Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

html2canvas does not photograph the browser window. It reads the DOM and CSS that page scripts are allowed to access, then reconstructs that content on a canvas. A CAPTCHA image hosted on another origin, or inside a cross-origin iframe, is outside that access boundary. The browser therefore omits it or taints the canvas, and html2canvas cannot override the restriction.

The fix depends on what you control: authorize cross-origin image use with CORS, serve the image through an authorized same-origin proxy, use the CAPTCHA provider’s approved integration, or take a browser-level screenshot when you need the visible tab rather than readable canvas pixels.

What html2canvas is (and is not) capturing

When you call html2canvas(element), the library walks the element’s DOM subtree, evaluates styles and paints a new canvas. It does not receive the browser compositor’s final bitmap. Pixels that page JavaScript cannot read are not automatically available to the reconstructed image.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The html2canvas FAQ states that “html2canvas cannot circumvent content policy restrictions set by your browser.” That is the key to the CAPTCHA problem: the restriction is enforced by the browser’s same-origin policy, not by a missing html2canvas option.

#1 Best Overall
Guermok Video Capture Card, 4K USB3.0 HDMI to USB C, 1080P 60FPS & 2K 30FPS
  • 【1080P 60FPS Video Capture Card】 This HDMI game capture card is based on USB3.0 high speed transmission port, input resolution up to 4K@30HZ, output resolution up to 2K@30Hz or 1920×1080@60Hz. Type c and USB interface can meet most of the devices in daily life. Easily meet the online capture, real-time recording, online meetings, live gaming and other functions, so you have a better visual enjoyment. Note: For capture use only; requires capture software to function and is not intended for direct screen casting to a monitor or TV
  • 【Ultra Low Latency Screen Sharing】 HDMI capture card is made of good quality aluminum alloy with strong heat dissipation, allowing you to enjoy ultra low latency while live gaming or video recording or live streaming, avoiding blue screens and lag. This HDMI to USBC capture card supports easy recording of good quality audio or HD video and transferring it to your computer or streaming platform, allowing you to record 60 fps HD video directly on your hard drive and real-time preview
  • 【Plug and Play, Easy to Carry】 This HDMI 1080P video capture card does not require any additional drivers or external power supply, just plug and play for fast capture. The capture card is small and lightweight, so you can put it in your bag for emergencies, making it very portable for outdoor live streaming. It's also a great way to share content in game recording, video conference, video recorder and online teaching
  • 【Wide Compatibility USB Capture Card】 Easily streams to Facebook, Youtube or Twitch. With the connection, this HDMI to USB C/3.0 video capture devices can be working on several Operating Systems and various software: Windows 7/ 8/ 10, Mac OS or above, Linux, Android, Laptop, Xbox One, PS3/PS4/PS5, Camera, DVDs, Set Top Box, Webcame, DSLR, Switch/Switch 2, TV BOX, HDTV, Potplayer/VLC, ZOOM, OBS Studio etc.
  • 【Package Content & Note】 1x HD Audio Capture Card , 1x USB 3.0 to USB C Adapter (A-side 3.0, B-side 2.0), 1x user manual. Please note that you need to restart the OBS Studio software after the audio setup is complete, otherwise it will result in no sound output. When using an adapter, if the device is recognized as USB 2.0, try using the other side with the USB-C port. Simply flip the capture card and reconnect it to be recognized as USB 3.0

Why a CAPTCHA is commonly cross-origin

Challenge providers usually deliver their image, script, or iframe from a separate origin. For example, your form may be on app.example while the challenge is loaded from captcha-provider.example. If that image is drawn into a canvas without permission from its server, the canvas becomes tainted. A tainted canvas cannot be read or exported by page code.

Rendering on the page versus exporting pixels

A browser may display a cross-origin image normally. Display permission and pixel-read permission are different. You can see the image in an <img> element, yet canvas.toDataURL(), canvas.toBlob(), or direct pixel reads can fail with a SecurityError. html2canvas skips resources that would make its output unusable when its default protection is active.

