# Request options

> Reference for the request options of the shotkit screenshot API, with an example request for each.

How the browser talks to the target site: identity, credentials, locale and network.

### `user_agent`

Custom User-Agent.

Type: `string`

```bash
curl -X POST "https://shotkit.net/api/take" \
  -H "X-Access-Key: YOUR_ACCESS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com","user_agent":"Mozilla/5.0 (compatible; MyPreviewBot/1.0)"}' \
  --fail-with-body -o shot.jpg
```

### `authorization`

Authorization header for the target.

Type: `string`

```bash
curl -X POST "https://shotkit.net/api/take" \
  -H "X-Access-Key: YOUR_ACCESS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://app.example.com/dashboard","authorization":"Bearer YOUR_APP_TOKEN"}' \
  --fail-with-body -o shot.jpg
```

### `headers`

Extra headers, one per line. `Name: value`, one per line in GET (or repeat the key), or an array in JSON.

Type: `list`

```bash
curl -X POST "https://shotkit.net/api/take" \
  -H "X-Access-Key: YOUR_ACCESS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com","headers":["Accept-Language: de-DE","X-Preview: true"]}' \
  --fail-with-body -o shot.jpg
```

### `cookies`

Cookies, one per line. Same syntax as `Set-Cookie`: `name=value; Domain=…; Path=…; Secure; HttpOnly`. `Domain` defaults to the `url`'s host.

Type: `list`

```bash
curl -X POST "https://shotkit.net/api/take" \
  -H "X-Access-Key: YOUR_ACCESS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://app.example.com/dashboard","cookies":["session=abc123; Secure; HttpOnly"]}' \
  --fail-with-body -o shot.jpg
```

### `time_zone`

Browser time zone.

Type: `enum`

Values: `America/Chicago`, `America/Denver`, `America/Los_Angeles`, `America/Mexico_City`, `America/New_York`, `America/Santiago`, `America/Toronto`, `America/Vancouver`, `Asia/Kuala_Lumpur`, `Asia/Shanghai`, `Asia/Tashkent`, `Asia/Tokyo`, `Europe/Berlin`, `Europe/Bucharest`, `Europe/Kyiv`, `Europe/Lisbon`, `Europe/London`, `Europe/Madrid`, `Europe/Paris`, `Pacific/Auckland`, `UTC`

```bash
curl -X POST "https://shotkit.net/api/take" \
  -H "X-Access-Key: YOUR_ACCESS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com","time_zone":"Asia/Tokyo"}' \
  --fail-with-body -o shot.jpg
```

### `proxy`

Your HTTP proxy (http://user:pass@host:port). Credentials in the URL are used for proxy authentication.

Type: `string`

```bash
curl -X POST "https://shotkit.net/api/take" \
  -H "X-Access-Key: YOUR_ACCESS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com","proxy":"http://user:pass@proxy.example.com:8080"}' \
  --fail-with-body -o shot.jpg
```

### `bypass_csp`

Bypass Content-Security-Policy.

Type: `boolean` · Default: `false`

```bash
curl -X POST "https://shotkit.net/api/take" \
  -H "X-Access-Key: YOUR_ACCESS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com","bypass_csp":true,"scripts":"document.body.append(Object.assign(document.createElement('\''script'\''), { src: '\''https://cdn.example.com/widget.js'\'' }))"}' \
  --fail-with-body -o shot.jpg
```
