Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Use Chrome DevTools Protocol (CDP) before you navigate. Enable the Network domain, listen for Network.requestWillBeSent and Network.requestWillBeSentExtraInfo, and join both event types by requestId. The extra-info event contains the request headers Chrome actually transmitted and the cookies considered for that request. When you need the current cookie jar rather than one request’s cookies, call Network.getCookies with the page URL.

Playwright and Puppeteer make the setup easier, but browser-managed headers such as Cookie, Host, and Accept-Encoding can be attached immediately before sending. Therefore, do not treat a manually supplied Cookie header as authoritative; inspect the context cookie store or CDP network events instead.

The three layers you can inspect

Wire-level request data

CDP’s Network domain is the lowest-level view available to a normal Chrome automation session. Network.requestWillBeSent gives you the request URL, method, frame, redirect information and an initial header object. Network.requestWillBeSentExtraInfo arrives from the network stack and includes the raw headers transmitted on the wire plus associatedCookies, including cookies that were blocked and their reasons.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The browser’s cookie jar

Network.getCookies returns cookies applicable to one or more URLs. This is the right call when you need the session state currently stored for a page, even if a particular request did not send every stored cookie because of domain, path, Secure, SameSite, expiration or partitioning rules.

#1 Best Overall
Sale
Philips 24 Inch Computer Monitor FHD 100Hz VA VESA Flicker-Free, 241V8LB
  • CRISP CLARITY: This 23.8″ Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
  • INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
  • THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors
  • WORK SEAMLESSLY: This sleek monitor is virtually bezel-free on three sides, so the screen looks even bigger for the viewer. This minimalistic design also allows for seamless multi-monitor setups that enhance your workflow and boost productivity
  • A BETTER READING EXPERIENCE: For busy office workers, EasyRead mode provides a more paper-like experience for when viewing lengthy documents

Framework-level observation

Playwright and Puppeteer expose request and response events and interception APIs. They are convenient for application logic, but their request-header view can be a snapshot taken before Chrome adds browser-controlled fields. Use framework events for filtering and debugging, and CDP when exact transmitted headers matter.

Prepare Chrome and enable CDP before navigation

  1. Start a dedicated headless Chrome profile. A separate profile prevents your production login cookies from being mixed with captured data.
  2. Launch with --headless (or the modern equivalent supported by your Chrome version). If another process owns the browser, expose a protected remote-debugging port or browser URL and attach to that existing session.
  3. Create a CDP session for the page target.
  4. Send Network.enable before page.goto or any action that can trigger requests.
  5. Register listeners for requestWillBeSent, requestWillBeSentExtraInfo, responseReceived and responseReceivedExtraInfo.

Events are not guaranteed to arrive in a convenient order. In particular, extra-info can precede or follow the matching request event. Buffer both records in a map keyed by requestId, then merge them when printing or processing a request.

Complete Node.js capture with Puppeteer and raw CDP

This script launches headless Chrome, records every request, joins late extra-info events, and prints the cookie jar for the target URL. Install Puppeteer with npm install puppeteer, then save the file as capture.js.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
const puppeteer = require('puppeteer');

(async () => {
  const targetUrl = process.argv[2] || 'https://example.com';
  const browser = await puppeteer.launch({
    headless: true,
    args: ['--headless=new']
  });
  try {
    const page = await browser.newPage();
    const cdp = await page.target().createCDPSession();
    const records = new Map();

    const recordFor = (requestId) => {
      if (!records.has(requestId)) {
        records.set(requestId, { requestId, request: null, requestExtra: null,
          response: null, responseExtra: null });
      }
      return records.get(requestId);
    };

    await cdp.send('Network.enable');

    cdp.on('Network.requestWillBeSent', event => {
      recordFor(event.requestId).request = event;
    });
    cdp.on('Network.requestWillBeSentExtraInfo', event => {
      recordFor(event.requestId).requestExtra = event;
    });
    cdp.on('Network.responseReceived', event => {
      recordFor(event.requestId).response = event;
    });
    cdp.on('Network.responseReceivedExtraInfo', event => {
      recordFor(event.requestId).responseExtra = event;
    });

    await page.goto(targetUrl, { waitUntil: 'networkidle2', timeout: 90000 });
    await new Promise(resolve => setTimeout(resolve, 500));

    for (const item of records.values()) {
      if (!item.request) continue;
      const sentHeaders = item.requestExtra?.headers || item.request.request.headers;
      console.log(JSON.stringify({
        requestId: item.requestId,
        url: item.request.request.url,
        method: item.request.request.method,
        headersSent: sentHeaders,
        associatedCookies: item.requestExtra?.associatedCookies || [],
        status: item.response?.response.status,
        responseHeaders: item.responseExtra?.headers || item.response?.response.headers
      }, null, 2));
    }

    const cookieResult = await cdp.send('Network.getCookies', { urls: [targetUrl] });
    console.log('COOKIE_JAR=' + JSON.stringify(cookieResult.cookies, null, 2));
  } finally {
    await browser.close();
  }
})();

Run it with node capture.js https://your-site.example/account. The headersSent value prefers the extra-info event, because that is the closest representation of what Chrome transmitted. The fallback is useful when a protocol implementation does not emit extra-info for a particular request.

