The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Complete the permitted sign-in flow in Playwright, wait for the final destination or an authenticated-page signal, save the browser’s authentication state, then load the protected page and take the screenshot. A successful click on “Sign in” is not proof that the browser has received all required cookies: an SSO flow can set them across several redirects.
Choose how to authenticate
Playwright supports UI-driven login and API-based authentication when the application provides an appropriate authentication API. Use the UI when the workflow needs to exercise the interactive sign-in path; use an API only when it is supported by the application and produces state the browser can reuse. Neither approach is universal across identity providers. See Playwright’s authentication guide.
UI-driven login
Navigate to the application’s sign-in page, fill the site-specific credentials, and submit the form. For SSO, the browser may then visit an identity provider and return to the application. Wait for the known post-login URL or an authenticated UI condition before saving state. Do not treat a click completing as proof of a completed login.
API-based authentication
If the application documents an authentication endpoint suitable for your test, use it to establish a session and transfer the resulting browser state into a Playwright context. Validate that the state actually opens the protected page. An API login may not exercise interactive SSO behavior, so it is not a substitute when that redirect path itself is what you need to test.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Save state after SSO, then reuse it
The following example uses UI sign-in and saves the authenticated context to a local state file. Replace the example URLs, selectors, and credentials with values for your application. It assumes the app returns to a known URL containing /dashboard and exposes a heading named “Dashboard”; those are application-specific signals, not universal SSO selectors.
import { chromium, expect } from '@playwright/test';
import fs from 'node:fs/promises';
const baseURL = process.env.APP_BASE_URL;
const username = process.env.APP_USERNAME;
const password = process.env.APP_PASSWORD;
const statePath = 'playwright/.auth/user.json';
if (!baseURL || !username || !password) {
throw new Error('Set APP_BASE_URL, APP_USERNAME, and APP_PASSWORD');
}
await fs.mkdir('playwright/.auth', { recursive: true });
const browser = await chromium.launch();
const context = await browser.newContext();
const page = await context.newPage();
try {
await page.goto(new URL('/login', baseURL).toString());
await page.getByLabel('Email').fill(username);
await page.getByLabel('Password').fill(password);
await page.getByRole('button', { name: /sign in/i }).click();
// Wait for the application's known return destination after SSO.
await page.waitForURL(url => url.origin === new URL(baseURL).origin && url.pathname.includes('/dashboard'));
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible();
await context.storageState({ path: statePath, indexedDB: true });
} finally {
await browser.close();
}
// A later capture run can reuse the saved authentication state.
const captureBrowser = await chromium.launch();
const captureContext = await captureBrowser.newContext({ storageState: statePath });
const capturePage = await captureContext.newPage();
try {
await capturePage.goto(new URL('/reports', baseURL).toString());
await expect(capturePage.getByRole('heading', { name: 'Reports' })).toBeVisible();
await capturePage.screenshot({ path: 'screenshot.png', fullPage: true });
} finally {
await captureBrowser.close();
}
This is a Playwright Test-style JavaScript example and uses @playwright/test for expect. Set credentials through environment variables rather than embedding them in the script. Store the state file in an ignored directory such as playwright/.auth; do not commit it.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Confirm the page is ready before capture
Navigation completion and application readiness are different checks. With multiple redirects, Playwright resolves navigation using the response from the last redirect, but that alone does not establish that the protected page has rendered the content you need. Use the signal that matches the application:
- Final URL: wait for the known post-login destination when the site has a stable return URL.
- Authenticated UI: assert a page-specific heading, account control, or other element that appears only when signed in. This is often more meaningful when the URL is variable.
- Target readiness: after navigating to the page to capture, wait for a target-page element before taking the screenshot. Replace the example “Reports” heading with an application-specific selector.
Use a viewport screenshot by omitting fullPage, or set fullPage: true to capture the full page. Consult the Playwright Page API for current screenshot options.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Know what saved browser state includes
Playwright’s reusable storage state covers cookies, local storage, IndexedDB, and passkey (WebAuthn) authentication. It does not automatically persist session storage, which is domain-specific and does not survive page loads. If your application requires session storage for sign-in, Playwright documents saving and restoring it with an initialization script; confirm that this is how your application works rather than assuming every SSO flow uses session storage.
Authentication state is sensitive. Playwright warns: “The browser state file may contain sensitive cookies and headers that could be used to impersonate you or your test account.” Keep it out of source control, restrict access to it, and regenerate it when the session expires. The example enables IndexedDB capture using Playwright’s documented option; confirm compatibility with the Playwright version used in your project.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Troubleshoot failed or incomplete captures
The script continues before SSO finishes
A login submission can trigger several redirects and cookie updates. Wait for the final application URL or an authenticated-page assertion, not just the sign-in click. If the URL can vary, prefer a visible application-specific signal.
The saved state opens the login page again
The state may have been saved before the redirect flow completed, may have expired, or may omit a mechanism the app uses. Re-run authentication, verify the final page is signed in before calling storageState, and check whether the application depends on session storage.
Recommended Free Tools
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
The screenshot is blank or missing protected content
Verify the target URL and assert a page-specific element before capture. A completed navigation does not guarantee that the application has finished rendering its content; wait for the relevant heading or control.
The state file exposes an account
Treat the file as a credential: remove it from version control, limit filesystem access, and refresh it if it may have been exposed. Do not place account secrets directly in source code.
Or skip the browser setup
If you already have a URL that ScreenshotNeo can capture, its one-request API returns an image or PDF. This does not automate your SSO login or transfer Playwright state; the target must be accessible to the API. For an authenticated page, use an approved method that makes the page accessible to the capture request, and do not put reusable secrets in a public URL.
ScreenshotNeo API documentation
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
ScreenshotNeo accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server offers screenshot and PDF tools for AI agents. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for the free plan.
Frequently Asked Questions
Can Playwright capture a page behind any SSO provider?
Not necessarily. The exact redirect, MFA, session-expiry, and anti-automation behavior depends on the target site and account.
Does Playwright storageState include session storage?
No. Session storage requires separate handling if the application relies on it.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