Diagnose the exact failure

  1. Compare origins. Check the page URL and the CAPTCHA image or iframe URL, including scheme, host and port. A difference in any of those makes it cross-origin.
  2. Inspect the image response. In browser developer tools, open Network, select the image request and look for an Access-Control-Allow-Origin response header that authorizes your page’s origin.
  3. Check the frame boundary. If the challenge is inside an iframe, inspect the iframe URL. A cross-origin frame’s contentDocument is inaccessible even when an image option is configured correctly.
  4. Identify the operation that fails. A screenshot that appears on screen is not proof that exported canvas pixels are readable. Look for errors from toDataURL, toBlob, getImageData, or your upload code.

What the html2canvas options can and cannot do

useCORS: true requests permission; it does not grant it

By default, html2canvas has useCORS: false. Setting it to true tells the browser to request images in CORS mode. The image server must still return a matching Access-Control-Allow-Origin header. If the server does not opt in, the request remains unusable for a readable canvas.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
html2canvas(document.querySelector('#form'), {
  useCORS: true,
  backgroundColor: '#fff'
}).then(canvas => {
  canvas.toBlob(blob => {
    if (!blob) throw new Error('Canvas could not be exported');
    // upload or download the blob here
  }, 'image/png');
});

The image itself also needs to be loaded with the appropriate crossorigin behavior when you create it manually. Both the request mode and the server response must agree; changing only JavaScript is insufficient.

allowTaint: true is not a bypass

allowTaint defaults to false, which causes html2canvas to avoid images that would taint the canvas. Setting allowTaint: true permits the image to be painted, but it does not make the canvas readable. Export and pixel APIs remain blocked on a tainted canvas, so this setting is useful only when you need to display the canvas and will never read or export it.

Rank #2
Audio Express AXHDCAP 4K HDMI Video Capture Card, Cam Link Card Game Audio Adapter HDMI to USB 2.0 Record Capture Device for Streaming, Live Broadcasting, Video Conference, Teaching, Gaming
  • [Enhanced 4K-1080P Video Capture Experience] Capture the Magic: Elevate your video recordings to new heights with our upgraded anti-static 1080P Video Capture Card. Immerse yourself in stunning visuals, supporting HDMI input at 4K 60FPS and USB output for capturing in 1080P, complete with rich stereo sound. Enjoy crystal-clear video recordings, dynamic gaming live streams, and professional conference broadcasts. Note: HDMI resolution: Max input can be 3840×2160@30Hz / Video output resolution: Max output can be 1920×1080@30Hz
  • [Seamless Real-Time Preview] Stay in the Moment: Our advanced ultra-low latency technology ensures seamless real-time transmission of video streams. Experience instant, lag-free previews, allowing you to capture every detail precisely. Effortlessly record video directly to your hard disk, all without compromising on quality or introducing any delays.
  • [Versatility and Broad Compatibility] Your Creative Hub: Connect your DSLR, camcorder, or action camera to a wide range of operating systems, including Windows, MacOS, and Linux. Unlock a world of possibilities with real-time streaming to popular platforms like Twitch, Youtube, OBS, Zoom, Potplayer, and VLC, giving you the tools to share your content effortlessly.
  • [Effortless Plug and Play] Simplicity Redefined: Say goodbye to complex installations. Our plug-and-play design eliminates the need for drivers or external power supplies. Seamlessly integrate high-definition acquisition into various scenarios, whether it's educational recordings, immersive gaming, precise medical imaging, captivating live streams, or professional broadcasting.
  • [Seize Every Detail with Precision] Unleash your creativity and attention to detail with our video capture card. Capture every nuance, every color, and every moment with precision, thanks to the enhanced capabilities of our technology. Whether you're a content creator, a gamer, or a professional, our capture card empowers you to seize the finest elements and bring them to life in your recordings and live streams.
html2canvas(node, {
  allowTaint: true
}).then(canvas => {
  // The canvas may display the image, but toDataURL/toBlob can still throw.
});

Other configuration flags do not change origin policy

Options such as foreignObjectRendering, image timeouts, scaling and window dimensions can affect fidelity or timing, but none grants access to another origin. Increasing a timeout cannot repair a denied CORS request.

