Recommended Free Tools
Short answer: Chrome’s Headless command-line interface can capture a screenshot, but its documented CLI flags do not provide a direct way to inject cookies or an arbitrary OAuth bearer token. For an authenticated page, use Puppeteer or the Chrome DevTools Protocol (CDP) to set the required cookie or request header before navigating, then capture the page after it is ready. Whether a cookie or token works depends on the site’s authentication rules.
Capture a public page with Chrome Headless CLI
For a page that does not require authentication, Chrome can capture a screenshot directly from the command line:
google-chrome --headless --screenshot --window-size=1280,900 'https://example.com/'
The documented --screenshot flag saves screenshot.png in the current working directory. Change directories first or move the resulting file if you need it elsewhere. The executable name and launch syntax vary by operating system and installation; Chrome’s current Headless documentation includes examples for Linux, macOS, and Windows. The updated Headless implementation shipped with Chrome 112. Use the current Headless documentation rather than the separate old Headless shell page, which is marked deprecated. Chrome Headless documentation Chrome Headless reference
Control the viewport and capture timing
--window-size=WIDTH,HEIGHT sets the viewport dimensions in pixels. Chrome’s reference gives --window-size=412,892 as an example. Two timing flags are available:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
- KEYBOARD: The keyboard works for Windows with hot keys that enable easy access to Media, My Computer, Mute, Volume up/down, and Calculator
- EASY SETUP: Experience simple installation with the USB wired connection
- VERSATILE COMPATIBILITY: This keyboard is designed to work with multiple Windows versions, including Vista, 7, 8, 10 offering broad compatibility across devices.
- SLEEK DESIGN: The elegant black color of the wired keyboard complements your tech and decor, adding a stylish and cohesive look to any setup without sacrificing function.
- FULL-SIZED CONVENIENCE: The standard QWERTY layout of this keyboard set offers a familiar typing experience, ideal for both professional tasks and personal use.
--timeout=5000sets a maximum wait of 5,000 milliseconds before capture, even if the page is still loading.--virtual-time-budget=42000advances time-dependent page code as if 42 seconds had passed. It can help when a page uses timers or delayed UI.
Neither flag guarantees that a particular application has finished rendering. A timeout is a cap, not a readiness test; virtual time is useful only when it matches the page’s timing behavior. For a dynamic authenticated page, a script that waits for an application-specific condition is usually a better fit.
Can Chrome CLI pass cookies or an OAuth token?
The cited Chrome CLI reference documents screenshot, viewport, and timing flags, but not a direct --cookie, cookie-file, or arbitrary Authorization-header flag. Do not add an undocumented authentication flag and assume Chrome will honor it. To supply authentication before the first page request, use a browser automation library such as Puppeteer or configure the relevant request through CDP’s Network domain.
Choose the credential method the site supports. A session cookie can authenticate a browser session if it is valid and scoped correctly. A bearer token can be attached as an HTTP request header, but that does not make it equivalent to a website login session; the application must accept that token on the page request and any subsequent requests that need authentication.
Rank #2
- Reliable Plug and Play: The USB receiver provides a reliable wireless connection up to 33 ft (1), so you can forget about drop-outs and delays and you can take it wherever you use your computer
- Type in Comfort: The design of this keyboard creates a comfortable typing experience thanks to the low-profile, quiet keys and standard layout with full-size F-keys, number pad, and arrow keys
- Durable and Resilient: This full-size wireless keyboard features a spill-resistant design (2), durable keys and sturdy tilt legs with adjustable height
- Long Battery Life: MK270 combo features a 36-month keyboard and 12-month mouse battery life (3), along with on/off switches allowing you to go months without the hassle of changing batteries
- Easy to Use: This wireless keyboard and mouse combo features 8 multimedia hotkeys for instant access to the Internet, email, play/pause, and volume so you can easily check out your favorite sites
Set cookies before navigation with Puppeteer
Install Puppeteer in a Node.js project, provide an authorized session cookie through environment variables, and set it in a browser context before opening the protected URL. This is an implementation illustration, not a tested recipe for a particular site. Replace the example host, path, and cookie details with values issued for your authorized session.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →import puppeteer from 'puppeteer';
const cookieName = process.env.SESSION_COOKIE_NAME;
const cookieValue = process.env.SESSION_COOKIE_VALUE;
if (!cookieName || !cookieValue) {
throw new Error('Set SESSION_COOKIE_NAME and SESSION_COOKIE_VALUE');
}
const browser = await puppeteer.launch({ headless: true });
try {
const context = browser.defaultBrowserContext();
await context.setCookie({
name: cookieName,
value: cookieValue,
url: 'https://example.com/',
secure: true,
httpOnly: true,
});
const page = await browser.newPage();
await page.setViewport({ width: 1280, height: 900 });
await page.goto('https://example.com/account', {
waitUntil: 'networkidle2',
});
await page.screenshot({ path: 'screenshot.png' });
} finally {
await browser.close();
}
Puppeteer’s BrowserContext.setCookie() sets cookies in the browser context; CDP also documents Network.setCookie and Network.setCookies. Puppeteer BrowserContext.setCookie CDP Network.setCookie
Match the site’s cookie scope and policy
A cookie that is syntactically set may still fail to authenticate. Its domain or URL, path, expiry, Secure and HttpOnly attributes, SameSite policy, and any partitioning constraints must be compatible with the cookie the site issued. Use the site’s supported cookie and login flow; do not copy a cookie from a session you are not authorized to use.
