Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Call response.securityDetails() on the Puppeteer HTTPResponse you want to inspect. It returns TLS and certificate metadata for a response received over a secure connection, or null when those details are unavailable. Handle that separately from page.goto() itself returning null.

Get the response and inspect its security details

For a navigation, use the value returned by page.goto(). This complete ES-module example checks both nullable results, prints the documented fields, and closes the browser even if navigation or inspection throws.

import puppeteer from 'puppeteer';

const browser = await puppeteer.launch();
try {
  const page = await browser.newPage();
  const response = await page.goto('https://example.com');

  if (response === null) {
    console.log('No navigation response object');
  } else {
    const details = response.securityDetails();
    if (details === null) {
      console.log('No secure-connection details for this response');
    } else {
      console.log({
        protocol: details.protocol(),
        issuer: details.issuer(),
        subject: details.subjectName(),
        subjectAlternativeNames: details.subjectAlternativeNames(),
        validFrom: details.validFrom(),
        validTo: details.validTo(),
      });
    }
  }
} finally {
  await browser.close();
}

The documented Puppeteer SecurityDetails API describes these details as belonging to a response received over a secure connection. At the time of the reviewed reference (Puppeteer 25.12.0, October 3, 2026), the methods shown above expose protocol, issuer, subject name, subject alternative names, and certificate validity timestamps. Check the API signatures against your installed Puppeteer version, since the repository’s main branch can change.

Understand null results and the returned fields

Two different reasons for null

  • page.goto() can return null for cases such as navigation to about:blank or a same-URL navigation that changes only the hash. In that case there is no response object on which to call the method.
  • If a response object exists but response.securityDetails() is null, Puppeteer has no secure-connection details to return for that response. Do not treat this as the same condition as a missing navigation response.

The navigation and response-event behavior is documented in the Puppeteer Page API.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What each method reports

Method Meaning
protocol() Security protocol in use; the API reference gives TLS 1.2 as an example.
issuer() Certificate issuer name.
subjectName() Certificate subject name.
subjectAlternativeNames() The certificate’s subject alternative names (SANs).
validFrom() Unix timestamp marking the start of the certificate validity period.
validTo() Unix timestamp marking the end of the certificate validity period.

Convert the validity timestamps for display with new Date(timestamp * 1000), because JavaScript dates take milliseconds while these values are Unix timestamps in seconds.

Inspect responses beyond the main navigation

When the response of interest is an image, script, API call, or another request made while a page is loading, listen for page response events. This example logs the response URL and protocol when security details are present, and null otherwise:

Rank #2
Sale
HTML and CSS: Design and Build Websites
  • HTML CSS Design and Build Web Sites
  • Comes with secure packaging
  • It can be a gift option
page.on('response', response => {
  const details = response.securityDetails();
  console.log(response.url(), details?.protocol() ?? null);
});

A response event supplies an HTTPResponse; the listener can therefore inspect the same securityDetails() method as a navigation response. For production code, filter by URL or another property so the listener processes only the responses relevant to your task.

Keep TLS metadata separate from other response checks

securityDetails() reports documented secure-connection metadata; it is not a general response-security summary. Puppeteer exposes other observations on HTTPResponse for different questions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • headers() for response headers, including policy headers. Header names are lowercase in the returned object. Duplicate header values are combined with commas, except Set-Cookie values, which are separated by newlines.
  • status() for the HTTP status code.
  • remoteAddress() for connection address information.
  • fromCache() and fromServiceWorker() for cache and service-worker state.
  • request() to reach the request associated with the response.

The API reference documents these as distinct response properties; the available certificate fields alone do not establish a complete certificate-chain report or an overall security verdict for a site.

Interpret redirects, HTTP errors, and failed requests correctly

A non-2xx status is still an HTTP response. For example, an HTTP 404 or 503 can complete normally as a response, so inspect response.status() rather than classifying every such status as a network failure.

Rank #4
Sale
Web Design with HTML, CSS, JavaScript and jQuery Set
  • Brand: Wiley
  • Set of 2 Volumes
  • A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers

Redirects involve separate requests: the redirecting request finishes and another request is issued for the destination URL. If you need the final destination’s metadata, inspect the response for that destination rather than assuming the first response describes it.

Puppeteer distinguishes request lifecycle events: a request emits request, then requestfinished when its response body has downloaded and the request is complete; a failed request instead emits requestfailed. A request that fails before an HTTP response exists has no response object from which to read security details. See the Page API event documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot missing or unexpected details

  • response is null: The navigation did not provide an HTTP response object, as can occur for about:blank or a same-URL hash change. Do not call a method on it.
  • securityDetails() is null: The response has no secure-connection details available through this method. Check that you are inspecting the intended response and that it was received over a secure connection.
  • You see an unexpected status: Read status(); HTTP error statuses still represent responses and are not equivalent to failed requests.
  • The inspected URL is a redirect hop: Track the response URL and inspect the subsequent destination response if that is the connection you need to examine.
  • A listener reports too many entries: Page response events cover page traffic, not just the main document. Filter on response.url() or other relevant response properties.
  • Validity dates look far in the future or past: Treat validFrom() and validTo() as Unix seconds and multiply by 1,000 when constructing a JavaScript Date.

Or skip the browser setup

If your goal is a page screenshot rather than inspecting Puppeteer’s response metadata, ScreenshotNeo is a website screenshot API and MCP server. It returns an image or PDF from one GET request; its documented behavior is screenshot capture, not a replacement for reading Puppeteer’s TLS fields.

For a screenshot, the cURL call is:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp

See the ScreenshotNeo API documentation for parameters and response details. Cookie banners, newsletter popups, and chat widgets are removed before capture; bot checks, blank pages, failed loads, timeouts, and cache hits are not billed. Its MCP server offers take_screenshot, get_page_info, and capture_pdf for AI agents and MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for ScreenshotNeo’s free plan.

Safety note

Puppeteer’s security policy says: “Puppeteer provides powerful capabilities for browser installation, automation, and inspection, and it is the responsibility of the calling code to ensure these are used safely and as intended.” This is general guidance for using the automation library, not a claim that securityDetails() itself is unsafe.

Frequently Asked Questions

Does a non-2xx response have security details?

It may still be an HTTP response; check whether its securityDetails() value is non-null rather than inferring availability from the status code.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is securityDetails() a complete website security audit?

No. It provides the documented connection and certificate metadata, not a complete site-security verdict.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.