What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
To get a screenshot API key, create an account with a provider, open its dashboard or access page, and create or copy the key. Treat that value like a password: keep it on your server in an environment variable or secrets manager, call the API over HTTPS, and never ship a long-lived provider key in browser JavaScript. If a key leaks, revoke or replace it immediately and update every deployment that used it.
This guide uses ScreenshotOne terminology where the documentation is specific: its credential is called access_key and is scoped to an organization. The same security pattern applies to other screenshot services, although their credential names and authentication methods differ.
What a screenshot API key is
A screenshot API key authenticates your application to a hosted browser or rendering service. The provider uses it to identify your account or organization, apply permissions and quota, and authorize a capture request. It is not the target website’s password and should not be confused with cookies, an Authorization header intended for the page being captured, or a public URL signature.
Keys are normally provisioned after you sign up or sign in. In ScreenshotOne, open the access page in the dashboard, select the correct organization context, and create or copy the access_key. Confirm the organization or project before copying: a valid key from the wrong context can look like an authentication failure or charge activity to an unexpected account.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
Get the key step by step
- Choose a provider. Compare where it accepts credentials, whether it supports signed public links, and how its endpoint and operational limits fit your application. Do not assume that a key format or plan from one provider works with another.
- Create an account and sign in. Complete any email or organization setup required by the service.
- Open the dashboard’s access, API, or project page. ScreenshotOne calls this the access page. Select the organization or project that should own the screenshots.
- Create or reveal the key once. Copy it directly into your password manager or deployment-secret workflow. Avoid pasting it into a chat, issue, ticket, or shell history.
- Store it as a deployment secret. A conventional variable name is
SCREENSHOT_API_KEY. Set it in your local environment file (excluded from version control), CI/CD secret store, or cloud secrets manager. - Make a server-side test request over HTTPS. Start with a harmless public URL and verify the response, HTTP status, and provider usage record.
Where providers accept the credential
Authentication placement is provider-specific. ScreenshotOne documents three forms:
- Query string:
access_keyappears in the request URL. - POST JSON: send the credential in the request body when using its POST form.
- Header: send it as
X-Access-Key.
Other services use different conventions. Urlbox uses project secret keys with bearer authentication; Browserless uses a dashboard token on its /screenshot endpoint; ApiFlash provides a dashboard access key for GET or POST. Read the current authentication section for the provider you selected rather than substituting a familiar parameter name.
Minimal ScreenshotOne request
GET https://api.screenshotone.com/take?url=https://example.com&access_key=<your access key>
Use URL encoding for a target URL that contains query parameters, fragments, spaces, or non-ASCII characters. Never put the literal key in source code that will be committed.
Store and transmit the key safely
Use environment variables or a secrets manager
Load the key at runtime instead of hard-coding it:
export SCREENSHOT_API_KEY='replace-with-your-key'
For production, set the variable in the hosting platform’s encrypted secret store. Keep local .env files out of source control, add them to .gitignore, restrict who can read deployment secrets, and avoid printing the variable during diagnostics.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
Use HTTPS every time
ScreenshotOne warns that HTTP does not encrypt requests and can expose API keys, authorization headers, cookies, and other sensitive data while in transit. Use the provider’s HTTPS hostname, validate TLS normally, and do not disable certificate verification to “fix” a connection error.
Keep calls behind your backend
A browser bundle is public by design. Anyone can inspect JavaScript, source maps, network requests, or browser storage and copy a key embedded there. In production, your browser should call your own endpoint; that endpoint validates the user request, adds the provider credential server-side, calls the screenshot API, and streams or stores the result.
// Browser (safe pattern): no provider key here
const response = await fetch('/api/screenshot?url=' + encodeURIComponent(targetUrl));
const image = await response.blob();
Your server should allow-list destinations or otherwise validate URLs if untrusted users can submit them. This reduces abuse such as internal-network probing and unexpected capture volume, independently of key secrecy.
Use signed links when a screenshot URL is public
If your application must expose a screenshot URL in an <img> tag or to an unauthenticated user, do not expose the long-lived API key. ScreenshotOne’s signed-link design uses a signature derived with a secret signing key. The server creates the signature, sends only the signed URL, and keeps the signing secret private. A person who sees the public URL cannot reuse the provider API key.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
ScreenshotOne says you generally do not need request signing when links are not shared publicly and the API is used only server-side. Signing is an access-control measure for public URLs, not a replacement for HTTPS or secret storage. Set an expiration or other application-level lifetime when the provider supports it, and avoid logging complete signed URLs if they grant capture access.
Complete server-side examples
cURL
curl -G "https://api.screenshotone.com/take"
--data-urlencode "url=https://example.com"
--data-urlencode "access_key=${SCREENSHOT_API_KEY}"
-o screenshot.png
The key remains in the process environment rather than in the command text. Be aware that some shells or process monitors can still expose arguments; prefer a header or POST form if your provider documents one and your environment records command lines.
