Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

html2canvas cannot reliably capture a CAPTCHA image when the image or its frame is outside your page’s origin. It does not take a literal screenshot of the browser. Instead, it reads the DOM and CSS that page scripts can access and reconstructs them on a canvas. Browser same-origin and canvas security rules still apply, so a cross-origin CAPTCHA may be skipped, or the resulting canvas may become unreadable. The practical fix depends on whether you control the image host, the CAPTCHA is in a cross-origin iframe, or you actually need a screenshot of the visible tab.

What html2canvas is—and why that matters

html2canvas walks the document, loads resources it is allowed to read, and paints a new canvas from the available HTML, CSS and images. It is therefore a DOM reconstruction, not a camera pointed at the display. Pixels that page JavaScript cannot inspect are not automatically available to html2canvas.

The html2canvas FAQ summarizes the boundary plainly: “html2canvas cannot circumvent content policy restrictions set by your browser.” A CAPTCHA is deliberately hosted and protected in ways that commonly trigger those restrictions.

Why the CAPTCHA disappears

The image is cross-origin

Compare the page origin (scheme, host and port) with the CAPTCHA image URL. If they differ, the browser requires the image server to opt in to cross-origin use with an appropriate Access-Control-Allow-Origin response. Without that permission, html2canvas may omit the image. This is not fixed by changing JavaScript on your page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

useCORS requests permission; it does not grant it

useCORS is false by default. Setting it to true tells the browser to request the image using CORS, but the request succeeds for canvas use only when the remote response authorizes your origin. If the response has no suitable CORS header, the option alone changes nothing.

allowTaint is not a bypass

allowTaint is also false by default. Enabling it can allow a cross-origin image to be drawn, but it does not make the canvas readable. Once a canvas is tainted, browser APIs such as toDataURL(), toBlob() and pixel reads are blocked with a SecurityError. Use this option only when you do not need to export or inspect the canvas, which is rarely useful for a CAPTCHA workflow.

The CAPTCHA is inside a cross-origin iframe

An iframe has its own document boundary. html2canvas can recurse into a same-origin iframe, but a page cannot read a third-party frame’s contentDocument. Image CORS settings do not grant access to that frame. A CAPTCHA provider must supply an approved integration or output path if your application needs data from it.

Diagnose the failure before changing code

  1. Inspect the image URL. In browser developer tools, check the CAPTCHA request and compare its origin with your page.
  2. Read the response headers. Look for Access-Control-Allow-Origin that authorizes the page origin. A missing or mismatched value means useCORS cannot help.
  3. Check the frame. If the image is rendered inside an iframe, determine whether the iframe origin exactly matches yours. A different origin is an access-boundary problem, not an image option problem.
  4. Identify the failing operation. If the picture appears but exporting with toDataURL(), toBlob() or pixel reads throws SecurityError, the canvas is tainted.
  5. Confirm your authority. Decide whether you operate the image server or an authorized proxy. Do not route another service’s CAPTCHA through a proxy without its permission.

If you control the CAPTCHA image host

Configure CORS on the image response

Authorize the exact application origin (for example, https://app.example.com) with Access-Control-Allow-Origin. Avoid using a wildcard when credentials are involved, and ensure caches vary responses by the requesting origin when your server emits different values. After the header is deployed, load the image with CORS and capture it:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
const canvas = await html2canvas(document.querySelector('#challenge'), {
  useCORS: true,
  allowTaint: false
});

canvas.toBlob(blob => {
  if (!blob) throw new Error('Canvas export failed');
  // Upload or download the blob here.
}, 'image/png');

The header must be present on the actual image response, including redirects and CDN responses. A header on the HTML page is insufficient.

Use a controlled same-origin proxy

If you own the image service but cannot expose it directly, retrieve the image server-side through a proxy you operate, then serve it from the same origin as the page. Restrict the proxy to approved hosts, validate URLs, enforce size and content-type limits, and protect it against server-side request forgery. This is an architecture choice for resources you are authorized to access, not a general method for evading a CAPTCHA provider’s controls.

If you do not control the CAPTCHA provider

Do not try to defeat the provider’s origin policy, solve or extract challenge data through undocumented endpoints, or describe a proxy as a workaround. Ask for the provider’s approved integration, data path or screenshot method. Many CAPTCHA systems intentionally prevent page scripts from reading challenge pixels; that behavior is part of their security model.

When you need a real browser screenshot

If the requirement is an image of what a user can see—not a canvas you can read from page JavaScript—use a browser screenshot API. The html2canvas FAQ points extension developers to visible-tab APIs: Chrome, Edge and Opera expose chrome.tabs.captureVisibleTab(); Firefox exposes browser.tabs.captureVisibleTab().

