Store Playwright login state as a short-lived secret, not as a project file: generate it in a trusted setup step or inject it only into a trusted scheduled job, keep it out of source control, restrict who and what can access it, and delete or refresh it when it expires. Protect screenshots, traces, reports, and logs too; they can expose authenticated data or execution secrets.
What Playwright login state contains—and why it is sensitive
Playwright’s authentication guide warns that saved authentication state may contain cookies and headers that can impersonate a user. The BrowserContext API reference describes additional possible state, including cookies, local storage, IndexedDB, origin private file system entries, and virtual WebAuthn credentials. When virtual credentials are included, the captured state carries private keys.
Treat the complete state file as a credential, with access no broader than the account and pages the screenshot job requires. Enable capture of WebAuthn credentials only if the application needs them, and apply the same protections to any separately saved session data.
Choose how the scheduled job gets valid state
Generate state during each run
Use a trusted setup step to authenticate through the flow supported by the application, save the resulting context state, then let the screenshot step reuse it. This avoids retaining authentication state between runs, but depends on a repeatable login flow and requires the job to receive any primary credentials securely. Playwright documents saving state and reusing it, including through setup projects, in its authentication guide.
#1 Best Overall
- USB-C 2-in-1 storage OTG: The Lexar JumpDrive Dual Drive D40E features USB Type-A and Type-C connectors in a slim, portable form factor for easy device compatibility
- Transfer speeds up to 100MB/s: Based on internal testing, performance may vary depending upon the host device, interface, and usage conditions. 1MB=1,000,000 bytes
- Plug and Play: Widely compatible with USB Type-C smartphones, tablets, laptops, Macs, and traditional Type-A devices, no software installation required. The 360° swivel design allows for easy switching between connectors without the hassle of losing a cap
- Durable & Compact: The Lexar D40E USB memory stick features a metal enclosure, withstands temperatures from 0° to 50° C (32°F to 122°F), and is lightweight at 26g with dimensions of 70.4 x 16.9 x 11.7mm
- Security & Warranty: Securely protects files using an advanced security software solution with 256-bit AES encryption. Backed by a Lexar 3-year limited warranty
Inject state generated earlier
Deliver a protected state file to the scheduled runner at runtime, using the secret-storage or protected-file mechanism available in your CI environment. This can suit applications whose login flow is difficult to automate, but it makes expiry, rotation, access restriction, and secure delivery especially important. Playwright describes state reuse; it does not prescribe a particular secret manager or delivery system.
Choose between these approaches by checking whether login is repeatable, how long state remains valid, how narrowly your CI can scope access, whether state must persist between runs, and whether the application depends on sessionStorage or WebAuthn. The right vault and workflow permissions depend on your CI provider and organization.
Rank #2
- High-speed USB 3.0 performance of up to 150MB/s(1) [(1) Write to drive up to 15x faster than standard USB 2.0 drives (4MB/s); varies by drive capacity. Up to 150MB/s read speed. USB 3.0 port required. Based on internal testing; performance may be lower depending on host device, usage conditions, and other factors; 1MB=1,000,000 bytes]
- Transfer a full-length movie in less than 30 seconds(2) [(2) Based on 1.2GB MPEG-4 video transfer with USB 3.0 host device. Results may vary based on host device, file attributes and other factors]
- Transfer to drive up to 15 times faster than standard USB 2.0 drives(1)
- Sleek, durable metal casing
- Easy-to-use password protection for your private files(3) [(3)Password protection uses 128-bit AES encryption and is supported by Windows 7, Windows 8, Windows 10, and Mac OS X v10.9 plus; Software download required for Mac, visit the SanDisk SecureAccess support page]
Set up a secure state lifecycle
- Generate or refresh state in a trusted process. Use the application’s approved authentication flow. Do not create or update reusable state from an untrusted pull request or a job that can expose it to untrusted code.