Rank #3
- All-day Comfort: The design of this standard keyboard creates a comfortable typing experience thanks to the deep-profile keys and full-size standard layout with F-keys and number pad
- Easy to Set-up and Use: Set-up couldn't be easier, you simply plug in this corded keyboard via USB on your desktop or laptop and start using right away without any software installation
- Compatibility: This full-size keyboard is compatible with Windows 7, 8, 10 or later, plus it's a reliable and durable partner for your desk at home, or at work
- Spill-proof: This durable keyboard features a spill-resistant design (1), anti-fade keys and sturdy tilt legs with adjustable height, meaning this keyboard is built to last
- Plastic parts in K120 include 51% certified post-consumer recycled plastic*
networkidle2 waits for a network-quiet condition during navigation, but that condition is not a universal signal that a single-page application has finished rendering. If the page renders later, wait for a selector or a known application state before calling screenshot(). Puppeteer’s documented page and header methods are described in its API reference. Puppeteer Page API
Send an OAuth bearer token with Puppeteer
If the target site explicitly accepts an OAuth access token as a bearer header on the requested page, set the extra header before navigation:
Free tools Windows power users keep installed
One-click scans. No signup required.
import puppeteer from 'puppeteer';
const accessToken = process.env.ACCESS_TOKEN;
if (!accessToken) {
throw new Error('Set ACCESS_TOKEN');
}
const browser = await puppeteer.launch({ headless: true });
try {
const page = await browser.newPage();
await page.setViewport({ width: 1280, height: 900 });
await page.setExtraHTTPHeaders({
Authorization: `Bearer ${accessToken}`,
});
await page.goto('https://example.com/account', {
waitUntil: 'networkidle2',
});
await page.screenshot({ path: 'screenshot.png' });
} finally {
await browser.close();
}
Puppeteer documents page.setExtraHTTPHeaders(); the configured headers are sent with every request initiated by that page. CDP has the corresponding Network.setExtraHTTPHeaders method. Puppeteer Page.setExtraHTTPHeaders CDP Network.setExtraHTTPHeaders
Rank #4
- 【Dreamy Rainbow Gaming Keyboard】K521 Gaming Keyboard Adopts a Different LED Backlight Design, Upgraded on the Traditional LED Backlight Effect, Making the Light More Penetrating, Giving You a More Dazzling Visual Effect, Making Your Gaming Process More Enjoyable
- 【One Touch Opens & Visual Feast】The K521 Red Dragon Keyboard has a One-Touch on/off Lighting Button for Added Convenience. It also has a Three-Position Adjustable Breathing Mode and a Four-Position Adjustable Brightness Lighting Mode
- 【Mechanical Feeling & Fast Tapping】The PC Keyboard Keys are Designed for Mechanical Feeling, Giving You a Better Feel During Use and the Ability to Trigger Keys Quickly, Allowing You to Win All Your Games
- 【19 Keys Anti-Ghosting Keyboard】Anti-Ghosting Ensures Every Button Can Be Triggered. This Allows You to Trigger Key Combinations In The Game Accurately, And Each Skill Can Be Accurately Released to Increase Your Winning Rate. Redragon K521 Will Be Your Perfect Partner
- 【12 Multimedia Combination Keys】The K521 Wired Gaming Keyboard is Equipped with 12 Multimedia Keys That Can Greatly Enhance Your Gaming/Office Efficiency and Make It More Convenient to Use
Do not assume every OAuth token is a web login
Attaching a bearer header only solves the transport step. The application may require a token with a particular audience or scope, may accept it only on an API endpoint rather than a top-level browser navigation, or may use an OAuth redirect and callback to establish session cookies and CSRF state. A page may also load cross-origin resources whose authentication rules differ from the initial request. Check the site’s authentication contract and use its supported flow; browser API documentation cannot establish that a particular application will accept a token.
Keep access tokens and session cookies out of source control, command transcripts, screenshots, and shared logs. Use environment variables or a secret manager, and avoid printing credential values during debugging.