Why the map is necessary

A redirect can reuse a request identifier or create a related record, and a service worker can produce traffic that does not look like a simple document load. Keeping all event types under their protocol identifier prevents a fast event handler from losing late cookie or response metadata. Do not delete a record immediately after requestWillBeSent; wait until navigation and its follow-up requests have settled.

Rank #2
Philips 22 Inch Computer Monitor FHD 100Hz VA VESA Flicker-Free, 221V8LB
  • CRISP CLARITY: This 22 inch class (21.5″ viewable) Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
  • 100HZ FAST REFRESH RATE: 100Hz brings your favorite movies and video games to life. Stream, binge, and play effortlessly
  • SMOOTH ACTION WITH ADAPTIVE-SYNC: Adaptive-Sync technology ensures fluid action sequences and rapid response time. Every frame will be rendered smoothly with crystal clarity and without stutter
  • INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
  • THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors

Playwright: inspect the context and attach a CDP session

Playwright’s high-level request object is excellent for URLs, methods, post data and response status. For an authoritative cookie list, use the browser context. For raw transmitted headers in Chromium, attach a CDP session to the page:

import { chromium } from 'playwright';

const browser = await chromium.launch({ headless: true });
const context = await browser.newContext();
const page = await context.newPage();
const cdp = await context.newCDPSession(page);
const byId = new Map();

const get = id => {
  if (!byId.has(id)) byId.set(id, {});
  return byId.get(id);
};

await cdp.send('Network.enable');
cdp.on('Network.requestWillBeSent', e => { get(e.requestId).request = e; });
cdp.on('Network.requestWillBeSentExtraInfo', e => { get(e.requestId).extra = e; });

await page.goto('https://example.com', { waitUntil: 'networkidle' });

for (const [requestId, value] of byId) {
  if (value.request) {
    console.log(requestId, value.extra?.headers || value.request.request.headers);
    console.log(value.extra?.associatedCookies || []);
  }
}

console.log(await cdp.send('Network.getCookies', {
  urls: ['https://example.com']
}));
console.log(await context.cookies());
await browser.close();

Playwright documents that Cookie, Host and Accept-Encoding may be attached by the network stack immediately before sending. A cookie header passed to route.continue() is ignored in favor of the browser’s cookie store. Set cookies with context.addCookies() or a storage state, then verify the result with context.cookies() or CDP rather than trying to override the header at route level.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Using Playwright routing for application logic

Use page.route('**/*', handler) when you need to block an image, change a test header, or log URL and method. Continue the request promptly; delaying every resource can make pages appear to hang. Keep CDP listeners enabled in parallel if you need the final wire-level header set.

Puppeteer without writing CDP listeners

Puppeteer can intercept and modify requests and responses through its request-interception API. This is suitable when you only need a subset of traffic:

const browser = await puppeteer.launch({ headless: true });
const page = await browser.newPage();
await page.setRequestInterception(true);
page.on('request', request => {
  if (request.resourceType() === 'image') return request.abort();
  console.log(request.method(), request.url(), request.headers());
  return request.continue();
});
page.on('response', response => {
  console.log(response.status(), response.url());
});
await page.goto('https://example.com', { waitUntil: 'networkidle2' });
await browser.close();

The intercepted request.headers() object is convenient but should not be used as proof that a browser-managed Cookie header was sent. Add the CDP session from the earlier script whenever that distinction matters.

Rank #3
Sale
Dell 24 Monitor - SE2426H - 23.8-inch FHD (1920x1080) 144Hz 1ms Display, in-Plane Switching (IPS) Technology, AMD FreeSync™, TÜV 3-Star 2X HDMI, Tilt
  • Clear visuals. Fluid motion: A 144Hz refresh rate and 1ms MPRT deliver smooth, tear‑free motion across work, gaming, and streaming for clearer, more fluid viewing.
  • Eye comfort: TÜV Rheinland 3‑star* certification reduces harmful blue light while preserving stunning color quality without compromise. *TÜV Rheinland 3-star eye comfort certification.
  • Wide viewing angle: Get consistent views across a wide 178° /178° viewing angle.
  • In-Plane Switching (IPS): See excellent color accuracy and consistency across wide viewing angles with In-plane Switching (IPS) technology.
  • Ultra-thin bezels: Maximize your viewing experience with thin bezels.

