Best Screenshot API for Capturing Websites Behind Basic Authentication
Compare screenshot APIs that document target-site HTTP Basic Auth, configure credentials correctly, and choose a safe path for protected-page captures.
For a website protected by HTTP Basic Authentication, the clearest documented starting point in the reviewed sources is Cloudflare Browser Rendering: its screenshot request accepts an authenticate object containing the target site’s username and password. ScreenshotNeo is the alternative to try first if you want a screenshot API with cookie-banner, popup, and chat-widget removal, and billing limited to clean screenshots; however, the supplied ScreenshotNeo documentation does not establish support for target-site HTTP Basic Auth. Confirm that requirement with ScreenshotNeo before sending it credentials.
“Best” depends on whether a provider explicitly supports the target’s authentication challenge, how it handles credentials, and whether it fits your capture workload. The comparison below is based on vendor documentation, not hands-on tests or comparable measurements of speed, price, reliability, or security.
1. Screenshot APIs to consider
| Service | What the reviewed documentation says | What to verify |
|---|---|---|
| ScreenshotNeo | Website screenshot API and MCP server. Its supplied product information describes clean captures, many capture options, and billing only for clean shots. | Target-site HTTP Basic Auth support is not established by the supplied facts. Ask or verify before use with protected pages. |
| Cloudflare Browser Rendering | Documents target-site HTTP Basic Auth through an authenticate object. It also documents cookies and extra HTTP headers. |
Test your target’s challenge, redirects, and final capture behavior; documentation does not promise success on every site. |
| AddScreenshots | The vendor says it accepts username and password for HTTP Basic or Digest prompts, plus custom headers and cookies. | Confirm current behavior, credential transport, terms, and target compatibility. |
| screenshot-api.net | Its documentation lists a basic_auth parameter for target-origin Basic Auth and recommends POST for credentials because query strings may be logged. |
Confirm current endpoint behavior and whether credentials can leak through your own request or application logs. |
| Webshrinker Website Screenshot API v2 | Documents HTTP Basic Auth to authenticate the request to Webshrinker itself, using its access key and secret key. | This is not evidence that it can log in to the target website. |
For a strict requirement of documented target-site Basic Auth, Cloudflare is the best-supported starting point in this source set. That is a documentation-based conclusion, not an overall ranking. No comparable source evidence settles which service is fastest, most reliable, cheapest for a particular workload, or safest for your organization.
2. Distinguish API credentials from website credentials
There can be two separate credential pairs in one capture:
- Screenshot API credentials authorize your request to the rendering provider. For Cloudflare, this is a bearer token in the API request.
- Target-site credentials answer the website’s HTTP Basic Auth challenge. Cloudflare documents these in the
authenticateobject.
Sending a screenshot API key does not log the browser into the target. Likewise, a provider’s use of HTTP Basic Auth for its own API does not prove it can authenticate to a protected origin.
3. Capture a Basic Auth page with Cloudflare
Cloudflare documents a POST to its account screenshot endpoint with the target URL and an authenticate object. The request also uses a Cloudflare API bearer token. Keep both credential sets secret and separate. See the [Cloudflare screenshot endpoint documentation](https://developers.cloudflare.com/browser-rendering/rest-api/screenshot-endpoint/) and [Browser Rendering API reference](https://developers.cloudflare.com/api/resources/browser_rendering/).
cURL
curl --request POST \
"https://api.cloudflare.com/client/v4/accounts/$CLOUDFLARE_ACCOUNT_ID/browser-rendering/screenshot" \
--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
--header "Content-Type: application/json" \
--data '{
"url": "https://protected.example.com/",
"authenticate": {
"username": "TARGET_USERNAME",
"password": "TARGET_PASSWORD"
}
}' \
--output capture.png
Set the account ID, API token, target username, and target password through your secret manager or shell environment. The response and output format depend on the endpoint’s current documented behavior; check its reference when choosing response options.
Python
import os
import requests
account_id = os.environ["CLOUDFLARE_ACCOUNT_ID"]
api_token = os.environ["CLOUDFLARE_API_TOKEN"]
url = f"https://api.cloudflare.com/client/v4/accounts/{account_id}/browser-rendering/screenshot"
payload = {
"url": "https://protected.example.com/",
"authenticate": {
"username": os.environ["TARGET_USERNAME"],
"password": os.environ["TARGET_PASSWORD"],
},
}
response = requests.post(
url,
headers={
"Authorization": f"Bearer {api_token}",
"Content-Type": "application/json",
},
json=payload,
timeout=90,
)
response.raise_for_status()
with open("capture.png", "wb") as image_file:
image_file.write(response.content)
Node.js
const accountId = process.env.CLOUDFLARE_ACCOUNT_ID;
const apiToken = process.env.CLOUDFLARE_API_TOKEN;
const endpoint = `https://api.cloudflare.com/client/v4/accounts/${accountId}/browser-rendering/screenshot`;
const payload = {
url: 'https://protected.example.com/',
authenticate: {
username: process.env.TARGET_USERNAME,
password: process.env.TARGET_PASSWORD,
},
};
const response = await fetch(endpoint, {
method: 'POST',
headers: {
Authorization: `Bearer ${apiToken}`,
'Content-Type': 'application/json',
},
body: JSON.stringify(payload),
});
if (!response.ok) {
throw new Error(`Screenshot request failed: ${response.status} ${await response.text()}`);
}
const image = Buffer.from(await response.arrayBuffer());
await import('node:fs/promises').then(({ writeFile }) => writeFile('capture.png', image));
Other authentication patterns
Basic Auth is only one way a site may protect a page. Cloudflare’s documentation also describes:
- Cookie-based sessions: provide the documented
cookiesarray when the target expects an established session. - Token or custom-header authentication: use documented
setExtraHTTPHeadersconfiguration for the required authorization header.
