# Screenshot a page behind a login

> Screenshot dashboards, admin pages and staging sites that need a login. Send a session cookie or a header with the request and the page opens signed in.

To screenshot a page that needs a login, send the session cookie of a signed-in user with the CurlShot request. The browser sets the cookie before it opens the page, so the site treats it as that user and shows the page instead of the sign-in form. Sites that use a token take it as an HTTP header, and password-protected staging sites take an Authorization value.

Page for people: https://curlshot.com/tools/screenshot-behind-login

## Steps

1. Sign in to the site as a user made for this, and copy its session cookie.
2. Send the address of the page with the cookie in the cookies field.
3. Save the screenshot of the signed-in page.

## What people use it for

- Dashboards and reports as an image in a weekly email
- Screenshots of your own app for docs and release notes
- Staging and preview sites behind a password
- Admin pages, for a record of how they looked

## The same thing with the API

```bash
curl -X POST "https://curlshot.com/api/v1/screenshot" \
  -H "X-Access-Key: YOUR_ACCESS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com/dashboard","cookies":["session=YOUR_SESSION_COOKIE; Domain=example.com; Secure"]}' \
  --output dashboard.png
```

An access key is free: https://curlshot.com/register. Read more:

- [Screenshot a page behind a login](https://curlshot.com/docs/guides/screenshot-behind-login.md)
- [Customize the page](https://curlshot.com/docs/customize.md)

## Questions

### How do I take a screenshot of a page that requires login?

Send the session cookie of a signed-in user in the cookies field of a CurlShot request. The page then opens as that user.

### What if the site uses a token and not a cookie?

Send it with the headers option, as a named HTTP header. For HTTP basic authentication use the authorization option.

### Which account should I use?

One made for screenshots, with read-only access to the pages you need and nothing else. Send the request with POST so the cookie is in the body and not in a web address.

### Can it click through a sign-in form?

A cookie or a header is the reliable way. The click option presses one element before the screenshot and scripts runs your own JavaScript on the page, for a step such as closing a dialog.

## Related

- [Full-page screenshot](https://curlshot.com/tools/full-page-screenshot.md): Take a screenshot of a whole web page, from the top to the very bottom, as one image. Paste the address, nothing to install. Also available as an API.
- [Screenshot API](https://curlshot.com/tools/screenshot-api.md): A screenshot API for developers. One HTTP request turns a URL, HTML or Markdown into a PNG, JPEG, WebP or PDF. Full page, devices, blocking, cache, MCP.
- [Element screenshot](https://curlshot.com/tools/element-screenshot.md): Capture one part of a web page instead of all of it: a chart, a pricing table, a card. Name the element with a CSS selector and get an image of it alone.
