How to Capture a Website Behind a Login with Thumbalizr
Thumbalizr documents URL-based screenshots, but its reviewed API docs do not explain authenticated sessions. Here is what works, what to verify, and an alternative.
Short answer: Thumbalizr’s reviewed Embed API documentation explains how to capture a URL and configure rendering, but it does not document session cookies, authorization headers, or scripted login. That means the documented API alone does not establish a way to capture a page after signing in. Confirm current support with Thumbalizr before sending credentials or relying on it for private content.
If the page is public, or otherwise accessible to Thumbalizr’s renderer without a login, you can submit its URL through the documented API. If access requires authentication, use only an authorized workflow that the provider explicitly supports. Never try to bypass the site’s access controls.
What Thumbalizr documents
Thumbalizr’s Embed API accepts a target URL and rendering options. Its documented request URL has this shape:
https://api.thumbalizr.com/api/v1/embed/{EMBED_API_KEY}/{TOKEN}/?{query}
The API key and secret are available in the member section after signup. The documentation describes the token as an MD5 digest derived from the query string and secret, and includes examples that URL-encode parameters. Keep the secret on a server you control; do not put it in browser JavaScript, a public repository, or a client-side application bundle.
The documented API options include image format, JPEG quality, thumbnail width, capture size (page or screen), delay, browser width and height, and browser country. Which options are available depends on the subscription tier. The response includes X-Thumbalizr-Status with values such as QUEUED, OK, or FAILED, along with generated-time and error headers.
Why a successful URL request may not capture a signed-in page
A URL identifies the page to request; it does not, by itself, provide the browser session that grants access. A site may require a session cookie, an authorization header, a basic-auth credential, or an interactive login flow. Thumbalizr’s reviewed API documentation does not explain how to establish or preserve any of these for a capture.
So a request can be well-formed and still produce a login page, access-denied page, or other public response. Do not infer that a rendering option such as delay or browser country authenticates the request. Before relying on Thumbalizr for private pages, ask its support whether the current service accepts the specific authorized authentication method you need, how credentials and captures are handled, and whether it can wait for the authenticated destination to render.
Try the documented workflow for an accessible page
- Check access. Make sure the page is available to Thumbalizr’s renderer without a private session, or first confirm a supported authorized authentication method with Thumbalizr.
- Choose documented options. Select the output format, page or screen capture, viewport dimensions, delay, and browser country as appropriate for your plan.
- Build the request using the documented token procedure. URL-encode the query parameters as required by Thumbalizr’s documentation. Do not invent a cookie or login parameter if it is not documented.
- Inspect the response. Check
X-Thumbalizr-Statusand the error headers. AQUEUEDresponse is not the same as a completed capture; handle completion according to the API’s current documentation. - Review the result. Confirm that the output shows the intended page, dimensions, and content. If it shows a login screen, the renderer did not have the required authenticated access.
The exact token-generation implementation and parameter names should come from the current Thumbalizr API documentation. The research reviewed for this article does not provide enough detail to reproduce a complete signed request safely here. In particular, do not paste a made-up token recipe or an undocumented session parameter into production code.
Plan limits and output considerations
At the time the reviewed Thumbalizr pages were checked, its demo described Free output as watermarked, screen-sized, and fixed at 1280×1024. Silver was described as offering unwatermarked full-page or screen captures at 1280×1024. Gold and Platinum were described as adding larger browser dimensions, custom delay, and US or European browser locations.
The feature page displayed monthly quotas of 100 screenshots for Free, 2,000 for Silver, 3,000 for Gold, and 5,000 or more for Platinum. It displayed monthly prices of free, $9, $13, and $20 for 5,000 Platinum screenshots, respectively. These are dated observations, not guaranteed current terms; check Thumbalizr’s current plan page before choosing a tier. Plan capacity does not confirm authenticated-page support.
If the page requires authentication
- Identify the auth mechanism. Determine whether the page uses basic auth, a bearer or other authorization header, a session cookie, or an interactive sign-in flow.
- Confirm authorization. Capture only content you are permitted to access, and check whether your organization allows sending its credentials or session tokens to a third-party renderer.