Remedy 1: configure CORS when you own the image service

If your team operates the CAPTCHA-like image endpoint, return a narrowly scoped authorization header for the application that embeds it:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Access-Control-Allow-Origin: https://app.example

Do not use a wildcard casually when credentials or sensitive responses are involved. Configure the server to answer the actual requesting origin, handle the required preflight behavior if applicable, and ensure caches vary correctly by origin. Then enable useCORS: true and verify the header on the real image response, not merely on an HTML page or an OPTIONS response.

After changing the server, clear a cached response, reload the page, and test a minimal canvas export. A visible image with no CORS header will continue to fail even though the page looks unchanged.

Remedy 2: use a controlled, authorized same-origin proxy

A server-side proxy can fetch the image with credentials available to your backend, then serve the result from the same origin as the page. This is a design for assets you are authorized to retrieve; it is not a general method for defeating a third-party CAPTCHA.

Rank #3
Video Capture Card, 4K USB3.0 HDMI to USB C, 1080P60FPS HDMI Capture Card for Streaming, Gaming, Video Recording Compatible with Switch, Xbox, PS4/5, OBS,iPad Mac OS Windows,Camera, Zoom(Silver)
  • 【4K HDMI Input, 2K@30Hz Recording】Powered by a true USB 3.0 high-speed interface, the capture card supports up to 4K@30Hz HDMI input and records at 2K@30Hz or 1080P@60Hz. Perfect for gamers, streamers, and professionals who need crisp, smooth video for live streaming, gameplay recording, or online meetings.
  • 【Ultra Low Latency Screen Sharing】Built with a premium aluminum alloy shell and advanced chipset for stable heat dissipation, ensuring ultra-low latency transmission. Capture high-quality video and dual-channel audio in real time—no lag, no frame drop—ideal for Twitch, YouTube, or OBS streaming.
  • 【Easy Plug and Play, Compact & Portable】No driver or external power required—just plug and play via USB 3.0 or Type-C connection to your Windows or macOS computer. Lightweight and compact design makes it easy to carry for outdoor streaming, live shows, or mobile recording setups.
  • 【Wide Compatibility & Multi-Device Support】Compatible with Windows 7 8 10 11, macOS, Linux,Android and supports most popular software such as OBS, Zoom, VLC, Twitch Studio, and more. Works seamlessly with PS4, PS5, Xbox, Switch, DSLR cameras, TV boxes, and other HDMI-output devices for streaming to YouTube, Twitch, etc.
  • 【What You Get】Includes: HDMI Capture Card, USB 3.0 to USB-C Adapter, User Manual. Tips: Make sure your tablet’s OTG function is enabled before connecting. Test your HDMI device with a monitor first to confirm video and audio output, then connect to the Video Capture Card for recording.
  1. Accept only an allow-listed image host or an internal asset identifier. Never turn the endpoint into an open URL fetcher.
  2. Fetch the resource on your server, enforce size and content-type limits, and apply your normal authentication and abuse controls.
  3. Return the image from your own origin with an appropriate cache policy.
  4. Point the page’s src at that endpoint and run html2canvas normally, or with useCORS: true if your own delivery path still uses CORS.

For a provider-managed CAPTCHA, ask for its documented server-side verification or an approved rendering path instead of proxying challenge assets without permission.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Remedy 3: handle a cross-origin iframe through the provider

html2canvas can render same-origin iframe content because the page can access that frame’s document. It cannot recursively read a cross-origin frame’s contentDocument. Image CORS settings do not remove this separate document boundary.

