Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Install the operating system’s xauth package in the same environment that runs xvfb-run, then make sure that environment can find the executable on its PATH. The wrapper checks for xauth before it starts Xvfb or launches wkhtmltopdf. If the lookup fails, it prints xvfb-run: error: xauth command not found and exits with status 3.

A successful check in your administrator shell is not enough when the command is launched by PHP-FPM, a systemd service, a container, a queue worker, or another application account. Diagnose and fix that invoking runtime, not just your interactive terminal.

What the error means

xvfb-run is a wrapper that starts a virtual X display and then runs a graphical command such as wkhtmltopdf inside it. To protect that display, the wrapper uses the xauth executable to create and remove X-authority entries.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Its first prerequisite check is effectively an executable lookup. When no usable xauth is found, the wrapper stops before Xvfb starts and before wkhtmltopdf reads your HTML or writes a PDF. Therefore, changing wkhtmltopdf options, the input URL, or the output filename cannot fix this particular message.

#1 Best Overall
Lenovo IdeaPad Slim 3 Linux Laptop, 15.6" FHD Touchscreen Laptop, 8-Core AMD Ryzen 7 5825U, 16GB RAM, 512GB SSD, Keypad, SD Card Reader, Stylus Pen + External Portable SSD + USB Hub, Linux Ubuntu OS
  • Powerful Linux Laptop: This IdeaPad Slim 3 Laptop comes pre-installed with Ubuntu Linux, offering fast performance, robust security, and a clean, user-friendly experience. Enjoy full customization, seamless hardware compatibility, and access to thousands of open-source apps. Whether you're working, creating, or coding, it's built to keep up with everything you do.
  • A Multitasking Master: The latest AMD Ryzen 7 5825U processor (up to 4.5 GHz) delivers powerful performance with 8 cores and 16 threads for smooth multitasking. Integrated AMD Radeon Graphics provide crisp visuals for streaming, browsing, photo editing, and casual gaming. With smart machine intelligence, it adapts to your needs for a fast, responsive experience.
  • 15.6" Full HD Display: The IdeaPad Slim 3 boasts an 88% screen-to-body ratio for a floating, edge-to-edge visual experience. TÜV Low Blue Light certification reduces eye strain, making it perfect for long work or study sessions.
  • Military-Grade Durability: The smart IdeaPad Slim 3 combines portability and durability, letting you work, study, and play on the go. With a profile 10% slimmer than the previous generation, it's lightweight yet military-grade rugged, ready for anything, anywhere.
  • Versatile Connectivity: Enjoy the security of a built-in webcam with a privacy shutter. Connect effortlessly with multiple ports: 2x USB A, 1x USB C, 1x HDMI, 1x SD Card Reader, 1x Headphone/Microphone combo. Bundle comes with Stylus Pen, 256GB Portable SSD and 5-in-1 Docking Station.
  • Missing executable: the package containing xauth is not installed in the runtime environment.
  • Inaccessible executable: xauth exists somewhere, but the user or service invoking xvfb-run has a different PATH, filesystem view, container image, or permission set.

The maintained Flatpak BaseApp implementation also lists both Xvfb and xauth as build dependencies and performs the same kind of check, so this is a wrapper prerequisite rather than a PDF-content error.

Fix it in the runtime that launches xvfb-run

  1. Check whether the invoking process can locate xauth

    Run this as the same user and inside the same container, service, worker, or application context that launches the command:

    command -v xauth
    xauth -V

    If command -v prints a path and xauth -V runs, the executable is visible to that context. If the first command prints nothing or returns a nonzero status, continue with installation or environment diagnosis.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Install the distribution package

    Install the package named xauth using your operating system’s package manager. Package names and commands vary by distribution and image, so confirm the correct command in that distribution’s documentation rather than applying one command universally. For example, Debian- or Ubuntu-based images commonly provide an xauth package through APT; Fedora- or RHEL-family images commonly provide one through DNF; Alpine images use APK. The important result is that an xauth executable is installed in the image or host where the command actually runs.

    After installation, repeat:

    command -v xauth
    xauth -V

    Do not install it only on your laptop if wkhtmltopdf runs on a server or in a rebuilt container. Add the package to the image or provisioning configuration so a new deployment does not lose it.

    Rank #2
    HP 17 Business Laptop - Linux Mint Cinnamon - Intel Quad-Core i5-10210U, 32GB RAM, 1TB PCIe NVMe SSD + 1TB Storage HDD, 17.3" Inch HD+ (1600x900) Display
    • Intel Core i5-10210U (up to 4.2GHz) - 1TB PCIe NVMe + 1TB HDD - 32GB DDR4 SDRAM
    • 17.3" HD+ (1600x900) Display, Intel UHD Graphics 620
    • Built in HD 720p Webcam with Microphone - Bluetooth Version4.2
    • I/O Ports: 2x USB 3.1 (Data Only), 1x USB 2.0, 1x HDMI, 1x Headphone/Microphone Combo Jack
    • Linux Mint Cinnamon 64-Bit - 6-Row Keyboard w/ Full Numberpad
  3. Compare the service environment with your shell

    If your terminal finds xauth but the application still reports the error, print the effective environment from the failing process. Compare the user identity and PATH:

    id
    printf '%sn' "$PATH"
    command -v xvfb-run
    command -v xauth

    A PHP-FPM worker, for example, may clear or replace environment variables that are present in an interactive login shell. The exact configuration differs by distribution and deployment, but the diagnostic is consistent: inspect the worker’s effective PATH, user, container, and service settings, then make the directory containing xauth available to that process.

