Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →To convert a password-protected page with PDFShift, send its URL and the source page’s credentials in a POST request to PDFShift’s PDF conversion endpoint, then save the binary response as a PDF. Use an auth object for HTTP Basic Authentication or a cookies array when you already have a valid authenticated session cookie. Separately, identify your PDFShift request with your X-API-Key header.
Choose the authentication method the page actually uses
| Source-page access | What to send to PDFShift | When it applies |
|---|---|---|
| HTTP Basic Authentication | An auth object with username and password |
The server protects the page with a Basic Auth challenge. |
| Existing authenticated session | A cookies array with cookie name and value |
You already have a valid session cookie for a page you are authorized to access. |
These are credentials for the webpage, not for PDFShift. Your PDFShift API key goes in the separate X-API-Key HTTP header. The official examples document Basic Auth and cookies; they do not establish that sending a username and password will automate an ordinary login form.
Convert a page protected by HTTP Basic Authentication
Use this method when the page server itself requests a Basic Auth username and password. The request body uses the page URL as source and the credentials in auth, as shown in PDFShift’s Basic Auth guide.
import requests
api_key = "YOUR_PDFSHIFT_API_KEY"
payload = {
"source": "https://www.example.com/protected-page",
"auth": {
"username": "YOUR_PAGE_USERNAME",
"password": "YOUR_PAGE_PASSWORD",
},
}
response = requests.post(
"https://api.pdfshift.io/v3/convert/pdf",
headers={"X-API-Key": api_key},
json=payload,
timeout=90,
)
response.raise_for_status()
with open("page.pdf", "wb") as pdf:
pdf.write(response.content)
Install the dependency with python -m pip install requests. raise_for_status() stops the script on an HTTP error rather than silently saving an error response under a PDF filename. The binary write mode preserves the returned PDF bytes.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- EDIT text, images & designs in PDF documents. ORGANIZE PDFs. Convert PDFs to Word, Excel & ePub.
- READ and Comment PDFs – Intuitive reading modes & document commenting and mark up.
- CREATE, COMBINE, SCAN and COMPRESS PDFs
- FILL forms & Digitally Sign PDFs. PROTECT and Encrypt PDFs
- LIFETIME License for 1 Windows PC or Laptop. 5GB MobiDrive Cloud Storage Included.
Convert a page using an existing session cookie
If you already have an authorized, valid session cookie, pass it in the conversion request’s cookies array. PDFShift’s cookie guide shows cookies with name and value, and supports optional secure and http_only Boolean fields.
import requests
api_key = "YOUR_PDFSHIFT_API_KEY"
payload = {
"source": "https://www.example.com/protected-page",
"cookies": [
{
"name": "SESSION_COOKIE_NAME",
"value": "SESSION_COOKIE_VALUE",
"secure": True,
"http_only": True,
}
],
}
response = requests.post(
"https://api.pdfshift.io/v3/convert/pdf",
headers={"X-API-Key": api_key},
json=payload,
timeout=90,
)
response.raise_for_status()
with open("page.pdf", "wb") as pdf:
pdf.write(response.content)
Include the optional flags only when they match the cookie you are supplying; they are not substitutes for a correct cookie name, value, or valid session. The guide documents how to send cookies, but does not establish how to obtain them, how long they remain valid, or whether every site’s session behavior will work.
Keep the two credentials separate
- Source-page credential: the
authobject or cookie values let the conversion process request the protected webpage. - PDFShift API key: the
X-API-Keyheader identifies your caller account to PDFShift.
PDFShift says it moved to the X-API-Key header on 2025-05-06. Its Help Center says a missing key can leave a request unauthenticated and result in a watermark; API-key problems can also produce 401 or 403 responses. If you need to check whether the key is being accepted, PDFShift points to GET https://api.pdfshift.io/v3/credits/usage. See its watermark and API-key explanation.