Use the provider’s supported integration, token-verification endpoint, or an explicitly supported screenshot mechanism. If the requirement is only to show the user what is on screen, keep the frame in the browser and avoid trying to extract its protected pixels into page JavaScript.

Remedy 4: take a native browser screenshot when you need the visible tab

A browser extension has a different capture primitive. The html2canvas FAQ points extension developers to chrome.tabs.captureVisibleTab() for Chrome, Edge and Opera, and browser.tabs.captureVisibleTab() for Firefox. These APIs capture the visible tab rather than reconstructing a DOM canvas and are not subject to html2canvas’s canvas-size limits.

A visible-tab screenshot is still not permission to inspect a protected frame’s DOM or extract challenge data. Follow the extension’s required permissions and the service’s rules. It also captures only what is visible; scroll a page or capture additional regions if your workflow needs content outside the viewport.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Capture Card, 4K HDMI Video Capture Card, Game Capture Card, 1080P 60FPS Video Capture Device, HDMI to USB 3.0 Capture Card for Streaming, Work with Camera/Xbox/PS4/PS5/PC/OBS
  • 【1080P HD High Quality】Capture resolution up to 1080p for video source and it is ideal for all HDMI devices such as PS4, PS3, Xbox One, Xbox 360, Wii U, DVDs, DSLR, Camera, Security Camera and set top box. Note: Video input supports 4K30/60Hz and 1080p120/144Hz. Does not support 4K120Hz/144Hz. Output supports up to 2K30Hz.
  • 【Plug and Play】No driver or external power supply required, true PnP. Once plugged in, the device is identified automatically as a webcam. Detect input and adjust output automatically. Won't occupy CPU, optional audio capture. No freeze with correct setting.
  • 【Compatible with Multiple Systems】suitable for Windows and Mac OS. High speed USB 3.0 technology and superior low latency technology makes it easier for you to transmit live streaming to Twitch, Youtube, Facebook, Twitter, OBS, Potplayer and VLC.
  • 【HDMI LOOP-OUT】Based on the high-speed USB 3.0 technology, it can capture one single channel HD HDMI video signal. There is no delay when you are playing game live.
  • 【Support Mic-in for Commentary】Rybozen capture card has microphone input and you can use it to add external commentary when playing a game. Please note: it only accepts 3.5mm TRS standard microphone headset.

Choosing the right approach

Requirement Best-fit approach Main limitation
Readable canvas pixels from an image you operate Server CORS plus useCORS: true The image server must authorize the requesting origin.
Same-origin delivery under your control Controlled backend proxy You must secure, restrict and operate the proxy.
Third-party CAPTCHA in an iframe Provider-approved integration or verification flow You cannot read a cross-origin frame document with html2canvas.
Exact pixels visible in an extension tab Native tab screenshot API Requires extension permissions and captures the visible tab, not DOM data.
Routine website screenshots or PDFs without browser setup ScreenshotNeo It is a screenshot service, not a way to defeat CAPTCHA protections.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

For ordinary website captures, ScreenshotNeo provides a single HTTP request and can return PNG, JPEG, WebP or PDF. Before capture it accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are identified in the response and are not billed as clean shots. That does not make a protected CAPTCHA readable or authorize bypassing it.

The service also offers an MCP server for Claude, Cursor and other MCP clients, with take_screenshot, get_page_info and capture_pdf tools. Available controls include full-page capture with lazy-image loading, CSS-selector element capture, dark mode, 12 device presets plus custom viewports, retina scale, PDF paper size/margins/orientation/page ranges, custom HTML/CSS and JavaScript, pre-capture clicks, hidden selectors, waits for selectors/delays/network idle, ad/tracker/request/resource blocking, custom headers/cookies/user agents/Authorization, timezone and geolocation, transparent backgrounds, image resizing, configurable-TTL caching, signed links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, a usage API and an OpenAPI specification. Parameter names used by other screenshot APIs are also accepted to ease migration.

