Free tools Windows power users keep installed
One-click scans. No signup required.
Browser automation can enter data, attach files, and move through a filing portal, but it does not grant permission to do so. Before writing code, identify the exact agency, jurisdiction, account type, agent route, authentication method, browser requirements, upload rules, and definition of an accepted filing. Some agencies prohibit browser automation outright and provide an approved API instead.
This guide shows how to make an authorized Playwright workflow safer and more reliable, how to decide between browser interaction and an official API, and how to verify that a filing was actually accepted.
Start with the portal’s rules, not the automation framework
There is no universal rule that government or regulated portals allow scripted browsers. The agency’s current terms control, and those terms can differ by country, service, filing type, and account role.
A direct example: HMRC Government Gateway
HM Revenue & Customs published an “Accessing HMRC’s web services” policy on 27 May 2026. It defines automation tools to include browser automation, screen scraping, scripted sign-in, and robotic process automation. The policy states: “HMRC’s current policy under the existing Government Gateway Terms and Conditions is that automation tools must not be used to enter data into or navigate Government Gateway.”
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
The same policy says that this restriction does not restrict APIs designed for software applications to submit information directly to HMRC systems. That is a UK-specific example, not evidence that every agency has an API or permits one.
Authorization is separate from technical access
Do not treat a working login as permission to automate. HMRC warns that third parties must not use sign-in details that do not belong to them. An authorized tax agent may access client data only with permission and through the prescribed Agent Services Account. India’s Income Tax Department likewise places responsibility for the secrecy, confidentiality, and security of portal credentials on the user.
- Confirm that the agency permits the browser route for this service.
- Use an account you are entitled to operate, or the agency’s documented delegated-agent mechanism.
- Never collect, reuse, or share another person’s credentials outside the portal owner’s authorized process.
- Do not attempt to defeat CAPTCHAs, multifactor authentication, bot checks, rate limits, or other account controls.
- Record the agency policy version and review it again immediately before production use.
Choose browser automation or an official API
Use the following decision framework before building a workflow.
| Question | Browser workflow | Agency API |
|---|---|---|
| Is the route authorized? | Only if the portal’s current terms allow scripted interaction. | Only if the agency publishes and permits that API for your filing role. |
| What does it integrate with? | The same visible pages a human uses, including page validations and upload controls. | Structured requests and responses defined by the agency. |
| Authentication | Requires careful handling of browser sessions, cookies, headers, and any MFA handoff. | Uses the API credentials, certificates, tokens, or agent mechanism specified by the agency. |
| Confirmation | Must capture the portal’s receipt, acknowledgment, or accepted/rejected review state. | Must preserve the API response and any agency-issued receipt or status. |
| Change risk | Pages, labels, browser support, and upload widgets can change. | Versioning and endpoint changes are governed by the agency’s API documentation. |
When an official API is available and permitted for the filing, it is usually the more stable integration surface. A browser workflow is appropriate only when the agency authorizes it and the required operation exists only in the portal interface.
Collect portal requirements before writing code
Create a service-specific checklist. Do not copy assumptions from another government site.
Identity and delegated access
- Legal entity, individual, representative, or agent account type.
- Whether a separate agent or delegate account is required.
- Permitted sign-in methods, MFA steps, certificate requirements, and session timeouts.
- Whether a human must approve a handoff or final declaration.
Browser and transport support
Support statements vary. The U.S. Executive Office for Immigration Review says its Respondent Access Portal works with major browsers and works best with Microsoft Edge and Google Chrome; it also says the portal can be used on mobile devices. The South African Revenue Service says its migrated HTML5 eFiling forms continue to work with Chrome, Edge, and Safari. An Indian Income Tax Department page lists Chrome 88–90, Edge 88–90, Firefox 86–88, and Opera 66–68 and requires JavaScript and cookies for transactions. Those versions are an example of dated portal guidance, not current browser recommendations.
The Canada Revenue Agency’s Corporation Internet Filing service illustrates another kind of requirement: TLS 1.2 or higher. Check the portal’s current browser, JavaScript, cookie, TLS, network, and device requirements immediately before deployment.
Rank #2
Documents and field constraints
- Accepted extensions, maximum bytes, page limits, naming rules, and malware scanning behavior.
- Whether each attachment must be uploaded separately or combined into one document.
- Required fields, date formats, character limits, and validation messages.
- Whether a draft can be saved and resumed, and how long a draft remains available.
For its own e-Filing attachments, India’s Income Tax Department recommends PDF scans at 300 DPI, black and white, on A4 or Letter paper, with pages in logical order. It advises using original documents and avoiding faint, faded, smudged, clipped, read/write-protected, or password-protected files. Those are service-specific instructions, not universal requirements. A document scanner can help convert paper records, but the target portal’s rules take precedence.
Build an authorized Playwright workflow
Playwright’s locator model favors user-facing roles and labels. Locators are central to its auto-waiting and retry behavior; its actions wait for actionability checks, and its assertions wait for expected conditions. That reduces race-prone fixed sleeps, but it cannot decide whether a filing is authorized or legally complete.
Install and prepare a controlled environment
- Use a dedicated machine or container with approved network access and a supported browser version.
