Comparing screenshot APIs

Comparing Urlbox or ScreenshotOne? Here's Shotvik, an EU-hosted screenshot API

Shotvik is an EU-hosted screenshot and OG-image API. If you're comparing it with Urlbox or ScreenshotOne, here's what Shotvik does, where its data goes, and what to check with any provider.

This page describes Shotvik only. It makes no statements about other services. For their hosting, terms and plans, read Urlbox’s and ScreenshotOne’s own documentation.

What Shotvik does

  • Screenshots of public web pages as PNG, JPEG or PDF with POST /v1/screenshot: custom viewports up to 3840 px, full-page captures, dark mode, device scale factor 1–3, and blocking of ad and cookie-banner requests.
  • Your own HTML and CSS to an image with POST /v1/html, rendered in headless Chromium.
  • Open Graph images from templates with POST /v1/og, or as signed og:image links that never contain your API key.
  • Product page URL to an OG image with /v1/og/from-url: Shotvik reads the product’s name, price and image from the page and returns a 1200×630 card. See the live demo.

What Shotvik doesn’t do: there’s no stealth mode, no captcha solving and no proxies. Every request carries ShotvikBot/0.1 (+https://shotvik.com/bot) in its User-Agent, so sites that block automated browsers can block Shotvik too, and you’ll get their block page or an error. Site owners can read what ShotvikBot does on /bot/.

Where your data goes with Shotvik

  • Processing and storage in the EU. The website, API, dashboard, database and backups run on Hetzner servers in Helsinki, Finland.
  • No CDN or proxy in front of the API. Cloudflare provides DNS for shotvik.com and forwards email to our support addresses; API traffic goes straight to our server.
  • Renders aren’t stored by default. The result is streamed back to you. With the opt-in cache (cache=true), an image is kept for up to 30 days.
  • Request log. For each API request: key and account ID, endpoint, target hostname (no path or query), time, status and duration. Your IP address is stored only as a salted hash. Entries are kept for 30 days. No render content is logged.
  • Email. Brevo (Paris, France) sends sign-in and invitation emails to users, plus internal alert emails to our own address, and stores that data in the EU. Some of Brevo’s own providers in the US and India may access it under Standard Contractual Clauses and, for the US, the EU-US Data Privacy Framework. Email to our support address arrives in Gmail via Cloudflare Email Routing; both are US companies.

The details, including retention periods and the companies involved, are in the privacy notice.

Contract and documents

  • Beta terms, the privacy notice and the acceptable use policy apply.
  • A data processing agreement (DPA) is coming. It isn’t published yet.
  • The companies we use are listed in the privacy notice, with what they handle and where.

Plans

During the beta, every account is on the free plan: 100 renders a month, 10 uncached renders per minute (cache hits don’t count) and 2 concurrent renders. There’s no overage and no card needed; at the monthly limit, requests stop until the next month. Paid plans will come later; there are no prices yet. What counts as a render is in Rate limits and plans.

Questions to ask any screenshot API

Take each provider’s answers from its own documentation, terms and DPA. Here are Shotvik’s.

Question Shotvik’s answer
Where are pages rendered, and where are results, caches and logs stored? Hetzner, Helsinki, Finland (EU), for all of them.
Are results stored by default? For how long? No. Only with the opt-in cache, for up to 30 days.
Is there a DPA and a list of sub-processors? The DPA is coming, not published yet. The companies involved are listed in the privacy notice.
Which companies outside the EU can access data, and on what basis? See Where your data goes: Brevo’s own US/India providers (SCCs, DPF) for email; Cloudflare and Google for DNS and support mail.
Is the API behind a CDN or proxy? No. For the API, Cloudflare provides DNS only.
What’s logged per request, and for how long? Hostname (no path or query), status, timing, account and key; IP only as a salted hash; 30 days.
How does the renderer identify itself? Does it get around bot protection? Always as ShotvikBot, with a link to /bot/. It doesn’t bypass bot protection.
What counts toward the quota, and what happens at the limit? Returned images and PDFs count; cache hits, blocked requests and our own errors don’t. At the limit, requests stop: no overage.
Do I need a card to try it? No.

The same questions work for Urlbox, ScreenshotOne or any other provider.

Trying Shotvik next to your current integration

  1. Look at real output first on the live demo, no account needed.
  2. Create a free account and create an API key in the dashboard.
  3. Send the same pages you render today and compare the results yourself:
curl https://api.shotvik.com/v1/screenshot \
  -H "Authorization: Bearer $SHOTVIK_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "https://example.com", "full_page": true}' \
  --fail-with-body --output example.png

Shotvik takes a JSON body with your key in Authorization: Bearer (or X-API-Key) and returns the file. Parameter names are in the screenshot reference; the quickstart walks through the first request.

Try Shotvik on your own pages

Free plan: 100 renders a month, no card. Or look at real output first, no account needed.