Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
For an HTTP-protected page, the documented httplib2 sequence is: create an httplib2.Http client, add the username and password with add_credentials(), then call request() with the HTTPS URL and method. The server can answer first with a 401 challenge; httplib2 then supplies the credentials for the supported authentication scheme and retries.
Install httplib2 and check the Python version
Install the package in the environment that will run your script:
python -m pip install httplib2
PyPI listed httplib2 0.32.0, released June 26, 2026, with a requirement of Python 3.8 or newer. Package metadata is time-sensitive, so check the current PyPI project page when pinning a deployment.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →The project describes httplib2 as an HTTP client supporting HTTP and HTTPS, connection keep-alive, arbitrary HTTP methods, safe GET redirects, response caching, and gzip/deflate compression. Those capabilities do not turn a form login, OAuth consent flow, or CAPTCHA into an HTTP-authentication request.
#1 Best Overall
How the authentication challenge works
HTTP authentication is normally a challenge-response exchange:
- Your client requests the protected URL.
- The server returns
401 Unauthorizedand aWWW-Authenticateheader naming an authentication scheme and realm. - The client retries with credentials appropriate to that challenge.
- If the credentials and permissions are accepted, the server returns the protected response; otherwise it returns another error.
Python’s official Basic Authentication HOWTO describes this 401 and WWW-Authenticate flow. httplib2’s documentation lists Basic, Digest, and WSSE authentication and provides add_credentials(name, password[, domain]) for supplying credentials when a challenge requires them.
Minimal authenticated GET in Python
This is the smallest useful pattern for a secured page. It adapts the official documentation’s Http, add_credentials, and HTTPS request pattern from a Basic-authenticated PUT to a GET:
import httplib2
http = httplib2.Http()
http.add_credentials("name", "password")
response, content = http.request(
"https://example.org/protected",
method="GET",
)
print(response.status)
print(content)
The returned response contains response metadata, including the HTTP status, while content contains the response body. Treat the URL, username, and password in this example as placeholders and use an endpoint for which you are authorized.
Rank #2
A safer script pattern for real applications
Do not place reusable credentials directly in source control. Read them from a secret manager or environment variables, restrict the credential scope where possible, and fail clearly on an unsuccessful status:
import os
import sys
import httplib2
url = os.environ.get("PROTECTED_URL", "https://example.org/protected")
username = os.environ["HTTP_USERNAME"]
password = os.environ["HTTP_PASSWORD"]
http = httplib2.Http()
http.add_credentials(username, password)
try:
response, content = http.request(url, method="GET")
except Exception as exc:
print(f"Request failed: {exc}", file=sys.stderr)
raise
status = int(response.status)
if status == 401:
raise RuntimeError("The server rejected the HTTP credentials (401)")
if status == 403:
raise RuntimeError("Credentials were accepted or recognized, but access is forbidden (403)")
if status < 200 or status >= 300:
raise RuntimeError(f"Unexpected HTTP status: {status}")
with open("protected-response.bin", "wb") as output:
output.write(content)
print(f"Saved {len(content)} bytes from {url}")
Keeping the body as bytes avoids assuming that the server used UTF-8. Decode it only after determining the response’s declared media type and character encoding.
Scope credentials with the optional domain
add_credentials accepts an optional domain argument:
Free tools Windows power users keep installed
One-click scans. No signup required.
http.add_credentials("name", "password", "example.org")
Use the domain to limit where those credentials are applicable when your program talks to more than one host. The helper’s documented purpose is to provide HTTP-authentication credentials for a challenge; it is not a general authorization policy or a substitute for server-side permissions.
Match the server’s authentication mechanism
| Server requirement | httplib2 support documented | What to do |
|---|---|---|
| Basic authentication | Yes | Call add_credentials, use HTTPS, and let the server challenge the client. |
| Digest authentication | Yes | Use the same client-and-credential setup, then verify the server’s challenge and required permissions. |
| WSSE authentication | Yes | Use the documented httplib2 mechanism and confirm the endpoint’s exact WSSE requirements. |
| Client TLS certificate | Separate helper documented | Use add_certificate(key, cert, domain) as appropriate; this is certificate-based TLS client authentication, not a username/password challenge. |
The official httplib2 overview documents both add_credentials and the separate add_certificate helper. Do not pass a client certificate where the server expects Basic, Digest, or WSSE credentials, or assume that a username/password will satisfy mutual TLS.
Use HTTPS when sending credentials
The official example combines Basic authentication with an HTTPS URL. Use HTTPS for any request carrying credentials and verify your deployment’s certificate-validation and CA requirements against the current httplib2 and Python documentation. The available project material does not establish a universal current certificate-validation default, so do not disable verification as a troubleshooting shortcut.
HTTPS protects the connection in transit; it does not grant permission to the resource. Keep credentials out of logs, exception messages, shell history, and URLs. A URL such as https://user:[email protected]/ can leak through proxies and logs and should not be used as a secret-management strategy.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What this pattern does not cover
HTML form sign-in
A page with a username form usually requires a POST, hidden fields, cookies, redirects, and sometimes a CSRF token. add_credentials addresses HTTP authentication challenges, not that browser session workflow.
OAuth authorization
OAuth commonly involves obtaining and refreshing a token, then sending an authorization header. Follow the service’s OAuth documentation rather than assuming that Basic credentials can replace the token flow.
