Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To access an HTTP-secured page with aiohttp, first identify the scheme the server requires—Basic, Digest, a bearer or custom authorization header, or a cookie-backed login—then send the matching credentials through an aiohttp.ClientSession. Reuse that session for related requests so its connection pool and cookie jar remain available, keep TLS verification enabled, and inspect the final response status and redirect history before treating the page as authenticated.
Choose the authentication method the server requires
There is no universal “secured page” login setting. The server may require HTTP authentication, a token, or a browser-like login flow that issues a session cookie. These methods are not interchangeable: use the target service’s documentation and access rules to determine what it expects. aiohttp’s stable reference currently identifies version 3.14.3; the advanced client guide cited for Digest behavior identifies 3.12.13, so check the API for the version installed in your project.
| Method | Use it when | Key consideration |
|---|---|---|
| Basic | The server explicitly requires HTTP Basic authentication. | In aiohttp 3.14, constructing BasicAuth is deprecated. The stable reference directs users to encode_basic_auth() and the request’s headers parameter. aiohttp stable client reference |
| Digest | The server challenges with HTTP Digest authentication. | The advanced client guide documents DigestAuthMiddleware; confirm its availability and usage for your installed version. aiohttp advanced client guide |
| Bearer or custom authorization | The service specifies a token or another value in the Authorization header. |
Authorization is removed when a redirect changes host or protocol, according to the advanced guide. Do not assume a redirected request carries the original credentials. |
| Cookie-backed login | A documented login flow returns a session cookie used on later requests. | Reuse one ClientSession; its default cookie jar can retain cookies from one response for subsequent requests. |
The examples below show the client-side mechanics. They do not grant access to a site or bypass its authorization controls. Use credentials and endpoints you are permitted to use.
Recommended Free Tools
Set up a reusable aiohttp session
ClientSession is aiohttp’s recommended interface for making requests. It maintains a connection pool and supports keepalives; its default cookie jar also preserves cookies between requests. Use it as an asynchronous context manager so the session closes cleanly when work is done. aiohttp stable client reference
#1 Best Overall
Install aiohttp in the environment where you will run the script:
python -m pip install aiohttp
Save the following as fetch_page.py. It sends a request, prints the final status and redirect history, and writes the response body to a file only for a successful HTTP status:
import asyncio
import aiohttp
async def main():
url = "https://example.com/private"
async with aiohttp.ClientSession() as session:
async with session.get(url) as response:
print("Status:", response.status)
print("Final URL:", response.url)
print("Redirects:", [str(item.url) for item in response.history])
response.raise_for_status()
body = await response.text()
print(body[:1000])
asyncio.run(main())
Replace the example URL and add exactly the authentication mechanism required by the service. raise_for_status() raises for unsuccessful HTTP statuses; if you need to inspect an error page or handle a particular status yourself, omit it and branch on response.status.
Send Basic authentication with current aiohttp
For a server that explicitly uses HTTP Basic authentication, aiohttp 3.14 deprecates constructing BasicAuth. The current stable reference documents encode_basic_auth(), which produces the value for the Authorization header. Avoid embedding credentials directly in source code; load them from an environment variable or secret store.
Rank #2
import asyncio
import os
import aiohttp
async def main():
url = "https://example.com/private"
username = os.environ["SITE_USERNAME"]
password = os.environ["SITE_PASSWORD"]
authorization = aiohttp.encode_basic_auth(username, password)
headers = {"Authorization": authorization}
async with aiohttp.ClientSession() as session:
async with session.get(url, headers=headers) as response:
print("Status:", response.status)
print("Redirects:", [str(item.url) for item in response.history])
response.raise_for_status()
print((await response.text())[:1000])
asyncio.run(main())
Set SITE_USERNAME and SITE_PASSWORD in the process environment before running the script. Basic authentication is appropriate only when the server expects it; use HTTPS so credentials are protected in transit, and retain normal TLS certificate checks.
Use Digest, bearer tokens, or a custom authorization header
Digest authentication
If the server responds with an HTTP Digest challenge, use aiohttp’s documented DigestAuthMiddleware rather than treating the credentials as Basic or sending a bearer token. The advanced guide retrieved for this behavior is for aiohttp 3.12.13, while the stable reference identifies 3.14.3. Confirm the middleware import and constructor against the documentation matching your installed release before deploying.
Bearer or custom authorization
When a service documents a bearer token, send the specified header. This example assumes a bearer scheme; follow the actual service’s documented scheme and token format:
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →import asyncio
import os
import aiohttp
async def main():
url = "https://example.com/api/private"
token = os.environ["SITE_TOKEN"]
headers = {"Authorization": f"Bearer {token}"}
async with aiohttp.ClientSession(headers=headers) as session:
async with session.get(url) as response:
print("Status:", response.status)
print("Final URL:", response.url)
print("Redirects:", [str(item.url) for item in response.history])
response.raise_for_status()
print(await response.text())
asyncio.run(main())
Session-level headers apply to requests made through that session. If a request redirects to a different host or protocol, aiohttp removes the Authorization header. That is a credential-safety behavior, not a reason to forward secrets manually to an unrelated destination. Inspect the redirect destination and use only documented endpoints.
