Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To access an HTTP-secured page with aiohttp, first identify the scheme the server requires—Basic, Digest, a bearer or custom authorization header, or a cookie-backed login—then send the matching credentials through an aiohttp.ClientSession. Reuse that session for related requests so its connection pool and cookie jar remain available, keep TLS verification enabled, and inspect the final response status and redirect history before treating the page as authenticated.

Choose the authentication method the server requires

There is no universal “secured page” login setting. The server may require HTTP authentication, a token, or a browser-like login flow that issues a session cookie. These methods are not interchangeable: use the target service’s documentation and access rules to determine what it expects. aiohttp’s stable reference currently identifies version 3.14.3; the advanced client guide cited for Digest behavior identifies 3.12.13, so check the API for the version installed in your project.

Method Use it when Key consideration
Basic The server explicitly requires HTTP Basic authentication. In aiohttp 3.14, constructing BasicAuth is deprecated. The stable reference directs users to encode_basic_auth() and the request’s headers parameter. aiohttp stable client reference
Digest The server challenges with HTTP Digest authentication. The advanced client guide documents DigestAuthMiddleware; confirm its availability and usage for your installed version. aiohttp advanced client guide
Bearer or custom authorization The service specifies a token or another value in the Authorization header. Authorization is removed when a redirect changes host or protocol, according to the advanced guide. Do not assume a redirected request carries the original credentials.
Cookie-backed login A documented login flow returns a session cookie used on later requests. Reuse one ClientSession; its default cookie jar can retain cookies from one response for subsequent requests.

The examples below show the client-side mechanics. They do not grant access to a site or bypass its authorization controls. Use credentials and endpoints you are permitted to use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set up a reusable aiohttp session

ClientSession is aiohttp’s recommended interface for making requests. It maintains a connection pool and supports keepalives; its default cookie jar also preserves cookies between requests. Use it as an asynchronous context manager so the session closes cleanly when work is done. aiohttp stable client reference

Install aiohttp in the environment where you will run the script:

python -m pip install aiohttp

Save the following as fetch_page.py. It sends a request, prints the final status and redirect history, and writes the response body to a file only for a successful HTTP status:

import asyncio
import aiohttp

async def main():
    url = "https://example.com/private"

    async with aiohttp.ClientSession() as session:
        async with session.get(url) as response:
            print("Status:", response.status)
            print("Final URL:", response.url)
            print("Redirects:", [str(item.url) for item in response.history])
            response.raise_for_status()
            body = await response.text()
            print(body[:1000])

asyncio.run(main())

Replace the example URL and add exactly the authentication mechanism required by the service. raise_for_status() raises for unsuccessful HTTP statuses; if you need to inspect an error page or handle a particular status yourself, omit it and branch on response.status.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Send Basic authentication with current aiohttp

For a server that explicitly uses HTTP Basic authentication, aiohttp 3.14 deprecates constructing BasicAuth. The current stable reference documents encode_basic_auth(), which produces the value for the Authorization header. Avoid embedding credentials directly in source code; load them from an environment variable or secret store.

import asyncio
import os
import aiohttp

async def main():
    url = "https://example.com/private"
    username = os.environ["SITE_USERNAME"]
    password = os.environ["SITE_PASSWORD"]

    authorization = aiohttp.encode_basic_auth(username, password)
    headers = {"Authorization": authorization}

    async with aiohttp.ClientSession() as session:
        async with session.get(url, headers=headers) as response:
            print("Status:", response.status)
            print("Redirects:", [str(item.url) for item in response.history])
            response.raise_for_status()
            print((await response.text())[:1000])

asyncio.run(main())

Set SITE_USERNAME and SITE_PASSWORD in the process environment before running the script. Basic authentication is appropriate only when the server expects it; use HTTPS so credentials are protected in transit, and retain normal TLS certificate checks.

Use Digest, bearer tokens, or a custom authorization header

Digest authentication

If the server responds with an HTTP Digest challenge, use aiohttp’s documented DigestAuthMiddleware rather than treating the credentials as Basic or sending a bearer token. The advanced guide retrieved for this behavior is for aiohttp 3.12.13, while the stable reference identifies 3.14.3. Confirm the middleware import and constructor against the documentation matching your installed release before deploying.

Bearer or custom authorization

When a service documents a bearer token, send the specified header. This example assumes a bearer scheme; follow the actual service’s documented scheme and token format:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
import asyncio
import os
import aiohttp

async def main():
    url = "https://example.com/api/private"
    token = os.environ["SITE_TOKEN"]
    headers = {"Authorization": f"Bearer {token}"}

    async with aiohttp.ClientSession(headers=headers) as session:
        async with session.get(url) as response:
            print("Status:", response.status)
            print("Final URL:", response.url)
            print("Redirects:", [str(item.url) for item in response.history])
            response.raise_for_status()
            print(await response.text())

asyncio.run(main())

Session-level headers apply to requests made through that session. If a request redirects to a different host or protocol, aiohttp removes the Authorization header. That is a credential-safety behavior, not a reason to forward secrets manually to an unrelated destination. Inspect the redirect destination and use only documented endpoints.

