Short answer: wkhtmltopdf documents --username and --password as HTTP Authentication options. The documentation does not establish that they enable Windows integrated authentication, use the logged-in Windows identity, or negotiate NTLM/Negotiate with every IIS deployment. Before changing flags, determine whether your server is returning an HTTP challenge, an application login page, or content that depends on an existing session.
What wkhtmltopdf actually documents
The upstream wkhtmltopdf usage documentation labels the options exactly as follows:
--username <username>— “HTTP Authentication username”--password <password>— “HTTP Authentication password”
Those labels describe credentials supplied for HTTP authentication. They do not promise Windows integrated authentication, delegation of the current Windows account, or compatibility with a particular IIS authentication provider. Do not treat a domain-qualified username format or a special command-line switch as a verified Windows SSO recipe.
A successful conversion therefore depends on the authentication layer used by the URL and on the exact wkhtmltopdf build, Windows environment, and server path. There is no documented, universal command that works across all Windows Authentication deployments.
Recommended Free Tools
#1 Best Overall
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
Identify the authentication layer first
Use the response from the same URL and network path that wkhtmltopdf will use. The three cases below look similar to a person but require different handling.
| What protects the page | What you may observe | Where identity is established | What the wkhtmltopdf documentation establishes |
|---|---|---|---|
| HTTP authentication challenge | A response such as HTTP 401 with a WWW-Authenticate challenge |
In the client request and HTTP exchange | --username and --password are documented for HTTP Authentication |
| Windows integrated authentication | An IIS or other host challenge using Windows authentication schemes, often through a proxy or load balancer | Windows/IIS infrastructure and the negotiated request | No source confirms a generally supported NTLM or Negotiate recipe for wkhtmltopdf |
| Application login and session | An HTML sign-in form, a redirect to login, or a page that requires a session cookie | The application creates a session after a login flow | The two HTTP credential flags do not document how to perform that application flow |
A page can also combine these layers. For example, a reverse proxy may authenticate the request while the application still requires its own session. Classify the first response and the final HTML rather than assuming that a visible login screen means HTTP Authentication.
A repeatable diagnostic procedure
- Freeze the test conditions. Record the complete URL, DNS name, port, proxy or load-balancer route, wkhtmltopdf version, Windows build, and the account that starts the conversion. Run the test from the same machine or network segment used in production.
- Inspect an unauthenticated response. A header-only request can show whether the endpoint immediately challenges the client:
curl -I https://intranet.example.test/reportThis command is only a diagnostic. It does not prove that wkhtmltopdf can negotiate the server’s scheme.
Rank #2
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
- 4GB DDR4 System Memory; 128GB Solid State Drive
- 11.6" HD (1366 x 768) Multi-Touch Display
- Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
- Windows 11 Pro
- Look at the response body and redirects. A 401 challenge points to an HTTP authentication exchange. A 200 response containing a sign-in form, or a redirect to
/login, points to an application session. A 200 response with a shell page that later fails may indicate scripts or resources making additional authenticated requests. - Test the documented options in isolation. For an endpoint that genuinely uses HTTP Authentication, the basic form is:
wkhtmltopdf --username "USER" --password "PASSWORD" "https://intranet.example.test/report" report.pdf
Use a test account with the minimum permissions needed to read the page. A successful PDF shows that this particular endpoint, account, build, and path accepted the exchange; it does not prove Windows SSO support in general.
- Check the generated PDF itself. An apparently successful process can still produce a PDF containing the login page, a redirect message, or an empty document. Compare the rendered text or page image with the authenticated page in a normal browser.
- Verify the server configuration separately. Microsoft’s ASP.NET Core 10.0 guidance covers configuring Windows Authentication in IIS and other hosting arrangements. It also explains that a proxy or load balancer must either handle authentication or pass the authentication information to the application. Those instructions configure the server side; they are not wkhtmltopdf client instructions.
- Retest without changing several variables. If you change the wkhtmltopdf version, proxy, authentication provider, and URL at once, you cannot identify the cause. Keep a small test matrix and change one item per run.
Using --username and --password safely
These options are appropriate to try when the server presents an HTTP Authentication challenge. They are not a substitute for an application login sequence or a guarantee of integrated Windows credentials.
- Quote the URL and values so shell metacharacters are not interpreted by the command processor.
- Do not assume that
DOMAIN\user,user@domain, or the currently logged-in Windows account will be accepted. The available documentation does not validate any of those forms for Windows integrated authentication. - Keep credentials out of shared batch files and build logs. Use the narrowest account and permissions your server allows, and rotate test credentials after troubleshooting.
- If the endpoint redirects between host names, verify authentication on the final host as well. A credential accepted by one host does not establish an application session on another host.
If the command returns a login page or an empty PDF, stop adding flags at random. Return to the response classification: the failure may be a Windows challenge that this build cannot negotiate, or an application session that was never created.
Rank #3
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
Why an application login behaves differently
A web application can display a login form even when the browser itself is running under a Windows account. After the form is submitted, the application may issue a session cookie, anti-forgery token, or another state value. A renderer that only supplies HTTP username and password fields has no documented way, from these options alone, to reproduce that multi-step exchange.
