ScreenshotNeo

BlogComparisons

Best Screenshot API for Websites Behind Cloudflare

For a Cloudflare-protected site you own, start with Cloudflare Browser Run and an owner-side WAF rule. For other sites, use authorized access; no reviewed source proves a universal bypass.

By the ScreenshotNeo team4 October 20269 min read

Short answer: For a website you own or are authorized to access, Cloudflare Browser Run is the clearest first-party starting point in the available documentation: it renders a page and captures a screenshot, and Cloudflare documents how a site owner can allow its requests through their own WAF rules. If you do not control the target site, there is no evidence here that any screenshot API reliably passes its Cloudflare protections. Do not choose a service on an unverified promise to bypass another site’s bot checks.

For a simpler hosted screenshot workflow, ScreenshotNeo is the first alternative to consider: it removes known consent banners, popups, and chat widgets before capture, bills only clean shots, and starts with 1,000 free screenshots per month. It does not claim to bypass Cloudflare protection on third-party sites. For a site you control, configure authorized access with the site’s owner-side rules.

What “behind Cloudflare” changes

A screenshot API opens a page in a browser and captures the rendered result. Cloudflare protection can instead present a bot check, challenge, or denial to that browser. The screenshot endpoint’s ability to render HTML and JavaScript does not prove it can pass another site’s protection.

Cloudflare states that Browser Run requests are always identified as bot traffic, and that changing the user agent does not bypass bot protection. Treat a challenge or block as an access decision, not as a rendering option to work around. If the site is yours, use its Cloudflare configuration to authorize the capture service. If it belongs to someone else, request access or use an approved data source.

Which API should you choose?

Option Best fit What the documentation supports Key limitation
ScreenshotNeo Hosted screenshots with clean output, explicit per-response page verdict and billing status, or use by an AI agent through MCP One GET request returns an image or PDF; many capture controls are available. Cookie banners, known popups, and chat widgets can be removed before capture. These product features do not establish that it can pass a Cloudflare challenge on a site you do not control. Arrange authorized access for protected sites.
Cloudflare Browser Run A Cloudflare customer capturing pages on a zone they own or are authorized to configure First-party screenshot and snapshot endpoints; REST API token or Workers binding; owner-side WAF configuration can allow Browser Run. Cloudflare identifies Browser Run requests as bot traffic. The documented allow rule is an owner-side integration, not a third-party bypass.
ScreenshotOne A ScreenshotOne customer who can configure the target site’s Cloudflare rules Its guide describes allowing its requests with a secret header or user-agent and a Cloudflare rule. This is a site-owner recipe. It does not demonstrate success against sites whose rules you cannot change.

The sources reviewed do not provide independently measured, comparable success rates, latency, or costs for third-party Cloudflare challenges. There is no evidence-based universal winner for that use case. Choose based on who controls the target, the needed output, and whether the site’s owner can authorize the requests.

Cloudflare Browser Run for a site you control

Browser Run (formerly Browser Rendering) is Cloudflare’s hosted headless browser service. Its screenshot endpoint accepts a URL or HTML, renders the page’s HTML and JavaScript, and captures an image. The API reference also documents viewport, full-page capture, clipping, and page-loading controls. A snapshot endpoint can return rendered content and a screenshot in one request.

Before you start

  1. Confirm you own the target zone or have permission to configure it.
  2. Choose REST access with a custom API token that has Browser Rendering edit permission, or use a Workers binding.
  3. If the zone’s bot or WAF settings block the request, follow Cloudflare’s owner-side guidance to create an appropriate WAF skip rule. Cloudflare’s FAQ says custom rules require Enterprise plan access; confirm current plan and product requirements in Cloudflare’s docs.
  4. Capture a known page and inspect the returned image for a challenge, denial, or incomplete rendering before using the result downstream.