AddScreenshots describes username/password for Basic or Digest prompts, and header and cookie parameters for other flows. For screenshot-api.net, the docs name basic_auth for target-origin authentication and recommend POST when transmitting credentials. Follow the provider’s current API reference for exact request syntax; those options are vendor claims, not independently verified here.
4. Choose and validate the right authentication flow
- Open the page in a browser or inspect the origin response to confirm it presents an HTTP Basic challenge. A branded login form is usually a different flow.
- Determine whether the protection applies to the exact URL, a redirect destination, or a whole hostname. Use the final protected URL as your test case.
- Check the provider’s own current documentation for target-site credentials, not just API-key authentication.
- Test with a non-sensitive page and dedicated, least-privilege credentials where possible.
- Verify the final response actually shows the intended page. A returned image alone does not prove authentication succeeded; it could capture a login prompt, denial page, or redirect.
- Check output format, dimensions, full-page behavior, and any capture controls your use case requires.
- Before production, review current pricing, quotas, retention, terms, and the handling of secrets and logs with the provider.
5. Protect credentials in requests and operations
- Do not put passwords in source code, committed configuration, analytics events, or error messages.
- Prefer request bodies or provider-supported secret mechanisms over URL query strings for credentials. Query strings can be recorded in access logs; screenshot-api.net’s documentation specifically warns about this risk and recommends POST.
- Restrict access to API tokens and target credentials, rotate them when exposed, and use separate credentials for development and production.
- Check whether your HTTP client, proxy, tracing system, or job queue logs request bodies and headers. Redact secrets before recording diagnostic data.
- Use HTTPS and confirm the provider’s current credential and data-retention terms before capturing sensitive pages.
- Do not assume a screenshot service’s API authentication method protects target credentials in the same way. Review the entire path from your application through the provider to the destination.
6. Troubleshooting
| Symptom | Likely cause | What to check |
|---|---|---|
| Provider returns an authorization error | The screenshot service rejected its own API token, account ID, or permissions. | Check the provider API token and account endpoint separately from the target username and password. |
| Screenshot shows a browser authentication prompt | Target credentials were missing, malformed, or not applied to the challenged origin. | Confirm target-site authentication is supported and credentials are attached to the correct target request. |
| Screenshot shows a login page | The page uses an application login or session flow, not HTTP Basic Auth, or the capture followed a redirect to that flow. | Use the target’s documented session cookies or authorization headers if supported; validate the final URL and rendered state. |
| Capture is an access-denied page | Credentials may be wrong, the account may lack access, or the site may impose additional access checks. | Check the same credentials and URL through an authorized browser session, then inspect redirects and the page’s visible result. |
| Works on one path but not another | Different paths or hosts can have distinct protection and redirects. | Test the exact URL, including scheme, host, path, and redirect destination; confirm how the provider applies credentials. |
| Intermittent failures or timeouts | The origin may be slow, the challenge or downstream page may fail, or provider limits and network conditions may intervene. | Retry selectively with bounded backoff, inspect provider error details, and avoid treating a timeout as proof of bad credentials. |
| Credential appears in logs | Request URLs, bodies, headers, or exception details may be captured by your infrastructure. | Redact logs, remove secrets from query strings where possible, rotate exposed credentials, and review proxy and tracing configuration. |
7. Performance, reliability, and cost
The reviewed sources do not establish comparable rendering speed, uptime, or prices across these services. Measure your own workload against a representative, non-sensitive target before choosing. Include page load time, image completeness, failure rate, output requirements, concurrency behavior, and the cost under your expected volume. Do not infer a successful login from a fast response or a successful HTTP request alone.
For reliable captures, validate the rendered result, keep retries bounded, and distinguish authentication failures from timeouts and provider-side errors. Avoid retrying indefinitely with the same credentials. Batch or schedule work according to the provider’s current limits, and check quotas and retention terms before scaling.
8. Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server from Yorker Media. Its supplied product information does not confirm target-site HTTP Basic Auth, so verify that support before using protected credentials. If the target authentication requirement is supported for your use case, its API returns a screenshot or PDF from a GET request:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for request parameters. Its supplied product facts say cookie and consent banners, newsletter popups, and chat widgets are removed before capture; bot checks, blank pages, and failed loads are never billed; and an MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots per month with no card, and paid plans start at $5 for 3,000. ScreenshotNeo is also available with a broad set of capture options, including full-page capture, element capture, device presets, custom headers and cookies, caching, async jobs, and bulk capture. Check the documentation for the parameter you need.
Sign up for ScreenshotNeo’s free plan: 1,000 screenshots a month, no card required.
9. FAQ
Does HTTP Basic Auth mean the website password is sent to the screenshot provider?
When a provider renders a protected page on your behalf, it needs a way to authenticate that browser request. Confirm exactly how the provider receives, transmits, logs, and retains the credentials before using sensitive accounts.
Can an API key for a screenshot service unlock the target site?
No. The provider’s API credential authorizes your call to that provider. The target site has its own authentication requirements.
Can I use Basic Auth credentials for a normal login form?
Not necessarily. A normal form often creates a session or requires cookies, tokens, or interactive steps. Identify the actual login flow and use a provider-supported method for it.
Which provider is cheapest or fastest?
The reviewed documentation does not support a cross-provider price or speed ranking. Check current plans and test your own representative pages and workload.
Sources
- Cloudflare Browser Rendering screenshot endpoint
- Cloudflare Browser Rendering API reference
- Webshrinker Website Screenshot API v2 documentation
Provider documentation for AddScreenshots and screenshot-api.net was included in the research dossier, but exact source URLs were not supplied there, so they are not linked here.