- Install Playwright and its browser only through your organization’s approved dependency process:
npm install playwrightfollowed bynpx playwright install chromium. - Keep test and production accounts separate. Never test by submitting a real filing unless the agency expressly provides a test or sandbox route.
- Store credentials and session files in a secret manager or protected runtime location, not in source control or log output.
Example Node.js flow
The following pattern is intentionally generic. Replace the URL, labels, selectors, and approval steps only after confirming the target portal’s rules. It stops at the point where a human or an authorized process must review the final declaration.
const { chromium } = require('playwright');
(async () => {
const browser = await chromium.launch({ headless: false });
const context = await browser.newContext({
storageState: process.env.PLAYWRIGHT_STATE || undefined
});
const page = await context.newPage();
await page.goto('https://agency.example.gov/filing', { waitUntil: 'domcontentloaded' });
await page.getByRole('heading', { name: /filing/i }).waitFor();
await page.getByLabel('Reference number').fill(process.env.REFERENCE_NUMBER);
await page.getByLabel('Filing date').fill('2026-09-29');
await page.getByLabel('Supporting document').setInputFiles('./documents/support.pdf');
await page.getByRole('button', { name: /save draft/i }).click();
await page.getByRole('status').waitFor();
// Review all values and declarations before any final submission.
await page.getByRole('checkbox', { name: /I confirm/i }).check();
await page.getByRole('button', { name: /submit/i }).click();
await page.getByRole('heading', { name: /submitted|confirmation|receipt/i }).waitFor();
const receipt = await page.locator('[data-receipt-number]').textContent();
if (!receipt) throw new Error('No receipt number was displayed');
console.log({ receipt: receipt.trim(), url: page.url() });
await browser.close();
})();
setInputFiles can assign a local path or in-memory file data to a file input. The portal still decides whether the file type, size, content, and scan pass its rules. Replace the example receipt selector with a stable, visible element from the actual service.
Python equivalent
from playwright.sync_api import sync_playwright
with sync_playwright() as p:
browser = p.chromium.launch(headless=False)
context = browser.new_context(storage_state="state.json")
page = context.new_page()
page.goto("https://agency.example.gov/filing", wait_until="domcontentloaded")
page.get_by_label("Reference number").fill("AUTHORIZED-REFERENCE")
page.get_by_label("Supporting document").set_input_files("documents/support.pdf")
page.get_by_role("button", name="Save draft").click()
page.get_by_role("checkbox", name="I confirm").check()
page.get_by_role("button", name="Submit").click()
page.get_by_role("heading", name="Confirmation").wait_for()
print(page.url)
browser.close()
Use a real reference value only in an authorized environment. The example intentionally does not automate an MFA challenge or attempt to bypass a bot defense.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Make the script resilient without hiding errors
Prefer semantic locators
Use getByRole, getByLabel, and other user-facing locators. They are less dependent on implementation details than long CSS or XPath chains. Role locators reflect how users and assistive technology perceive controls, but Playwright explicitly says they do not replace an accessibility audit or conformance test.
Wait for evidence, not elapsed time
Do not use a fixed 10-second pause as proof that a page is ready. Wait for the expected heading, label, status message, network-idle condition where appropriate, or receipt element. Set explicit action and navigation timeouts, then fail closed when the expected condition is absent.
Rank #3
Separate stages and make retries safe
- Validate input files locally before opening the portal.
- Save a draft when the portal supports drafts.
- Record the page URL and visible status after each material transition.
- Never blindly retry a final submission. First check whether a receipt, transaction ID, acknowledgment number, or submitted status already exists.
- Use an idempotency or reference field if the agency provides one.
Authentication and browser-state security
Playwright’s authentication guidance warns that saved browser state can contain cookies and headers capable of impersonating an account. Keep state files out of source control, restrict file permissions, avoid copying them into bug reports, and delete or expire them when no longer needed. Mask credentials, tokens, personal data, and uploaded-document paths in logs.
Prefer an interactive, agency-approved sign-in for MFA rather than storing a reusable password. If the portal requires a human approval step, design the workflow to pause and request that approval instead of attempting to automate around it.
Recommended Free Tools
Upload is not the same as filing
A successful file transfer or a clicked button does not establish legal or operational completion. EOIR’s Respondent Access Portal instructions distinguish uploading from submitting: the user uploads a document, submits it for staff review, and receives an email stating acceptance or rejection. Its FAQ says the electronic filing process is complete once accepted.
An Indian Income Tax Department e-Proceedings example displays a success message with a Transaction ID and Acknowledgment Number after successful submission and sends an email to the registered address. Your evidence checklist should therefore include:
- the final portal status, not merely an upload-progress message;
- the receipt, transaction ID, acknowledgment number, or equivalent;
- the submission timestamp and filing reference;
- the portal email or downloadable confirmation, if provided;
- any later acceptance, rejection, or staff-review notice.
Store the receipt according to your retention policy, with access controls appropriate to the filing’s personal and confidential information.