Follow a cookie-backed login flow
Some sites do not use HTTP Basic or Digest. Instead, a login request establishes a session cookie, which the server expects on a later request. Use the service’s documented login URL, form field names, and CSRF requirements; these differ by site. Keeping both requests on the same ClientSession allows its cookie jar to carry cookies received in the login response.
import asyncio
import os
import aiohttp
async def main():
login_url = "https://example.com/login"
page_url = "https://example.com/private"
form = {
"username": os.environ["SITE_USERNAME"],
"password": os.environ["SITE_PASSWORD"],
}
async with aiohttp.ClientSession() as session:
async with session.post(login_url, data=form) as login_response:
print("Login status:", login_response.status)
print("Login redirects:", [str(item.url) for item in login_response.history])
login_response.raise_for_status()
async with session.get(page_url) as response:
print("Page status:", response.status)
print("Page redirects:", [str(item.url) for item in response.history])
response.raise_for_status()
print((await response.text())[:1000])
asyncio.run(main())
This is a structural example, not a universal website login recipe. A real flow may require a CSRF token, a particular content type, a preliminary page request, or additional fields. A successful login response alone does not prove the second request is authenticated: check the final page content and redirect history for signs that the server returned its login screen again.
Handle redirects, status codes, and response bodies deliberately
aiohttp follows redirects by default. The request API allows you to turn that behavior off with allow_redirects=False, which can help diagnose where authentication is being sent. By default, a session does not automatically raise an exception for every unsuccessful response; use raise_for_status on the session or per request, or inspect the response explicitly. aiohttp stable client reference
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
async with aiohttp.ClientSession() as session:
async with session.get(
"https://example.com/private",
allow_redirects=False,
) as response:
print("Status:", response.status)
print("Location:", response.headers.get("Location"))
print((await response.text())[:1000])
- 401 Unauthorized: check that the requested authentication scheme, username, password, or token matches the service’s requirements.
- 403 Forbidden: the server has not granted the requested access. Verify account permissions and the service’s access rules rather than trying to bypass them.
- Redirect to a login page: inspect
response.historyand the final URL. The original request may not have authenticated, or a cookie-backed flow may not have completed. - Unexpected content with a success status: HTTP success alone does not establish that the response is the protected resource. Check the returned page or content type.
Keep TLS verification enabled
TLS certificate validation is enabled by default; aiohttp documents ssl=True as the normal validation setting. Setting ssl=False disables certificate validation. Do not use it as a routine fix for an authentication error: it weakens protection against an impostor server and does not correct a wrong password, token, redirect, or permission. aiohttp stable client reference
Or skip the browser setup
If your goal is a visual capture rather than an authenticated HTML response, ScreenshotNeo is a website screenshot API and MCP server for developers. Its one-request API returns a PNG, JPEG, WebP, or PDF; use it only for pages you can legitimately access. For a page requiring authentication, supply the appropriate access credentials and settings for that page.
cURL example, using the documented API endpoint and parameter names:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Replace the target URL with the page to capture. See the ScreenshotNeo documentation for the API’s authentication and parameters. ScreenshotNeo removes cookie banners, popups, and chat widgets before the shot; bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots per month with no card, and paid plans start at $5 for 3,000 screenshots. Sign up free for ScreenshotNeo.
Troubleshooting common failures
AttributeErroror missing authentication helper: check the installed aiohttp version and consult the documentation for that release. The stable reference identifies 3.14.3, where constructingBasicAuthis deprecated in favor ofencode_basic_auth().- The request ends at a login page: print the final URL and each URL in
response.history. Confirm the credentials were sent using the expected scheme, or that the login flow’s cookies were retained by reusing the same session. - A token works on the first host but not after a redirect: aiohttp removes
Authorizationwhen the redirect changes host or protocol. Verify the intended destination and the service’s documented redirect behavior; do not disclose credentials to an untrusted host. - The program exits without displaying an HTTP error: inspect
response.statusor callresponse.raise_for_status(). Decide whether to raise or handle the status based on the application’s needs. - Certificate verification fails: investigate the server certificate and local trust configuration. Do not disable verification as a general workaround.
- Login POST succeeds but protected GET does not: confirm the service’s required form fields, CSRF handling, and login endpoint, then check whether the response actually established cookies. The correct flow is specific to the service.
Performance and reliability considerations
For related requests, one ClientSession avoids repeatedly creating client state and preserves its connection pool and cookies. Always close it, preferably with async with. Authentication state is not a substitute for checking each response: redirects, expired sessions, permission changes, and server errors can still produce a page other than the one you intended.
The cited aiohttp documentation describes API behavior, not a performance benchmark or a guarantee of access to any specific website. Use the target service’s documented API when available, respect its rate and access policies, and avoid retrying authentication failures as if they were transient network errors.
Best Value
FAQ
Does aiohttp log into any website automatically?
No. aiohttp provides HTTP client mechanisms; the website determines the required authentication flow and whether your account is allowed to access the resource.
Can I use cookies and an Authorization header in the same session?
A session can make requests with headers and also maintain a cookie jar, but whether a given server accepts both is determined by that server’s documented protocol.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsShould I disable TLS verification if authentication fails?
No. Authentication failures should be diagnosed by checking the scheme, credentials, permissions, status, and redirects. TLS validation protects the connection and is enabled by default.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

