Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Use Puppeteer to launch Chrome with your unpacked extension, sign in to the site through its permitted login flow, wait for a page-specific authenticated state, and capture it with page.screenshot(). An extension can add browser behavior or be triggered on the page, but it does not log you into the website. The example below uses a separate, persistent browser profile so an authorized session can be retained between runs.
What you need before you start
- A current Puppeteer installation and a Chrome extension in an unpacked directory.
- Permission to access the target account and automate its normal login flow.
- A writable directory for a dedicated browser profile. Treat it as sensitive: it can contain live session data.
Puppeteer’s Chrome Extensions guide documents loading unpacked extensions at launch or installing one at runtime. The guide and API names can change across versions, so check the Chrome Extensions guide and use the API supported by the Puppeteer version deployed in your environment. The current documentation identifies Puppeteer 25.12.0; verify your installed version rather than assuming the current documentation matches an older project.
Load an extension and capture an authenticated page
Launch with a known extension directory
When the extension path is known before startup, pass it through enableExtensions. This complete example opens a dedicated profile, pauses for a normal sign-in, checks an example authenticated-page selector, and saves a screenshot. Replace the extension path, sign-in URL, target URL, and selector with values for your site.
import puppeteer from 'puppeteer';
const extensionPath = '/absolute/path/to/unpacked-extension';
const profilePath = '/absolute/path/to/puppeteer-profile';
const loginUrl = 'https://example.com/login';
const targetUrl = 'https://example.com/account';
const authenticatedSelector = '[data-testid="account-home"]';
const browser = await puppeteer.launch({
headless: false,
userDataDir: profilePath,
enableExtensions: [extensionPath],
});
try {
const page = await browser.newPage();
await page.goto(loginUrl, { waitUntil: 'domcontentloaded' });
console.log('Sign in through the site in the opened browser window.');
// Wait for a site-specific element that appears only when signed in.
await page.waitForSelector(authenticatedSelector, { timeout: 120000 });
await page.goto(targetUrl, { waitUntil: 'domcontentloaded' });
await page.waitForSelector(authenticatedSelector, { timeout: 30000 });
await page.screenshot({ path: 'capture.png', fullPage: true });
} finally {
await browser.close();
}
The selector in this example is illustrative, not a universal login check. Choose an element or other condition that proves the target page is both rendered and authenticated. A successful navigation or network-idle event alone does not establish that the site accepted the session. Puppeteer’s Screenshots guide documents Page.screenshot().
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Install the extension after launch
If the extension directory is selected dynamically, launch with extensions enabled, then install the directory using the runtime API. This is an alternative to supplying a list at launch; use the API available in your installed version.
import puppeteer from 'puppeteer';
const browser = await puppeteer.launch({
headless: false,
userDataDir: '/absolute/path/to/puppeteer-profile',
enableExtensions: true,
});
try {
const extension = await browser.installExtension(
'/absolute/path/to/unpacked-extension'
);
const page = await browser.newPage();
await page.goto('https://example.com/account', {
waitUntil: 'domcontentloaded',
});
await page.waitForSelector('[data-testid="account-home"]', {
timeout: 30000,
});
await page.screenshot({ path: 'capture.png', fullPage: true });
} finally {
await browser.close();
}
Use launch-time loading for a fixed set of extensions. Runtime installation is useful when the script must choose extensions after launch. Keep the unpacked directory available to the running process. See Puppeteer’s LaunchOptions interface for launch configuration details.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Keep the website session separate from extension behavior
The site’s own login flow establishes the ordinary web-app session. A dedicated userDataDir provides a persistent place for that browser session; using a separate directory also avoids depending on a personal Chrome profile. Puppeteer documents userDataDir as a launch option and notes that Chrome needs a writable user-data directory.
Do not treat Page.authenticate() as a general account-login mechanism. It is for HTTP authentication credentials, not signing into a typical web application. Puppeteer’s cookie API describes cookie fields such as name, value, domain, path, expiry, and security attributes, but that documentation does not establish that copying cookies is permitted, sufficient, or appropriate for a particular site. Use an authorized login or session-setup method for the site.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
If the extension must perform an action, Puppeteer documents page.triggerExtensionAction(extension) and extension.triggerAction(page). The extension APIs can also inspect an extension service worker or background page and evaluate code in an extension content-script realm. Those operations control extension behavior; they do not authenticate the page. See the Extension class reference.
