Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To capture a page that requires login, save the cookies from the Puppeteer BrowserContext used for your authorized login, restore those cookie objects into the same kind of context before navigating, wait for a site-specific sign of authenticated content, then call page.screenshot(). Cookie replay works only while the site still accepts that session.

Save cookies after an authorized login

Puppeteer can retrieve cookies from a browser context and set them later. Keeping the page and cookie jar in an explicit BrowserContext makes it clear which isolated browser storage belongs to the page.

import puppeteer from 'puppeteer';
import { writeFile } from 'node:fs/promises';

const browser = await puppeteer.launch();
try {
  const context = await browser.createBrowserContext();
  const page = await context.newPage();

  await page.goto('https://example.com/login');
  // Complete the site's authorized login steps here.

  const cookies = await context.cookies();
  await writeFile('cookies.json', JSON.stringify(cookies, null, 2), {
    mode: 0o600,
  });
} finally {
  await browser.close();
}

Replace the example URL and login placeholder with a flow you are authorized to run. The restrictive file mode is an operational precaution, not a security feature provided or guaranteed by Puppeteer.

Protect the saved file

Cookie values can function as credentials. Keep the file out of source control and logs, restrict access to it, and delete it when it is no longer needed. Puppeteer documents cookie APIs and fields, not a secure cookie-storage system.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Restore cookies before navigating

Load the saved cookie objects into the context before opening the page that needs authentication. Create the page from that context so it uses the restored storage.

import puppeteer from 'puppeteer';
import { readFile } from 'node:fs/promises';

const browser = await puppeteer.launch();
try {
  const context = await browser.createBrowserContext();
  const cookies = JSON.parse(await readFile('cookies.json', 'utf8'));
  await context.setCookie(...cookies);

  const page = await context.newPage();
  await page.goto('https://example.com/account', {
    waitUntil: 'domcontentloaded',
  });
  await page.waitForSelector('[data-testid="account-home"]');
  await page.screenshot({ path: 'account.png', fullPage: true });
} finally {
  await browser.close();
}

Change the account URL and selector to match the target application. If the site does not expose a stable selector, wait for another application-ready signal that distinguishes the authenticated view from a login page or loading shell.

Keep cookie scope and context intact

A BrowserContext isolates browser storage, including cookies and local storage. Restoring cookies into one context does not authenticate a page created in another. Puppeteer’s browser-level cookie methods operate as shortcuts to the default context; use context-level methods when you need explicit isolation.

Cookie records can include a name and value plus scope and security attributes such as domain, expiry, httpOnly, path, sameSite, secure, partition key, priority, and source scheme. If expires is omitted, the cookie is a session cookie. A cookie parameter can also use a URL, which can affect default domain, path, and source scheme.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Preserve the cookie objects returned by Puppeteer instead of reducing them to just { name, value }.
  • Restore the records into a context before navigating to the relevant site.
  • Do not assume a copied cookie remains valid: it may have expired, been revoked or rotated, or be restricted by the site’s session policy.

If the site rejects the restored session, use a fresh authorized login rather than trying to bypass its authentication controls.

Wait for authenticated content, not just navigation

waitUntil: 'domcontentloaded' marks a navigation lifecycle point; it does not establish that a client-rendered authenticated page has finished loading. Follow navigation with a site-specific readiness check, such as an account heading or an application-ready marker you control. Then capture with page.screenshot().

Puppeteer returns a Uint8Array from page.screenshot() by default; requesting encoding: 'base64' returns a base64 string. Use path when you want Puppeteer to write the image file directly.

Cookie sessions and HTTP authentication are different

Situation Credential type Puppeteer API What it handles
Website or application login session Browser cookies issued by the site BrowserContext.cookies() and BrowserContext.setCookie() Reads and restores browser cookie state; the site still decides whether the session is valid.
HTTP authentication challenge HTTP authentication credentials Page.authenticate() Supplies credentials for HTTP authentication. Puppeteer enables request interception behind the scenes, which may affect performance.

Page.authenticate() is not a general replacement for a cookie-based website login. Choose the API for the authentication mechanism the target actually uses.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common failures and fixes

The page redirects to login

The cookies may be expired, revoked, rotated, scoped to another host or path, or rejected under the site’s session policy. Confirm you restored the full records into the context before navigation. If the site still rejects them, perform a fresh authorized login and save a new set.

The page loads, but the screenshot shows a shell or spinner

The navigation event completed before the application rendered its authenticated view. Replace a navigation-only wait with a selector or other readiness signal specific to the page.

The restored cookies appear to have no effect

Check that the page was created from the context receiving setCookie(), and that the cookie records retain their domain or URL association and attributes. A different context has separate storage.

The credentials are for a server HTTP challenge

Use Page.authenticate() for HTTP authentication rather than treating it as an application cookie session. Account for its request-interception behavior if performance matters.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
The SQL Programming Language: .
  • Used Book in Good Condition
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If you need a screenshot without managing a Puppeteer browser session, ScreenshotNeo is a website screenshot API and MCP server. A single GET request returns an image or PDF. It is not a way to replay your private Puppeteer cookie jar or access pages requiring your authenticated browser session.

For a public page, this cURL call saves a WebP screenshot. See the ScreenshotNeo API documentation for request options.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo accepts cookie and consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each of those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and each response says which outcome occurred through X-Page-Verdict and X-Billed headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents and MCP clients. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 screenshots.

Sign up for ScreenshotNeo’s free plan to try 1,000 screenshots a month without a card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.