Accessibility is a requirement, not a side effect
The eCourts e-Filing accessibility statement describes keyboard navigation, explicit form-label association, structured headings and table headers, and file-type and size information. These features help people using keyboards or assistive technology. A script that can locate a role is not proof that the portal is accessible; Playwright says role locators do not replace accessibility audits and conformance testing.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesKeep a human-review path available. Test focus order, error messages, declarations, and receipt retrieval with the assistive technologies and keyboard-only methods relevant to your users.
Rank #4
Performance, reliability, and operating cost
Performance
- Reuse a browser context only within the same authorized account and isolation boundary.
- Upload files from local storage rather than repeatedly downloading them during a run.
- Wait for the narrowest reliable condition instead of waiting for every network request to become idle on a page with long-lived analytics connections.
- Do not parallelize submissions for one account unless the agency explicitly permits concurrent sessions.
Reliability
- Pin and periodically test the supported browser version.
- Capture screenshots or HTML only when needed for diagnostics, and redact sensitive data before sharing.
- Monitor portal notices, maintenance windows, browser-support changes, and revised upload rules.
- Run a dry-run or draft-only path after every locator or document-template change.
Cost and operational controls
The main costs are engineering maintenance, secure credential handling, human review, document preparation, and recovery from portal changes. A cheaper script is not a safer filing process if it cannot prove acceptance or causes duplicate submissions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting common failures
“Automation is prohibited” or the account is blocked
Stop the workflow. Re-read the current agency terms and contact the agency or authorized integration owner. Do not rotate IP addresses, disguise the browser, or attempt to defeat bot controls. If an official API exists, evaluate that route instead.
Login loops or unexpected MFA prompts
Check session expiry, clock synchronization, cookie policy, TLS support, and whether the account requires an interactive human step. Do not save or reuse another person’s session state. Start a fresh authorized context and follow the portal’s documented agent process.
Locator timeout
Confirm that the expected page and account role loaded, inspect the visible label or accessible role, and replace brittle CSS chains with user-facing locators. A timeout can indicate a permissions problem or a portal redesign, not merely a need for a longer delay.
File rejected
Check extension, byte size, page count, password protection, scan readability, orientation, and the portal’s current instructions. For India’s cited attachment guidance, use readable 300-DPI black-and-white PDFs in the specified paper format; do not assume those settings apply elsewhere.
Submit button succeeded but no receipt appeared
Do not click again immediately. Refresh only through a safe, documented method; inspect the current filing list or draft status; check email; and contact the agency if the status remains ambiguous. A visible receipt or accepted/rejected result is the evidence you need.
Browser works manually but not in automation
Compare browser version, JavaScript and cookie settings, TLS support, viewport, network policy, and account permissions. Check whether the portal intentionally requires a human gesture or an external certificate device. Do not bypass that requirement.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
Or skip the browser setup
If your need is to document a public portal instruction page or a non-sensitive status page rather than submit a filing, ScreenshotNeo can return a screenshot with one request. It is not a filing-submission API and should not be used to expose confidential account pages.
ScreenshotNeo removes cookie and consent banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and each response reports the page verdict and billing status in headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 screenshots per month without a card; paid plans start at $5 for 3,000 shots.
cURL
See the ScreenshotNeo documentation for parameters and response details.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Every feature is available on every plan, including full-page capture with lazy images loaded, CSS-selector element capture, device presets, retina scale, PDF options, custom CSS and JavaScript, click-before-capture, selector hiding, wait conditions, request blocking, custom headers and cookies, timezone and geolocation, transparent backgrounds, resizing, configurable caching, signed links, asynchronous jobs with signed webhooks, bulk capture of 100 URLs per call, a usage API, and an OpenAPI specification. Parameter names used by other screenshot APIs also work, which can simplify migration.
Create a free ScreenshotNeo account with 1,000 screenshots a month and no card.
Pre-production checklist
- Agency terms explicitly permit the chosen route.
- Account owner or agent has documented authority.
- Authentication and browser state are protected and excluded from source control.
- Browser, TLS, JavaScript, cookie, and device requirements are current.
- Files pass the portal’s exact type, size, readability, and naming rules.
- Locators use visible labels or roles and assertions wait for expected states.
- Final submission is separated from draft and review steps.
- Retries cannot create duplicate filings.
- Receipt, acknowledgment, and later acceptance or rejection are retained.
- A manual recovery path exists for outages, redesigns, and ambiguous statuses.
Frequently Asked Questions
Does a portal’s mobile support mean its pages can be automated on mobile?
No. A statement that people can use a portal on mobile describes human access, not permission, browser-driver support, or an automation contract. Verify the service’s own terms and supported integration route.
Who should approve a production filing bot?
The portal account owner, the agency or authorized agent administrator, and your organization’s security or compliance owner should approve the route, data handling, and recovery procedure before live submissions.
Can a screenshot prove that an agency accepted a filing?
No. A screenshot can document what a page displayed, but acceptance is established by the portal’s receipt, acknowledgment, accepted status, or official notice under that agency’s process.
The Bottom Line
Automate a filing portal only when the agency authorizes browser interaction and the account owner authorizes your access. Build around visible labels, protected session state, portal-specific document rules, and a final receipt or acceptance status; otherwise use the agency’s documented API or manual process.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

