ScreenshotNeo

BlogHow-to

How to Convert a Password-Protected Webpage to PDF with Html2Pdf.app

Html2Pdf.app does not document access to your signed-in browser session. For a page you can access, use Print → Save as PDF, or supply authorized rendered HTML.

By the ScreenshotNeo team4 October 20269 min read

Short answer: Html2Pdf.app documents converting publicly reachable URLs or raw HTML. Its documentation does not describe importing your browser login session, cookies, or a website password. So do not assume that entering a private page’s URL will work. If you are authorized to view the page, open it while signed in and use your browser’s Print → Save as PDF command. Check the PDF afterward for missing content and broken page breaks.

This guide explains what Html2Pdf.app can and cannot do according to its public documentation, how to save your own signed-in page, and how to use the service for pages that are public or HTML you are authorized to provide. Never send your personal website password or session cookie to an unverified converter.

1. Understand what “password-protected” means

A PDF converter needs to be able to load the source page. A URL that works in your browser because you are signed in may redirect an unauthenticated converter to a login page, an access-denied page, or a blank result. Html2Pdf.app’s documentation describes URL input as a publicly reachable page and also supports raw HTML; it does not document interactive login, session transfer, cookie import, or website-password parameters. That documentation gap is not proof that no private integration exists, but the documented API is not a way to reuse your browser session. See the Html2Pdf.app documentation.

Situation Practical route
You can open the page while signed in, and need a copy for your own use Print the page from your signed-in browser and save it as a PDF.
The page is publicly reachable without signing in Use Html2Pdf.app’s URL conversion, then check the output.
You own or are authorized to export the page’s rendered HTML Use the documented raw-HTML input, subject to its API format and resource-loading constraints.
The page is private and you are considering giving a service your password or session cookie Do not share those credentials with an unverified converter. Use your browser’s print function or an approved export method from the site owner.

2. Save a page you can access using your browser

  1. Open the page in the browser where you are already signed in. Confirm that the content you need has finished loading.
  2. Open the browser’s Print command. It is commonly available from the browser menu or a keyboard shortcut; the exact label and shortcut vary by browser and operating system.
  3. Choose Save as PDF or the equivalent PDF destination.
  4. Review the print preview. Adjust paper size, orientation, scale, margins, or page selection if those controls are available and needed.
  5. Save the file, open it, and check the pages you care about. Look for missing images, clipped columns, unexpected blank pages, hidden sections, and awkward page breaks.

Some websites use print-specific CSS that changes the page: navigation, backgrounds, or interactive sections may be hidden or restyled. A browser-generated PDF reflects what the browser’s print renderer produces, which may differ from the screen view. If the page owner offers a download or export function, that may preserve the content more reliably.

3. Convert a public URL with Html2Pdf.app

For a page that is publicly reachable, Html2Pdf.app documents a URL conversion API. The API uses POST https://api.html2pdf.app/v1/generate and an X-API-Key header. Keep the key in a backend, server-side script, or trusted job. Do not put it in browser JavaScript, a public repository, or a client-side template. The examples below use placeholders because the service key and exact request fields must come from the current official documentation.

cURL

curl -X POST "https://api.html2pdf.app/v1/generate" \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  --data '{"url":"https://example.com"}' \
  --output page.pdf

Replace the example URL with a publicly reachable page. Check the documentation for the current required JSON schema and response behavior before using this in a job.

Python

import os
import requests

api_key = os.environ["HTML2PDF_API_KEY"]
response = requests.post(
    "https://api.html2pdf.app/v1/generate",
    headers={
        "X-API-Key": api_key,
        "Content-Type": "application/json",
    },
    json={"url": "https://example.com"},
    timeout=60,
)
response.raise_for_status()
with open("page.pdf", "wb") as pdf_file:
    pdf_file.write(response.content)

Set HTML2PDF_API_KEY in the server or job environment. If the response is an error document rather than a PDF, inspect the HTTP status and response content type before saving it as a PDF.

Node.js

const apiKey = process.env.HTML2PDF_API_KEY;
if (!apiKey) throw new Error("Set HTML2PDF_API_KEY first");

const response = await fetch("https://api.html2pdf.app/v1/generate", {
  method: "POST",
  headers: {
    "X-API-Key": apiKey,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({ url: "https://example.com" }),
});

if (!response.ok) {
  throw new Error(`PDF conversion failed: HTTP ${response.status} ${await response.text()}`);
}

const pdf = Buffer.from(await response.arrayBuffer());
await import("node:fs/promises").then(({ writeFile }) => writeFile("page.pdf", pdf));

These examples show the documented endpoint and authentication method, but the request schema and exact returned content should be confirmed against the current API documentation. The homepage also offers an online converter for public webpage URLs without an API key; that does not establish that it can access pages behind your login. See the Html2Pdf.app homepage.

