Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use the authentication method the site expects: set an Authorization header for a bearer token, page.authenticate() for HTTP authentication, or a cookie in the browser context for an existing web session. Headless Chrome uses the same Puppeteer authentication APIs as headful Chrome; the important choice is the credential type and where it should be sent.

Choose the authentication method the site requires

First check the target service’s authentication instructions. “Authentication token” can mean different things, and putting a credential in the wrong place will not authenticate the request.

What the site expects Puppeteer method Credential scope
Bearer token or another custom request header page.setExtraHTTPHeaders() Every request the page initiates
HTTP authentication challenge, such as Basic or Digest page.authenticate() HTTP authentication handled by Puppeteer
Existing browser login session BrowserContext.setCookie() or Browser.setCookie() Requests matching the cookie’s domain and policy
Token should go only to selected requests Request interception and conditional headers Requests your handler explicitly allows

These approaches are not interchangeable. A bearer token is usually sent in an Authorization header, but the target service defines the exact header and format. An HTTP challenge is not a generic bearer-token setter. A cookie must match the application’s actual session cookie requirements.

Send a bearer token in a request header

For a bearer-token API or site that expects Authorization: Bearer …, set the extra headers before navigation so the initial document request includes them:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
import puppeteer from 'puppeteer';

const token = process.env.ACCESS_TOKEN;
if (!token) throw new Error('Set ACCESS_TOKEN before running this script');

const browser = await puppeteer.launch({ headless: true });
try {
  const page = await browser.newPage();
  await page.setExtraHTTPHeaders({
    authorization: `Bearer ${token}`,
  });

  const response = await page.goto('https://example.com/private', {
    waitUntil: 'domcontentloaded',
  });
  console.log('HTTP status:', response?.status());
} finally {
  await browser.close();
}

Replace the example URL with the protected page and store the token in the environment rather than embedding it in source code. Puppeteer’s setExtraHTTPHeaders API sends extra headers with every request initiated by that page. Header names are lowercased, and outgoing header order is not guaranteed.

Understand the scope before reusing the page

This is page-wide configuration, not a destination-specific token rule. If the page loads third-party resources or later navigates to another origin, do not assume the token is restricted to the intended host. The API reference describes page-wide behavior but does not promise origin-level filtering. Keep the authenticated page dedicated to the intended site, or use request interception to attach the credential only to approved requests.

Use HTTP authentication for an HTTP challenge

When the server challenges the browser for HTTP credentials, call page.authenticate() before navigating:

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
import puppeteer from 'puppeteer';

const username = process.env.HTTP_USERNAME;
const password = process.env.HTTP_PASSWORD;
if (!username || !password) {
  throw new Error('Set HTTP_USERNAME and HTTP_PASSWORD before running this script');
}

const browser = await puppeteer.launch({ headless: true });
try {
  const page = await browser.newPage();
  await page.authenticate({ username, password });
  const response = await page.goto('https://example.com/private', {
    waitUntil: 'domcontentloaded',
  });
  console.log('HTTP status:', response?.status());
} finally {
  await browser.close();
}

page.authenticate() is for HTTP authentication, not for setting an arbitrary bearer token. Puppeteer enables request interception internally to implement this method, which may affect performance. See the Puppeteer authenticate API reference for the method’s current behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reuse a session cookie in an isolated browser context

If the application gives you an existing session cookie, set it on a browser context before opening the protected page. A newly created browser context isolates its cookies and cache from other contexts:

import puppeteer from 'puppeteer';

const cookieValue = process.env.SESSION_COOKIE;
if (!cookieValue) throw new Error('Set SESSION_COOKIE before running this script');

const browser = await puppeteer.launch({ headless: true });
const context = await browser.createBrowserContext();
try {
  await context.setCookie({
    name: 'session',
    value: cookieValue,
    url: 'https://example.com',
    httpOnly: true,
    secure: true,
  });

  const page = await context.newPage();
  const response = await page.goto('https://example.com/private', {
    waitUntil: 'domcontentloaded',
  });
  console.log('HTTP status:', response?.status());
} finally {
  await context.close();
  await browser.close();
}

The cookie name and attributes above are examples, not universal settings. Use the cookie’s real name, value, domain or URL, path, expiry, and security attributes as required by the target application. A cookie scoped to a different domain or path will not be sent where you expect. Prefer BrowserContext.setCookie() or Browser.setCookie(); Puppeteer deprecates the Page-level cookie setter. See the BrowserContext.setCookie reference and Page cookie API documentation.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Attach a token only to selected requests

