Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

For an HTTP-protected page, the documented httplib2 sequence is: create an httplib2.Http client, add the username and password with add_credentials(), then call request() with the HTTPS URL and method. The server can answer first with a 401 challenge; httplib2 then supplies the credentials for the supported authentication scheme and retries.

Install httplib2 and check the Python version

Install the package in the environment that will run your script:

python -m pip install httplib2

PyPI listed httplib2 0.32.0, released June 26, 2026, with a requirement of Python 3.8 or newer. Package metadata is time-sensitive, so check the current PyPI project page when pinning a deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The project describes httplib2 as an HTTP client supporting HTTP and HTTPS, connection keep-alive, arbitrary HTTP methods, safe GET redirects, response caching, and gzip/deflate compression. Those capabilities do not turn a form login, OAuth consent flow, or CAPTCHA into an HTTP-authentication request.

How the authentication challenge works

HTTP authentication is normally a challenge-response exchange:

  1. Your client requests the protected URL.
  2. The server returns 401 Unauthorized and a WWW-Authenticate header naming an authentication scheme and realm.
  3. The client retries with credentials appropriate to that challenge.
  4. If the credentials and permissions are accepted, the server returns the protected response; otherwise it returns another error.

Python’s official Basic Authentication HOWTO describes this 401 and WWW-Authenticate flow. httplib2’s documentation lists Basic, Digest, and WSSE authentication and provides add_credentials(name, password[, domain]) for supplying credentials when a challenge requires them.

Minimal authenticated GET in Python

This is the smallest useful pattern for a secured page. It adapts the official documentation’s Http, add_credentials, and HTTPS request pattern from a Basic-authenticated PUT to a GET:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
import httplib2

http = httplib2.Http()
http.add_credentials("name", "password")
response, content = http.request(
    "https://example.org/protected",
    method="GET",
)

print(response.status)
print(content)

The returned response contains response metadata, including the HTTP status, while content contains the response body. Treat the URL, username, and password in this example as placeholders and use an endpoint for which you are authorized.

A safer script pattern for real applications

Do not place reusable credentials directly in source control. Read them from a secret manager or environment variables, restrict the credential scope where possible, and fail clearly on an unsuccessful status:

import os
import sys
import httplib2

url = os.environ.get("PROTECTED_URL", "https://example.org/protected")
username = os.environ["HTTP_USERNAME"]
password = os.environ["HTTP_PASSWORD"]

http = httplib2.Http()
http.add_credentials(username, password)

try:
    response, content = http.request(url, method="GET")
except Exception as exc:
    print(f"Request failed: {exc}", file=sys.stderr)
    raise

status = int(response.status)
if status == 401:
    raise RuntimeError("The server rejected the HTTP credentials (401)")
if status == 403:
    raise RuntimeError("Credentials were accepted or recognized, but access is forbidden (403)")
if status < 200 or status >= 300:
    raise RuntimeError(f"Unexpected HTTP status: {status}")

with open("protected-response.bin", "wb") as output:
    output.write(content)

print(f"Saved {len(content)} bytes from {url}")

Keeping the body as bytes avoids assuming that the server used UTF-8. Decode it only after determining the response’s declared media type and character encoding.

Scope credentials with the optional domain

add_credentials accepts an optional domain argument:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
http.add_credentials("name", "password", "example.org")

Use the domain to limit where those credentials are applicable when your program talks to more than one host. The helper’s documented purpose is to provide HTTP-authentication credentials for a challenge; it is not a general authorization policy or a substitute for server-side permissions.

Match the server’s authentication mechanism

Server requirement httplib2 support documented What to do
Basic authentication Yes Call add_credentials, use HTTPS, and let the server challenge the client.
Digest authentication Yes Use the same client-and-credential setup, then verify the server’s challenge and required permissions.
WSSE authentication Yes Use the documented httplib2 mechanism and confirm the endpoint’s exact WSSE requirements.
Client TLS certificate Separate helper documented Use add_certificate(key, cert, domain) as appropriate; this is certificate-based TLS client authentication, not a username/password challenge.

The official httplib2 overview documents both add_credentials and the separate add_certificate helper. Do not pass a client certificate where the server expects Basic, Digest, or WSSE credentials, or assume that a username/password will satisfy mutual TLS.

Use HTTPS when sending credentials

The official example combines Basic authentication with an HTTPS URL. Use HTTPS for any request carrying credentials and verify your deployment’s certificate-validation and CA requirements against the current httplib2 and Python documentation. The available project material does not establish a universal current certificate-validation default, so do not disable verification as a troubleshooting shortcut.

HTTPS protects the connection in transit; it does not grant permission to the resource. Keep credentials out of logs, exception messages, shell history, and URLs. A URL such as https://user:[email protected]/ can leak through proxies and logs and should not be used as a secret-management strategy.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What this pattern does not cover

HTML form sign-in

A page with a username form usually requires a POST, hidden fields, cookies, redirects, and sometimes a CSRF token. add_credentials addresses HTTP authentication challenges, not that browser session workflow.

OAuth authorization

OAuth commonly involves obtaining and refreshing a token, then sending an authorization header. Follow the service’s OAuth documentation rather than assuming that Basic credentials can replace the token flow.

