authentication does not itself solve a bot challenge. |
| A normal page with missing content or styling | Page rendering or resource loading may be failing. | Inspect whether the page depends on delayed content, fonts, or other external resources; distinguish this from a Cloudflare challenge. |
| No usable capture | The request may have failed, timed out, or returned an unexpected page. | Inspect the API response and the rendered result, then isolate authentication, protection, and page-load behavior. |
2. Try ApiFlash’s documented proxy option
If you have permission to capture the target and have confirmed that bot protection is the obstacle, ApiFlash’s FAQ identifies the proxy parameter as the troubleshooting path. The exact parameter value and proxy configuration depend on the proxy service and ApiFlash API setup; use ApiFlash’s current documentation for the accepted value and syntax. Do not assume that a residential proxy or a web-unlocker proxy will work against a particular site.
- Request the target without changing other settings and inspect what the screenshot contains.
- Determine whether the result is a bot challenge, a login page, or a page-rendering problem.
- If it is bot protection, consult ApiFlash’s documentation and configure its
proxyparameter for a proxy service appropriate to the target. - Capture again and inspect the returned image. A successful API request alone does not establish that the intended page loaded.
- If the challenge remains, treat that target as inaccessible through the current route rather than assuming a different setting will guarantee access.
Example request shape
The following shows the general request shape only. ApiFlash’s exact endpoint, API key parameter, screenshot options, and proxy value must come from its current API documentation; they are not specified in the research available for this article.
# Illustrative only: replace endpoint and parameters with ApiFlash's documented values.
curl -G 'API_FLASH_ENDPOINT' \\
--data-urlencode 'access_key=YOUR_API_KEY' \\
--data-urlencode 'url=https://example.com' \\
--data-urlencode 'proxy=YOUR_DOCUMENTED_PROXY_VALUE' \\
-o capture.png
Do not paste proxy credentials or API keys into public logs, source control, or client-side code. Follow the provider’s current documentation for credential handling and accepted proxy syntax.
3. Separate Cloudflare protection from login authentication
A page can require a valid user session independently of any bot protection. ApiFlash documents passing cookies for cookie-based sessions and headers for token-based authentication. These can help a capture reach an authenticated page when you are authorized to access it; they do not establish that Cloudflare will permit the capture request. ApiFlash FAQ
- Cookie-based session: ApiFlash’s FAQ says to pass cookie values using
cookies. Confirm that the session is valid and has access to the requested page. - Token authentication: ApiFlash says to use
headersfor token authentication. Check that the token is valid and sent in the format required by the site. - Site you control: ApiFlash’s FAQ also discusses a secret-key route and JavaScript login automation for authenticated pages. Consult its documentation for the exact setup.
Keep authentication credentials private. Also, ApiFlash notes that custom headers apply to all requests, including external font requests, and can cause browser security restrictions to block fonts. It suggests self-hosting fonts or using cookies for authentication instead of broad custom headers in that situation. ApiFlash FAQ
4. Do not confuse a Cloudflare Worker with access to a protected target
ApiFlash’s guides use “Cloudflare Worker” for a way to route API calls through a Worker. The guide describes benefits such as improving delivery speed, helping hide the API key, using a custom domain, and controlling caching. It does not claim that a Worker enables ApiFlash to capture a separate website protected by Cloudflare. These are two different request paths: your caller’s request to ApiFlash, and ApiFlash’s browser request to the target site. ApiFlash guides
5. Alternative: Cloudflare Browser Rendering
Cloudflare documents a Browser Rendering screenshot endpoint that can capture a URL or supplied HTML. Its documentation also describes authentication inputs such as cookies and HTTP credentials. Cloudflare explicitly says that setting a user agent does not bypass bot protection. This is a documented browser-rendering option, not a universal way to capture third-party sites whose owners’ security controls block the request. Cloudflare Browser Run screenshot documentation
6. Or skip the browser setup
If your goal is a screenshot and you do not want to configure browser capture infrastructure, ScreenshotNeo is a website screenshot API and MCP server for developers. It makes a screenshot request with a URL and can return PNG, JPEG, WebP, or PDF. See the ScreenshotNeo API documentation for request options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
timeout=90,
)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo accepts cookie and consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each of those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing, and responses identify the page verdict and billing status in headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. A screenshot API cannot guarantee access to every site protected by Cloudflare, so check the returned result and respect the site’s access rules.