    Free tools Windows power users keep installed

    One-click scans. No signup required.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  4. Retry the original command

    Once the same runtime can execute xauth, retry your xvfb-run wkhtmltopdf ... command. Passing the xauth check only removes this prerequisite failure; it does not guarantee that Xvfb can start, that the display is usable, or that wkhtmltopdf can load the document.

Useful verification commands

These checks distinguish an absent package from a service-environment problem:

# Locate both wrapper and authorization utility
command -v xvfb-run
command -v xauth

# Show the resolved files and permissions
ls -l "$(command -v xvfb-run)" "$(command -v xauth)"

# Show the service account when testing as that account
id
printf 'PATH=%sn' "$PATH"

# Confirm the wrapper itself can be invoked
xvfb-run --help

If command -v xauth succeeds but xvfb-run still says it is missing, check for a different xvfb-run being selected, a restricted service environment, or a container boundary. Use absolute paths temporarily to isolate lookup issues:

Rank #3
Lenovo Business Laptop - Linux Mint (Cinnamon) - Intel i5-1335U, 16GB RAM, 256GB SSD, 15.6" FHD 1920x1080 Display, Full Keyboard, Fast Charging
  • Intel Core i5-1335U Processor (12M Cache, 12 Threads, up to 4.6 GHz) - 256GB Solid State Drive - 16GB DDR4 SDRAM
  • 15.6" FHD (1920x1080) Non-Touch Anti-Glare Display - Intel UHD 620 Integrated Graphics - Stereo Speakers
  • 720p HD Webcam with Privacy Shutter. Integrated Microphone - Intel Dual Band Wireless-AC (2x2) 8265, Bluetooth Version 4.2
  • I/O Ports: 2x USB 3.0, 1x USB 3.1 Type-C 3.1, Headphone/Mic Combo Port, 4-in-1 Card Reader, HDMI, Kensington Mini-Lock Slot
  • Linux Mint (Cinnamon) 64-Bit - Keyboard with Full NumberPad - Fast Charging
/usr/bin/xauth -V
/usr/bin/xvfb-run --help

The paths above are examples; use the paths printed by your own command -v commands.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common environments and failure modes

Interactive shell works, PHP-FPM fails

This is the classic discrepancy: an administrator’s shell has a login PATH, while PHP-FPM starts with a deliberately minimal environment. Check the PHP-FPM pool and service configuration for environment clearing or an explicit PATH, then restart the worker after changing configuration. Verify from the worker context rather than assuming a shell test represents it. The reported PHP-FPM case is an anecdotal diagnostic example, not a universal configuration recipe.

Container build succeeds, runtime fails

The package may have been installed in a build stage but omitted from the final image. Run command -v xauth inside the running container, not on the host or in an intermediate stage. Add the package installation to the final image and redeploy. Also check that the command is not being executed in a sidecar or separate container with a different filesystem.

Root finds xauth, an application user does not

Root’s environment and filesystem permissions can differ from those of the service account. Test with the service account, preserve only the minimum required permissions, and ensure the directory containing xauth is readable and executable by that account. Avoid “fixing” the issue by running the whole renderer as root unless your deployment’s security model explicitly requires it.

A symlink or custom installation is invisible

If xauth was installed in a nonstandard directory, add that directory to the invoking process’s PATH or configure the service to use the absolute executable path where supported. Confirm that the target file exists in the same mount namespace and that its interpreter and shared libraries are available.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The error changes after the fix

A new message is progress: the wrapper has passed its initial xauth lookup and reached another stage. Examples include an inability to start Xvfb, display authorization errors, missing fonts, network failures, or wkhtmltopdf rendering problems. Capture the new message separately and troubleshoot that component; do not continue treating it as an xauth installation error.

Automate the preflight check

For deployment scripts, fail early with a useful message instead of waiting for a user request to expose the missing dependency:

#!/bin/sh
set -eu

if ! command -v xauth >/dev/null 2>&1; then
  echo "xauth is required by xvfb-run but is not on PATH" >&2
  exit 3
fi

if ! command -v xvfb-run >/dev/null 2>&1; then
  echo "xvfb-run is not installed or is not on PATH" >&2
  exit 3
fi

exec xvfb-run wkhtmltopdf "$@"

This check confirms discoverability, not successful PDF rendering. Keep separate logging for the wrapper, Xvfb, and wkhtmltopdf so a later failure is identifiable.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When you do not need wkhtmltopdf’s browser setup

If your actual requirement is a clean image or PDF of a public webpage rather than a local wkhtmltopdf pipeline, ScreenshotNeo can provide the capture through one HTTP request. It avoids maintaining Xvfb, wkhtmltopdf, and xauth in your runtime.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup:

ScreenshotNeo accepts cookie and consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each cleanup step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed as clean shots, and the response identifies the result with X-Page-Verdict and X-Billed headers. It also provides an MCP server with take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.