CAPTCHAs and bot controls

A CAPTCHA or bot-check page is an access-control mechanism, not a Basic, Digest, or WSSE challenge. Do not use httplib2 to bypass it; obtain authorized API access or use the service’s supported integration.

Cookies and an existing browser session

Adding credentials does not automatically import your browser’s cookies or logged-in state. If the endpoint requires a session cookie, implement the service’s documented session flow and handle cookies explicitly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Equivalent requests for interoperability checks

These examples are useful when comparing a server’s behavior outside Python. They send Basic credentials directly and are not httplib2 code.

cURL

curl --fail --user "$HTTP_USERNAME:$HTTP_PASSWORD" 
  "https://example.org/protected"

Node.js

const user = process.env.HTTP_USERNAME;
const pass = process.env.HTTP_PASSWORD;
const token = Buffer.from(`${user}:${pass}`).toString('base64');

const response = await fetch('https://example.org/protected', {
  headers: { Authorization: `Basic ${token}` }
});

if (!response.ok) {
  throw new Error(`HTTP ${response.status}`);
}

const body = await response.arrayBuffer();
console.log(`Received ${body.byteLength} bytes`);

A server that requires Digest or WSSE will not accept these Basic-only examples. Inspect the server’s WWW-Authenticate challenge and use the matching client support.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common failures

Symptom Likely cause Fix
401 Unauthorized after adding credentials Wrong username/password, wrong scheme, wrong realm, or credentials not valid for that host. Inspect the response’s WWW-Authenticate header, confirm the account’s permission, and use the matching Basic, Digest, or WSSE setup.
403 Forbidden The server recognized the request but the account is not authorized for the resource. Ask the service administrator for the required permission; changing the password will not grant a missing authorization.
Credentials work on one host but not another Credentials are scoped to a host, realm, or configured domain. Use the correct URL and, where appropriate, pass the optional domain to add_credentials.
A form-login page is returned instead of the resource The endpoint expects a browser session or application login, not HTTP authentication. Use the provider’s documented session, API-key, or OAuth flow.
TLS or certificate error Certificate-chain, hostname, CA, or deployment configuration problem. Fix the trust configuration and hostname; do not turn off certificate verification merely to make the request pass.
The response is an HTML bot check or CAPTCHA The service is challenging the client with a bot-control page. Use an authorized API or approved integration. httplib2 credentials do not solve a CAPTCHA.
Unexpected redirect The protected URL redirects to another host, login route, or scheme. Record the final URL and status, verify that the redirect is expected, and do not forward credentials to an unrelated host.

Reliability, caching, and request design

  • Reuse an httplib2.Http instance when making multiple requests so its connection-management behavior can work across the sequence.
  • Choose the method explicitly. The documented client supports arbitrary HTTP methods; a GET is appropriate for retrieval, while PUT, POST, or another method must follow the endpoint’s contract.
  • Set an application-level timeout and retry policy appropriate to the operation. Retrying a read may be safe in some systems; retrying a non-idempotent write can create duplicate side effects.
  • Decide whether caching is acceptable for the resource. httplib2 supports caching, but protected or rapidly changing data may require cache controls that match your confidentiality and freshness requirements.
  • Log status, host, and timing for diagnosis, but redact authorization headers, passwords, cookies, and sensitive response bodies.

Neither the documentation cited here nor the package metadata establishes a universal performance benchmark or uptime guarantee. Measure your own endpoint under its real network and authentication conditions.

Or skip the browser setup

If your actual goal is a visual screenshot or PDF of a page you are authorized to capture, ScreenshotNeo provides a single HTTP request instead of maintaining a browser automation stack. It is a screenshot API and MCP server for developers; it is not a way to bypass a site’s authentication or access controls. For a page that needs authorization, use its supported custom headers or cookies and the site’s permission model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a public example, the documented call is:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo documentation for options such as full-page capture, CSS-selector element capture, custom headers and cookies, waits, JavaScript, PDF output, signed links, asynchronous jobs, bulk capture, and caching. Before capture it accepts the cookie/consent banner like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and each response identifies the page verdict and billing result in headers.

ScreenshotNeo also offers an MCP server with take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 shots per month without a card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account to try it.

Checklist before shipping

  • Confirm the endpoint actually uses HTTP authentication rather than a form, OAuth, cookie, or bot-control flow.
  • Use an HTTPS URL and keep credentials outside source control.
  • Create one httplib2.Http, call add_credentials, and then call request with the intended method.
  • Scope credentials with the optional domain when your application contacts multiple hosts.
  • Handle 401, 403, redirects, TLS failures, and non-success statuses explicitly.
  • Keep response data as bytes until its encoding is known, and redact secrets from logs.

Frequently Asked Questions

Can the same httplib2 client be used for more than one protected request?

Yes. Keep the configured Http instance and issue additional requests, while ensuring that each destination and credential scope is authorized.

When should I use add_certificate instead of add_credentials?

Use add_certificate only when the server requires a client TLS certificate. Use add_credentials for the HTTP authentication schemes documented by httplib2.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where can I verify the package’s current release requirements?

Check the live httplib2 PyPI metadata; the listing cited here recorded version 0.32.0 and Python 3.8 or newer on June 26, 2026.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.