Rank #2
- Edit PDFs with Ease. Modify text, images, and layouts directly within your PDF documents.
- Convert & Organize. Export PDFs to Word, Excel, or ePub, and organize files with ease.
- Read & Annotate. Enjoy intuitive reading modes and powerful tools to comment, highlight, and mark up PDFs.
- Create & Manage PDFs. Create new PDFs, combine multiple files, scan documents, and compress for easy sharing.
- Fill & Sign Forms. Complete forms and digitally sign documents with secure e-signature tools.
Protect credentials and check authorization
- Use placeholders in examples and keep real API keys, page passwords, and session tokens out of public repositories, browser-side code exposed to untrusted users, screenshots, and logs.
- A session cookie is a bearer credential: anyone who can use it may be able to act as the logged-in session. Handle it as carefully as a password.
- Only convert pages you are authorized to access. Because this workflow sends page credentials or session cookies to a third-party conversion service, check whether that is permitted by your organization.
Troubleshoot failed or unexpected PDFs
The PDF contains a login page
Check how the source page is protected. If it is an HTTP Basic Auth challenge, use auth; if it relies on a logged-in session, supply the right current cookie or cookies. The documented methods do not verify generic login-form automation. SSO, MFA challenges, CAPTCHA, and JavaScript-driven sign-in are not established as supported by the cited PDFShift guides.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The API returns 401 or 403, or the result is watermarked
Check the PDFShift credential separately from the page credential: make sure X-API-Key is present and valid. Then verify that the Basic Auth pair or cookie is current and belongs to the source page. PDFShift documents missing or problematic API-key behavior and recommends checking the usage endpoint to confirm key acceptance.
The cookie is rejected or the page is still inaccessible
Confirm that the cookie name and value were copied correctly and that the session has not expired. A cookie from another domain or an expired session may not authorize the requested page; that is a practical limitation of session-based access, not a guarantee about PDFShift compatibility.
Rank #3
- EVERY PDF TOOL UNLOCKED - 30+ tools in one app: edit text and images, convert, merge, split, compress, sign, OCR, redact, watermark, batch process, and more. No feature gates, no upsells, nothing held back.
- PAY ONCE, OWN FOREVER — A one-time purchase, not a subscription. Other apps runs $240/year — Scrivar is yours for life, with free updates included.
- UNLIMITED eSIGN, BUILT IN — Send contracts and forms for signature and track every step. Recipients sign in their browser with no account or app needed. Replace DocuSign and save hundreds a year.
- PC, MAC, AND WEB — Install on any Win 10/11 PC or macOS 11+ Mac (Intel or Apple Silicon), or work in your browser at scrivar.com. Same tools, same account, everywhere you work.
- OCR + FULL OFFICE CONVERSION — Turn scanned documents into searchable, selectable text, and convert PDFs to and from Word, Excel, and PowerPoint with formatting kept intact.
The output file is not a usable PDF
Keep the response handling binary: use response.content and open the output file with "wb". Keep raise_for_status() before writing so an HTTP error is not mistaken for a successful PDF.
Or skip the browser setup
If you need a clean screenshot rather than a PDF of an authenticated page, ScreenshotNeo is a website screenshot API and MCP server. A one-call screenshot request looks like this (see the ScreenshotNeo API documentation):
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
ScreenshotNeo accepts cookie and consent banners before capture and removes 60+ known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing, with response headers indicating the page verdict and billing status. An MCP server offers take_screenshot, get_page_info, and capture_pdf tools for AI agents. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000.
Sign up for ScreenshotNeo’s free plan.
Frequently Asked Questions
Can PDFShift use a username and password for any password-protected webpage?
No. The documented username-and-password method is for HTTP Basic Authentication. An ordinary interactive login form is not established as supported by the cited guides.
Does the PDFShift API key go in the `auth` object?
No. The `auth` object is for the webpage’s Basic Auth credentials; the PDFShift key belongs in the `X-API-Key` header.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

