NewAPI
Signed URLs for screenshots in an img tag.
Put a screenshot straight into a web page with a signed URL, without exposing your secret key.
A signed URL is a screenshot request your server signs once. Anyone can load it, but no one can change it, so it can go straight into an <img> tag.
- Create a publishable key in the dashboard. You get a
pk_…key, which goes in the URL askey, and a signing secret, which stays on your server. - Compute HMAC-SHA-256 of the query string with the signing secret, and add the result as
signature. - It works on every plan, at the same price and with the same cache as other requests, with
GETonly.
Keys now say where they belong: sk_… for a secret key, sent in the Authorization header, and pk_… for a publishable key, sent in a signed URL. Neither works in the other’s place.
A signed URL doesn’t expire. It works until you revoke its key, so treat a published one as public.
Try it on your own pages.
Everything in this changelog is live. 100 free screenshots a month, no credit card needed.