Sign up free for 1,000 screenshots a month, with no card required.
7. Troubleshooting checklist
| Problem | Cause to investigate | Next step |
|---|---|---|
| Screenshot shows a Cloudflare challenge | The target’s bot protection blocked the capture request. | Try ApiFlash’s documented proxy option with a suitable proxy service. ApiFlash does not guarantee success, especially with strict protection. |
| Screenshot shows a login screen | The request lacks a valid authenticated session. | For an authorized page, check the session cookies or token headers using ApiFlash’s documented cookies or headers options. |
| Login works but a challenge remains | Authentication succeeded or was supplied, but bot protection is a separate obstacle. | Treat the challenge separately and consult ApiFlash’s proxy guidance; valid credentials do not guarantee Cloudflare access. |
| Fonts disappear when custom headers are used | ApiFlash says headers apply to all requests, including external font requests, which can trigger browser security restrictions. | Consider self-hosting fonts or using cookies for authentication instead of broad custom headers. |
| A Cloudflare Worker route works, but the target still blocks capture | The Worker changes the route from the caller to ApiFlash; it does not establish that the target accepts ApiFlash’s request. | Diagnose the target-side bot protection independently. |
| Cloudflare Browser Rendering still gets blocked | A user-agent setting does not bypass bot protection, according to Cloudflare’s documentation. | Do not treat user-agent configuration as a bypass; use an authorized capture workflow appropriate to the site. |
8. Reliability, performance, and cost considerations
Reliability
ApiFlash’s FAQ says it does not publicly display uptime statistics, and the reviewed sources provide no Cloudflare-specific success rate. There is no sourced basis for predicting success on a particular site or protection configuration. For a workflow that depends on a target, verify the actual screenshot output and handle challenge pages or failed captures as possible outcomes. ApiFlash FAQ
Performance
ApiFlash’s Cloudflare Worker guide discusses improving delivery speed for API calls routed through a Worker. That is not evidence that a Worker speeds up or unblocks rendering of a Cloudflare-protected target. The reviewed sources give no comparative timing or benchmark for Cloudflare-protected captures. ApiFlash guides
Cost
The reviewed sources do not provide enough pricing detail to compare ApiFlash plans or proxy costs. Check current provider pricing before adding a proxy: the relevant cost can include both the screenshot API and the separate proxy service. Avoid paying for a proxy on the assumption it will work; the FAQ describes proxy levels as target-dependent and does not guarantee access. For ScreenshotNeo’s stated plans, 1,000 shots per month are free with no card; paid plans are $5 for 3,000, $15 for 15,000, $39 for 60,000, $99 for 250,000, and $249 for 1,000,000, with two months free on yearly billing. Every feature is on every plan.
9. FAQ
Does ApiFlash support every site that uses Cloudflare?
No. ApiFlash says some bot-protected sites may block its screenshot API, and strict protection may remain inaccessible.
Will using a residential proxy always work?
No. ApiFlash says a residential proxy may be sufficient for some defenses; stricter defenses may require a specialized web-unlocker proxy. Neither is a guarantee.
Does ApiFlash’s Cloudflare Worker capture Cloudflare-protected websites?
The Worker guide describes routing API calls through a Worker. It does not claim that this grants access to a separate protected target website.
Does sending login cookies bypass Cloudflare?
No. Cookies or headers can provide authentication for an authorized page. Bot protection is a separate issue.
Does setting a user agent in Cloudflare Browser Rendering bypass protection?
No. Cloudflare’s screenshot endpoint documentation explicitly says its user-agent option does not bypass bot protection.


