The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Use the authentication method the site actually requires. For a page that accepts an existing session cookie, pass it with --cookie name value (URL-encode the value). For HTTP authentication, use --username and --password. A normal web login form, MFA challenge, CAPTCHA, or identity-provider redirect is not automatically handled by these options.
wkhtmltopdf is a command-line HTML-to-PDF tool whose project usage documentation describes conversion with patched Qt. Read the official usage options, then verify that they match your installed executable.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Image to PDF Converter | Buy on Amazon |
Identify what “password-protected” means
People use that phrase for several different access controls. Choose the matching mechanism before changing PDF layout or JavaScript settings.
| What the site uses | wkhtmltopdf mechanism | What it does not prove |
|---|---|---|
| A valid session cookie already exists | --cookie <name> <value> |
It does not log in or refresh an expired session. |
| HTTP Basic or another server HTTP challenge | --username <username> and --password <password> |
These are not a website login-form submission. |
| A required request header | --custom-header <name> <value>, optionally with --custom-header-propagation |
Propagation may send a credential to embedded-resource requests. |
| Interactive login, MFA, CAPTCHA, or single sign-on | No documented automatic login flag | JavaScript and delay switches only affect rendering and timing. |
Cookies are session state, not the account password. Treat a session cookie like a credential: do not paste a real value into a public article, ticket, shared shell history, CI log, or chat transcript.
Recommended Free Tools
#1 Best Overall
- All item converter to pdf
Check the exact wkhtmltopdf build first
- Run
wkhtmltopdf --versionand record the complete output. - Run
wkhtmltopdf --extended-helpand confirm that the cookie, cookie-jar, authentication, header, and timing options shown below exist. - Use documentation matching that executable. The project usage text describes a build using patched Qt, while the Debian Bookworm package documentation notes a package that does not use patched Qt. Their rendering and option behavior can therefore differ.
The Debian Bookworm option reference is available in its wkhtmltopdf manpage. The project also publishes API-level setting descriptions in its libwkhtmltox documentation.
Print a page with a known session cookie
Use --cookie once for each cookie the target request needs. The project usage text says the option is repeatable and that the value should be URL encoded.
wkhtmltopdf --cookie SESSION_COOKIE 'URL_ENCODED_VALUE'
'https://example.invalid/protected-page' output.pdf
Preparing the value safely
- Copy the cookie name exactly, including capitalization.
- URL-encode characters such as spaces, semicolons, quotation marks, or shell metacharacters before passing the value.
- Quote both the value and URL so the shell does not interpret punctuation.
- Limit the cookie to the intended host and path. Do not use a broad domain cookie when a host-only cookie is sufficient.
- Delete temporary command history or rotate the session after an accidental exposure, according to your organization’s security policy.
A cookie only works while the server considers it valid. If the PDF contains a login page, inspect the redirect and response behavior rather than repeatedly changing margins or page size.
Use a cookie jar for read/write cookie state
--cookie-jar tells wkhtmltopdf to read and write cookies at the specified path.
wkhtmltopdf --cookie-jar /path/to/cookies.txt
'https://example.invalid/protected-page' output.pdf
The documented option does not establish a browser-export workflow, nor does it guarantee compatibility with an arbitrary browser’s encrypted cookie database. Confirm the file format expected by your build and protect the file with operating-system permissions. A cookie jar is state storage; it is not a login automation system.
When a jar is useful
- A wrapper has already created a compatible cookie file.
- Several conversions in one controlled process must share cookie state.
- The conversion should persist cookies set during navigation.
Use HTTP authentication, not cookie flags
If the web server challenges the request with HTTP authentication, provide the documented username and password options:
wkhtmltopdf --username 'HTTP_USER' --password 'HTTP_PASSWORD'
'https://example.invalid/protected-page' output.pdf
The project describes --password specifically as an HTTP Authentication password, paired with --username. This is different from entering credentials into an HTML form. Avoid placing real secrets directly on a shared command line; shells, process listings, CI diagnostics, and audit logs may expose arguments. Use a protected wrapper, environment-specific secret facility, or other control appropriate to your system.
Supply a custom header when the server requires one
Some protected endpoints expect a header rather than a cookie or HTTP challenge:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallwkhtmltopdf --custom-header 'X-Example-Token' 'REDACTED_VALUE'
'https://example.invalid/protected-page' output.pdf
--custom-header-propagation applies configured headers to each resource request. Use it only when the site requires that behavior. A page can load images, stylesheets, scripts, fonts, or frames from other hosts; propagating a credential header to those requests may disclose it. The documentation describes the propagation behavior, not a universal security boundary, so confirm the target site’s request model.