- Ask Thumbalizr about that exact mechanism. Get confirmation of current support, credential handling and retention, and any required wait behavior before sending secrets.
- Choose a documented fit if needed. If Thumbalizr cannot support the authorized flow, evaluate a provider whose current documentation explicitly supports the site’s auth type. For example, Capture.page documents HTTP Basic Authentication; Screenshot Scout documents session cookies or an Authorization header; ScreenshotOne documents cookies and authorization headers for sites that permit them. These are provider-specific documented capabilities, not evidence that Thumbalizr has them.
- Verify with a non-sensitive test page first. Check that the capture reaches the intended destination and that credentials are not exposed in URLs, browser code, logs, or shared output.
Compare providers on the exact auth method, whether they can wait for the authenticated page to render, credential and screenshot handling, full-page and viewport options, geography, quotas, and current price. The cited authentication options establish only what those providers document; they do not establish which service has stronger security or better performance.
Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| The capture shows a sign-in page | The renderer reached the URL without the session needed for the private page. | Confirm that the page is authorized for capture and ask Thumbalizr whether it supports the specific authentication method. Do not assume the API can reuse your browser session. |
Status is QUEUED |
The job has not yet reported a completed capture. | Follow the current API’s completion workflow and inspect status again; do not treat a queued response as an image. |
Status is FAILED |
The capture did not complete; the response’s error headers may give a reason. | Read the error headers, confirm the URL is reachable by the renderer, and check that the request and options are valid for your subscription. |
| The request is rejected or returns an unexpected result | The token, query encoding, or parameter values may not match the documented signing process. | Rebuild the request from Thumbalizr’s current API examples. Encode query values correctly and keep the secret private. |
| Output is watermarked or not full-page | The selected plan or demo mode may limit output. | Check current plan terms and verify whether the chosen tier supports the required size and watermark settings. |
| The right content is missing despite a successful capture | The page may need more rendering time, may depend on a location, or may require auth not available to the renderer. | Use documented delay or country options where supported. If authentication is the cause, confirm provider support rather than adding undocumented credentials. |
Performance, reliability, and cost
- Rendering time: A configured delay can give a page more time to render, but it also makes each capture take longer. Use only the delay needed for the page and confirm the option is included in your plan.
- Completion handling: Account for queued jobs and check the status and error headers. A successful HTTP exchange alone does not establish that the final screenshot is ready or depicts the authenticated content.
- Reliability: Validate the output for the expected page and state, especially when access depends on a session. Keep a failure path for failed jobs and unexpected login screens.
- Cost: Match expected volume and required dimensions to the current subscription. The quotas and prices above were observed on Thumbalizr pages during research and may change. Confirm current limits before budgeting.
- Credential handling: Do not place API secrets or site credentials in public client code. Before sending private credentials to any hosted capture service, review its current data-handling terms and your own access policies.
Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server. For an authorized page that its renderer can access, one GET request returns an image or PDF. This example captures a URL; it does not log in to a protected site or bypass access controls. See the ScreenshotNeo API documentation for supported parameters and authentication options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
- Cookie banners, popups, and chat widgets are removed before the shot; each cleanup step can be turned off.
- Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed; response headers report the page verdict and billing status.
- An MCP server lets AI agents use screenshot, page-info, and PDF-capture tools.
- 1,000 screenshots a month are free with no card; paid plans start at $5 for 3,000. Every feature is on every plan.
Sign up free for 1,000 screenshots a month, with no card required.
FAQ
Can I pass my existing browser cookies to Thumbalizr?
The reviewed Thumbalizr API documentation does not describe a cookie parameter or a way to transfer a browser session. Ask Thumbalizr to confirm current support before trying to send cookies.
Can Thumbalizr perform the login form steps for me?
The reviewed documentation does not describe scripted login. Confirm with Thumbalizr directly; do not rely on an undocumented workflow for private pages.
Does a larger delay make a login-protected page accessible?
No. A delay can allow rendering to finish where supported, but it does not provide credentials or establish a session.
Is a URL with a temporary access token always safe to submit?
No. A token embedded in a URL may grant access to whoever obtains it. Follow the site owner’s rules and the capture provider’s current credential-handling guidance, and avoid sharing sensitive capture URLs.


