Let SnapRender through your firewall

If your site sits behind Cloudflare or another firewall, it may answer SnapRender with a security check instead of your page. Your captures then show Just a moment... or Performing security verification. One rule in Cloudflare fixes it in about two minutes, on any plan, including the free one. Your site stays protected from everyone else.

Updated October 6, 2026

On this page

How it works

Firewalls challenge visitors they do not recognize, and SnapRender is sometimes not recognized by a strict firewall, so it shows the check page. A rule that recognizes SnapRender, by its address or by a secret header that only your captures send, lets your captures reach the real page.

Without and with a rule Without a rule, the firewall stops SnapRender with a security check. With a rule that matches SnapRender's address or your access header, the capture reaches your site. Without a rule SnapRender your capture Your firewall shows a security check Your page never reached With a rule SnapRender our address or your header Your firewall rule matches: let it in Your page captured as visitors see it

The fix: allow SnapRender's IP address in Cloudflare

One rule, about 2 minutes, available on every Cloudflare plan, free included.

Show me the steps

The fix

Allow SnapRender's IP address

Works on every Cloudflare plan, free included. It lets SnapRender past every security check Cloudflare offers: custom rules, Bot Fight Mode, Browser Integrity Check and Under Attack mode.

1

Copy our address

187.77.75.63

Every capture comes from this address. Also as JSON and plain text.

This address may change. If it does, we will tell you by email and with a notice on our website, so you can update your rule.

2

Open the IP access rule form in Cloudflare

  1. Open Cloudflare and, under Domains, click your site.
  2. Copy the address from your browser's address bar and paste it here:
Open the IP access rule form

The button opens your site's New IP access rule page. Nothing you paste leaves this page.

Or by hand

  1. In Cloudflare, under Domains, click your site.
  2. In the left menu, click Security, then Security rules.
  3. The address in your browser now ends in /security/security-rules. Add /ip-access-rules/create to the end and press Enter. The page New IP access rule opens.
  1. Domains
  2. Your site
  3. Security
  4. Security rules
  5. + /ip-access-rules/create

Why not the Create rule button? Its menu shows Custom rules, Rate limiting rules, Managed rules and Templates; IP access rules appears there only after your site has one. Do not use Custom rules for this: its actions are Managed Challenge, Block, Non-Interactive Challenge, Skip and Interactive Challenge, with no Allow.

3

Fill it in and create the rule

IP, IP range, country name, or ASN
187.77.75.63
Action
Allow (it starts as Block, so change it)
Zone
This website
Notes
SnapRender

Type or paste the address and press Enter, then choose Create. This is how it looks in Cloudflare:

Cloudflare's New IP access rule form filled in: 187.77.75.63, action Allow, zone This website, notes SnapRender
4

Check that it works

Wait about a minute for Cloudflare to apply the rule, then capture your page with our free screenshot tool. It uses the same address as the API, so if it shows your page, your API captures will too. No account needed.

Open the free screenshot tool

Still seeing "Just a moment..."? Check that the rule lists 187.77.75.63, This website and Allow (not Block), and that it is Active.

Done. If our address ever changes, we will tell you by email and with a notice on our website, and update /ips.json.

Advanced, optional

Allow only your own captures: secret header

Most sites do not need this. The IP rule above lets every SnapRender capture through; this stricter setup lets through only captures from your account. SnapRender adds a header with your secret value to every capture of your domains, and your firewall lets that value through.

Needs: a paid Cloudflare plan (Pro or higher), or the free plan with Bot Fight Mode switched off, because no rule can skip Bot Fight Mode.

1

Add your domain in Site access

Open Site access

Add your domain, such as example.com (it covers its subdomains too), and copy the rule expression shown there.

Site access in the SnapRender dashboard with example.com added, its access header and the Check button
2

Open a new custom rule in Cloudflare

Create a custom rule in Cloudflare

Cloudflare asks you to sign in and pick your site, then opens the new rule form. The same page by hand:

  1. Your site
  2. Security
  3. Security rules
  4. Create rule
  5. Custom rules
3

Fill in the rule

Rule name
Allow SnapRender
Expression
Choose Edit expression and paste the expression from Site access
Action
Skip
WAF components to skip
All remaining custom rules (at least this one; tick the others your plan shows)
Execution order
First

Then choose Deploy and confirm, and give Cloudflare about a minute to apply it. The expression looks like any(http.request.headers["x-snaprender-access"][*] eq "sra_...") with your own value.

