ScreenshotNeo

BlogHow-to

GrabzIt Screenshot API Authentication and API Key Setup

Set up GrabzIt credentials safely for server libraries, REST requests, or browser JavaScript, and troubleshoot common authentication errors.

By the ScreenshotNeo team4 October 20269 min read

GrabzIt issues an Application Key and Application Secret through an account. For server-side libraries, configure both credentials on your server; for REST requests, send the Application Key as the key parameter or a Bearer token; for GrabzIt’s browser JavaScript API, use the Application Key and authorize the domains that may use it. Keep the Secret out of browser code, and do not call the REST API directly from a browser because that exposes the key.

This guide covers the credential setup and request patterns documented by GrabzIt. GrabzIt’s documentation does not specify a particular secrets manager, key rotation schedule, or environment-variable convention, so those operational choices depend on your hosting platform.

1. Get the GrabzIt Application Key and Secret

  1. Create or sign in to your GrabzIt account.
  2. Obtain the account’s Application Key and Application Secret from the account area.
  3. Store them in trusted server-side configuration for integrations that use the server libraries. Do not commit real credentials to source control or embed the Secret in code delivered to a browser.
  4. For REST API access, consider the documented IP authorization control and allow only the server IP addresses that should make requests.

GrabzIt’s overview describes the Key and Secret as the credentials needed for API access and mentions domain and IP restrictions as access controls. The exact restriction available depends on the integration: the browser JavaScript guide specifically requires authorizing domains, while the REST guide recommends authorizing server IPs.

2. Choose the authentication method for your integration

Integration Credentials used Where it runs Key security control
Server-side client library Application Key and Secret Trusted server runtime Keep both values in server-side configuration; the Node.js library is documented as server-side only.
REST API Application Key as key parameter or Bearer token Server or other trusted backend Do not call it from browser code; authorize allowed server IPs where appropriate.
Browser JavaScript API Application Key Browser on an authorized domain Authorize the domains allowed to use the key; do not put the Secret in page code.

Choose based on where the request runs. A backend can keep credentials private. Browser JavaScript is a distinct documented integration that uses a key and domain authorization; it does not make a server-side Secret safe to publish.

3. Configure a server-side client library

GrabzIt provides server-side library guides for Node.js, Python, PHP, ASP.NET, and Java. The guides initialize a client with the account’s Application Key and Secret. Install the library using the instructions for your language and pass credentials from server-side configuration.

For example, in Node.js, keep the credential values in the server process environment and initialize the library according to GrabzIt’s current Node.js guide:

// Server-side only. Install and import the GrabzIt Node.js library
// according to its official guide.
const key = process.env.GRABZIT_APPLICATION_KEY;
const secret = process.env.GRABZIT_APPLICATION_SECRET;

if (!key || !secret) {
  throw new Error('Set GRABZIT_APPLICATION_KEY and GRABZIT_APPLICATION_SECRET');
}

// Pass key and secret to the GrabzIt client constructor shown in the
// official Node.js library documentation.

This snippet shows the configuration boundary, not a complete screenshot call: constructor and capture method names vary by the specific library documentation. Do not guess those API names; follow the official guide for the library version you install. The same rule applies to Python, PHP, ASP.NET, and Java.

4. Authenticate to the GrabzIt REST API

The REST endpoint documented for conversion is https://api.grabz.it/convert. The Application Key can be sent in the query as key, or in an HTTP Authorization header as a Bearer token. Send REST requests from a backend so that the key is not exposed to visitors.

cURL: key parameter

curl --get 'https://api.grabz.it/convert' \
  --data-urlencode 'key=YOUR_APPLICATION_KEY' \
  --data-urlencode 'url=https://example.com' \
  --output capture

Use the additional conversion parameters required by your capture. The documentation says parameter values must be URL encoded; --data-urlencode handles encoding for these query parameters. Choose an output filename and extension appropriate to the response format requested.

cURL: Bearer token

curl 'https://api.grabz.it/convert?url=https%3A%2F%2Fexample.com' \
  -H 'Authorization: Bearer YOUR_APPLICATION_KEY' \
  --output capture

Do not send the key using both methods unless your integration has a specific reason. Keep the full request on the server. Query-string credentials can appear in request logs, so use the documented Bearer option when that better fits your logging and infrastructure practices.

Python: server-side REST request

import requests

application_key = 'YOUR_APPLICATION_KEY'
url = 'https://example.com'
response = requests.get(
    'https://api.grabz.it/convert',
    params={'key': application_key, 'url': url},
    timeout=90,
)

content_type = response.headers.get('Content-Type', '')
if 'application/json' in content_type:
    raise RuntimeError(f'GrabzIt returned an error: {response.text}')
response.raise_for_status()

with open('capture', 'wb') as output:
    output.write(response.content)

Install the dependency with python -m pip install requests. In a deployed application, read the key from server-side configuration instead of leaving the placeholder in source. Check the response content type before treating the body as an image: GrabzIt’s REST documentation says JSON indicates an error and contains explanatory fields.

