Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. Microlink can capture a signed-in page when you send the target site’s session cookie or authorization token as a forwarded HTTP request header. The documented method uses Microlink’s Pro endpoint and API key; header forwarding requires a Pro plan. Keep the session secret out of the URL and make the capture request from your backend.

How Microlink accesses a signed-in page

Microlink’s browser needs a valid session for the target site. You provide that session with a header whose name starts with x-api-header-. Microlink removes that prefix and forwards the remaining header to the target site: x-api-header-cookie becomes cookie, and x-api-header-authorization becomes authorization. The target site then decides whether the supplied session is valid and what the browser can see. Microlink’s guide to capturing pages behind a login documents this workflow.

Use the Pro endpoint at pro.microlink.io and provide your Microlink API key in the x-api-key header. Microlink’s documentation says custom header forwarding requires Pro; the documented free endpoint does not provide it. See the Microlink API overview for its API-key and plan details.

Send the session cookie or bearer token

Node.js with a session cookie

Microlink’s guide shows this Node.js client pattern. Set the API key and cookie in server-side environment variables, then replace the example page URL with the page your application is authorized to capture:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
import createClient from 'microlink.io'

const microlink = createClient({
  apiKey: process.env.MICROLINK_API_KEY
})

const { url } = await microlink.screenshot('https://app.example.com/dashboard', {
  headers: {
    'x-api-header-cookie': `session=${process.env.SESSION_COOKIE}`
  }
})

console.log(url)

The cookie value shown here is illustrative. Use the cookie name and value issued by the target site; do not paste a real session into source code, logs, or a published example.

Bearer token

If the target application authenticates requests with a bearer token, forward its authorization header instead of a cookie:

Rank #2
Free Fling File Transfer Software for Windows [PC Download]
  • Intuitive interface of a conventional FTP client
  • Easy and Reliable FTP Site Maintenance.
  • FTP Automation and Synchronization
headers: {
  'x-api-header-authorization': `Bearer ${process.env.ACCESS_TOKEN}`
}

Include the token format expected by the target site. Do not send both forms unless the target’s authentication flow requires both.

cURL request

The equivalent HTTP pattern sends the Microlink key and forwarded session as request headers. Keep the screenshot options in the request and substitute your authorized target URL and server-side secrets:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G 'https://pro.microlink.io' 
  -H "x-api-key: $MICROLINK_API_KEY" 
  -H "x-api-header-cookie: session=$SESSION_COOKIE" 
  --data-urlencode 'url=https://app.example.com/dashboard' 
  --data-urlencode 'screenshot=true'

Microlink’s use-case guide provides the current endpoint and request pattern; consult it if your integration uses different screenshot parameters or response handling.

Wait for a signed-in element

A capture can start before the authenticated interface finishes rendering. Use waitForSelector to wait for an element that appears only in the signed-in view, such as a dashboard heading. Choose a selector that reliably distinguishes the page you want from its login form, and verify what the API returns if that selector never appears.

If the resulting image still shows a login form, check the cookie name and value, the cookie’s domain and expiration, the Pro endpoint, and the API key. Also confirm that the target accepts the authentication method being forwarded and that the account can access the requested page.

Keep captures and credentials isolated

Microlink says each capture runs in its own isolated browser. If different users capture the same URL, give each user a distinct cacheKey so one user’s cached result is not returned for another. Treat session cookies and bearer tokens as credentials: only forward sessions you are authorized to use and store, and never use a third party’s session without authorization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep authenticated capture calls on your backend. Microlink’s guide advises against putting sensitive values in the public headers query parameter; use the x-api-header-* request headers for cookies and tokens. A URL can be copied, logged, or exposed in browser history, so it is not an appropriate place for session secrets.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server for developers. It accepts a URL in one GET request and can return an image or PDF. For a basic screenshot, use this cURL call; replace the target URL and API key with your own:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo documentation for request options. ScreenshotNeo removes cookie banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed. Its MCP server lets AI agents use screenshot tools. The Free plan includes 1,000 screenshots per month without a card; paid plans start at $5 for 3,000 screenshots.

Sign up for ScreenshotNeo free: 1,000 screenshots a month, no card required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Can I screenshot a page behind a login on the free Microlink plan?

No. Microlink’s documented forwarding of custom headers, including session cookies and authorization tokens, requires Pro.

Why does my screenshot still show the login form?

The forwarded session may be invalid, expired, scoped to a different domain, or sent to the wrong endpoint. Verify the cookie or token, Pro endpoint, API key, and whether the target account can access that page.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.