4

Press Check in Site access

SnapRender loads your domain the way a capture does and tells you whether it gets through.

The Check result in Site access: example.com, working, SnapRender gets through

On the free plan with Bot Fight Mode on, this rule cannot work: turn Bot Fight Mode off in Cloudflare's security settings, or use the IP rule above.

Done. Your captures of these domains send the header from now on. It keeps working if our address changes.

Other firewalls and hosts

Most firewalls and hosting platforms can allow a request by its IP address or by a request header. Either allow 187.77.75.63, or allow requests whose X-SnapRender-Access header equals your value from Site access. Then take a capture, or press Check in Site access, to confirm.

For developers: send headers per request

Site access needs no code. If you prefer to manage a secret yourself, send it with each capture in the headers object of POST /v1/screenshot. Headers go only to the target's domain and its subdomains, never to other sites, and are refused in GET requests because URLs end up in logs.

curl -X POST https://app.snap-render.com/v1/screenshot \
  -H "X-API-Key: $SNAPRENDER_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "https://example.com", "headers": {"X-Screenshot-Secret": "your-secret"}}' \
  --output example.png

Limits and reserved names are in the API reference.

Keep it safe

  • Treat the header value like a password. Do not put it in public code or pages.
  • SnapRender sends it only to the domains you register and their subdomains, never to other sites, even after a redirect.
  • If it may have leaked, create a new value in Site access and update your rule. The old value stops working at once.
  • The IP rule trusts every SnapRender capture. Use the advanced header option if only your own captures should pass.

FAQ

Why do my captures show "Just a moment..." or "Performing security verification"?+

That is a firewall security check page. Your site's firewall (often Cloudflare) asks visitors it does not recognize to pass a check first, and SnapRender is sometimes not recognized by a strict firewall. SnapRender captures exactly what the site returns, so the capture shows the check. Allowing SnapRender's IP address fixes it.

Does this work on the free Cloudflare plan?+

Yes. Allowing an IP address is available on every Cloudflare plan, free included, and it lets SnapRender past every security check Cloudflare offers on that plan: custom rules, Bot Fight Mode, Browser Integrity Check and Under Attack mode.

I cannot find "IP access rules" in the Create rule menu.+

Cloudflare only shows it after your site has at least one IP access rule; until then the Create rule menu lists Custom rules, Rate limiting rules, Managed rules and Templates. Use step 2: paste your site's Cloudflare address to get a direct link, or go to Security, then Security rules, and add /ip-access-rules/create to the end of the address in your browser.

Do I need the secret header too?+

No. The IP address rule is enough. The secret header is an optional, stricter setup for people who want only their own captures to pass, and it needs a paid Cloudflare plan or Bot Fight Mode switched off.

Does this weaken my site's protection?+

No. Everyone else still gets your full protection. The IP rule lets through requests from SnapRender's address, which includes captures made by other SnapRender users. The secret header lets through only requests that carry your value, which only your own captures send.

Do I have to change my API calls?+

No. Once the rule is in place, your existing captures show your page. With the advanced header option, SnapRender adds your header to every capture of your domains automatically.

Can SnapRender get past a security check without a rule?+

No. Security checks are the site owner's decision, and SnapRender respects them. When you own the site, one rule lets your captures through.

Does my header ever reach another website?+

No. It goes only to the domains you register and their subdomains. If a page redirects or loads content from another site, those requests never carry it.

My scheduled captures reported a big change after I added the rule.+

Expected. The previous captures were the check page; the first capture after the rule shows your real page. Later captures compare as usual.

I use a different firewall or host.+

Most firewalls can allow a request by IP address or by a request header. Allow 187.77.75.63, or allow requests whose X-SnapRender-Access header equals your value from Site access.

Your captures, your page

Allow our address in Cloudflare, then check your page with the free screenshot tool.