Python option with Playwright

Python Playwright can use the same Chromium CDP events. Install it with pip install playwright and run playwright install chromium once on the machine:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
from playwright.async_api import async_playwright
import asyncio

async def main():
    async with async_playwright() as p:
        browser = await p.chromium.launch(headless=True)
        context = await browser.new_context()
        page = await context.new_page()
        cdp = await context.new_cdp_session(page)
        records = {}

        def slot(request_id):
            return records.setdefault(request_id, {})

        cdp.on('Network.requestWillBeSent',
               lambda e: slot(e['requestId']).update(request=e))
        cdp.on('Network.requestWillBeSentExtraInfo',
               lambda e: slot(e['requestId']).update(extra=e))
        await cdp.send('Network.enable')
        await page.goto('https://example.com', wait_until='networkidle')

        for request_id, item in records.items():
            if 'request' in item:
                request = item['request']['request']
                extra = item.get('extra', {})
                print(request_id, request['url'])
                print(extra.get('headers', request.get('headers', {})))
                print(extra.get('associatedCookies', []))

        print(await cdp.send('Network.getCookies', {
            'urls': ['https://example.com']
        }))
        await browser.close()

asyncio.run(main())

Interpreting cookies correctly

Sent cookies versus stored cookies

associatedCookies describes cookies Chrome considered for one request. Entries can contain blocked reasons, so presence in this array does not guarantee transmission. Network.getCookies describes the current jar for the URL scope you provide. Compare both when diagnosing why a session cookie is missing.

Domains, paths and schemes

A cookie for app.example.com is not automatically sent to api.example.com. A path restriction can exclude an otherwise valid cookie, and Secure cookies require HTTPS. Include the exact URL, including path, in Network.getCookies when investigating scope.

Partitioned and third-party cookies

Modern Chrome can partition cookies by top-level site. An embedded frame may therefore see a different jar from a top-level navigation. Record the frame and initiator fields from the request event, and test the same embedding context rather than opening the endpoint in a new tab.

Redirects, service workers and cached responses

  • Redirects: process every request event. The URL and headers can change between hops, and authorization or cookie policy may differ on the destination origin.
  • Service workers: a worker can fulfill a request without a conventional network round trip. Keep response events and the request’s frame or loader identifiers so you can distinguish worker-handled traffic.
  • Cache: a memory or disk-cache hit may not produce the same network events as a fresh fetch. Disable cache through CDP for a controlled diagnostic run, or use a new profile when comparing results.
  • HTTP/2 and HTTP/3: protocol-level header compression means the event values are the useful decoded representation; packet captures are not required for normal application debugging.
  • Response cookies: Network.responseReceivedExtraInfo can expose blocked Set-Cookie records and raw response headers, which is useful when login state fails to persist.

What to log and what to redact

Request headers often contain bearer tokens, session cookies, API keys, CSRF values and personal identifiers. Before writing JSON to CI logs or a ticket, remove or hash Cookie, Authorization, Proxy-Authorization, and any application-specific session fields. Store captures for the shortest period needed, restrict file permissions, and never paste a live session cookie into source control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Samsung 27" Essential S3 (S36GD) Series FHD 1800R Curved Computer Monitor
  • CURVED FOR ENHANCED ENGAGEMENT: An immersive viewing experience with a curved monitor that wraps more closely around your field of vision; It creates a wider view, enhancing depth perception and minimizing peripheral distraction
  • SMOOTH PERFORMANCE FOR SEAMLESS CONTENT: Stay in the action when playing games, watching videos, or working on creative projects; The 100Hz refresh rate reduces lag and motion blur so you don't miss a thing in fast-paced moments¹
  • MORE GAMING POWER: Gain the edge with optimizable game settings; Color and image contrast can be adjusted to see scenes more vividly and spot enemies hiding in the dark; Game Mode adjusts any game to fill the screen so you can view every detail²
  • KEEP IT EASY ON THE EYES: Care for your eyes and stay comfortable, even during long sessions; Advanced eye comfort technology certified by TÜV reduces eye strain by minimizing blue light and reducing irritating screen flicker²
  • INCREASED VERSATILITY: Connect to more; Plug devices straight into your monitor for increased flexibility, making your computing environment even more convenient

A practical redaction function can preserve structure without secrets:

function redact(headers) {
  const hidden = new Set(['cookie', 'authorization', 'proxy-authorization', 'x-api-key']);
  return Object.fromEntries(Object.entries(headers || {}).map(([name, value]) => [
    name, hidden.has(name.toLowerCase()) ? '<redacted>' : value
  ]));
}
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common failures

No requests appear

Most often, Network.enable was sent after navigation or the CDP session is attached to the wrong target. Create the session from the page target, enable Network first, then navigate. If a popup performs the request, attach to that new page target too.

