Quattro Expertise
screenshot3
Headless screenshot service for vos3. Give it a page URL and an API3 token; it renders the page in a real browser and returns a PNG.
It drives a real Chromium against vos3, so Mapbox tiles, contours and DOM markers render exactly as a user sees them. Works for any vos3 page, not only map frames.
Endpoint
GET https://screenshot3.q-e.nl/screenshot?url=<page>
Authorization: Bearer <api3 token>
Try it
Authentication
Send the API3 access token as Authorization: Bearer <token>. It is validated against API3 before any rendering, and the shot shows only what that user may see. The token may also be passed as a token query parameter for callers that cannot set headers (an <img src>, say) — the header wins when both are present. Prefer the header: it keeps the credential out of access logs and Referer headers.
A browser that is signed in to vos3 needs neither: vos3 sets its access_token cookie on .q-e.nl, so this host receives it and uses it as a last resort — for same-site requests only, so a third-party page cannot borrow your session through an <img>. That is what the Try form above relies on.
| Param | Req | Default | Notes |
|---|---|---|---|
url | yes | — | Full target URL. Host must be allowed (see below). URL-encode it if it contains &. |
token | no* | — | API3 access token — *required unless sent as an Authorization: Bearer header or carried by the vos3 session cookie (same-site requests only). |
wait | no | map-ready | map-ready · networkidle · load · selector:<css>. Use networkidle for non-map pages. |
width | no | 1600 | Viewport width, px (320–4000). |
height | no | 1200 | Viewport height, px (320–4000). |
scale | no | 2 | Device pixel ratio (1–4). Higher = print quality. |
fullPage | no | false | true captures the full scrollable page. |
Examples
# a map frame (default map-ready wait)
curl -H "Authorization: Bearer <API3_TOKEN>" \
"https://screenshot3.q-e.nl/screenshot?url=https://vos3.q-e.nl/frames/projects/22022/sensor-map" -o map.png
# any other page
curl -H "Authorization: Bearer <API3_TOKEN>" \
"https://screenshot3.q-e.nl/screenshot?url=https://vos3.q-e.nl/console/projecten&wait=networkidle" -o page.png
# token in the URL instead — for callers that cannot set a header
curl "https://screenshot3.q-e.nl/screenshot?url=https://vos3.q-e.nl/frames/projects/22022/sensor-map&token=<API3_TOKEN>" -o map.png
Responses
| Status | Meaning |
|---|---|
| 200 | image/png |
| 400 | Missing/invalid url, or host not allowed |
| 401 | No token (header, query or session cookie), or API3 rejected it |
| 502 | API3 unreachable for token validation |
| 504 | Timed out waiting for the page to render |
vos3 page parameters
Anything the page itself understands rides along inside url — this service passes it through untouched. For map frames: bbox=<lng,lat,lng,lat> and bearing=<deg> frame the map on a fixed rectangle at a fixed rotation, and forceLabels=true shows marker labels at any zoom. Use that last one when a capture comes back with unlabelled markers: a wide bbox or a short frame fits below the zoom at which labels normally appear, and a PNG cannot be zoomed in.
Allowed hosts
url must point at one of: q-e.nl. Other hosts are rejected (SSRF guard).
Health check: GET https://screenshot3.q-e.nl/health