Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

After creating a Thumbalizr account, find your API key and secret in the account’s “member section,” as Thumbalizr’s API documentation calls it. For the Embed API, put the key in the endpoint path and compute a request token from the query string followed by your secret. Keep that secret on a server you control, and URL-encode request values—especially the page URL.

Where to find your Thumbalizr API key and secret

Sign up for a Thumbalizr account, then look in the member section. Thumbalizr’s documentation says the key and secret are available there, but does not specify exact dashboard clicks. Its demo page also says users can register for a free account and obtain an API key: Thumbalizr demo. The official API instructions are at Thumbalizr API documentation.

If you cannot locate the credentials, consult the current account area or contact Thumbalizr. The cited documentation does not establish a particular recovery or rotation procedure, so do not rely on guessed menu names or steps.

How Embed API authentication works

The Embed API request uses the API key in the URL path and a token computed from the request query string plus the secret. Thumbalizr’s documented example is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
https://api.thumbalizr.com/api/v1/embed/EMBED_API_KEY/TOKEN/?url=https://www.google.com/&mode=page

For that example, the token input is the literal query string followed immediately by the secret:

url=https://www.google.com/&mode=pageSECRET

Calculate the MD5 hash of that exact string and use the resulting hexadecimal digest as TOKEN. In a real request, replace the example values with your own target URL, parameters, key, and secret. The token is not a substitute for protecting the secret: anyone who obtains the secret can generate tokens.

Rank #2
Sale
HTML and CSS: Design and Build Websites
  • HTML CSS Design and Build Web Sites
  • Comes with secure packaging
  • It can be a gift option

Build the request consistently

  1. Choose the query parameters for the capture. The documentation identifies url as required; other supported settings include width, format, JPEG quality, timestamp, size, delay, browser width and height, and country.
  2. Construct the query string in the order and form you will use for the request. Append the secret directly to that query string for the token calculation, then compute its MD5 hash.
  3. Percent-encode parameter values when placing them in the request URL, particularly the target url, which may itself contain query parameters or reserved characters. Follow Thumbalizr’s examples for keeping the token input and transmitted query aligned; do not casually reorder or alter the parameters between signing and sending.
  4. Put the key and computed token into the documented endpoint path, then send the request with the encoded query string.

Thumbalizr’s documentation provides implementation examples in PHP, Python, Ruby, Perl, and Bash. Check its current instructions for syntax details for your language rather than assuming every language’s URL-encoding and MD5 APIs behave identically.

Choose the API for the way you will use the screenshot

Thumbalizr describes the Embed API as the option for putting thumbnails directly on a website. Its documentation warns against using the old API to embed a screenshot directly on a public webpage unless you can hide the API key from visitors, and recommends the Embed API for that use. Do not place the secret in browser JavaScript, HTML, or any public asset. Generate the token on a server and return or embed only the result your site needs.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The documentation characterizes the older API as better suited to offline downloads. Whether using that API or the Embed API, keep credentials in private server-side configuration and check the current official documentation for endpoint and account requirements.

Request settings, defaults, and response status

Beyond the required target URL, Thumbalizr documents options for output width, format, JPEG quality, timestamp, size, delay, browser dimensions, and country. Available values can depend on membership level, and the profile supplies defaults for options omitted from a request. Treat old tier examples as illustrative rather than a guarantee of current account entitlements; verify the live documentation and your account.

Rank #4
Sale
Web Design with HTML, CSS, JavaScript and jQuery Set
  • Brand: Wiley
  • Set of 2 Volumes
  • A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers

For Embed API responses, the docs describe the X-Thumbalizr-Status header with values QUEUED, OK, and FAILED. On failure, inspect X-Thumbalizr-Error for details. A queued response is not the same as a completed screenshot, so handle the documented status behavior in the integration rather than assuming every successful HTTP exchange contains a finished image.

Troubleshooting authentication and capture requests

  • Token rejected: Recreate the exact query string used for the token, append the secret without extra spaces or separators, and hash it with MD5. Check parameter order, spelling, encoding, and whether the transmitted query differs from the signed input.
  • Target URL is malformed: Percent-encode the value of url, including characters such as & that otherwise delimit separate API parameters. Ensure the target URL itself includes its scheme, such as https://.
  • Capture fails or remains queued: Read X-Thumbalizr-Status and, for a failure, X-Thumbalizr-Error. The documentation lists these headers but does not define every possible failure condition.
  • An option is unavailable: Some values depend on membership level. Check current account entitlements and profile defaults rather than relying on an old example or assuming an omitted option has no effect.
  • Credentials are missing: The official directions only identify the member section; they do not establish a precise recovery or rotation workflow. Use Thumbalizr’s account support rather than exposing credentials while troubleshooting.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If you need a screenshot endpoint rather than Thumbalizr-specific authentication, ScreenshotNeo is another option. Its API returns a screenshot or PDF from a GET request, and its documented behavior is to remove cookie banners, popups, and chat widgets before capture. Bot checks, blank pages, and failed loads are not billed; an MCP server lets AI agents take screenshots. The free plan includes 1,000 shots per month with no card, and paid plans start at $5 for 3,000 shots.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Example request (replace the URL with the page you want):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for the access key and request options. Sign up for ScreenshotNeo to get 1,000 free screenshots a month with no card.

Frequently Asked Questions

Does the Thumbalizr Embed API require both a key and a secret?

Yes. The documented Embed API puts the key in the endpoint path and uses a token derived from the query string plus the secret.

Can I put the Thumbalizr secret in frontend code?

No. Keep it server-side and compute the token there; public client code can expose credentials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.