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
// Extension context (permissions and active-tab rules apply)
chrome.tabs.captureVisibleTab(windowId, {format: 'png'}, dataUrl => {
  if (chrome.runtime.lastError) {
    console.error(chrome.runtime.lastError.message);
    return;
  }
  // dataUrl is the screenshot of the visible tab.
});

A visible-tab screenshot is not permission to read a protected frame’s DOM or to extract CAPTCHA secrets. Follow the browser’s extension permissions and the service’s terms. Native screenshot APIs also have different viewport, permission and size behavior from html2canvas, so choose them for visual capture rather than canvas data access.

Choosing the right approach

Approach What it captures Required permission Typical failure
html2canvas, same-origin resources DOM/CSS reconstruction Page can read the resources Unsupported CSS or unloaded assets
html2canvas with useCORS DOM/CSS plus CORS-authorized images Image server sends a matching CORS header Image omitted when the header is absent
Controlled same-origin proxy DOM/CSS after server-side retrieval You are authorized to fetch and relay the image SSRF, cache, redirect or content-type mistakes
Native visible-tab screenshot Pixels visible in the browser tab Extension permissions and browser policy Wrong tab, permission denial or protected content rules

Common errors and fixes

“The CAPTCHA is missing, but the rest of the page works”

The image is probably cross-origin or loaded after capture. Verify its origin and response header, then wait for the image’s load event before calling html2canvas. If the server does not authorize CORS, use an approved integration or authorized proxy.

“Setting useCORS: true changed nothing”

The remote host must opt in. Inspect the image response itself; the option cannot manufacture Access-Control-Allow-Origin.

“SecurityError: The operation is insecure”

Your canvas is tainted and an export or pixel-read API is blocked. Keep allowTaint: false, remove or authorize the offending image, and capture again.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

“The image is in an iframe”

Determine whether the iframe is same-origin. If not, html2canvas cannot access its document. Request an official provider workflow or use a permitted visible-tab screenshot when a visual record is all you need.

“The proxy works locally but fails in production”

Check production redirects, CDN headers, TLS, cache variation, authentication, response size limits and content type. Ensure the browser receives the final image with the expected same-origin URL.

“The screenshot is blank or incomplete”

Capture after fonts and images finish loading, wait for dynamically inserted CAPTCHA elements, and avoid exporting before the returned promise resolves. For a long page, remember that DOM reconstruction and browser screenshot APIs have different viewport and size limits.

Performance, reliability and cost considerations

  • Reduce work: capture the smallest containing element instead of the entire document when that meets your requirement.
  • Wait deliberately: use an image-load promise or a targeted delay rather than an arbitrary long timeout.
  • Do not retry blindly: repeated CAPTCHA requests can trigger provider defenses. Log the URL origin, CORS result, frame origin and export error, while avoiding challenge contents and secrets.
  • Separate visual evidence from automation data: a screenshot can document what a user saw, but it does not make protected pixels available to application code.
  • Plan for failure: handle missing images, timeouts, blocked frames and SecurityError explicitly, and provide a provider-approved fallback.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

For an authorized page where you simply need a rendered screenshot or PDF, ScreenshotNeo provides an API and MCP server for developers. It accepts a URL and returns PNG, JPEG, WebP or PDF; its server-side browser can accept cookie/consent banners and remove more than 60 known consent platforms, newsletter popups and chat widgets before capture. Each response reports whether the page was clean, a bot check/CAPTCHA, blank, timed out, failed or served from cache; only clean shots are billed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use the API according to the ScreenshotNeo documentation:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

It also offers full-page and element capture, device and retina settings, dark mode, PDF controls, custom CSS and JavaScript, click and wait actions, request blocking, headers, cookies, user agents, timezone and geolocation, transparent backgrounds, resizing, chosen-TTL caching, signed links, asynchronous webhooks, bulk capture, usage reporting and an OpenAPI specification. Its MCP server exposes take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients. These features do not grant permission to defeat a CAPTCHA; use them only for pages and captures you are authorized to access.

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; yearly billing gives two months free, and every feature is on every plan. Sign up for the free ScreenshotNeo plan.

FAQ

Can I solve the problem by converting the CAPTCHA to a data URL?

Only if your page is already authorized to read the image. Converting a resource you cannot read does not remove the browser’s origin restrictions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does a same-origin policy error mean html2canvas is broken?

No. The error indicates that the browser is enforcing an access boundary html2canvas cannot override.

Will a screenshot API make CAPTCHA pixels readable to my JavaScript?

No. It returns a server-side capture artifact; it does not expose a protected iframe document or bypass the provider’s security controls.

Frequently Asked Questions

Should I set both useCORS and allowTaint to true?

No. useCORS can work when the image server authorizes your origin. allowTaint does not make an unauthorized canvas exportable and can cause SecurityError during export.

What should I ask a CAPTCHA vendor for?

Request its documented integration, authorized image/data endpoint, or approved screenshot workflow, and confirm whether your intended use—rendering, export or visual evidence—is allowed.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.