How to Screenshot a Webpage That Requires Login with APITemplate.io
APITemplate documents PDF generation from publicly accessible URLs, but its API key does not log in to a target site. Here are the options for an authenticated page.
Short answer: APITemplate.io’s reviewed URL workflow does not document logging in to a target website before capture. Its URL-to-PDF documentation describes converting a publicly accessible page to a PDF. The X-API-KEY authenticates your request to APITemplate; it is not the username, password, cookie, or session for the website you want to capture. If the page requires login, use a browser workflow that signs in to an account you are authorized to access, or confirm authenticated-page support with APITemplate before building around it.
What APITemplate supports for URLs
APITemplate documents a URL-to-PDF route at POST /v2/create-pdf-from-url. Its guide describes rendering publicly accessible pages with a headless Chromium browser. Treat the output as a PDF, not a screenshot image. The reviewed documentation does not describe a target-site login, session-cookie, or authenticated browser-context option. That means the docs do not establish that this route can reach a page available only after an interactive login. APITemplate documentation
APITemplate also has a separate image-generation workflow based on its own templates. That is not documented as arbitrary webpage screenshot capture. The legacy v1 reference is marked unsupported; use the current v2 documentation for APITemplate workflows. APITemplate documentation
Choose the workflow that matches access requirements
| Page and output | Appropriate approach | What to verify |
|---|---|---|
| Public page, PDF is acceptable | APITemplate URL-to-PDF | Current API request schema, output behavior, regional endpoint and limits |
| Page requires an account login | Browser automation or a browser you manage, authenticated with an authorized account | Whether the chosen system supports session handling, secure credential storage, and the required output format |
| Page requires login and APITemplate is mandatory | Ask APITemplate or consult its full current API reference | Get explicit confirmation of supported target-site authentication before depending on it |
Do not put a website password into the APITemplate API-key field. Do not assume that sending an Authorization header to APITemplate forwards it to the target website; the reviewed material does not document that behavior.
Convert a publicly accessible page to PDF with APITemplate
This is the documented category of workflow, and it does not solve the login step. Consult the current APITemplate PDF guide and API reference for the exact request fields and regional endpoint you use. The following illustrates the documented method and authentication boundary; confirm the current request schema before deployment.
curl -X POST "https://api.apitemplate.io/v2/create-pdf-from-url" \
-H "X-API-KEY: YOUR_APITEMPLATE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"url":"https://example.com/public-page"}'
The endpoint generates a PDF from an accessible URL. This request does not provide a target-site login or browser session. Use only a page the renderer can access without a login unless APITemplate confirms another supported method.
Capture an authenticated page with a browser session
When login is essential, the browser performing the capture must have an authenticated session. A self-managed Playwright browser is one way to do this: navigate to the site, complete login using the site’s supported flow, verify that the expected page is loaded, and capture it. The example below uses environment variables for credentials and writes a full-page PNG. Adapt selectors and any multi-factor or single-sign-on steps to the site; do not attempt to bypass access controls.
// Save as capture.mjs. Install with: npm install playwright
// Run with SITE_URL=https://example.com/login PAGE_URL=https://example.com/account \
// SITE_USER='name' SITE_PASSWORD='secret' node capture.mjs
import { chromium } from 'playwright';
const { SITE_URL, PAGE_URL, SITE_USER, SITE_PASSWORD } = process.env;
if (!SITE_URL || !PAGE_URL || !SITE_USER || !SITE_PASSWORD) {
throw new Error('Set SITE_URL, PAGE_URL, SITE_USER, and SITE_PASSWORD');
}
const browser = await chromium.launch({ headless: true });
const context = await browser.newContext();
const page = await context.newPage();
try {
await page.goto(SITE_URL, { waitUntil: 'domcontentloaded', timeout: 30000 });
await page.getByLabel(/email|username/i).fill(SITE_USER);
await page.getByLabel(/password/i).fill(SITE_PASSWORD);
await page.getByRole('button', { name: /sign in|log in/i }).click();
await page.waitForURL(url => !url.href.includes('/login'), { timeout: 30000 });
await page.goto(PAGE_URL, { waitUntil: 'networkidle', timeout: 60000 });
await page.screenshot({ path: 'authenticated-page.png', fullPage: true });
} finally {
await context.close();
await browser.close();
}
The selectors in this generic example will not match every login form. Replace them with selectors for the actual site and add a positive check that confirms the authenticated account or page is visible before taking the screenshot. Some sites require a one-time code, SSO, a consent step, or another approved login flow; handle those according to the site’s policies. For recurring jobs, a persistent authenticated browser state can avoid logging in on every run, but its cookies are credentials: restrict file access, exclude the state from source control, rotate or revoke it when needed, and never publish it.
cURL, Python, and Node.js boundary
cURL can call a documented HTTP endpoint, such as APITemplate’s public-URL PDF workflow above. It does not itself run an interactive browser login flow. For authenticated capture, use browser automation or an existing authorized browser session.
# A direct request to APITemplate does not log in to the target website.
curl -X POST "https://api.apitemplate.io/v2/create-pdf-from-url" \
-H "X-API-KEY: YOUR_APITEMPLATE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"url":"https://example.com/public-page"}'
# Python browser automation: install with
# pip install playwright
# python -m playwright install chromium
import asyncio
import os
from playwright.async_api import async_playwright
async def main():
site_url = os.environ['SITE_URL']
page_url = os.environ['PAGE_URL']
username = os.environ['SITE_USER']
password = os.environ['SITE_PASSWORD']
async with async_playwright() as p:
browser = await p.chromium.launch(headless=True)
context = await browser.new_context()
page = await context.new_page()
try:
await page.goto(site_url, wait_until='domcontentloaded', timeout=30000)
await page.get_by_label('Email').fill(username)
await page.get_by_label('Password').fill(password)
await page.get_by_role('button', name='Sign in').click()
await page.wait_for_url(lambda url: '/login' not in url, timeout=30000)
await page.goto(page_url, wait_until='networkidle', timeout=60000)
await page.screenshot(path='authenticated-page.png', full_page=True)
finally:
await context.close()
await browser.close()
asyncio.run(main())
Change the labels and button name to match the page. A generic login selector can fail or select the wrong element; verify the signed-in state before saving output.