Capture a screenshot

Cloudflare’s endpoint uses your Cloudflare account and browser-rendering API token. Replace the placeholders with your account ID, token, and authorized target URL. This cURL example sends a JSON body and saves the returned response; consult the endpoint reference for the current response format and optional fields.

curl -X POST \
  "https://api.cloudflare.com/client/v4/accounts/YOUR_ACCOUNT_ID/browser-rendering/screenshot" \
  -H "Authorization: Bearer YOUR_CLOUDFLARE_API_TOKEN" \
  -H "Content-Type: application/json" \
  --data '{"url":"https://your-authorized-domain.example","viewport":{"width":1440,"height":900},"fullPage":true}' \
  --output page.png

For Cloudflare’s exact current request schema, authentication, and response details, use the Cloudflare Browser Run screenshot documentation. The endpoint supports URL or HTML input; adapt the body to the documented schema if capturing HTML directly. Do not treat a successful HTTP response alone as proof that the protected page’s intended content was captured.

Other Cloudflare capture controls

  • Viewport: Set the width and height for the layout you need.
  • Full page: Capture beyond the initial viewport when the page and endpoint options allow it.
  • Clip: Capture a defined region when a full-page image is unnecessary.
  • Page loading: Select the documented loading or wait controls that suit the page. Dynamic pages may need an explicit wait condition.
  • Snapshot: Use the snapshot endpoint when one request should return rendered content as well as a screenshot. Check its response schema before wiring it into a pipeline.

Option names and supported values can change. Verify them against the current screenshot endpoint reference and snapshot API reference before deployment.

Allow a screenshot service on your own Cloudflare site

If Cloudflare blocks a service that you have intentionally authorized, configure access at the target zone. Keep the rule narrow: match the service’s documented secret header or other supported identifier, scope it to the intended requests, and use the skip action and rule ordering described by your Cloudflare plan and product documentation. Avoid broad exceptions that would weaken protection for unrelated traffic.

For Browser Run, Cloudflare documents an owner-side WAF skip rule and notes that custom rules require Enterprise plan access. For ScreenshotOne, its guide describes a secret header or user-agent rule for a site whose Cloudflare settings you control. Follow the providers’ current instructions and test the rule on a non-sensitive page. These recipes grant authorized service requests access to your own site; they are not evidence that either service can get through another organization’s challenge.

Or skip the browser setup

For an authorized URL, ScreenshotNeo takes a screenshot with one GET request. The parameter names commonly used by other screenshot APIs also work, which can make a switch easier. See the ScreenshotNeo API documentation for the full request options.

curl -G "https://api.screenshotneo.com/v1/shot" \
  -d access_key=YOUR_API_KEY \
  --data-urlencode url=https://your-authorized-domain.example \
  -o shot.webp
import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={
        "access_key": "YOUR_API_KEY",
        "url": "https://your-authorized-domain.example",
    },
    timeout=90,
)
r.raise_for_status()
with open("shot.webp", "wb") as f:
    f.write(r.content)
const q = new URLSearchParams({
  access_key: 'YOUR_API_KEY',
  url: 'https://your-authorized-domain.example',
});
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
const image = Buffer.from(await res.arrayBuffer());
await import('node:fs/promises').then(fs => fs.writeFile('shot.webp', image));

For an authorized page, cookie banners, known newsletter popups, and chat widgets are removed before capture; each cleanup step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing, and response headers report the page verdict and billing status. An MCP server gives Claude, Cursor, and other MCP clients screenshot, page-info, and PDF tools. The free plan includes 1,000 screenshots per month without a card; paid plans start at $5 for 3,000. These features do not grant permission to access a protected site or guarantee a Cloudflare challenge will be cleared.

Sign up free for 1,000 screenshots a month with no card.

Pick the right capture method

  1. Own the Cloudflare zone and need a Cloudflare-native browser? Start with Browser Run, then configure the owner-side WAF allowance if required.
  2. Own or have authorization for the site and want a hosted screenshot API? Compare output format, wait behavior, cleanup, billing visibility, and the capture controls your workflow needs. ScreenshotNeo is the first hosted alternative to try for clean shots and no-charge failed or cache-hit responses.
  3. Need rendered HTML plus an image? Review Cloudflare’s snapshot endpoint and verify its response format fits your pipeline.
  4. Do not control the protected site? Ask its owner for permission, credentials, an allowlist, or an official API. Do not rely on user-agent changes or a provider’s generic screenshot capability as proof of access.