Handle JavaScript and delayed content carefully
JavaScript controls do not turn wkhtmltopdf into a modern browser-login client. They can, however, affect whether already-authorized content finishes rendering.
wkhtmltopdf --enable-javascript --javascript-delay 3000
--cookie SESSION_COOKIE 'URL_ENCODED_VALUE'
'https://example.invalid/protected-page' output.pdf
The usage documentation also describes a window-status option for waiting until page script sets a chosen status. Use a delay or status wait only when you know what the page does:
- Delay: waits a fixed number of milliseconds and can waste time on fast pages or still be too short on slow ones.
- Window status: can be more deterministic when your own page script sets the expected value, but it depends on that script executing successfully.
- JavaScript enable/disable: changes rendering behavior; it does not establish support for MFA, CAPTCHA, or contemporary identity-provider flows.
Do not attempt to bypass a site’s access controls. Obtain authorization and use a service account or documented export route where possible.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
A repeatable diagnostic workflow
- Test access outside PDF generation. In an authorized browser session, confirm that the URL works and note whether access is cookie-based, HTTP-authenticated, header-based, or an interactive redirect.
- Capture the minimum state. Start with the one required cookie or header, not a complete browser profile.
- Run a simple conversion. Omit layout flags so authentication is isolated from rendering.
- Inspect the result. Check whether the PDF contains the protected content, a login page, a redirect notice, or an empty document.
- Add timing only if needed. Use a measured delay or a known window-status signal for content assembled after navigation.
- Check subresources. If text appears but images or styles do not, determine whether those resources use another host or need propagated headers.
- Remove secrets. Delete temporary cookie files and secure logs after the conversion.
Troubleshooting common failures
The output is a login page
The cookie may be expired, URL encoding may be wrong, the cookie name may be misspelled, or its domain/path may not match the URL. Revalidate the session and target host. If the site requires an interactive login or SSO redirect, the documented cookie and HTTP-auth flags do not demonstrate support for that flow.
HTTP authentication still fails
Confirm that the server is issuing HTTP authentication rather than displaying an HTML form. Check the username, password, scheme, and exact URL. Do not switch to --cookie unless the server actually sets a session cookie.
Images, CSS, or fonts are missing
Those assets may be fetched in separate requests or from another host. Determine whether they require a header or cookie. If you use --custom-header-propagation, assess the credential-disclosure risk before enabling it.
The page is blank or incomplete
Verify the build with --version, test JavaScript behavior, and use an appropriate delay or window-status wait. A blank result can also indicate a failed load, blocked resource, or incompatible page script; authentication flags alone cannot diagnose every rendering problem.
The command works on one machine but not another
Compare executable versions, package builds, Qt details, URL encoding, cookie-file permissions, and network policy. Match advice to the installed build rather than assuming every distribution’s binary behaves identically.
Security and operational checklist
- Use a dedicated, least-privileged account or short-lived session where the site supports it.
- Keep cookie jars outside shared directories and restrict their permissions.
- Prevent secrets from entering shell history, process listings, build logs, and error reports.
- Use HTTPS and verify the destination host before sending cookies or headers.
- Do not propagate authentication headers to third-party resources unless explicitly required and approved.
- Delete temporary PDFs and credential files when they are no longer needed.
- Record the wkhtmltopdf version with reproducible jobs so a package change does not silently alter output.
Or skip the browser setup
ScreenshotNeo provides a hosted screenshot API and MCP server when you do not want to manage a browser process. It accepts a URL in one GET request and can return PNG, JPEG, WebP, or PDF. Before capture it accepts cookie/consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify the page verdict and billing status with X-Page-Verdict and X-Billed headers. It also offers take_screenshot, get_page_info, and capture_pdf tools through an MCP server for Claude, Cursor, and other MCP clients.
For a PDF or image endpoint, use the documented API parameters and supply your authorized URL. See the ScreenshotNeo documentation for all options, including cookies, headers, JavaScript, waiting, PDF settings, and signed links.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Every feature is available on every plan. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for the free ScreenshotNeo plan to try it without a card.
Frequently Asked Questions
Can I pass my browser’s cookie database directly to wkhtmltopdf?
Not necessarily. The documented cookie-jar option reads and writes a cookie file, but the sources do not guarantee compatibility with any browser’s encrypted database or export format. Convert or create a compatible jar only through an authorized, controlled workflow.
Will wkhtmltopdf complete an MFA or CAPTCHA challenge?
The documented options cover cookies, HTTP authentication, headers, JavaScript, and waiting. They do not establish support for interactive MFA, CAPTCHA, or modern identity-provider login flows.
Which option should I try when the protected page redirects?
Identify the access mechanism first. A missing or expired cookie, incorrect scope, HTTP-auth mismatch, or unsupported interactive login can all produce a redirect; changing PDF layout options will not correct authentication.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




