How to Use CloudConvert to Convert Password-Protected Web Pages to PDF
Use CloudConvert to capture a page protected by request-header authentication, and learn when an interactive login requires a browser instead.
CloudConvert can capture a web page as a PDF when the protected page can be accessed with request headers supported by its capture workflow. It does not follow from the public documentation that every login-protected page will work: interactive sign-in, session cookies, multi-factor authentication, and browser-only flows are not established as supported by the capture operation. If the page requires those, use an authorized browser session and its Print or Save as PDF feature, or ask the site for an export.
This guide covers URL capture with CloudConvert’s API, how to supply credentials safely, how to handle the resulting file, and what to do when the page requires an interactive session. “Password-protected web page” means a page behind website access control here; an encrypted PDF is a different case.
1. Identify what is protected
| What you have | Approach |
|---|---|
| A page URL that accepts an Authorization header or another supported request header | Try CloudConvert’s capture-website operation with the site’s documented header scheme. |
| A page that requires signing in through a form, session cookie, one-time code, MFA, or browser interaction | The reviewed capture documentation does not establish that CloudConvert can reproduce that session. Use an authorized signed-in browser and Print to PDF, or a site-provided export. |
| An existing PDF file that is encrypted with an opening password | Use a PDF decryption operation with the PDF password if you are authorized. This does not sign in to a website. |
CloudConvert’s capture-website operation renders a URL to PDF. Its HTML-to-PDF API page says custom Authorization headers can be sent for protected resources. That supports a header-based route, but it is not a promise that every authentication method or every protected subresource will work.
2. Create credentials and prepare the request
- Create a CloudConvert API key with the
task.writescope required to create jobs. CloudConvert API v2 requests authenticate with anAuthorization: Bearer API_KEYheader; see the API introduction and Jobs API reference. - Find the exact authentication scheme the site supports. For example, a site may document a bearer token, but do not assume the scheme or header name. Use only credentials you are authorized to use.
- Keep both CloudConvert’s API key and the site’s credentials on a trusted server. Do not put them in browser-side JavaScript, source control, logs, or a publicly visible URL.
- Build a job with a
capture-websitetask and anexport/urltask. Set the capture URL and PDF output format. Add the site’s required headers only in the manner supported by the current operation parameters.
The JSON below illustrates the task relationship and header intent. It is a structural example, not a tested request: confirm exact parameters in CloudConvert’s current operation reference or Job Builder. The dossier-reviewed documentation does not establish that arbitrary capture headers, cookies, or headers for every page subresource are supported.
{
"tasks": {
"capture-page": {
"operation": "capture-website",
"url": "https://example.com/member/page",
"output_format": "pdf"
},
"export-pdf": {
"operation": "export/url",
"input": "capture-page"
}
}
}
3. Create the job and retrieve the PDF
CloudConvert jobs are composed of tasks. The following cURL example creates a job using the documented API authentication pattern and task shape. It deliberately leaves the site-specific authorization out: add it only after confirming the current capture-website parameter syntax and the website’s authentication requirements in the official docs. Do not substitute a guessed cookie or password.
curl --request POST \
--url https://api.cloudconvert.com/v2/jobs \
--header "Authorization: Bearer $CLOUDCONVERT_API_KEY" \
--header "Content-Type: application/json" \
--data '{
"tasks": {
"capture-page": {
"operation": "capture-website",
"url": "https://example.com/member/page",
"output_format": "pdf"
},
"export-pdf": {
"operation": "export/url",
"input": "capture-page"
}
}
}'
Set CLOUDCONVERT_API_KEY in the server environment before running the command. The response contains a job and its task status. Poll or otherwise monitor the job using the API workflow documented by CloudConvert, then read the completed export task’s result URL and download the file promptly. The quickstart says export URLs are valid for 24 hours; save the PDF to your own approved storage if you need it longer. See the Quickstart Guide.
For applications, use CloudConvert’s current Job Builder or API reference to supply all required fields, wait for completion, inspect task errors, and download the export URL from the completed result. The dossier does not provide verified language-specific SDK request syntax, so avoid copying an invented SDK example into production.
4. When a header is insufficient
A website login often establishes a browser session through redirects, cookies, form submissions, JavaScript, or an MFA challenge. A URL capture operation is not equivalent to signing in interactively. The reviewed CloudConvert references do not document a general browser-login sequence or session-cookie reuse for this operation.
- Check whether the site offers an API token or a documented Authorization-header flow for the page.
- If it does, confirm CloudConvert’s current capture parameters for sending that header, and verify whether the page’s dependent resources also require authentication.
