To capture a page that requires login, save the cookies from the Puppeteer BrowserContext used for your authorized login, restore those cookie objects into the same kind of context before navigating, wait for a site-specific sign of authenticated content, then call page.screenshot(). Cookie replay works only while the site still accepts that session.
Save cookies after an authorized login
Puppeteer can retrieve cookies from a browser context and set them later. Keeping the page and cookie jar in an explicit BrowserContext makes it clear which isolated browser storage belongs to the page.
import puppeteer from 'puppeteer';
import { writeFile } from 'node:fs/promises';
const browser = await puppeteer.launch();
try {
const context = await browser.createBrowserContext();
const page = await context.newPage();
await page.goto('https://example.com/login');
// Complete the site's authorized login steps here.
const cookies = await context.cookies();
await writeFile('cookies.json', JSON.stringify(cookies, null, 2), {
mode: 0o600,
});
} finally {
await browser.close();
}
Replace the example URL and login placeholder with a flow you are authorized to run. The restrictive file mode is an operational precaution, not a security feature provided or guaranteed by Puppeteer.
Protect the saved file
Cookie values can function as credentials. Keep the file out of source control and logs, restrict access to it, and delete it when it is no longer needed. Puppeteer documents cookie APIs and fields, not a secure cookie-storage system.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Restore cookies before navigating
Load the saved cookie objects into the context before opening the page that needs authentication. Create the page from that context so it uses the restored storage.
import puppeteer from 'puppeteer';
import { readFile } from 'node:fs/promises';
const browser = await puppeteer.launch();
try {
const context = await browser.createBrowserContext();
const cookies = JSON.parse(await readFile('cookies.json', 'utf8'));
await context.setCookie(...cookies);
const page = await context.newPage();
await page.goto('https://example.com/account', {
waitUntil: 'domcontentloaded',
});
await page.waitForSelector('[data-testid="account-home"]');
await page.screenshot({ path: 'account.png', fullPage: true });
} finally {
await browser.close();
}
Change the account URL and selector to match the target application. If the site does not expose a stable selector, wait for another application-ready signal that distinguishes the authenticated view from a login page or loading shell.
Keep cookie scope and context intact
A BrowserContext isolates browser storage, including cookies and local storage. Restoring cookies into one context does not authenticate a page created in another. Puppeteer’s browser-level cookie methods operate as shortcuts to the default context; use context-level methods when you need explicit isolation.
Rank #2
Cookie records can include a name and value plus scope and security attributes such as domain, expiry, httpOnly, path, sameSite, secure, partition key, priority, and source scheme. If expires is omitted, the cookie is a session cookie. A cookie parameter can also use a URL, which can affect default domain, path, and source scheme.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches- Preserve the cookie objects returned by Puppeteer instead of reducing them to just
{ name, value }. - Restore the records into a context before navigating to the relevant site.
- Do not assume a copied cookie remains valid: it may have expired, been revoked or rotated, or be restricted by the site’s session policy.
If the site rejects the restored session, use a fresh authorized login rather than trying to bypass its authentication controls.
Wait for authenticated content, not just navigation
waitUntil: 'domcontentloaded' marks a navigation lifecycle point; it does not establish that a client-rendered authenticated page has finished loading. Follow navigation with a site-specific readiness check, such as an account heading or an application-ready marker you control. Then capture with page.screenshot().
Puppeteer returns a Uint8Array from page.screenshot() by default; requesting encoding: 'base64' returns a base64 string. Use path when you want Puppeteer to write the image file directly.
Cookie sessions and HTTP authentication are different
| Situation | Credential type | Puppeteer API | What it handles |
|---|---|---|---|
| Website or application login session | Browser cookies issued by the site | BrowserContext.cookies() and BrowserContext.setCookie() |
Reads and restores browser cookie state; the site still decides whether the session is valid. |
| HTTP authentication challenge | HTTP authentication credentials | Page.authenticate() |
Supplies credentials for HTTP authentication. Puppeteer enables request interception behind the scenes, which may affect performance. |
Page.authenticate() is not a general replacement for a cookie-based website login. Choose the API for the authentication mechanism the target actually uses.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Common failures and fixes
The page redirects to login
The cookies may be expired, revoked, rotated, scoped to another host or path, or rejected under the site’s session policy. Confirm you restored the full records into the context before navigation. If the site still rejects them, perform a fresh authorized login and save a new set.
Rank #4
The page loads, but the screenshot shows a shell or spinner
The navigation event completed before the application rendered its authenticated view. Replace a navigation-only wait with a selector or other readiness signal specific to the page.
The restored cookies appear to have no effect
Check that the page was created from the context receiving setCookie(), and that the cookie records retain their domain or URL association and attributes. A different context has separate storage.
The credentials are for a server HTTP challenge
Use Page.authenticate() for HTTP authentication rather than treating it as an application cookie session. Account for its request-interception behavior if performance matters.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Best Value
- Used Book in Good Condition
Or skip the browser setup
If you need a screenshot without managing a Puppeteer browser session, ScreenshotNeo is a website screenshot API and MCP server. A single GET request returns an image or PDF. It is not a way to replay your private Puppeteer cookie jar or access pages requiring your authenticated browser session.
For a public page, this cURL call saves a WebP screenshot. See the ScreenshotNeo API documentation for request options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
ScreenshotNeo accepts cookie and consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each of those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and each response says which outcome occurred through X-Page-Verdict and X-Billed headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents and MCP clients. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 screenshots.
Sign up for ScreenshotNeo’s free plan to try 1,000 screenshots a month without a card.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