4. Supply raw HTML when you are authorized to do so

The documentation accepts raw HTML as an alternative to a public URL. This is useful when you control the page or have permission to export its rendered markup. It does not itself retrieve a third-party page behind login: you must already have the HTML, and linked images, stylesheets, fonts, and scripts may still need to be available to the renderer.

Use the API’s documented raw-HTML field and request shape from the current docs. Avoid copying sensitive page content into a third-party service until you have reviewed its data-handling terms. Html2Pdf.app says generated PDFs are processed temporarily and not permanently stored on its servers, while selected request metadata and a supplied source URL may be retained in conversion logs. For sensitive material, read the service’s privacy policy and data-processing terms before submitting it.

5. Rendering settings and their limits

Html2Pdf.app documents settings that can affect how a public page or supplied HTML renders. They tune rendering; they do not authenticate you to a private website.

Setting What it affects What it does not do
waitFor Waits from 0 to 10 seconds for JavaScript or asynchronous resources before rendering. Does not sign in, bypass access controls, or guarantee that a slow page has finished loading.
media Selects print or screen media behavior, which can change CSS and visibility. Does not preserve both layouts automatically; inspect the PDF for the layout you need.
userPassword Sets a password needed to open the generated PDF. Does not provide a password for the source webpage.
ownerPassword Sets PDF permissions. Does not grant access to the input page or make its content private during conversion.

The service documentation describes PDF encryption as 128-bit AES. Treat output protection separately from source access: encrypting a generated PDF does not mean the converter could access a login-only page. Also account for CSS media rules, available fonts and other resources, and JavaScript load timing, all of which the documentation identifies as rendering factors.

6. Troubleshooting

Symptom Likely cause What to try
The PDF shows a login screen instead of the page The converter fetched the URL without your browser’s authenticated session. For a page you can access, print it from your signed-in browser. Do not send your personal password or session cookie to an unverified service.
The request fails with an authentication error The API key is missing, invalid, or sent in the wrong header. Send the key in X-API-Key from a trusted server-side environment and check the current docs for the required request format.
The PDF is blank or missing part of the page The page may rely on JavaScript, asynchronous resources, or content that appears after the renderer captures it. For eligible public or supplied content, check waitFor within its documented 0–10 second range. Confirm the content is available without a login and review the returned status and file.
Images, fonts, or styles are missing Resources may not be publicly accessible or may not have loaded in the rendering environment. Check resource URLs and access permissions. For raw HTML, make required resources available to the renderer and inspect the output again.
The layout differs from the browser window Print and screen CSS can produce different output, and fonts or page settings affect pagination. Try the documented media choice that matches the desired result. Review page size, margins, and the resulting PDF.
The PDF opens with a password prompt A PDF opening password may have been configured with userPassword. Use the intended PDF password or regenerate without that output setting if you control the request. This is separate from the source website login.
The saved file is not a valid PDF The request may have returned an error response that the script wrote to a file. Check the HTTP status and response headers before saving; surface error bodies instead of treating every response as PDF bytes.

7. Reliability, privacy, and cost considerations

  • Reliability: Browser printing relies on the page being loaded and accessible in your session. API conversion relies on the renderer being able to fetch the URL or its resources. A longer render wait may help with asynchronous content, but cannot fix a login requirement.
  • Privacy: Do not share website passwords or session cookies with a converter. Keep Html2Pdf.app API keys server-side. Check its privacy policy and data-processing terms before sending confidential page contents or URLs.
  • Cost: Check the service’s current pricing and limits before automating conversions. Do not infer cost or free quotas from the code examples. For occasional personal copies, browser print may avoid an API workflow entirely.
  • Output quality: Always open and inspect the generated PDF when completeness matters. Browser print preview and a sample API output can reveal layout, missing-content, and pagination issues before processing many pages.

8. Or skip the browser setup

If your goal is a screenshot or PDF capture workflow for pages your capture process can access, ScreenshotNeo is a website screenshot API and MCP server. It does not make a private page accessible without authorized access. One GET request can return a PNG, JPEG, WebP, or PDF; see the ScreenshotNeo API documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo accepts cookie and consent banners like a visitor and removes 60+ known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks, blank pages, failed loads, timeouts, and cache hits cost nothing, with the page verdict and billing status in response headers. Its MCP server gives AI agents tools to take screenshots, inspect page information, and capture PDFs. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000.

Sign up free for 1,000 screenshots a month, with no card required.

FAQ

Can Html2Pdf.app use the login I already have open in my browser?

The reviewed public documentation does not describe importing that session. Do not assume a URL conversion will inherit your browser login.

Does putting a password on the PDF unlock the source page?

No. userPassword protects the output PDF. It is separate from credentials for the webpage being converted.

Can I convert a login-only page if I copy its HTML?

Only if you are authorized to export and submit that content. Raw HTML is an input option, not a mechanism for extracting a page from a third-party account.

Is browser Print to PDF suitable for an official record?

It can make a readable copy, but it may not preserve interactive behavior, hidden content, or the site’s authoritative records. Use the site’s official export or recordkeeping process when one is required.