Python
import os
import requests
api_key = os.environ["SCREENSHOT_API_KEY"]
response = requests.get(
"https://api.screenshotone.com/take",
params={"url": "https://example.com", "access_key": api_key},
timeout=90,
)
response.raise_for_status()
with open("screenshot.png", "wb") as file:
file.write(response.content)
Node.js
const apiKey = process.env.SCREENSHOT_API_KEY;
if (!apiKey) throw new Error('SCREENSHOT_API_KEY is not set');
const query = new URLSearchParams({
url: 'https://example.com',
access_key: apiKey
});
const response = await fetch(`https://api.screenshotone.com/take?${query}`);
if (!response.ok) throw new Error(`Screenshot request failed: ${response.status}`);
const data = Buffer.from(await response.arrayBuffer());
await import('node:fs/promises').then(fs => fs.writeFile('screenshot.png', data));
For a POST or header-based provider, move the same value into the documented JSON field or X-Access-Key header. Do not send both forms unless the documentation explicitly requires it.
What to do if the key leaks
- Replace or revoke it in the provider dashboard. Stop using the exposed value; do not wait to see whether it is abused.
- Update every deployment secret. Rotate local development, CI, staging, production, workers, and scheduled jobs.
- Remove copies. Delete it from repositories, issue comments, build logs, screenshots, chat messages, and shell history where possible. If it entered version control, treat the entire history as exposed and rotate again after cleanup.
- Inspect provider and application logs. Look for unexpected URLs, volume, or timestamps. Preserve relevant evidence without publishing the credential.
- Prevent recurrence. Add secret scanning, review environment-variable changes, redact query strings in logs, and route browser traffic through your backend.
Choosing among screenshot API credentials
| Provider | Credential model documented | Public-link signing | Endpoint/authentication note |
|---|---|---|---|
| ScreenshotNeo | API key via its documented API | Signed links available | HTTPS GET endpoint; supports a broad capture API and MCP server |
| ScreenshotOne | access_key scoped to an organization |
Signature derived with a secret signing key | GET, POST JSON, or X-Access-Key header |
| Urlbox | Project secret key | Check current provider documentation | Bearer authentication |
| Browserless | Dashboard token | Check current provider documentation | Token used on /screenshot |
| ApiFlash | Dashboard access key | Check current provider documentation | GET or POST |
Prices, quotas, retention, latency, and rate limits are plan- and time-dependent; verify them on each provider’s current plan page before committing to an architecture.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Common errors and fixes
401 or “invalid key”
- Check for a truncated copy, leading or trailing whitespace, or a revoked key.
- Confirm the organization or project selected in the dashboard.
- Verify that the credential is in the exact query, JSON, or header field the provider documents.
403 or permission denied
- The key may lack access to the requested feature, project, or domain.
- Check account verification, IP restrictions, allow-lists, and organization policy.
400 or malformed URL
- URL-encode the target, especially nested query strings and ampersands.
- Use the provider’s required HTTP method and content type.
The browser request works locally but fails in production
- Confirm the production secret is configured in the running service, not only in the dashboard.
- Check deployment logs for a missing variable without printing its value.
- Move the call from frontend code to a backend proxy; CORS success does not make a browser-exposed key safe.
Unexpected usage or quota depletion
- Rotate the key, review logs, and invalidate public URLs that contain unsafely exposed credentials.
- Add authentication, rate limits, URL validation, and caching to your proxy.
Or skip the browser setup: ScreenshotNeo
ScreenshotNeo is a screenshot API and MCP server for developers. It removes cookie/consent banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and each response reports the page verdict and billing status in X-Page-Verdict and X-Billed headers. Its MCP tools—take_screenshot, get_page_info, and capture_pdf—let Claude, Cursor, or another MCP client request captures.
One request returns PNG, JPEG, WebP, or PDF. The API supports full-page and element capture, device presets and custom viewports, dark mode, retina scale, PDF paper and page controls, HTML/CSS rendering, custom JavaScript and CSS, clicks, waits, resource blocking, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, chosen cache TTLs, signed links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, usage reporting, and an OpenAPI specification. Common parameter names used by other screenshot APIs also work, easing migration.
Keep the ScreenshotNeo key server-side just as you would any other provider key. See the ScreenshotNeo documentation for the current parameters and authentication details.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
ScreenshotNeo’s Free plan includes 1,000 shots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is on every plan. Create a free ScreenshotNeo account.
Frequently Asked Questions
Can I put a screenshot API key in frontend JavaScript?
No for a long-lived production key. Browser code and network requests are inspectable, so call your backend and have it add the provider credential.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
Should I use a query parameter or header?
Use the exact method documented by your provider. ScreenshotOne supports query, POST JSON, and the X-Access-Key header; a different provider may require bearer authentication.
Do I need signed requests for every screenshot?
No. Signing is primarily for URLs that will be public. A server-only integration with private responses generally does not need public-link signing.
What is the first step after a suspected leak?
Revoke or replace the key in the dashboard, update all deployment secrets, then inspect logs and repositories for copies or unexpected use.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

