Screenshots
Countries and attestation
Add country to load a page the way people there get it. There are 227 countries. A screenshot from a chosen country uses 2 credits.
Not open to every account yet. Screenshots from a chosen country are being opened account by account. Until yours is, a request with country is refused with option_unavailable before anything is captured. Everything below describes how it works once it is open for you.
The country you see is the one we observed
We check where the page was really loaded from, with two independent location databases. The answer reports that country, never the one you asked for.
- If we cannot confirm the country, you get the error
country_not_obtained, and no screenshot from somewhere else. A failed screenshot is not charged. - With the image, the header
X-Country-Observedcarries the country. Withresponse=json, it is incountry.observed. - A country we do not have is refused with
country_not_available.
The list of countries
GET /v1/countries returns the two-letter codes you can use. No key needed. The count is what we measured, on the date given in measured_at.
The attestation
Every screenshot taken from a country comes with a signed record: where it was loaded from, when, what the page answered, and a fingerprint of the image. It is in the attestation field, and at GET /v1/screenshots/{id}/attestation.
| Field | Description |
|---|---|
requested_country |
The country you asked for. |
observed |
What we saw: country, kind of network, the network operator, a masked address, and what each location database said. |
response |
What the page answered: status, final address, redirects, title. |
screenshot_sha256 |
The fingerprint of the image file. |
strict_pass |
true only when the observed country matches and stayed the same during the capture. |
signature |
An Ed25519 signature, with the id of the key that made it. |
The address the page was loaded from is never given in full: the attestation keeps only its masked form.
What it is, and is not. A technical attestation of one capture, signed by us. It is not legal proof.
Check the signature
- Get our public keys at
GET /v1/attestation-keysand pick the one whosekey_idmatches. - Remove the
signaturefield from the attestation. - Write what is left as JSON with keys sorted at every level, with no escaping of slashes or accents.
- Verify the base64 signature against that text with Ed25519.
What a country changes, and what it does not
- The page is loaded through a network connection in that country, so the site answers as it does for people there: prices, language, availability, legal notices.
- It does not set the browser language or clock. Add
languageandtimezoneif the site follows those: see Devices and sizes. - We make no promise that a website will not notice the visit. If it shows a bot check instead of its page, the screenshot fails with
challenge_page.