Call response.securityDetails() on the Puppeteer HTTPResponse you want to inspect. It returns TLS and certificate metadata for a response received over a secure connection, or null when those details are unavailable. Handle that separately from page.goto() itself returning null.
Get the response and inspect its security details
For a navigation, use the value returned by page.goto(). This complete ES-module example checks both nullable results, prints the documented fields, and closes the browser even if navigation or inspection throws.
import puppeteer from 'puppeteer';
const browser = await puppeteer.launch();
try {
const page = await browser.newPage();
const response = await page.goto('https://example.com');
if (response === null) {
console.log('No navigation response object');
} else {
const details = response.securityDetails();
if (details === null) {
console.log('No secure-connection details for this response');
} else {
console.log({
protocol: details.protocol(),
issuer: details.issuer(),
subject: details.subjectName(),
subjectAlternativeNames: details.subjectAlternativeNames(),
validFrom: details.validFrom(),
validTo: details.validTo(),
});
}
}
} finally {
await browser.close();
}
The documented Puppeteer SecurityDetails API describes these details as belonging to a response received over a secure connection. At the time of the reviewed reference (Puppeteer 25.12.0, October 3, 2026), the methods shown above expose protocol, issuer, subject name, subject alternative names, and certificate validity timestamps. Check the API signatures against your installed Puppeteer version, since the repository’s main branch can change.
Understand null results and the returned fields
Two different reasons for null
page.goto()can returnnullfor cases such as navigation toabout:blankor a same-URL navigation that changes only the hash. In that case there is no response object on which to call the method.- If a response object exists but
response.securityDetails()isnull, Puppeteer has no secure-connection details to return for that response. Do not treat this as the same condition as a missing navigation response.
The navigation and response-event behavior is documented in the Puppeteer Page API.
#1 Best Overall
What each method reports
| Method | Meaning |
|---|---|
protocol() |
Security protocol in use; the API reference gives TLS 1.2 as an example. |
issuer() |
Certificate issuer name. |
subjectName() |
Certificate subject name. |
subjectAlternativeNames() |
The certificate’s subject alternative names (SANs). |
validFrom() |
Unix timestamp marking the start of the certificate validity period. |
validTo() |
Unix timestamp marking the end of the certificate validity period. |
Convert the validity timestamps for display with new Date(timestamp * 1000), because JavaScript dates take milliseconds while these values are Unix timestamps in seconds.
Inspect responses beyond the main navigation
When the response of interest is an image, script, API call, or another request made while a page is loading, listen for page response events. This example logs the response URL and protocol when security details are present, and null otherwise:
Rank #2
- HTML CSS Design and Build Web Sites
- Comes with secure packaging
- It can be a gift option
page.on('response', response => {
const details = response.securityDetails();
console.log(response.url(), details?.protocol() ?? null);
});
A response event supplies an HTTPResponse; the listener can therefore inspect the same securityDetails() method as a navigation response. For production code, filter by URL or another property so the listener processes only the responses relevant to your task.
Keep TLS metadata separate from other response checks
securityDetails() reports documented secure-connection metadata; it is not a general response-security summary. Puppeteer exposes other observations on HTTPResponse for different questions:
Rank #3
headers()for response headers, including policy headers. Header names are lowercase in the returned object. Duplicate header values are combined with commas, exceptSet-Cookievalues, which are separated by newlines.status()for the HTTP status code.remoteAddress()for connection address information.fromCache()andfromServiceWorker()for cache and service-worker state.request()to reach the request associated with the response.
The API reference documents these as distinct response properties; the available certificate fields alone do not establish a complete certificate-chain report or an overall security verdict for a site.
Interpret redirects, HTTP errors, and failed requests correctly
A non-2xx status is still an HTTP response. For example, an HTTP 404 or 503 can complete normally as a response, so inspect response.status() rather than classifying every such status as a network failure.
Rank #4
- Brand: Wiley
- Set of 2 Volumes
- A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers
Redirects involve separate requests: the redirecting request finishes and another request is issued for the destination URL. If you need the final destination’s metadata, inspect the response for that destination rather than assuming the first response describes it.
Puppeteer distinguishes request lifecycle events: a request emits request, then requestfinished when its response body has downloaded and the request is complete; a failed request instead emits requestfailed. A request that fails before an HTTP response exists has no response object from which to read security details. See the Page API event documentation.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBest Value
Troubleshoot missing or unexpected details
responseis null: The navigation did not provide an HTTP response object, as can occur forabout:blankor a same-URL hash change. Do not call a method on it.securityDetails()is null: The response has no secure-connection details available through this method. Check that you are inspecting the intended response and that it was received over a secure connection.- You see an unexpected status: Read
status(); HTTP error statuses still represent responses and are not equivalent to failed requests. - The inspected URL is a redirect hop: Track the response URL and inspect the subsequent destination response if that is the connection you need to examine.
- A listener reports too many entries: Page response events cover page traffic, not just the main document. Filter on
response.url()or other relevant response properties. - Validity dates look far in the future or past: Treat
validFrom()andvalidTo()as Unix seconds and multiply by 1,000 when constructing a JavaScriptDate.
Or skip the browser setup
If your goal is a page screenshot rather than inspecting Puppeteer’s response metadata, ScreenshotNeo is a website screenshot API and MCP server. It returns an image or PDF from one GET request; its documented behavior is screenshot capture, not a replacement for reading Puppeteer’s TLS fields.
For a screenshot, the cURL call is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
See the ScreenshotNeo API documentation for parameters and response details. Cookie banners, newsletter popups, and chat widgets are removed before capture; bot checks, blank pages, failed loads, timeouts, and cache hits are not billed. Its MCP server offers take_screenshot, get_page_info, and capture_pdf for AI agents and MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for ScreenshotNeo’s free plan.
Safety note
Puppeteer’s security policy says: “Puppeteer provides powerful capabilities for browser installation, automation, and inspection, and it is the responsibility of the calling code to ensure these are used safely and as intended.” This is general guidance for using the automation library, not a claim that securityDetails() itself is unsafe.
Frequently Asked Questions
Does a non-2xx response have security details?
It may still be an HTTP response; check whether its securityDetails() value is non-null rather than inferring availability from the status code.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsIs securityDetails() a complete website security audit?
No. It provides the documented connection and certificate metadata, not a complete site-security verdict.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