The Cookie header is absent

Check requestWillBeSentExtraInfo.headers, not only the framework request object. Then inspect associatedCookies for blocked reasons and call Network.getCookies with the exact URL. Domain, path, HTTPS, expiration, SameSite and partitioning rules commonly explain the difference.

Extra-info never matches

Do not assume one-to-one timing. Keep records until the navigation is complete, key them by the exact requestId, and handle requests that finish before an extra-info event arrives. Some non-network or worker-served operations will not provide every event type.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Navigation times out

Prefer a realistic readiness condition such as domcontentloaded when a page keeps polling. Set a finite timeout, capture the records collected so far, and close the browser in a finally block. Blocking analytics or large media through routing can reduce noise, but do not block resources required for the login flow you are diagnosing.

Best Value
Sale
Sceptre New 22-Inch Gaming Monitor, FHD 1080p, Up to 144Hz, HDMI, DisplayPort, Built-in Speakers, Machine Black (E225W-FW144 Series, 2026)
  • 【INTEGRATED SPEAKERS】Whether you're at work or in the midst of an intense gaming session, our built-in speakers provide rich and seamless audio, all while keeping your desk clutter-free.
  • 【EASY ON THE EYES】 Protect your eyes and enhance your comfort with Blue-Light Shift technology. This feature reduces harmful blue light emissions from your screen, helping to alleviate eye strain during long hours of use and promoting healthier viewing habits.
  • 【WIDEN YOUR PERSPECTIVE】Our sleek minimal bezel design ensures undivided attention. The nearly bezel-free display seamlessly connects in a dual monitor arrangement, delivering an unobstructed view that lets you focus on more at once, completely distraction-free.

An attached browser exposes the wrong account

Remote debugging inherits the existing profile’s cookies and login state. Use a dedicated profile and protect the debugging endpoint; never expose an unauthenticated remote-debugging port to a network.

Choosing CDP, Playwright or Puppeteer

Option API level Best for Header fidelity Cookie access Maintenance trade-off
Raw CDP Chrome protocol Exact event metadata, blocked-cookie reasons, response extra-info Highest; use extra-info events Network.getCookies plus associated cookies More event correlation and target management
Playwright Automation framework Cross-browser tests, routing, storage state High when paired with a Chromium CDP session; framework headers alone are not final context.cookies() and CDP Higher-level APIs reduce boilerplate
Puppeteer JavaScript CDP/WebDriver BiDi library JavaScript-first Chrome automation and interception High with a CDP session; interception view can precede browser-managed fields Page cookies or CDP Simple Chrome workflows, less browser abstraction than Playwright

Or skip the browser setup

If your actual goal is a clean image or PDF of a page rather than debugging its network traffic, ScreenshotNeo provides a single HTTP request. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and each response reports its verdict in X-Page-Verdict and X-Billed headers. Its MCP server provides take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.

See the parameter reference in the ScreenshotNeo documentation. cURL:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G 'https://api.screenshotneo.com/v1/shot' -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get('https://api.screenshotneo.com/v1/shot', params={'access_key': 'YOUR_API_KEY', 'url': 'https://stripe.com'}, timeout=90)
open('shot.webp', 'wb').write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots, and every feature is included on every plan. Create a free ScreenshotNeo account to try it.

Frequently Asked Questions

Can I capture headers from a browser I did not launch?

Yes. Attach to a Chrome instance through its protected remote-debugging port or browser URL, create a CDP session for the relevant page target, and enable the Network domain before the next navigation. The attached profile’s cookies and login state are inherited.

Why do I see a cookie in the jar but not in the request?

The cookie may fail domain, path, Secure, SameSite, expiration or partitioning checks. The request’s associatedCookies entry includes blocked reasons that identify which policy prevented sending.

Is headless Chrome required for CDP network capture?

No. Headless is only a runtime configuration. The same CDP Network events can be collected from a headed Chrome session or an existing remotely attached browser.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How can I capture only API calls?

Record all CDP request events, then filter by URL, resource type, frame or method before storing them. Filtering after correlation preserves redirect and extra-info relationships without adding interception delays.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.