One reported case describes credentials held in a session while the generated result still contained the logon page. That report is evidence of an environment-specific failure, not a confirmed universal diagnosis or workaround. Treat session-based sites as a separate integration project: identify the login endpoint, the session state required by the application, and whether your security policy permits an automated rendering account.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Windows Authentication, IIS, and intermediaries
Windows Authentication is a server and hosting configuration as well as a client interaction. IIS settings, ASP.NET Core hosting, reverse proxies, and load balancers can each affect which challenge reaches the renderer. Microsoft’s guidance says that an intermediary must authenticate the request itself or pass authentication information to the application. A browser succeeding on a user’s desktop therefore does not establish that a headless renderer can use the same identity path.
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Ask the server administrator to identify the scheme actually enabled at the endpoint and at every intermediary. Capture whether the first response is a challenge, which host issued it, and whether the final request reached the application. Do not label the setup “NTLM-compatible” or “Negotiate-compatible” solely because a browser works.
Version changes and the historical 0.11/0.12 report
A historical issue opened on April 14, 2015 reports that an IIS Windows Authentication site worked with wkhtmltopdf 0.11 but produced an empty PDF after a move to 0.12. The issue is marked Invalid, so it does not establish a general regression, a supported fix, or behavior for current builds. The repository archive notice on the issue page is dated January 2, 2023.
If your failure follows a version change, record both versions, the Windows build, the server’s authentication scheme, the HTTP response, and whether the output is empty or contains a login page. Reproduce with a minimal URL before attributing the result to a version-wide incompatibility.
Best Value
- WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
- 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
- 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
- CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
- LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.
Troubleshooting by symptom
| Symptom | Likely layer to investigate | Next action |
|---|---|---|
| The command receives HTTP 401 | HTTP challenge or Windows challenge | Inspect the challenge and server path. Try the documented credentials only if the endpoint is using HTTP Authentication; do not assume they negotiate Windows SSO. |
| The PDF contains the sign-in form | Application session or redirect | Confirm the final URL and response body. The username/password flags do not document an application login flow. |
| The PDF is empty | Authentication failure, renderer/version interaction, or page-side failure | Compare versions, capture the HTTP result, test a minimal page, and check whether the server returned content at all. |
| A browser works but wkhtmltopdf does not | Different client capabilities or network path | Run both from the same host, identify the server’s challenge, and verify proxy/load-balancer handling. Browser success alone is not a compatibility test. |
| Credentials appear correct but access is still denied | Wrong authentication layer or account permissions | Confirm whether the site expects a session, whether the account can open the exact URL, and whether the final host differs after redirects. |
| Failure begins after an upgrade | Build-specific behavior | Keep the old and new versions available for a controlled comparison. Report exact versions and output symptoms rather than inferring a universal regression. |
What a support-quality test record contains
- Exact wkhtmltopdf version and architecture.
- Windows edition/build and the account context running the process.
- Target URL, redirects, proxy or load-balancer route, and DNS result.
- HTTP status, challenge or login-page evidence, and whether the PDF is empty, authenticated, or a sign-in page.
- Server authentication scheme and the relevant IIS or ASP.NET Core hosting arrangement.
- Whether the behavior changes between wkhtmltopdf 0.11, 0.12, or another specifically identified build.
This information separates a client-option question from a server configuration or application-session problem without exposing passwords.
Or skip the browser setup:
If your real requirement is a clean screenshot or PDF and you can represent access with request headers, cookies, or an authorization value, ScreenshotNeo provides a single HTTP call. It supports custom headers, cookies, and Authorization, but the supplied product information does not claim NTLM or Negotiate support; verify that your protected endpoint accepts the credentials you can send.
Before capture, ScreenshotNeo can accept cookie/consent banners and remove more than 60 known consent platforms, newsletter popups, and chat widgets. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and the response identifies the result with X-Page-Verdict and X-Billed headers. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients.
See the ScreenshotNeo documentation for request options. The following calls use the documented endpoint; replace the example URL only after confirming that your authentication method can be sent as headers, cookies, or an authorization value.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' }); const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo includes full-page capture, CSS-selector element capture, device presets, arbitrary viewports, retina scale, PDF paper and page-range controls, custom CSS and JavaScript, click and wait actions, request blocking, geolocation and timezone settings, transparent backgrounds, resizing, selectable cache TTLs, signed links, asynchronous jobs with signed webhooks, bulk capture for up to 100 URLs per call, a usage API, and an OpenAPI specification. Every feature is included on every plan.
| Plan | Included shots | Price |
|---|---|---|
| Free | 1,000 per month | No card required |
| Starter | 3,000 | $5 |
| Growth | 15,000 | $15 |
| Pro | 60,000 | $39 |
| Scale | 250,000 | $99 |
| Business | 1,000,000 | $249 |
Yearly billing gives two months free. You can start with 1,000 screenshots a month at no charge and no card by creating a ScreenshotNeo account.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