// Node.js with Playwright: npm install playwright
import { chromium } from 'playwright';
const browser = await chromium.launch({ headless: true });
const context = await browser.newContext();
const page = await context.newPage();
try {
await page.goto(process.env.SITE_URL, { waitUntil: 'domcontentloaded' });
await page.getByLabel('Email').fill(process.env.SITE_USER);
await page.getByLabel('Password').fill(process.env.SITE_PASSWORD);
await page.getByRole('button', { name: 'Sign in' }).click();
await page.waitForURL(url => !url.href.includes('/login'));
await page.goto(process.env.PAGE_URL, { waitUntil: 'networkidle' });
await page.screenshot({ path: 'authenticated-page.png', fullPage: true });
} finally {
await context.close();
await browser.close();
}
Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server. Its one-call API is intended for URLs the capture service can access; it does not supply an authenticated session for a private page. For a public URL, use the API as follows. See the ScreenshotNeo API documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
- Cookie banners, newsletter popups, and chat widgets are removed before the shot.
- Bot checks, blank pages, and failed loads are never billed.
- An MCP server lets AI agents use screenshot tools.
- 1,000 screenshots a month are free with no card; paid plans start at $5 for 3,000.
Create a free ScreenshotNeo account for 1,000 screenshots a month with no card.
Options and operational considerations
Browser capture settings
- Wait condition:
domcontentloadedis quick but may precede client-rendered content.networkidlecan wait for a quiet page but may time out on applications with persistent network activity. Prefer a page-specific ready selector when available. - Viewport and full page: Set the viewport for responsive layouts. Full-page capture can trigger lazy-loaded content only if the page scrolls or the browser otherwise causes it to load; inspect the result for missing images or sections.
- Authentication: Prefer the site’s approved login mechanism. Store secrets outside code and logs. Treat browser storage state and cookies as secrets with access limits and rotation.
- PDF versus image: Playwright can save a screenshot image; a browser can also print to PDF. APITemplate’s cited URL workflow is specifically PDF generation.
- Regional processing: APITemplate lists regional endpoints and says requests and generated files are processed and stored in the selected region. Regional endpoint timeout and payload limits differ; consult its current reference for your region and workload. APITemplate documentation
Performance, reliability, and cost
Browser startup, login redirects, multi-factor steps, third-party scripts, and page rendering all add time. Reuse a browser process for batches where appropriate, but isolate browser contexts between accounts so cookies and local storage do not leak. Use explicit timeouts, bounded retries for transient navigation failures, and a positive authenticated-state check. Do not blindly retry a failed login; it can trigger account lockouts.
With a self-managed browser, account for the compute and maintenance required to run Chromium, store credentials safely, and handle changes to the login form. The reviewed APITemplate documentation does not establish authenticated-page support, pricing for this use case, or a capture benchmark. Confirm current plan limits, endpoint limits, and data handling terms directly before estimating production cost or sending private material to a rendering service.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| APITemplate returns a login page or access error | The renderer cannot access the protected page, and the API key only authenticates the APITemplate request | Use an authorized browser session, or confirm target-site authentication support with APITemplate |
| API key rejected | Missing, invalid, or incorrectly placed APITemplate credential | Check that X-API-KEY is the APITemplate key and follow the current v2 request reference |
| Browser automation cannot find the username field | Selectors differ, fields are inside a frame, or the login form has not rendered | Inspect the page structure, wait for the form, and target the correct frame and accessible label |
| Login succeeds but capture shows a sign-in page | Redirect or session state was not established, or the target URL is outside the signed-in account’s access | Assert the expected signed-in element, inspect the final URL, then navigate to the protected page |
| Timeout waiting for network idle | The app keeps polling or streaming requests open | Wait for a specific content selector or use a shorter readiness condition followed by a page-specific wait |
| Screenshot is missing images or lower-page content | Lazy loading, delayed rendering, or full-page behavior | Scroll through the page or wait for target elements to load, then capture and inspect again |
| Automated login triggers a challenge or account lock | The site applies its own security controls or sees repeated failed attempts | Stop retries, use the site’s permitted authentication flow, and ask the account administrator or site owner for an approved automation method |
| PDF request works in one region but not another | Regional endpoint limits or processing behavior differ | Check the current APITemplate regional API reference for timeout and payload limits |
FAQ
Can APITemplate take a screenshot after I log in?
The reviewed public documentation does not establish that capability. It documents URL-to-PDF generation for publicly accessible pages; ask APITemplate to confirm any target-site session feature.
Does the APITemplate API key log me into my website?
No such behavior is documented. It is the credential for the APITemplate API request.
Does APITemplate return a PNG for its URL endpoint?
The reviewed URL endpoint is documented as PDF generation. APITemplate’s template-based image API is a separate workflow.
Can I use ScreenshotNeo for a page that requires login?
The ScreenshotNeo call shown here takes a URL; the supplied product facts do not establish logging into a target site. Use an authorized authenticated browser workflow for private pages.
Is browser automation appropriate for every protected site?
No. Use it only with authorization and in line with the site’s access rules. Some sites require a human-approved login or prohibit automated access.