Choose profile persistence and browser mode deliberately
- Persistent, isolated profile: use a dedicated
userDataDirif an authorized login should remain available between runs. Restrict access to the profile directory and do not commit it, publish it, or share it as an ordinary artifact. - Fresh profile: use a new temporary profile when each run should begin without retained browser state. You will need to complete an authorized login or other approved session setup again.
- Headful or headless: headful mode is useful when a person needs to interact with the login page. Puppeteer’s current browser documentation says Puppeteer v20 and later uses Chrome for Testing, with headless and headful modes sharing the same browser code path. Still verify your extension and Puppeteer version in the environment where the capture will run.
The official documentation does not promise that reusing an existing personal Chrome profile is safe or conflict-free. Prefer a dedicated profile for automation rather than assuming a profile already open in Chrome can be reused.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Run Chrome with its sandbox intact
Keep Chrome’s sandbox enabled in normal deployments. Puppeteer’s troubleshooting guidance strongly discourages running with --no-sandbox and recommends configuring the sandbox. If Chrome will not launch in a container, first investigate host sandbox support and whether the profile directory is writable; do not make sandbox removal the routine fix. See Puppeteer troubleshooting.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteTroubleshoot common failures
| Symptom | Likely cause | What to check or do |
|---|---|---|
| Chrome fails to launch | The profile directory is not writable, or the host/container sandbox is not configured. | Use a writable, dedicated userDataDir and diagnose the host sandbox setup. Follow the troubleshooting guidance instead of routinely disabling the sandbox. |
| The extension is missing | The unpacked path is wrong, unavailable to the process, or the selected loading API does not match the installed Puppeteer version. | Confirm the directory exists and remains available, then check the extension guide and your installed version. Use either launch-time enableExtensions: [path] or runtime installation with enableExtensions: true. |
| The script times out waiting for the authenticated selector | Login may not have completed, the selector may not be unique to the signed-in page, or the target page may render differently. | Inspect the page in the browser, complete the site’s permitted login flow, and choose a selector or other condition that is specific to authenticated content. Do not substitute network idleness for proof of authentication. |
| The extension loads but does not affect the page | Loading an extension does not necessarily invoke its action. | Check whether the extension requires its default action, and use the documented extension action API where appropriate. Keep extension execution separate from the site’s login steps. |
Page.authenticate() does not sign in to the account |
It handles HTTP authentication, not a normal application login form or session. | Use the site’s authorized login flow or an explicitly approved session setup. |
| A previously logged-in run is no longer authenticated | The site may have expired or invalidated the session, or the run may be using a different profile. | Confirm the exact userDataDir, then sign in again through the permitted flow and verify the authenticated state before capture. |
Performance, reliability, and cost considerations
- Wait for the right signal: wait for a target-specific authenticated element or state rather than relying only on navigation completion. This avoids capturing a login screen or partially rendered account page.
- Keep extension work scoped: load only the extension behavior needed for the capture and trigger it explicitly when required. The documentation describes APIs, not a universal performance cost for a particular extension.
- Protect retained state: a persistent profile saves repeated login work but also retains session data. Limit who and what can read it, and use a fresh profile when retention is unnecessary.
- Test the deployed combination: browser mode, Puppeteer version, extension version, and host/container configuration all matter. The official browser support guidance does not guarantee compatibility for every extension.
- Budget for the actual workflow: there is no documented timing or cost figure for this specific combination. Measure it in the intended environment, including login handling, page readiness, extension actions, and screenshot output.
Or skip the browser setup
If the goal is simply a clean capture of a publicly accessible page, ScreenshotNeo offers a screenshot API and MCP server. It is not a way around a site’s authentication controls: this example captures a public page and does not log into an account. See the ScreenshotNeo API documentation for request options and response details.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
ScreenshotNeo accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and the response identifies the page verdict and billing status in headers. Its MCP server gives AI agents tools for screenshots, page information, and PDF capture. The Free plan includes 1,000 shots a month with no card; paid plans start at $5 for 3,000 shots.
Sign up for ScreenshotNeo’s free plan to get 1,000 screenshots a month with no card.
Frequently Asked Questions
Can Puppeteer use a Chrome extension in headless mode?
Puppeteer’s current browser documentation says Puppeteer v20 and later uses Chrome for Testing and shares the same browser code path in headless and headful modes. Verify the extension in your actual deployed version and environment.
Does loading a Chrome extension log me into a website?
No. Extension loading and extension actions control the extension; the website’s permitted login or session setup controls whether the page is authenticated.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