Reliability, performance, and cost

Reliability

  • Validate the captured content, not only the HTTP status. A browser can return an image of a challenge or an error page.
  • For authorized sites, keep a test URL that exercises the same authentication and rendering path as production.
  • Use explicit waits for dynamic content where supported, and set sensible client-side timeouts. A longer wait cannot make an unauthorized request permissible.
  • For unattended jobs, record the target, capture time, output type, and status so that empty or unexpected images can be investigated.

Performance

Page rendering time depends on the target’s resources and scripts, the selected wait condition, and whether the page is dynamic. The reviewed documentation does not provide a comparable latency benchmark across these providers. Reduce unnecessary page work only when the service exposes a documented blocking or wait option, and avoid claiming a speed advantage without measurements on your own authorized pages.

Cost

Cloudflare’s cited endpoint documentation does not establish a comparable total cost for this workload; check current plan limits and pricing before estimating volume. ScreenshotNeo’s listed plans are Free: 1,000 shots per month; Starter: $5 for 3,000; Growth: $15 for 15,000; Pro: $39 for 60,000; Scale: $99 for 250,000; and Business: $249 for 1,000,000. Yearly billing gives two months free, and every feature is on every plan. Only clean shots are billed; failed loads, challenges, blank pages, timeouts, and cache hits cost nothing. Confirm current plan details at the product site.

Troubleshooting

Symptom Likely cause What to do
The image shows a Cloudflare challenge or bot check The browser request is being classified as bot traffic, or the site has not authorized it. If you control the zone, use the documented owner-side WAF configuration and verify plan eligibility. Otherwise, request access from the owner. Changing the user agent is not a documented bypass.
Browser Run is blocked on a zone you own The zone’s WAF or bot settings apply to the request. Follow Cloudflare’s Browser Run FAQ for a narrowly scoped skip rule. Cloudflare says custom rules require Enterprise plan access; confirm your current plan.
ScreenshotOne is challenged on your site Your Cloudflare rules do not yet allow the authorized ScreenshotOne request. Follow ScreenshotOne’s current Cloudflare guide and configure its documented secret header or user-agent rule on the zone you control.
The screenshot is blank or content is missing The page may not have finished rendering, may require authentication, or may have returned an error or challenge. Check the page in an authorized browser session, confirm credentials and target URL, use a documented wait control, and inspect the actual captured image or page result.
Dynamic content is absent The capture happened before the page populated that content. Use an available selector or page-loading wait option where supported; avoid arbitrary long delays when a specific readiness condition is available.
API authentication fails The token, account identifier, permission, or authorization header is wrong or outdated. For Cloudflare REST access, check the account ID and use a custom API token with Browser Rendering edit permission. For other services, verify the key and endpoint against their official docs.
A successful response contains an unexpected format The endpoint may return structured data or an error rather than the image format expected by your client. Check the documented response schema and content type before saving the body as an image; inspect non-success responses separately.

Frequently asked questions

Does Cloudflare Browser Run bypass Cloudflare?

No. Cloudflare says Browser Run requests are always identified as bot traffic. Its documented WAF allowance is for an owner configuring their own zone.

Can I use a screenshot API on a site I do not own?

Only when you have permission. A provider’s ability to capture ordinary pages is not evidence that it can or should pass a third party’s bot protections.

Is there a proven best API for third-party Cloudflare-protected sites?

Not from the sources reviewed. They do not provide independent, reproducible comparisons of challenge success, latency, and cost across providers.

When should I use Cloudflare’s snapshot endpoint?

When your authorized workflow needs rendered content and a screenshot from one request, subject to the endpoint’s current response schema.

Can I make a Cloudflare exception for any screenshot provider?

Only if you control the zone and the provider documents a supported identifier and configuration path. Keep the exception limited to the intended service requests.

Sources