CAPTCHAs and bot controls
A CAPTCHA or bot-check page is an access-control mechanism, not a Basic, Digest, or WSSE challenge. Do not use httplib2 to bypass it; obtain authorized API access or use the service’s supported integration.
Cookies and an existing browser session
Adding credentials does not automatically import your browser’s cookies or logged-in state. If the endpoint requires a session cookie, implement the service’s documented session flow and handle cookies explicitly.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesEquivalent requests for interoperability checks
These examples are useful when comparing a server’s behavior outside Python. They send Basic credentials directly and are not httplib2 code.
Best Value
cURL
curl --fail --user "$HTTP_USERNAME:$HTTP_PASSWORD"
"https://example.org/protected"
Node.js
const user = process.env.HTTP_USERNAME;
const pass = process.env.HTTP_PASSWORD;
const token = Buffer.from(`${user}:${pass}`).toString('base64');
const response = await fetch('https://example.org/protected', {
headers: { Authorization: `Basic ${token}` }
});
if (!response.ok) {
throw new Error(`HTTP ${response.status}`);
}
const body = await response.arrayBuffer();
console.log(`Received ${body.byteLength} bytes`);
A server that requires Digest or WSSE will not accept these Basic-only examples. Inspect the server’s WWW-Authenticate challenge and use the matching client support.
Troubleshooting common failures
| Symptom | Likely cause | Fix |
|---|---|---|
401 Unauthorized after adding credentials |
Wrong username/password, wrong scheme, wrong realm, or credentials not valid for that host. | Inspect the response’s WWW-Authenticate header, confirm the account’s permission, and use the matching Basic, Digest, or WSSE setup. |
403 Forbidden |
The server recognized the request but the account is not authorized for the resource. | Ask the service administrator for the required permission; changing the password will not grant a missing authorization. |
| Credentials work on one host but not another | Credentials are scoped to a host, realm, or configured domain. | Use the correct URL and, where appropriate, pass the optional domain to add_credentials. |
| A form-login page is returned instead of the resource | The endpoint expects a browser session or application login, not HTTP authentication. | Use the provider’s documented session, API-key, or OAuth flow. |
| TLS or certificate error | Certificate-chain, hostname, CA, or deployment configuration problem. | Fix the trust configuration and hostname; do not turn off certificate verification merely to make the request pass. |
| The response is an HTML bot check or CAPTCHA | The service is challenging the client with a bot-control page. | Use an authorized API or approved integration. httplib2 credentials do not solve a CAPTCHA. |
| Unexpected redirect | The protected URL redirects to another host, login route, or scheme. | Record the final URL and status, verify that the redirect is expected, and do not forward credentials to an unrelated host. |
Reliability, caching, and request design
- Reuse an
httplib2.Httpinstance when making multiple requests so its connection-management behavior can work across the sequence. - Choose the method explicitly. The documented client supports arbitrary HTTP methods; a GET is appropriate for retrieval, while PUT, POST, or another method must follow the endpoint’s contract.
- Set an application-level timeout and retry policy appropriate to the operation. Retrying a read may be safe in some systems; retrying a non-idempotent write can create duplicate side effects.
- Decide whether caching is acceptable for the resource. httplib2 supports caching, but protected or rapidly changing data may require cache controls that match your confidentiality and freshness requirements.
- Log status, host, and timing for diagnosis, but redact authorization headers, passwords, cookies, and sensitive response bodies.
Neither the documentation cited here nor the package metadata establishes a universal performance benchmark or uptime guarantee. Measure your own endpoint under its real network and authentication conditions.
Or skip the browser setup
If your actual goal is a visual screenshot or PDF of a page you are authorized to capture, ScreenshotNeo provides a single HTTP request instead of maintaining a browser automation stack. It is a screenshot API and MCP server for developers; it is not a way to bypass a site’s authentication or access controls. For a page that needs authorization, use its supported custom headers or cookies and the site’s permission model.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →For a public example, the documented call is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo documentation for options such as full-page capture, CSS-selector element capture, custom headers and cookies, waits, JavaScript, PDF output, signed links, asynchronous jobs, bulk capture, and caching. Before capture it accepts the cookie/consent banner like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and each response identifies the page verdict and billing result in headers.
ScreenshotNeo also offers an MCP server with take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 shots per month without a card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account to try it.
Checklist before shipping
- Confirm the endpoint actually uses HTTP authentication rather than a form, OAuth, cookie, or bot-control flow.
- Use an HTTPS URL and keep credentials outside source control.
- Create one
httplib2.Http, calladd_credentials, and then callrequestwith the intended method. - Scope credentials with the optional domain when your application contacts multiple hosts.
- Handle 401, 403, redirects, TLS failures, and non-success statuses explicitly.
- Keep response data as bytes until its encoding is known, and redact secrets from logs.
Frequently Asked Questions
Can the same httplib2 client be used for more than one protected request?
Yes. Keep the configured Http instance and issue additional requests, while ensuring that each destination and credential scope is authorized.
When should I use add_certificate instead of add_credentials?
Use add_certificate only when the server requires a client TLS certificate. Use add_credentials for the HTTP authentication schemes documented by httplib2.
Where can I verify the package’s current release requirements?
Check the live httplib2 PyPI metadata; the listing cited here recorded version 0.32.0 and Python 3.8 or newer on June 26, 2026.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

