Set browser permissions on a Puppeteer BrowserContext, scoped to the origin your test visits. In the stable Puppeteer 25.12.0 reference, overridePermissions() is documented but deprecated; the current Next reference documents setPermission() with explicit permission states. Check the reference for your installed version before choosing between them.
Choose the permission API for your Puppeteer version
Puppeteer configures permissions on a browser context, not on a Page. A context can be the browser’s default context or a separate context created for a test. Configure it before navigating to or exercising the feature that needs the permission.
| API | Input | Documented behavior and status |
|---|---|---|
overridePermissions(origin, permissions) |
An origin string and an array of permission names | In the stable Puppeteer 25.12.0 reference, this method is deprecated in favor of setPermission(). Listed permissions are granted; permissions omitted from the array are automatically denied for that origin. |
setPermission(origin, ...permissions) |
An origin string or '*', followed by permission descriptors and states |
The current Next API reference documents this form. It lets you specify states such as 'granted'. That future-facing reference does not establish identical release status or omitted-permission behavior to the stable API. |
Use the API available in the Puppeteer release actually installed in your project. The stable page identifies version 25.12.0, while the Next page is future-facing and may change. See the stable BrowserContext API reference and the Next BrowserContext API reference.
Grant a permission with the stable override API
This example follows the stable reference’s array-of-permissions form. It grants geolocation to https://example.com; because omitted permissions are denied for that origin under this API, do not treat the array as a list of only the permissions you happen to want to mention.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
const puppeteer = require('puppeteer');
(async () => {
const browser = await puppeteer.launch();
const context = browser.defaultBrowserContext();
await context.overridePermissions('https://example.com', ['geolocation']);
const page = await context.newPage();
await page.goto('https://example.com');
// Exercise the page feature that requires geolocation here.
// This clears all permission overrides for this context.
await context.clearPermissionOverrides();
await browser.close();
})();
The origin should match the site under test. For separate test isolation, Puppeteer also documents creating a new browser context; contexts do not share cookies or cache with one another. See the Browser.createBrowserContext() API reference.
Set an explicit permission state with the current Next API
The Next reference documents a descriptor-plus-state object. This example grants geolocation. Confirm that the installed release supports this method and signature before using it in production.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
await context.setPermission('https://example.com', {
permission: { name: 'geolocation' },
state: 'granted',
});
The Next signature accepts an origin string or '*' and a variable number of permission/state objects. Do not assume permissions you omit are denied as they are with overridePermissions(); the cited Next reference does not state that behavior.
Allow clipboard access
Puppeteer’s Mouse API documentation discusses granting clipboard-read and clipboard-write to access the clipboard. With the stable override-style API, the permissions are supplied as names:
Recommended Free Tools
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
await context.overridePermissions('https://example.com', [
'clipboard-read',
'clipboard-write',
]);
Use the equivalent descriptor-and-state form only if it is supported by your installed Puppeteer version and browser. The official material cited here does not provide a complete compatibility matrix for every permission descriptor and browser combination. See the Puppeteer Mouse API documentation.
Reset permission overrides after a test
clearPermissionOverrides() removes all permission overrides for the context. It is context-wide, not an origin-specific undo operation, so call it with that scope in mind when a context is shared across tests.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
await context.clearPermissionOverrides();
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Common problems and fixes
- The method or signature is unavailable: You may be following the Next API while using a release that does not expose it. Check the reference matching your installed Puppeteer version; use the stable documented method only with awareness that it is deprecated there.
- The page still shows a permission prompt or denial: Confirm you set the permission on the context that owns the page, and that the origin matches the page. Apply the setting before exercising the feature.
- An unrelated permission is denied: With
overridePermissions(), omitted permissions are automatically denied for that origin. Include the required permissions in the array, or use an explicit-state API if your installed version supports it. - A permission name is rejected or has no effect: Permission availability and behavior depend on the browser and Puppeteer combination. The legacy permission type lists examples such as geolocation, notifications, camera, microphone and clipboard access, but it is obsolete and is not a current compatibility matrix. Verify support for the descriptor you need rather than assuming all names work everywhere.
- A later test behaves unexpectedly: The reset method clears overrides for the whole context. Prefer a dedicated context when tests need independent permission settings.
Or skip the browser setup
If your goal is a screenshot rather than testing a page’s permission-dependent behavior, ScreenshotNeo provides a screenshot API and MCP server. Its capture flow accepts consent banners like a visitor and removes 60+ known consent platforms, newsletter popups and chat widgets; those steps can be turned off. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers report the page verdict and billing status. AI agents can use its MCP tools, including take_screenshot, get_page_info and capture_pdf.
One GET request captures a URL. See the ScreenshotNeo API documentation for request options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Sign up for the free plan.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

