Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk5 min

GrabzIt Screenshot API Authentication and API Key Setup

GrabzIt uses a Key and Secret for server-side libraries, a Key parameter or Bearer token for REST, and an authorized domain for browser JavaScript.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GrabzIt screenshot API authentication depends on where your code runs: server-side libraries use an Application Key and Secret, REST requests use the Application Key as a query parameter or Bearer token, and the browser JavaScript API uses an Application Key with authorized domains. Keep the Secret out of browser code, and do not call the REST API directly from a public web page.

Where do I find my GrabzIt Application Key and Secret?

Sign in to your GrabzIt account and obtain the credentials there. GrabzIt’s API overview says API access requires an Application Key and Application Secret and advises keeping them safe. It also describes domain and IP restrictions as ways to limit access.

Use the pair according to the integration you choose. The Secret belongs in a trusted server environment, not source code delivered to a browser. The exact secret-storage method depends on your hosting platform; the cited GrabzIt guidance does not specify a particular vault or rotation mechanism.

Which authentication method should I use?

Integration Credentials Where it runs and key protection
Server-side language library Application Key and Secret Use in a server runtime you control; keep both credentials in server-side configuration. GrabzIt identifies its Node.js library as server-side only.
REST API Application Key as a key parameter or Bearer token Make requests from a server or trusted backend, not browser code. Consider authorizing server IP addresses.
Browser JavaScript API Application Key Use the documented browser integration only with the domains you have authorized for that key.

These are distinct integration paths in GrabzIt’s API overview, REST documentation, and JavaScript guide. The key-protection controls differ because browser code is visible to site visitors while server-side code is not ordinarily delivered to them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

How do I set up a server-side client library?

GrabzIt documents client libraries for Node.js, Python, PHP, ASP.NET, and Java. The library examples initialize a client with the Application Key and Secret issued for your account. Install the appropriate library by following its language-specific guide, then load the credentials from server-side configuration rather than placing them in public source or browser-delivered code. GrabzIt’s server library documentation also points to demo applications.

  1. Obtain the Application Key and Secret in your GrabzIt account.
  2. Install the library for your server-side language using GrabzIt’s corresponding guide.
  3. Make the credentials available only to the server process.
  4. Initialize the library client with the key and secret, following the language guide’s documented method.
  5. Run a capture from the server and handle the result using that library’s documented workflow.

The exact initialization syntax differs by language and library version, so use the relevant official guide rather than copying a generic constructor from another language.

How do I authenticate to the GrabzIt REST API?

The REST endpoint documented by GrabzIt is https://api.grabz.it/convert. Send the Application Key either as a key parameter or in the Authorization header as a Bearer token. The REST guide warns: “Do not use this API on the client side, it will expose your Application Key!” Keep requests on your server.

Key in the query parameter

For a server-side HTTP client, pass the key as the key parameter and URL-encode parameter values. Use your account’s key and the conversion options supported by the REST documentation:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.grabz.it/convert" 
  --data-urlencode "key=YOUR_APPLICATION_KEY" 
  --data-urlencode "url=https://example.com" 
  -o capture

Replace the example URL with the page to capture and supply the output options required by your use case. Store the key in server-side configuration in production rather than committing it to source control or publishing it in a web page.

Bearer authorization header

The alternative is to send the same Application Key in the authorization header. For example, with cURL:

curl "https://api.grabz.it/convert?url=https%3A%2F%2Fexample.com" 
  -H "Authorization: Bearer YOUR_APPLICATION_KEY" 
  -o capture

The URL parameter in this example is encoded. The REST documentation supports both authentication forms; choose one rather than exposing the key in browser-delivered code.

Submitting HTML instead of a URL

GrabzIt’s REST guide says HTML conversion must use HTTP POST. Send the parameters as key-value pairs in the request body and set the content type to application/x-www-form-urlencoded. URL-encode parameter values. Do not put HTML into a browser-side REST call as a way around the key-exposure problem.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Restricting REST access

The REST page recommends authorizing the IP addresses of servers permitted to access the API. This is a recommended restriction, not evidence that every account is restricted by default. Check the account’s available settings and authorize only the server addresses that should make requests.

Rank #4
ziyue 2 Pack Hook Security Magnetic Tool Key for Wall (2Pack)
  • 【Premium Material】High-quality magnet material in black ABS house, durable and never rusts.
  • 【Easy to Install】Super easy to install, no drill needed.
  • 【Wide Application】You could use them to display your items, and press the paper on the whiteboard, keep two doors closed, and little gadget to attract wrenches, keys, etc.
  • 【Package Item】There are 3 combinations for you, 1 set, 2 set, 4 set, just choose according to your need.
  • 【Satisfaction Guarantee】Your satisfaction is our top aim, if encounter any problems, please feel free to contact us.

Can I use my GrabzIt key in JavaScript?

Yes, if you mean GrabzIt’s documented browser-side JavaScript API: that integration uses an Application Key and requires you to authorize the domains where the key may be used. Follow the JavaScript guide to include its library and call a conversion method with the key and the URL or HTML to capture.

Do not put the Application Secret in browser code. Also, do not call the REST API directly from the browser: GrabzIt explicitly warns that doing so exposes the Application Key. The browser JavaScript API’s domain authorization is a separate control, not a reason to publish the server-side Secret.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should I check when authentication fails?

  • A library rejects authentication: Confirm that you supplied both the account’s Application Key and Secret and used the library intended for your server-side language.
  • A REST request fails: Verify that it runs on a server, that the key is sent either in the key parameter or Bearer header, and that parameter values are URL-encoded.
  • HTML conversion fails: Send it as an HTTP POST with form-encoded key-value pairs and Content-Type: application/x-www-form-urlencoded.
  • The REST response is JSON: GrabzIt’s REST guide says an application/json response indicates an error; inspect the returned JSON for the explanation.
  • Browser JavaScript does not work: Confirm that the page’s current domain is authorized for the Application Key. The JavaScript guide says the API will not work without authorized domains.

GrabzIt’s REST documentation recommends Postman for simplifying API testing. It describes the response as the capture when successful, so check response headers and content type before treating a response body as an image or other capture output.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

For a screenshot request without setting up GrabzIt credentials and a capture client, ScreenshotNeo offers a one-request API. This cURL example saves the result to a file:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for request options. ScreenshotNeo accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status. An MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 screenshots a month without a card; paid plans start at $5 for 3,000 shots.

Sign up for ScreenshotNeo’s free plan: 1,000 screenshots a month with no card.

Frequently Asked Questions

Why does the GrabzIt JavaScript API need an authorized domain?

Domain authorization limits which pages may use the Application Key in the browser-side integration; GrabzIt says the JavaScript API will not work without authorized domains.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.