Follow a cookie-backed login flow

Some sites do not use HTTP Basic or Digest. Instead, a login request establishes a session cookie, which the server expects on a later request. Use the service’s documented login URL, form field names, and CSRF requirements; these differ by site. Keeping both requests on the same ClientSession allows its cookie jar to carry cookies received in the login response.

import asyncio
import os
import aiohttp

async def main():
    login_url = "https://example.com/login"
    page_url = "https://example.com/private"

    form = {
        "username": os.environ["SITE_USERNAME"],
        "password": os.environ["SITE_PASSWORD"],
    }

    async with aiohttp.ClientSession() as session:
        async with session.post(login_url, data=form) as login_response:
            print("Login status:", login_response.status)
            print("Login redirects:", [str(item.url) for item in login_response.history])
            login_response.raise_for_status()

        async with session.get(page_url) as response:
            print("Page status:", response.status)
            print("Page redirects:", [str(item.url) for item in response.history])
            response.raise_for_status()
            print((await response.text())[:1000])

asyncio.run(main())

This is a structural example, not a universal website login recipe. A real flow may require a CSRF token, a particular content type, a preliminary page request, or additional fields. A successful login response alone does not prove the second request is authenticated: check the final page content and redirect history for signs that the server returned its login screen again.

Handle redirects, status codes, and response bodies deliberately

aiohttp follows redirects by default. The request API allows you to turn that behavior off with allow_redirects=False, which can help diagnose where authentication is being sent. By default, a session does not automatically raise an exception for every unsuccessful response; use raise_for_status on the session or per request, or inspect the response explicitly. aiohttp stable client reference

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
async with aiohttp.ClientSession() as session:
    async with session.get(
        "https://example.com/private",
        allow_redirects=False,
    ) as response:
        print("Status:", response.status)
        print("Location:", response.headers.get("Location"))
        print((await response.text())[:1000])
  • 401 Unauthorized: check that the requested authentication scheme, username, password, or token matches the service’s requirements.
  • 403 Forbidden: the server has not granted the requested access. Verify account permissions and the service’s access rules rather than trying to bypass them.
  • Redirect to a login page: inspect response.history and the final URL. The original request may not have authenticated, or a cookie-backed flow may not have completed.
  • Unexpected content with a success status: HTTP success alone does not establish that the response is the protected resource. Check the returned page or content type.

Keep TLS verification enabled

TLS certificate validation is enabled by default; aiohttp documents ssl=True as the normal validation setting. Setting ssl=False disables certificate validation. Do not use it as a routine fix for an authentication error: it weakens protection against an impostor server and does not correct a wrong password, token, redirect, or permission. aiohttp stable client reference

Or skip the browser setup

If your goal is a visual capture rather than an authenticated HTML response, ScreenshotNeo is a website screenshot API and MCP server for developers. Its one-request API returns a PNG, JPEG, WebP, or PDF; use it only for pages you can legitimately access. For a page requiring authentication, supply the appropriate access credentials and settings for that page.

cURL example, using the documented API endpoint and parameter names:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Replace the target URL with the page to capture. See the ScreenshotNeo documentation for the API’s authentication and parameters. ScreenshotNeo removes cookie banners, popups, and chat widgets before the shot; bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots per month with no card, and paid plans start at $5 for 3,000 screenshots. Sign up free for ScreenshotNeo.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common failures

  • AttributeError or missing authentication helper: check the installed aiohttp version and consult the documentation for that release. The stable reference identifies 3.14.3, where constructing BasicAuth is deprecated in favor of encode_basic_auth().
  • The request ends at a login page: print the final URL and each URL in response.history. Confirm the credentials were sent using the expected scheme, or that the login flow’s cookies were retained by reusing the same session.
  • A token works on the first host but not after a redirect: aiohttp removes Authorization when the redirect changes host or protocol. Verify the intended destination and the service’s documented redirect behavior; do not disclose credentials to an untrusted host.
  • The program exits without displaying an HTTP error: inspect response.status or call response.raise_for_status(). Decide whether to raise or handle the status based on the application’s needs.
  • Certificate verification fails: investigate the server certificate and local trust configuration. Do not disable verification as a general workaround.
  • Login POST succeeds but protected GET does not: confirm the service’s required form fields, CSRF handling, and login endpoint, then check whether the response actually established cookies. The correct flow is specific to the service.

Performance and reliability considerations

For related requests, one ClientSession avoids repeatedly creating client state and preserves its connection pool and cookies. Always close it, preferably with async with. Authentication state is not a substitute for checking each response: redirects, expired sessions, permission changes, and server errors can still produce a page other than the one you intended.

The cited aiohttp documentation describes API behavior, not a performance benchmark or a guarantee of access to any specific website. Use the target service’s documented API when available, respect its rate and access policies, and avoid retrying authentication failures as if they were transient network errors.

FAQ

Does aiohttp log into any website automatically?

No. aiohttp provides HTTP client mechanisms; the website determines the required authentication flow and whether your account is allowed to access the resource.

Can I use cookies and an Authorization header in the same session?

A session can make requests with headers and also maintain a cookie jar, but whether a given server accepts both is determined by that server’s documented protocol.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Should I disable TLS verification if authentication fails?

No. Authentication failures should be diagnosed by checking the scheme, credentials, permissions, status, and redirects. TLS validation protects the connection and is enabled by default.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.