Node.js: server-side REST request

const applicationKey = process.env.GRABZIT_APPLICATION_KEY;
const targetUrl = 'https://example.com';
if (!applicationKey) throw new Error('Missing GRABZIT_APPLICATION_KEY');

const endpoint = new URL('https://api.grabz.it/convert');
endpoint.searchParams.set('key', applicationKey);
endpoint.searchParams.set('url', targetUrl);

const response = await fetch(endpoint);
const contentType = response.headers.get('content-type') || '';
if (contentType.includes('application/json')) {
  throw new Error(`GrabzIt returned an error: ${await response.text()}`);
}
if (!response.ok) throw new Error(`HTTP ${response.status}`);

const bytes = new Uint8Array(await response.arrayBuffer());
await import('node:fs/promises').then(fs => fs.writeFile('capture', bytes));

Run this in a server-side Node.js environment with a version that provides global fetch, or use an HTTP client supported by your runtime. The request uses URL APIs to encode parameter values.

Submitting HTML instead of a URL

When converting HTML through REST, GrabzIt documents using HTTP POST, putting parameters in the request body as key-value pairs, and setting the content type to application/x-www-form-urlencoded. URL-encode the form values. Do not send HTML as an unencoded query string. Use the exact parameter names and required fields from the REST documentation for the conversion you need.

5. Set up the browser JavaScript API

GrabzIt’s browser JavaScript API is a separate option for page-side integrations. Obtain an Application Key, include the JavaScript library as described in its guide, and call the documented conversion method with the key plus the URL or HTML to capture. Before it can work, authorize the domains allowed to use that key in the account settings.

The key is visible to users when placed in page code, which is why the JavaScript API relies on domain authorization. Do not copy the server-side Secret into JavaScript. For backend integrations, prefer the server library or REST API instead of exposing a REST key in browser requests.

6. Verify the setup safely

  1. Start with a request from the intended runtime: server library, backend REST request, or an authorized browser domain.
  2. For REST, confirm the endpoint, authentication method, and URL encoding. If submitting HTML, confirm POST and form-encoded body data.
  3. Inspect the response headers before saving the body as an image. A JSON response is an error response according to the REST guide; read its contents.
  4. For the JavaScript API, check that the page’s current domain is among the domains authorized for the Application Key.
  5. Use domain or IP restrictions where appropriate, and avoid printing credentials in application logs.

GrabzIt recommends Postman as a way to simplify REST API testing. Postman is still a client: keep its credentials in a private environment and avoid sharing exported requests containing live keys.

7. Common authentication and setup errors

Symptom Likely cause Fix
Server library initialization fails One credential is missing, copied incorrectly, or replaced with a placeholder. Retrieve the account’s Application Key and Secret and pass both to the library constructor as its guide specifies.
REST call returns JSON instead of an image The API returned an error; the response body explains it. Check Content-Type, read the JSON body, then correct the reported request or authentication issue.
REST call fails for a URL containing special characters Parameter values were not URL encoded. Use a URL/query builder or form encoder rather than concatenating raw values.
HTML conversion is rejected or parsed incorrectly HTML was sent using the wrong method or content type. Send an HTTP POST with key-value pairs in the body and application/x-www-form-urlencoded, as documented.
Browser JavaScript API does not work on a domain The domain has not been authorized for the Application Key. Add the intended domain to the key’s authorized domains and retry from that domain.
Secret or key appears in a public bundle Server credentials were placed in browser-delivered code or a frontend environment variable. Remove them from the frontend, rotate/reissue credentials if exposed using the account’s available controls, and move REST calls to a trusted backend. The supplied documentation does not describe a specific rotation procedure.
REST request works locally but not from deployment A configured IP restriction may not include the deployed server’s outbound address. Check the allowed server IP configuration and authorize the correct egress address if the account uses that restriction.

8. Reliability, performance, and cost considerations

Authentication itself adds little application-side work; request reliability depends on handling HTTP failures and API error bodies. Set a finite timeout in your HTTP client, avoid treating every response body as an image, and log status and error details without logging credentials. For applications that capture repeatedly, retry only failures that are safe to retry and use bounded backoff so temporary errors do not create request bursts.

The cited GrabzIt setup documentation does not provide latency benchmarks, rate limits, pricing figures, or a cost model for this authentication flow. Check the current account and product documentation before estimating production volume or cost. Restricting access to the intended domains or server IPs reduces the chance of unauthorized use of credentials.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server from Yorker Media. Its one-call API returns an image or PDF, with the API options documented in the ScreenshotNeo documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
  • Cookie banners, popups, and chat widgets are removed before the shot.
  • Bot checks, blank pages, and failed loads are never billed; response headers report the page verdict and billing status.
  • An MCP server lets AI agents use take_screenshot, get_page_info, and capture_pdf.
  • 1,000 screenshots a month are free with no card; paid plans start at $5 for 3,000.

Sign up for ScreenshotNeo free: 1,000 screenshots a month, no card required.

FAQ

Where do I find my GrabzIt Application Key and Secret?

In your GrabzIt account. The API overview says both are required for API access and should be kept safe.

How do I authenticate to the GrabzIt REST API?

Send the Application Key as the key parameter or as Authorization: Bearer YOUR_APPLICATION_KEY from a server-side or otherwise trusted environment.

Can I use my GrabzIt key in JavaScript?

The documented GrabzIt JavaScript API uses an Application Key in browser code. Authorize the domains that may use it. Do not put the Application Secret in JavaScript, and do not call the REST API from the browser.

Why does the GrabzIt JavaScript API need an authorized domain?

GrabzIt requires allowed domains for the browser API so someone cannot simply copy the page code and use the account’s resources from an unauthorized site.

Can I put the REST key in the URL?

GrabzIt documents a key parameter and a Bearer header. A query parameter may be recorded in URL logs; use server-side handling and select the documented method that fits your logging controls.

Official GrabzIt references