- Keep it out of Git. Playwright recommends putting the authentication directory in
.gitignore. Check existing history and build contexts too; ignoring a file prevents future tracking, not exposure of a copy already committed. - Deliver state only to the job that needs it. Inject it at runtime or create it in the job’s workspace. Limit access to approved schedules and other trusted triggers, and grant only the repository or cloud permissions needed for the capture.
- Use an ephemeral workspace when practical. Keep the state available only for the run, then remove it along with other temporary authentication files. Playwright notes that project output directories can be cleaned before each test run when state does not need to persist.
- Handle expiration deliberately. Authentication lifetime is application-specific. Detect failed or expired authentication, then refresh through an approved process or stop the capture safely. Do not print raw state to logs or upload it as an ordinary artifact.
- Delete or rotate state that is no longer needed. If a state file may have been exposed, treat it as compromised: revoke or invalidate the relevant session through the application where possible, replace the stored state, and review who could access the exposed copy.
Keep secrets out of untrusted CI runs
Make the screenshot workflow run only on trusted schedules or other approved events. Playwright’s CI documentation notes that GitHub Actions workflows triggered by pull requests from forks cannot access secrets. Preserve that boundary rather than weakening it to make screenshots run. The exact permission settings vary by CI provider; verify the provider’s current controls and restrict both secret access and workflow permissions.
A schedule does not by itself make every part of a workflow trusted. Review which branches, events, reusable workflows, scripts, and contributors can change or invoke the job. Avoid exposing a secret to a job that checks out and executes untrusted code.
Rank #3
- What You Get - 2 pack 64GB genuine USB 2.0 flash drives, 12-month warranty and lifetime friendly customer service
- Great for All Ages and Purposes – the thumb drives are suitable for storing digital data for school, business or daily usage. Apply to data storage of music, photos, movies and other files
- Easy to Use - Plug and play USB memory stick, no need to install any software. Support Windows 7 / 8 / 10 / Vista / XP / Unix / 2000 / ME / NT Linux and Mac OS, compatible with USB 2.0 and 1.1 ports
- Convenient Design - 360°metal swivel cap with matt surface and ring designed zip drive can protect USB connector, avoid to leave your fingerprint and easily attach to your key chain to avoid from losing and for easy carrying
- Brand Yourself - Brand the flash drive with your company's name and provide company's overview, policies, etc. to the newly joined employees or your customers
Protect screenshots and debugging artifacts
A screenshot of a logged-in page may reveal personal or business information even when the state file is never uploaded. Playwright also warns in its CI documentation that traces, HTML reports, and console logs can contain sensitive execution data, including credentials and access tokens, as well as test and application source code.
- Upload captures and diagnostics only to storage with access controls appropriate to the page’s sensitivity.
- Encrypt artifacts before sharing them if the destination or sharing path is not sufficiently protected.
- Limit artifact retention to what debugging or reporting actually requires, and restrict who can download it.
- Review traces, reports, and logs before making them broadly accessible; do not assume a diagnostic file is safe because it is not named
auth.json. - Set capture targets and test accounts so screenshots expose only the data needed for the task.
Playwright’s GitHub Actions CI example uses retention-days: 30 for artifacts. That is an example configuration value, not a universal security recommendation; choose retention based on your data and operational requirements.
Rank #4
- GOOD VALUE PACKAGE - 1 Pack 32GB Memory Stick USB 2.0 Flash Drives with great cost performance and high quality.
- BIG CAPACITY - The available capacity: 29.10GB-29.8GB, You can save the data of movies, music, photos, designs, programs, manuals, handouts in a high speed.Good performance in digital data storing, transferring and sharing with families, friends, workmates, clients and machines.
- EASY TO USE & PLUG AND WORK - Support windows 7 / 8 / 10 / Vista / XP / 2000 / ME / NT Linux and Mac OS, Compatible with USB2.0 and below.
- TWISTTURN DESIGN & EASY CARRY - The metal clip rotates 360° round the ABS plastic body which with rubber oil skin feeling finish. The capless design can avoid lossing of cap, and providing efficient protection to the USB port.
