Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

If Puppeteer shows a proxy login page or reports a proxy-authentication error while using Crawlera, first check the proxy endpoint and proxy credentials. Do not treat it as a certificate problem by default: proxy authentication, a website’s own login, and TLS certificate validation are three different issues. Also note that Crawlera is now Zyte Smart Proxy Manager (SPM), which Zyte says has been retired and replaced by Zyte API. The right fix depends on whether you are maintaining an older integration or migrating to Zyte’s current options.

Identify which authentication is failing

“HTTPS authentication” can describe several failures that happen at different points in a request. Identify the failing layer before changing Puppeteer settings; a credential for one layer will not solve another.

  • Proxy authentication: The proxy asks the browser or client to authenticate. A proxy login page or a proxy-authentication error can indicate that the endpoint, key, or way credentials are sent is wrong.
  • Destination-site authentication: The website itself requires a username, password, session cookie, or other sign-in. These are website credentials, not the proxy API key.
  • TLS or certificate validation: The browser cannot validate a certificate on the connection to the proxy or destination. This is a certificate trust or connection configuration issue, not a missing proxy password.

A historical Crawlera support thread describes a user on Puppeteer v1.6.0 seeing a proxy login page and net::ERR_UNEXPECTED_PROXY_AUTH. The administrator advised using the Crawlera API key from account settings. That report is a useful clue if your symptom matches, but it is an old support exchange, not a current, tested integration recipe. Do not assume that every modern proxy-authentication error has the same cause.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check the service, endpoint, and credentials first

  1. Establish what the code actually connects to. Search configuration, environment variables, and launch arguments for the proxy hostname. Older projects may still name proxy.crawlera.com. Confirm your account’s current service and migration status in its dashboard and current Zyte documentation before replacing an endpoint or copying credentials from a forum post.
  2. Verify the proxy key in the account that owns the endpoint. A proxy API key belongs in the proxy-authentication configuration, not in the target website’s login fields. Check that it has not been truncated, surrounded by unintended whitespace, or loaded from the wrong environment. Avoid printing secrets to logs while debugging.
  3. Confirm the authentication format for that service and interface. A proxy endpoint and a browser-control endpoint can use different authorization mechanisms. Do not carry an old username/password convention into a new interface unless its documentation specifies that format.
  4. Retest a single target and inspect the actual error. Separate the navigation result from any page content. A proxy login screen, a website login form, a 401 response, and a certificate error point to different layers.

Zyte’s current proxy-mode documentation gives api.zyte.com:8011 as the proxy endpoint and api.zyte.com:8014 for its HTTPS proxy interface. Treat these as configuration facts for the documented Zyte interfaces, not as a drop-in replacement for every old Crawlera setup. Check current account-specific instructions before changing a production endpoint.

Configure Puppeteer authentication for the right challenge

Puppeteer’s current Page.authenticate() API is documented for HTTP authentication. It accepts a credentials object, and Puppeteer notes that request interception is enabled behind the scenes, which may affect performance. That does not make it a universal fix for every proxy, website, or TLS error.

For a service and Puppeteer version whose documented setup expects credentials through page-level HTTP authentication, the shape of the call is:

await page.authenticate({
  username: process.env.PROXY_USERNAME,
  password: process.env.PROXY_PASSWORD,
});
await page.goto('https://example.com', { waitUntil: 'domcontentloaded' });

This snippet illustrates Puppeteer’s authentication API; it does not establish that a particular Crawlera-era endpoint accepts this exact credential arrangement. Follow the instructions for the proxy interface and Puppeteer/Chromium versions you actually deploy. If both the proxy and destination ask for credentials, do not assume one page-level credential pair can correctly satisfy both challenges.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Likewise, adding a Proxy-Authorization value as an ordinary page request header is not automatically equivalent to completing the proxy’s authentication handshake. Page headers apply to browser requests; proxy authentication is handled between the browser and proxy. The historical support report does not validate a custom-header workaround as a reliable current fix.

Investigate certificates only when the error is TLS-related

If the browser reports certificate authority, certificate name, or TLS validation errors, inspect the connection mode and certificate instructions for that mode. Do not turn off HTTPS certificate checks to fix a proxy password error. Puppeteer’s ignoreHTTPSErrors option changes certificate handling; it does not supply missing proxy credentials and can weaken security.

Zyte distinguishes ordinary proxy mode, which can route requests to HTTPS target URLs without using an HTTPS proxy interface, from its separate HTTPS proxy interface. Zyte’s documentation says the latter requires compatible tooling and its CA certificate. If you deliberately use that interface, follow the current CA installation and account instructions. Do not install a CA or switch proxy modes simply because the target URL begins with https://.

