Free tools Windows power users keep installed
One-click scans. No signup required.
GrabzIt screenshot API authentication depends on where your code runs: server-side libraries use an Application Key and Secret, REST requests use the Application Key as a query parameter or Bearer token, and the browser JavaScript API uses an Application Key with authorized domains. Keep the Secret out of browser code, and do not call the REST API directly from a public web page.
Where do I find my GrabzIt Application Key and Secret?
Sign in to your GrabzIt account and obtain the credentials there. GrabzIt’s API overview says API access requires an Application Key and Application Secret and advises keeping them safe. It also describes domain and IP restrictions as ways to limit access.
Use the pair according to the integration you choose. The Secret belongs in a trusted server environment, not source code delivered to a browser. The exact secret-storage method depends on your hosting platform; the cited GrabzIt guidance does not specify a particular vault or rotation mechanism.
Which authentication method should I use?
| Integration | Credentials | Where it runs and key protection |
|---|---|---|
| Server-side language library | Application Key and Secret | Use in a server runtime you control; keep both credentials in server-side configuration. GrabzIt identifies its Node.js library as server-side only. |
| REST API | Application Key as a key parameter or Bearer token |
Make requests from a server or trusted backend, not browser code. Consider authorizing server IP addresses. |
| Browser JavaScript API | Application Key | Use the documented browser integration only with the domains you have authorized for that key. |
These are distinct integration paths in GrabzIt’s API overview, REST documentation, and JavaScript guide. The key-protection controls differ because browser code is visible to site visitors while server-side code is not ordinarily delivered to them.
Recommended Free Tools
#1 Best Overall
How do I set up a server-side client library?
GrabzIt documents client libraries for Node.js, Python, PHP, ASP.NET, and Java. The library examples initialize a client with the Application Key and Secret issued for your account. Install the appropriate library by following its language-specific guide, then load the credentials from server-side configuration rather than placing them in public source or browser-delivered code. GrabzIt’s server library documentation also points to demo applications.
- Obtain the Application Key and Secret in your GrabzIt account.
- Install the library for your server-side language using GrabzIt’s corresponding guide.
- Make the credentials available only to the server process.
- Initialize the library client with the key and secret, following the language guide’s documented method.
- Run a capture from the server and handle the result using that library’s documented workflow.
The exact initialization syntax differs by language and library version, so use the relevant official guide rather than copying a generic constructor from another language.
How do I authenticate to the GrabzIt REST API?
The REST endpoint documented by GrabzIt is https://api.grabz.it/convert. Send the Application Key either as a key parameter or in the Authorization header as a Bearer token. The REST guide warns: “Do not use this API on the client side, it will expose your Application Key!” Keep requests on your server.
Key in the query parameter
For a server-side HTTP client, pass the key as the key parameter and URL-encode parameter values. Use your account’s key and the conversion options supported by the REST documentation:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →curl -G "https://api.grabz.it/convert"
--data-urlencode "key=YOUR_APPLICATION_KEY"
--data-urlencode "url=https://example.com"
-o capture
Replace the example URL with the page to capture and supply the output options required by your use case. Store the key in server-side configuration in production rather than committing it to source control or publishing it in a web page.
Bearer authorization header
The alternative is to send the same Application Key in the authorization header. For example, with cURL:
curl "https://api.grabz.it/convert?url=https%3A%2F%2Fexample.com"
-H "Authorization: Bearer YOUR_APPLICATION_KEY"
-o capture
The URL parameter in this example is encoded. The REST documentation supports both authentication forms; choose one rather than exposing the key in browser-delivered code.
Submitting HTML instead of a URL
GrabzIt’s REST guide says HTML conversion must use HTTP POST. Send the parameters as key-value pairs in the request body and set the content type to application/x-www-form-urlencoded. URL-encode parameter values. Do not put HTML into a browser-side REST call as a way around the key-exposure problem.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRestricting REST access
The REST page recommends authorizing the IP addresses of servers permitted to access the API. This is a recommended restriction, not evidence that every account is restricted by default. Check the account’s available settings and authorize only the server addresses that should make requests.
Rank #4
- 【Premium Material】High-quality magnet material in black ABS house, durable and never rusts.
- 【Easy to Install】Super easy to install, no drill needed.
- 【Wide Application】You could use them to display your items, and press the paper on the whiteboard, keep two doors closed, and little gadget to attract wrenches, keys, etc.
- 【Package Item】There are 3 combinations for you, 1 set, 2 set, 4 set, just choose according to your need.
- 【Satisfaction Guarantee】Your satisfaction is our top aim, if encounter any problems, please feel free to contact us.
Can I use my GrabzIt key in JavaScript?
Yes, if you mean GrabzIt’s documented browser-side JavaScript API: that integration uses an Application Key and requires you to authorize the domains where the key may be used. Follow the JavaScript guide to include its library and call a conversion method with the key and the URL or HTML to capture.
Do not put the Application Secret in browser code. Also, do not call the REST API directly from the browser: GrabzIt explicitly warns that doing so exposes the Application Key. The browser JavaScript API’s domain authorization is a separate control, not a reason to publish the server-side Secret.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should I check when authentication fails?
- A library rejects authentication: Confirm that you supplied both the account’s Application Key and Secret and used the library intended for your server-side language.
- A REST request fails: Verify that it runs on a server, that the key is sent either in the
keyparameter or Bearer header, and that parameter values are URL-encoded. - HTML conversion fails: Send it as an HTTP POST with form-encoded key-value pairs and
Content-Type: application/x-www-form-urlencoded. - The REST response is JSON: GrabzIt’s REST guide says an
application/jsonresponse indicates an error; inspect the returned JSON for the explanation. - Browser JavaScript does not work: Confirm that the page’s current domain is authorized for the Application Key. The JavaScript guide says the API will not work without authorized domains.
GrabzIt’s REST documentation recommends Postman for simplifying API testing. It describes the response as the capture when successful, so check response headers and content type before treating a response body as an image or other capture output.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
Or skip the browser setup
For a screenshot request without setting up GrabzIt credentials and a capture client, ScreenshotNeo offers a one-request API. This cURL example saves the result to a file:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for request options. ScreenshotNeo accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status. An MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 screenshots a month without a card; paid plans start at $5 for 3,000 shots.
Sign up for ScreenshotNeo’s free plan: 1,000 screenshots a month with no card.
Frequently Asked Questions
Why does the GrabzIt JavaScript API need an authorized domain?
Domain authorization limits which pages may use the Application Key in the browser-side integration; GrabzIt says the JavaScript API will not work without authorized domains.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