cURL

See the ScreenshotNeo documentation for the complete parameter reference.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot failed: ${res.status}`);
const data = Buffer.from(await res.arrayBuffer());
require('fs').writeFileSync('shot.webp', data);

Plans and cost

Plan Included shots Price
Free 1,000 per month $0, no card
Starter 3,000 $5
Growth 15,000 $15
Pro 60,000 $39
Scale 250,000 $99
Business 1,000,000 $249

Every feature is included on every plan, and yearly billing gives two months free. Response headers identify the page verdict and whether the request was billed, which helps reconcile usage and failed captures.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Create a free ScreenshotNeo account to get 1,000 screenshots each month with no card; paid plans start at $5 for 3,000 shots.

Troubleshooting checklist

The image is visible, but html2canvas leaves a blank area

  • Confirm the image host differs from the page host.
  • Verify that the actual image response includes Access-Control-Allow-Origin for your page.
  • Enable useCORS: true, reload without a stale cached response, and test again.
  • If the server cannot authorize your origin, use an authorized proxy or an approved provider workflow.

SecurityError: Tainted canvases may not be exported

At least one drawn resource lacks the required CORS permission. Remove that resource, fix its response headers, or stop exporting the canvas. allowTaint: true does not solve export restrictions.

Best Value
Capture Card, USB Video Capture Card Device, Audio Video Converter Grabber for RCA to USB-Convert VHS Mini DV VCR Hi8 DVD to Digital, for PC TV Tape Player Camcorder, MAC Windows Vista Compatible
  • AV TO USB Converter: Capture videos and audios from VHS, VCR, Hi8, DV tapes to a PC, with the help of our USB Video Converter. Save room while digitizing your favorite old memories
  • Quality Capture Card: Our USB Video Capture Card converting anolog RCA composite input into HD 720P USB output and capturing audio without any sound card. Advanced signal processing technology provides you with great precision, colors, resolutions, and details.
  • Plug and Play: Automatically install the driver once you hook up this RCA to USB Converter to a PC. No external power is needed. User-friendly and easy to operate
  • Wide Compatibility: The Video Capture Card can work with video devices with RCA connector or S-Video connector, such as VHS, VCR, Hi8, camcorder, compatible with Windows and Mac OS. Support video formats like NTSC, PAL, and support brightness, contrast, hue, and saturation control
  • Note: The Video Converter is used with acquisition software. We recommend OBS Studio or PotPlayer for Windows, and QuickTime Player for Mac. They can be downloaded for free online. Please operate according to the steps in User Manual or contact us if you have any questions

Only the CAPTCHA inside a frame is missing

Check the iframe origin. A cross-origin frame requires provider cooperation; changing image options on the parent page cannot grant contentDocument access.

The capture times out or is incomplete

Wait for the image’s load event or a known selector before calling html2canvas. Check that lazy-loaded content has entered the DOM, but remember that waiting affects timing, not origin permissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The native extension screenshot is blank or rejected

Check the extension manifest and host permissions, ensure a tab is active and visible, and call the API from the extension context permitted by the browser. A background page cannot assume it can capture an arbitrary hidden tab.

Performance and reliability considerations

  • Use a smaller capture region instead of the entire document when you need one form or panel.
  • Set a deliberate scale and viewport; very large canvases consume substantial memory and can hit browser limits.
  • Wait on a selector or image load rather than using an unnecessarily long fixed delay.
  • Expect cross-origin failures to be deterministic: retries do not create permission.
  • For a proxy, cache only content you are allowed to cache and enforce response-size limits.
  • For extension screenshots, capture the visible viewport in stages when a page exceeds one screen.

The practical decision is straightforward: if you need exportable pixels, obtain authorization at the image server or use an approved server-side path. If you need what a human sees, use a browser screenshot API. html2canvas cannot turn a protected CAPTCHA into readable canvas data.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.