- WARRANTY & SUPPORT - SIMMAX logo is laser printed on the USB connector surface, our products are of good quality and we promise that any problem about the product within one year since you buy.
Check sessionStorage and WebAuthn separately
sessionStorage
Playwright’s standard storage-state mechanism does not persist sessionStorage. The authentication guide provides a custom save-and-restore pattern for applications that rely on it. Use that workaround only after confirming the app needs session storage, and secure the separately saved data as carefully as other authentication material.
Virtual WebAuthn credentials
The BrowserContext API reference notes that storage state can include virtual WebAuthn credentials and that those credentials contain private keys. Do not enable or retain them casually. If the application requires them, restrict access and retention as you would for other private-key material.
Best Value
- 【16GB Flash Drive】USB flash drives with 16GB capacity, meet your needs of daily use on work, school, home and travelling for photos, music, videos, files storage and transfer. IMEASON thumb drives can be used to store different files, easy to data backup.
- 【Metal Swivel Cap Design】USB thumb drive is metal swivel cover provides extra protection for the usb thumbdrive connector, no usb drive cap to lose; keychain design makes it easier to carry without worrying lose it.
- 【Wide Compatibility】USB drive supports Windows 7/8/10/11 / Vista / XP / Unix / 2000 / ME / NT Linux and Mac OS, also Supports USB 2.0 and 1.1 ports. USB Stick support TV, desktop, notebook computer, car, audio and other device. The USB Memory Stick is your great data storage and transfer companion with traveling and working.
- 【Easy to use】usb memory stick is plug and play without any software installation. Just simply plug the Flashdrive into the port of your USB-compatible devices such as computer, laptop to start data storage or transmission.
- 【What You Get】16 GB USB Flash Drive Thumb Drive, The default format of the usb storage flash drive is FAT32.
Troubleshoot common scheduled-capture failures
- The job opens a logged-out page. The saved state may have expired, been revoked, or may not cover the authentication mechanism the app uses. Confirm the app’s session lifetime and login requirements, then refresh through the approved setup flow; avoid dumping state into CI logs while diagnosing.
- The state file is missing in CI. Check that the trusted setup step actually writes it, that the runtime injection path matches the path configured for Playwright, and that the workspace or job boundary does not discard it before use.
- A fork pull request cannot run the secret-backed capture. This is an intentional GitHub Actions secret boundary, not a reason to expose secrets to fork code. Run the capture on an approved trusted event or use a workflow design that does not give the untrusted job access to the secret.
- Authentication works in a browser but not after restoring state. Check whether the app depends on sessionStorage or another mechanism outside the standard saved state. Add custom sessionStorage handling only if required by the application.
- Artifacts reveal more than expected. Restrict downloads and retention, review traces and reports for sensitive execution data, and stop uploading diagnostics that are not necessary for the screenshot job.
- A saved state includes unexpected credentials. Check whether virtual WebAuthn credential capture is enabled or needed. Since captured virtual credentials carry private keys, omit them unless required and protect any resulting state accordingly.
Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server. One GET request can return an image or PDF; its clean-shot flow accepts consent banners and removes known consent platforms, newsletter popups, and chat widgets before capture. Those cleanup steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify the page verdict and billing status in headers. An MCP server offers screenshot tools for AI agents.
For example, request a WebP screenshot of a page with cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for authentication and request options. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. For scheduled captures, still protect any credentials used to access private pages and secure the resulting screenshots.
Sign up for 1,000 free screenshots a month with no card.
Free tools Windows power users keep installed
One-click scans. No signup required.
Frequently Asked Questions
Can I reuse Playwright storageState in CI?
Yes. Playwright supports saving browser context state and configuring later tests to reuse it. Deliver the file only to a trusted job and treat it as a secret.
Where should I keep Playwright auth.json?
Keep it out of version control and make it available only to the trusted runtime job that needs it. The appropriate secret-storage mechanism depends on your CI and access-control setup.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

