Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →To capture an authenticated page, use Selenium to sign in through the application’s normal SSO flow in the same browser session, switch to the correct tab if the identity provider opens one, wait for an authenticated page marker and the content you need, then save a screenshot. A completed navigation alone does not prove that sign-in or client-side rendering has finished.
How the SSO screenshot workflow works
SSO is not a single Selenium command. Selenium controls a browser; the website and identity provider determine the redirects, prompts, and authentication requirements. In an OAuth 2.0 authorization-code flow, the user authenticates through the browser at the authorization server before the browser returns to the client with an authorization code. OpenID Connect adds authentication and identity semantics over OAuth 2.0. The exact pages and steps depend on your application’s and identity provider’s configuration. RFC 6749 and the OpenID Connect Core 1.0 specification describe those protocols.
- Start an authorized WebDriver session and open the application’s regular sign-in page.
- Complete SSO in that browser session, including any organization-approved MFA or interactive checkpoint.
- If the flow uses another tab or window, switch to the context containing the application.
- Wait for an application-specific authenticated marker and the target content.
- Save a viewport screenshot or capture the target element.
- Quit the driver and store screenshots and session data appropriately.
Runnable Python example
This example uses Selenium’s Python bindings and Chrome. Install Selenium with python -m pip install selenium and make Chrome available. Selenium’s driver management behavior can depend on your environment; if automatic driver setup is unavailable, configure a compatible driver or use your organization’s approved remote WebDriver. Selenium describes WebDriver as driving a browser natively, locally or remotely. See the WebDriver documentation and browser options.
Replace the example URLs and selectors with values from your application. The example pauses for you to complete the normal sign-in flow in the launched browser; it does not attempt to automate or bypass MFA. A reliable authenticated marker should be specific to your application, such as an account menu or logged-in navigation item.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
from pathlib import Path
from selenium import webdriver
from selenium.webdriver.common.by import By
from selenium.webdriver.support import expected_conditions as EC
from selenium.webdriver.support.ui import WebDriverWait
LOGIN_URL = "https://app.example.com/sign-in"
AUTH_MARKER = (By.CSS_SELECTOR, "[data-testid='account-menu']")
TARGET = (By.CSS_SELECTOR, "main [data-testid='report']")
options = webdriver.ChromeOptions()
# For a visible, interactive SSO and MFA flow, do not enable headless mode.
driver = webdriver.Chrome(options=options)
wait = WebDriverWait(driver, 60)
try:
driver.get(LOGIN_URL)
input("Complete the approved SSO sign-in in the browser, then press Enter here: ")
# Validate the application context instead of assuming a particular window handle.
wait.until(EC.presence_of_element_located(AUTH_MARKER))
target = wait.until(EC.visibility_of_element_located(TARGET))
Path("screenshots").mkdir(exist_ok=True)
driver.save_screenshot("screenshots/report-page.png")
target.screenshot("screenshots/report-element.png")
finally:
driver.quit()
The first image captures the current browser window’s viewport; the second captures the selected element. Selenium’s screenshot APIs and examples are documented in its WebDriver documentation. Element capture is useful for a focused crop, but it does not include the rest of the viewport.
Handle a new SSO tab or window
Selenium operates in a current browsing context. If the SSO provider or application opens a new tab, inspect the window handles after starting the flow and switch before waiting for the authenticated marker or taking the screenshot. Do not rely on handle order to identify the right destination; test for a page-specific condition.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
before = set(driver.window_handles)
# Trigger the site's SSO action here, if it is not already in progress.
# For example: driver.find_element(By.CSS_SELECTOR, "button.sso").click()
wait.until(lambda d: len(set(d.window_handles) - before) > 0)
new_handles = set(driver.window_handles) - before
# A newly opened handle is a candidate, not proof that it is the application.
for handle in new_handles:
driver.switch_to.window(handle)
if "app.example.com" in driver.current_url:
break
wait.until(EC.presence_of_element_located(AUTH_MARKER))
Flows may instead navigate the existing tab or return to an earlier one, so inspect current handles and validate the final destination rather than assuming a new handle must exist. See Selenium’s guide to working with windows and tabs.