- If the site requires an interactive session, sign in using a browser you control and are authorized to use, then choose Print or Save as PDF. Check site policy before saving or redistributing protected content.
- If the desired source is already a PDF download, use a file-import workflow instead of website capture. CloudConvert’s separate import files documentation describes
import/urlfor downloading a file URL and additional request headers. That operation imports a file; it does not render a web page. - If the PDF itself is encrypted, CloudConvert’s PDF operations describe decryption using that PDF’s password. This is separate from website authentication.
5. Or skip the browser setup
If the page is publicly reachable and your goal is a screenshot rather than a PDF, ScreenshotNeo is a website screenshot API and MCP server. One GET request returns PNG, JPEG, WebP, or PDF. Its cleanup accepts cookie and consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each cleanup step can be turned off. Only clean shots are billed: bot checks, CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and the response reports the page verdict and billing status in headers. An MCP server gives AI agents tools for screenshots, page information, and PDF capture. The free plan includes 1,000 shots per month without a card; paid plans start at $5 for 3,000 shots. Review the ScreenshotNeo API documentation for parameters and response behavior.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
timeout=90,
)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
These examples capture a URL; they do not authenticate to an interactive website login. ScreenshotNeo also supports PDF output, custom headers and cookies, full-page capture, wait conditions, and other capture options; check the docs for the current parameter names. Sign up for 1,000 free screenshots a month with no card.
6. Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| CloudConvert returns an authentication or permission error | The API key is missing, invalid, or lacks task.write. |
Send the key as a Bearer token over HTTPS and create a key with the required scope. |
| The job is created but the capture task fails | The task parameters are invalid, the URL cannot be reached, or the target requires an unsupported login flow. | Inspect the task error, validate the operation fields against the current reference, and try a URL you can access without interactive sign-in. |
| The PDF contains a login page | The capture request did not establish the website’s authenticated session. | Confirm the site’s supported header method and CloudConvert’s current capture-header support. For form, cookie, or MFA login, use an authorized browser print flow if the site permits it. |
| The page shell appears but images or other resources are missing | Subresources may have separate authentication or access requirements; reviewed docs do not establish header forwarding to every resource. | Check resource access requirements and operation documentation. Do not assume the main document’s authorization applies to all assets. |
| The export URL no longer works | CloudConvert quickstart documents export URLs as temporary, valid for 24 hours. | Download after job completion and store the PDF in an approved destination. |
| You have a password-protected PDF, not a protected web page | The input is an encrypted document. | Use the PDF decryption operation with its password if authorized; do not use website capture to unlock it. |
7. Performance, reliability, and cost
- Performance: A capture must load the page and render it before export. Large pages and slow or blocked resources can increase completion time. Avoid assuming a fixed duration; inspect job and task status.
- Reliability: Treat job creation and completion as separate steps. Check task status and errors before trusting an export, and download the temporary URL promptly. For recurring workflows, retain job identifiers and your own output storage policy.
- Credential safety: Use least-privilege API keys, keep secrets server-side, and avoid logging Authorization values. CloudConvert’s signed URL documentation warns against embedding sensitive information in publicly visible signed job payloads; see Signed URLs.
- Cost: CloudConvert pricing is credit-based and its live page lists free, package, subscription, and enterprise options. Charges depend on conversion credits and current plan terms; check CloudConvert pricing before estimating a workflow. Do not treat a free allowance as permanent pricing.
- ScreenshotNeo option: ScreenshotNeo lists 1,000 free shots monthly, then plans of $5 for 3,000, $15 for 15,000, $39 for 60,000, $99 for 250,000, and $249 for 1,000,000; yearly billing gives two months free, and every feature is on every plan. These are the supplied product prices; confirm current terms on its site.
8. Frequently asked questions
Can CloudConvert save a page behind a login as a PDF?
It can capture a URL as PDF, and its HTML-to-PDF page documents custom Authorization headers for protected resources. Whether that works depends on the site’s supported authentication pattern and the operation’s current parameters.
Does CloudConvert need my website password?
Not necessarily. For a header-based integration, use the credential or token specified by the site. The reviewed docs do not establish a general form-login or browser-session workflow. Never send a password unless the site and integration explicitly require it and you can protect it.
Can I use import/url to turn a protected page into a PDF?
import/url downloads an existing file. Use capture-website to render a page; import is appropriate when the URL already points to a downloadable document.
Does PDF decryption log me into the website?
No. PDF decryption applies to an existing encrypted PDF and requires that document’s password. Website login and PDF encryption are separate problems.
Can I automate a page that uses MFA?
The reviewed public capture documentation does not establish support for completing an MFA or interactive browser login. Use an authorized workflow offered by the site, such as a documented token or browser export.