Choose a current Zyte route if you are migrating

Zyte says SPM has been retired and replaced by Zyte API. Its current documentation describes two relevant routes. This does not prove every legacy local Puppeteer integration stopped working immediately; it means new implementation decisions should be based on current supported interfaces rather than an old Crawlera example.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Route Control model Puppeteer fit Authorization model Important qualification
Zyte API proxy mode Routes traffic from your existing client or software through a proxy endpoint. Zyte documents it as a migration option but cautions that proxy mode is not optimized for browser automation tools. Proxy endpoint plus API key supplied as proxy credentials. Use the endpoint and credential format specified for the account and current interface.
Zyte API hosted browser over CDP A remote browser controlled by your Puppeteer script over Chrome DevTools Protocol. Explicitly documented for Puppeteer and other CDP-compatible clients. Basic authorization on the browser connection, constructed from the API key followed by a colon. Access has account eligibility requirements, including subscription or spending setup and business verification; check current account guidance.

In practical terms, choose proxy mode when the requirement is to route traffic from existing software and its constraints suit your use case. Consider CDP when you want to keep writing Puppeteer browser-control code while the browser itself runs remotely. Zyte documents CDP authentication as Basic authorization made from the API key plus a colon. Construct and send that header using the current Zyte connection instructions rather than placing the key in page content or a target-site login.

Zyte’s CDP diagnostics distinguish a 401 authentication failure—such as a missing, malformed, incorrect, or wrongly placed key—from a 403 account-access restriction where required account prerequisites are unmet. These meanings apply to the documented Zyte CDP connection, not to every Crawlera deployment or every HTTP response from a target website.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot by symptom

Puppeteer displays a proxy login page

  • Confirm that the browser is connecting to the intended proxy host and port, not an obsolete example or an unintended system proxy.
  • Check the API key and the service’s expected proxy-credential format in the account dashboard or current docs.
  • Confirm that credentials are attached to the proxy challenge rather than being entered as the destination website’s credentials.
  • Remember that the well-known Crawlera forum symptom was reported with Puppeteer v1.6.0; it is historical evidence, not confirmation that a current deployment has the same defect.

The error is ERR_UNEXPECTED_PROXY_AUTH

This error is consistent with a proxy-authentication problem, but it is not a complete diagnosis. Check the endpoint, key, and credential mechanism together. If those appear correct, record the Puppeteer and Chromium versions, proxy interface, and sanitized response details, then compare them with the provider’s current integration guidance.

The website asks the user to sign in

That may be the destination site’s own login flow rather than a proxy prompt. Authenticate to the destination using its supported session or login method, separately from proxy credentials. Do not expose either set of credentials in logs or source control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A certificate or authority error appears

Confirm whether you selected an HTTPS proxy interface and whether your tooling trusts the CA certificate required for that interface. If you are using ordinary proxy mode to reach an HTTPS destination, do not assume that switching to the HTTPS proxy interface is necessary. Avoid disabling certificate validation as a blanket workaround.

Zyte CDP returns 401 or 403

  • 401: Check that the API key is present, valid, and sent in the documented Basic authorization format on the browser connection.
  • 403: Check subscription or spending setup and business verification requirements for the account. A valid key alone may not grant access.

Performance, reliability, and cost considerations

Authentication configuration is only one part of browser reliability. Puppeteer notes that Page.authenticate() enables request interception behind the scenes and may affect performance. If you add it while diagnosing, keep the change scoped to the needed page or flow and compare behavior with the same target and workload. Avoid drawing conclusions from a single navigation when the failure is intermittent.

For a managed service, account eligibility, endpoint retirement, and migration status matter as much as code. Verify these before planning a rollout, and test a representative set of destinations before switching production traffic. No universal success rate, speed, or cost follows from the available technical guidance; those depend on the service plan, target sites, workload, and account configuration.

Or skip the browser setup

If the job is to capture a website screenshot rather than control a full browsing session through Crawlera, ScreenshotNeo is a separate screenshot API and MCP server. It does not fix a Zyte/Crawlera proxy-authentication problem or replace arbitrary Puppeteer automation. One GET request returns an image or PDF; the following example saves an image response:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" 
  -d access_key=YOUR_API_KEY 
  --data-urlencode url=https://example.com 
  -o shot.webp

See the ScreenshotNeo API documentation for parameters and response details. Cookie and consent banners are accepted and removed before capture, along with supported newsletter popups and chat widgets; those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, with page verdict and billing information included in response headers. Its MCP server provides screenshot tools for AI agents, and the free plan includes 1,000 screenshots per month without a card; paid plans start at $5 for 3,000 shots. Sign up for the free plan.

FAQ

Does Puppeteer’s Page.authenticate() solve every proxy-authentication error?

No. It is Puppeteer’s API for HTTP authentication, but the correct method depends on the proxy interface and deployed versions. Puppeteer also notes that request interception is enabled behind the scenes.

Does an HTTPS target require Zyte’s HTTPS proxy interface?

Not necessarily. Zyte documents ordinary proxy mode for HTTPS target URLs; its separate HTTPS proxy interface has additional tooling and CA requirements.

Is the old Crawlera endpoint guaranteed to keep working?

The historical forum thread does not establish present-day availability. Check the current account dashboard and Zyte migration documentation for the service and endpoint applicable to your account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.