See the complete parameter reference in the ScreenshotNeo documentation. This cURL request returns a WebP capture:

Best Value
GMKtec G3S Mini PC Intel N95 Processor (Up to 3.4GHz) 8GB RAM 256GB M.2 SSD
  • 12th Intel Alder Lake N95 Processor – The GMKtec G3 S Mini PC is powered by the 12th Gen Intel N95 processor with 4 cores, 4 threads, 6MB cache and a burst frequency up to 3.4GHz. Compared with N100/N5105/N5100/N5095, the N95 delivers up to 36% overall performance improvement. Perfect for routine tasks, office work, and home entertainment, this compact mini desktop is more convenient than traditional bulky PCs.
  • 8GB RAM & 256GB SSD Storage – Pre-installed with 8GB DDR4 memory and a fast 256GB M.2 2242 SSD, the G3 S mini desktop offers quicker startup, smoother multitasking, and faster file transfers. Enjoy seamless performance whether you’re working on multiple applications, browsing, or streaming content.
  • Rich Interfaces & Connectivity – The G3 S mini computer comes equipped with USB 3.2 (up to 10Gbps), dual HDMI 2.0 (4K@60Hz), and a 3.5mm audio jack. With support for WiFi 5, Bluetooth 5.0, and Gigabit Ethernet (RJ45 1000MbE), it connects easily with monitors, projectors, printers, office equipment, and other peripherals, making it versatile for both home and business use.
  • Dual 4K Display Support – Featuring upgraded Intel UHD Graphics (up to 1000MHz), the G3 S supports 4K video playback and AV1 decoding for a smooth viewing experience. With dual HDMI outputs, you can connect two 4K@60Hz displays simultaneously, enabling efficient multitasking for work and entertainment.
  • GMKtec WARRANTY - GMKtec offers a 1-year limited GMKtec's warranty for each mini PC, starting from the date of the purchase. All defects due to design and workmanship are covered. With a professional after sales team always ready to attend to your needs, you can simply relax and enjoy your mini PC.
curl -G "https://api.screenshotneo.com/v1/shot" 
  -d access_key=YOUR_API_KEY 
  --data-urlencode url=https://stripe.com 
  -o shot.webp

The equivalent Python request is:

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)

And Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot failed: ${res.status}`);

ScreenshotNeo includes full-page and lazy-image capture, CSS-selector element capture, dark mode, device presets and custom viewports, retina scale, PDF paper and margin controls, custom CSS and JavaScript, clicks, selector or network-idle waits, request and resource blocking, headers, cookies, user agents, authorization, timezone and geolocation, transparent backgrounds, resizing, configurable caching, signed links, asynchronous webhooks, bulk capture for up to 100 URLs per call, a usage API, and an OpenAPI specification. Parameters used by other screenshot APIs are accepted to make migration easier.

Pricing starts with 1,000 screenshots per month free without a card. Paid plans are Starter $5 for 3,000, Growth $15 for 15,000, Pro $39 for 60,000, Scale $99 for 250,000, and Business $249 for 1,000,000; yearly billing provides two months free, and every feature is included on every plan. Sign up for the free plan to try it without a card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Checklist before you close the incident

  • Run command -v xauth as the actual invoking user.
  • Install the distribution’s xauth package in the host, final container image, or runtime where wkhtmltopdf executes.
  • Verify the service’s effective PATH, user, mounts, and container boundary.
  • Confirm both xauth -V and xvfb-run --help work in that context.
  • Retry and classify any subsequent Xvfb or wkhtmltopdf error independently.
  • Persist the dependency in provisioning or image configuration so redeployments remain reproducible.

Frequently Asked Questions

Does wkhtmltopdf itself provide xauth?

No. xauth is an operating-system utility used by the xvfb-run wrapper to manage X display authorization; it is not a wkhtmltopdf input or rendering option.

Why does xvfb-run exit with status 3?

The wrapper uses status 3 for its missing-xauth prerequisite error. Once xauth is available, later failures can have different exit statuses and causes.

Should I reinstall wkhtmltopdf first?

Not for this message. First prove that the invoking runtime can locate xauth. Reinstall or reconfigure wkhtmltopdf only if a separate error remains after the wrapper passes its prerequisite check.

Can I solve this only by exporting PATH in my terminal?

Only if the same terminal launches the command. Services and workers often have independent environments, so their own effective PATH must include the directory containing xauth.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.