Wait for authentication and rendered content
A navigation call can finish when the document reaches a readiness state while a JavaScript application is still loading data or painting the part you need. Wait for a stable application marker and then the actual target element. Selenium recommends condition-based waits; mixing implicit and explicit waits can lead to unpredictable timing. See Selenium’s waiting strategies.
Recommended Free Tools
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Authentication marker: choose an element that only appears after successful sign-in, such as the account menu or an authenticated navigation link.
- Screenshot target: wait for the specific report, table, chart, or other content to become visible.
- Additional readiness: if the page displays a loading indicator, wait for it to disappear as well; use a page-specific condition instead of an arbitrary long sleep.
For content that loads after the target element first appears, wait for a meaningful state change—for example, a loading indicator disappearing or the expected result text appearing. A fixed sleep can be useful for diagnosis but is brittle as a final synchronization strategy.
Choose viewport or element capture
| Capture | Use it when | What it includes |
|---|---|---|
| Current-window screenshot | You need the visible page context, including surrounding navigation and layout. | The current browser window’s viewport. |
| Element screenshot | You need a focused image of a particular panel, chart, or report. | The selected element rather than the entire viewport. |
Both choices require switching to the correct window and confirming the page is authenticated and rendered first. Selenium’s window, screenshot, and interaction APIs are covered in the WebDriver documentation.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Security and session handling
Run this only against an application and account you are authorized to access. MFA and conditional-access requirements are organization policy, not screenshot defects. Use an approved test identity, documented test identity-provider configuration, or an authorized interactive checkpoint where required. Do not try to defeat MFA or treat copied session tokens as a generic shortcut. OWASP’s Authentication Cheat Sheet covers authentication security considerations.
Cookies are scoped to browser context and domain, and an SSO flow can depend on state at both the application and identity provider. Manually inserting a cookie is not a general replacement for completing the configured flow. See Selenium’s documentation on working with cookies. Avoid leaving an authenticated browser open, and restrict access to screenshot files that may contain private data.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Troubleshoot common failures
| Symptom | Likely cause | What to check or change |
|---|---|---|
| Screenshot shows sign-in or the identity provider | The callback has not completed, the wrong tab is active, or the app is not authenticated. | Check driver.current_url and window handles; switch to the application context and wait for its authenticated marker. |
| SSO opens an unexpected tab | The flow changed browsing contexts. | Compare handles before and after the SSO action, switch to candidate handles, and identify the correct one by URL or a page-specific element—not handle ordering. |
| Page appears loaded but the screenshot misses content | Dynamic rendering or data loading continues after document readiness. | Wait for the target element and any relevant loading state to reach the condition needed for the image. |
| Cookie insertion does not authenticate the session | Cookies may be domain-scoped, or the flow may require additional provider state or policy checks. | Use the normal authorized SSO flow; do not use copied tokens as a generic authentication bypass. |
| MFA prompt blocks unattended execution | The configured policy requires user verification or an approved test path. | Ask the application or identity-provider administrator about an authorized test identity or interactive checkpoint. Do not attempt to bypass the control. |
Or skip the browser setup
If your goal is a clean screenshot rather than exercising an authenticated SSO flow, ScreenshotNeo is a website screenshot API and MCP server. It accepts one GET request with a URL and can return PNG, JPEG, WebP, or PDF. Its cleanup can accept cookie or consent banners and remove supported consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Clean shots alone are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, with the result identified in response headers. This does not replace logging in to a private SSO-protected page.
For a public page, one cURL call is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for request options. An MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for ScreenshotNeo’s free plan.
Frequently Asked Questions
Does Selenium automatically complete every SSO flow?
No. The identity provider, application configuration, and any required user interaction determine the flow; Selenium controls the browser but does not make every sign-in flow automatable.
Can I use a headless browser for SSO?
It depends on the identity provider and organization policy. The example uses a visible browser because it supports an authorized interactive sign-in checkpoint; confirm any unattended test setup with your administrators.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