Choose the capture method that matches the authentication need
| Need | Documented approach | Trade-off |
|---|---|---|
| Public page, fixed viewport | Chrome CLI with --headless --screenshot --window-size=… |
Minimal setup; the cited CLI reference does not document direct cookie or bearer-header injection. Chrome Headless reference |
| Set cookies before page load | Puppeteer browser context or CDP Network cookie methods | Script setup is needed, and the cookie must be correctly scoped and unexpired. Puppeteer CDP |
| Attach a bearer header to page requests | Puppeteer extra headers or CDP Network extra headers | Header attachment is supported; whether the target site accepts the token remains application-specific. Puppeteer CDP |
| Inspect an invisible browser during diagnosis | Headless Chrome with remote debugging and CDP | Offers inspection and control; protect the debugging endpoint and make it accessible only to trusted local tooling. Chrome Headless debugging guide |
These approaches have different setup and authentication controls. The cited official documentation does not provide comparative speed or reliability benchmarks, so choose based on the control your workflow needs rather than an assumed performance ranking.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- All-day Comfort: This USB keyboard creates a comfortable and familiar typing experience thanks to the deep-profile keys and standard full-size layout with all F-keys, number pad and arrow keys
- Built to Last: The spill-proof (2) design and durable print characters keep you on track for years to come despite any on-the-job mishaps; it’s a reliable partner for your desk at home, or at work
- Long-lasting Battery Life: A 24-month battery life (4) means you can go for 2 years without the hassle of changing batteries of your wireless full-size keyboard
- Simply plug the USB receiver into a USB port on your desktop, laptop or netbook computer and start using the keyboard right away without any software installation
- Simply Wireless: Forget about drop-outs and delays thanks to a strong, reliable wireless connection with up to 33 ft range (5); K270 is compatible with Windows 7, 8, 10 or later
Wait for the page state that makes a useful screenshot
For a static page, a short CLI timeout may be sufficient. For an authenticated app, capture only after the intended content is visible. Use a selector that appears only after the relevant view has loaded, or an application-specific condition you can verify. Do not treat a successful navigation response, network quiet, or a longer delay as proof that the correct account page rendered.
Before capturing, consider whether the page needs a particular viewport, whether content is below the fold, and whether a cookie banner or other overlay hides the information you need. The basic CLI capture uses the viewport dimensions you specify; a script can set the viewport and wait before taking the screenshot. Ensure the output location is writable and that credentials are not exposed in artifacts.
Troubleshooting Chrome Headless authenticated screenshots
- The command fails to start: Confirm the installed Chrome executable name and version, then use the current platform-specific Headless launch syntax. Headless behavior and flags can be version-sensitive; Chrome’s updated implementation shipped with Chrome 112. Chrome Headless documentation
- No screenshot appears: Check the current working directory and permissions. The CLI reference’s default output is
screenshot.pngin the current directory; scripted examples can specify a path explicitly. - The image shows a login page: Check the cookie’s host/domain or URL, path, expiration, Secure and SameSite requirements, and whether the application expects an OAuth redirect instead of a bearer header. A browser API can set a credential but cannot make an incompatible or expired credential valid.
- The token works for an API call but not the page: Confirm that the site accepts bearer authentication on top-level page requests and that the token has the required audience and scope. The site may require its interactive login flow or session cookies.
- The screenshot is blank or incomplete: For a simple CLI capture, adjust
--timeoutto suit the page. Use virtual time only when it fits the page’s timing behavior. For scripted capture, wait for a page-specific selector or state instead of relying solely on network quiet. - You need to see what the hidden browser loaded: Chrome’s Headless debugging guide describes remote debugging with
--remote-debugging-portand attaching DevTools. Restrict access to that endpoint to trusted local tooling. Chrome Headless debugging guide
Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server. Its API takes a URL in one GET request and returns an image or PDF; its documented options also include custom headers and cookies for pages that require them. See the ScreenshotNeo API docs for authentication and request options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Adapt the target URL and add the authentication options required by the target site. ScreenshotNeo removes cookie and consent banners, newsletter popups, and chat widgets before capture; each cleanup step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and responses identify the page verdict and billing status in headers. Its MCP server gives AI agents tools for screenshots, page information, and PDF capture. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots.
Sign up for ScreenshotNeo’s free plan to try 1,000 screenshots a month without a credit card.
Frequently Asked Questions
Can I take a screenshot of a page that requires a login?
Yes, if you use an authorized session and the site’s supported authentication method. Set the needed cookie or header before navigation, then capture after the protected content is ready.
Does setting an OAuth header complete the OAuth login flow?
No. It attaches a header to page requests; the site must accept that token for the requested page and any resources that need authentication.
Where does Chrome Headless save its CLI screenshot?
The documented default is screenshot.png in the current working directory.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

