Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Use cy.session() to cache the browser authentication state created by a login flow, then restore it instead of repeating the login in later tests. Put the login and a success assertion in the session’s setup callback, validate that the cached state still authenticates, and visit the page under test after cy.session() returns when test isolation is enabled.
What cy.session() caches and when it helps
cy.session(id, setup, options) saves cookies, localStorage, and sessionStorage after setup and validation. A later call with the same ID restores that browser state and skips setup while the session remains valid. This is useful when many tests need the same authenticated starting point but do not need to exercise the login interface itself.
Cypress’s test-performance guide estimates that a full login flow typically takes 2–5 seconds per test and says 100 tests may add 3–8 minutes of authentication overhead. These are Cypress’s illustrative estimates, not guaranteed timings for your application. Cypress test-performance guide.
Build a reusable UI-login session
Define the session once in a custom command or shared helper so specs use the same identity, setup, and validation rules. The example below assumes your application provides the indicated selectors, redirects after login, and exposes an authenticated-user API endpoint.
Free tools Windows power users keep installed
One-click scans. No signup required.
const login = (username, password) => {
cy.session(
['login', username],
() => {
cy.visit('/login')
cy.get('[data-test=name]').type(username)
cy.get('[data-test=password]').type(password, { log: false })
cy.get('form').contains('Log In').click()
cy.url().should('contain', '/login-successful')
},
{
validate() {
cy.request('/api/user').its('status').should('eq', 200)
},
}
)
}
it('shows the account page', () => {
login(Cypress.env('username'), Cypress.env('password'))
cy.visit('/account')
// assertions for the test
})
The URL assertion belongs inside setup: Cypress should not cache a state until the login has actually completed. The validate request checks that the restored browser state still works. Keep credentials outside source control; Cypress documents accessing environment values in session setup and suppressing password logging with { log: false }. See Cypress env documentation.
Choose an ID that represents the resulting session
The ID must distinguish every non-secret setup input that could produce a different authenticated state. Include a username, role, or tenant when that changes the session. Cypress accepts strings, arrays, and objects, and deterministically serializes arrays and objects. Do not put passwords or tokens in the ID: it is visible in Cypress reporting and debugging tools.
Visit the page under test after restoring
With testIsolation enabled, Cypress clears the page when caching and restoring the browser context. Call cy.visit('/account') or the relevant route after the session command. Without that visit, subsequent commands can run against a blank page. Consult the cy.session() API reference for the behavior associated with your configured isolation value.
Use an API login when the app supports it
If your application has a reliable authentication endpoint, establishing the session through HTTP can avoid navigating and typing through the login UI. Cypress documents using cy.request() in setup and checking its response; cookies set by the server are available to the browser through Cypress’s cookie jar.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchcy.session(
['login', username],
() => {
cy.request('POST', '/api/login', { username, password })
.its('status')
.should('eq', 200)
},
{
validate() {
cy.request('/api/user').its('status').should('eq', 200)
},
}
)
cy.visit('/account')
Adapt the endpoint, method, payload, and success condition to the application’s actual API. If authentication uses a bearer token rather than a server-set cookie, store the token in localStorage during setup so it is part of the browser state Cypress caches. A useful validation endpoint returns success only when the current user is authenticated. See Cypress API testing.
Understand validation and cache scope
What validation does
The validate callback runs after setup and when Cypress restores a saved session. If validation fails on restore, Cypress runs setup again; if validation fails immediately after setup, the test fails. Prefer a meaningful authenticated API request or a protected-page check over a check that merely proves the browser still has some cookies.
Rank #4
Sharing between specs
Set cacheAcrossSpecs: true when you want a session reused across specs in the same cypress run on one machine:
cy.session(
['login', username],
setupLogin,
{
validate: validateLogin,
cacheAcrossSpecs: true,
}
)
This cache does not carry over to a separate run or to another parallel CI machine. Each participating spec must call the session with consistent ID, setup, validation, and option values. Put the definition in a shared helper or custom command to reduce mismatches. Cypress records that cacheAcrossSpecs was added in 10.9.0 and that cy.session() became available by default in 12.0.0 after removal of experimentalSessionAndOrigin; check the API reference and your installed Cypress version before relying on version-specific behavior.
Recommended Free Tools
Best Value
Common problems and fixes
| Symptom | Likely cause | Fix |
|---|---|---|
| Blank page or commands fail after login | With test isolation enabled, the page was cleared during session caching or restoration. | Visit the page under test after cy.session() returns. |
| 401 after a cached session is restored | The session expired or setup did not establish complete authentication state. | Assert login success inside setup and validate with an authenticated endpoint. A failed restore validation will make Cypress recreate the session. |
| The wrong account, role, or tenant appears | The ID does not distinguish inputs that change the authenticated state. | Add the relevant non-secret identity inputs to the ID; never add passwords or tokens. |
| A session is not reused across specs | Cross-spec reuse is limited to one run on one machine, or specs use inconsistent session definitions. | Use cacheAcrossSpecs: true, share one definition, and expect each parallel machine or later run to establish its own cache. |
| Tests pass only in a particular order | Disabling test isolation can let browser state leak between tests. | Do not disable isolation solely as a speed workaround. Cypress cautions that it can cause inconsistency, including when a test is run alone with .only(). |
Or skip the browser setup
For capturing a web page as an image or PDF rather than testing its authentication flow, ScreenshotNeo offers a one-request website screenshot API. It can accept cookie or consent banners and remove more than 60 known consent platforms, newsletter popups, and chat widgets before capture; those cleanup steps can be turned off. Its responses identify page verdict and billing status, and bot checks, blank pages, timeouts, failed loads, and cache hits are not billed. An MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for parameters and response details. The Free plan includes 1,000 shots a month with no card; paid plans start at $5 for 3,000 shots. Sign up for 1,000 free screenshots a month, with no card required.
Frequently Asked Questions
Does cy.session() skip the login test itself?
It caches authentication setup for tests that need an already logged-in state; keep dedicated tests for the login flow when you need to test that interface.
Can I reuse a cached session across separate Cypress runs?
No. The cross-spec cache is scoped to one run on one machine.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