When a token must not accompany every request the page makes, enable interception and add the header only for the intended origin. This gives you finer control, but changes request handling: every intercepted request must be resolved.

import puppeteer from 'puppeteer';

const token = process.env.ACCESS_TOKEN;
if (!token) throw new Error('Set ACCESS_TOKEN before running this script');

const allowedOrigin = 'https://example.com';
const browser = await puppeteer.launch({ headless: true });
try {
  const page = await browser.newPage();
  await page.setRequestInterception(true);

  page.on('request', request => {
    if (request.isInterceptResolutionHandled()) return;

    let isAllowed = false;
    try {
      isAllowed = new URL(request.url()).origin === allowedOrigin;
    } catch {
      // Invalid or nonstandard URL: continue without adding the credential.
    }

    if (isAllowed) {
      const headers = {
        ...request.headers(),
        authorization: `Bearer ${token}`,
      };
      void request.continue({ headers });
    } else {
      void request.continue();
    }
  });

  await page.goto(`${allowedOrigin}/private`, {
    waitUntil: 'domcontentloaded',
  });
} finally {
  await browser.close();
}

The handler continues both allowed and other requests; leaving one unresolved can stall navigation or page activity. If several listeners may resolve a request, check request.isInterceptResolutionHandled() and coordinate their behavior to avoid resolving a request twice. Puppeteer documents these requirements in its network interception guide and request resolution API.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not treat interception as a free filter

Interception adds per-request control-flow work and can affect performance. Use it when the credential-scope benefit matters; otherwise a dedicated page with extra headers is simpler. Avoid registering unrelated interception handlers unless they all have a clear, compatible resolution path.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Headless mode does not change the authentication API

Puppeteer’s headless setting controls how Chrome runs, not which authentication scheme the site accepts. In current Puppeteer, headless operation is the default; headless: true selects the current headless mode, while headless: 'shell' selects the separate legacy chrome-headless-shell binary. Choose the header, HTTP authentication, cookie, or interception method based on the site’s protocol. Puppeteer’s headless modes guide explains the distinction.

Compatibility documentation is version-sensitive. The Puppeteer supported-browsers page lists Puppeteer v25.12.0 with Chrome for Testing 154.0.8037.57; verify the mapping for the version you install rather than assuming it remains current. The same page states Chrome for Testing supports headless and headful operation through the same code path: Puppeteer supported browsers.

Troubleshoot authentication failures

  • The page still shows a login screen. Confirm the site expects the credential type you used, that the bearer prefix and header name match its instructions, or that the session cookie is current and correctly scoped.
  • The first request is unauthenticated. Set headers, credentials, or cookies before calling page.goto(); changing them after navigation cannot retroactively authenticate the document request.
  • A token appears on unrelated requests. setExtraHTTPHeaders() applies to all requests initiated by that page. Use a dedicated page/context or origin-filtered interception.
  • Navigation hangs after enabling interception. Check that every request reaches continue(), abort(), or another valid resolution path; inspect handlers for early returns that leave a request unresolved.
  • Puppeteer reports a request was already handled. More than one handler may be resolving it. Check isInterceptResolutionHandled() before acting and coordinate listeners.
  • HTTP credentials do not work with a bearer-token endpoint. page.authenticate() is for HTTP challenges. Send the bearer credential in the header the service specifies instead.
  • A cookie is silently ignored. Validate its actual domain/URL, path, expiry, and secure requirements against the target site. The example values are not a substitute for the application-issued cookie data.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is a screenshot rather than browser automation, ScreenshotNeo takes a URL in one API request and returns an image or PDF. It accepts consent banners like a visitor and removes known cookie/consent platforms, newsletter popups, and chat widgets before capture; each of those steps can be disabled. Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing, with the outcome reported in response headers. Its MCP server exposes screenshot and page-information tools to AI agents.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a public page, a one-call cURL example is:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for parameters, including authenticated-request options. Do not put a secret token in a URL or expose credentials in a public screenshot link; use the service’s documented credential mechanism and restrict access appropriately. ScreenshotNeo includes 1,000 screenshots per month free with no card, and paid plans start at $5 for 3,000. Sign up for the free plan.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

FAQ

Can I pass a token through Puppeteer’s launch options?

For these common site-authentication methods, configure the page or browser context with the method the site expects; the approaches here use page headers, HTTP authentication, cookies, or request interception.

Should I use a cookie or an Authorization header?

Use whichever the site’s authentication contract requires. A login session cookie and a bearer token represent different mechanisms, and substituting one for the other will not make it valid.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.