Call await page.authenticate({ username, password }) before navigating to the protected page, then capture it with page.screenshot(). Read credentials from environment variables rather than placing real passwords in source code.
Capture a page protected by HTTP authentication
This example uses Puppeteer’s documented Page.authenticate() and screenshot flow. It is illustrative and has not been runtime-tested for this article. The official screenshots guide uses networkidle2 in an example; it is one possible readiness condition, not a guarantee that every page is ready.
As an Amazon Associate I earn from qualifying purchases.
import puppeteer from 'puppeteer';
const browser = await puppeteer.launch();
try {
const page = await browser.newPage();
await page.authenticate({
username: process.env.BASIC_AUTH_USERNAME,
password: process.env.BASIC_AUTH_PASSWORD,
});
await page.goto('https://example.com/protected', {
waitUntil: 'networkidle2',
});
await page.screenshot({ path: 'screenshot.png', fullPage: true });
} finally {
await browser.close();
}
Page.authenticate() takes a credentials object or null, returns a promise, and supplies credentials for HTTP authentication. Passing null disables authentication. Puppeteer enables request interception behind the scenes to implement this feature, which may affect performance; the documentation does not quantify the impact. See the Page.authenticate() API and the Puppeteer screenshots guide.
Keep credentials out of source code
Set BASIC_AUTH_USERNAME and BASIC_AUTH_PASSWORD in your runtime environment or secret store. The environment-variable pattern is a security practice, not a Puppeteer requirement. Do not publish actual credentials or include them in screenshots, command output, or checked-in code.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Choose what and when to capture
Viewport, full page, or a clipped region
By default, fullPage is false, so the screenshot covers the viewport. Set fullPage: true to capture the full document, or use the clip option to capture a specific region. Puppeteer also supports capturing an individual element with ElementHandle.screenshot(). Consult the ScreenshotOptions interface for the available options.
Readiness and output
Choose a navigation wait condition that fits the protected page. networkidle2 is shown in Puppeteer’s screenshot guide, but sites with ongoing network activity or delayed content may need a different readiness strategy. A successful navigation wait is not by itself proof that the correct authenticated content loaded.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
You can save the result with path, as in the example, or request bytes or base64 through screenshot options. The output type defaults to PNG; when saving to a path, Puppeteer can infer the file type from the extension. Options include type, encoding, fullPage, and clip.
Troubleshoot authentication and capture failures
- You see a 401 response or sign-in/error page: Confirm the site uses HTTP authentication, and verify the username and password for that challenge. The API is documented for HTTP authentication generally; the Chrome DevTools Protocol describes challenges including HTTP 401 and 407 and lists Basic and Digest schemes. Exact behavior can depend on Puppeteer version, browser, protocol mode, proxy or server challenge, and redirects.
- The request still appears unauthenticated: Ensure
await page.authenticate(...)completes beforepage.goto(). If authentication works in a different browser or proxy setup, check compatibility in the deployed Puppeteer/browser configuration rather than assuming every challenge or redirect chain behaves identically. - The screenshot is incomplete or blank: Check that the page reached the intended authenticated content before capturing. Revisit the chosen wait condition and whether you need a viewport, full-page, or clipped screenshot; the documentation does not provide a complete diagnostic matrix for every protected site.
- Capture takes longer after enabling authentication: Puppeteer says authentication enables request interception internally and may affect performance, but does not publish a quantified overhead. Measure in your own browser and network environment if latency matters.
The Puppeteer API page accessed October 3, 2026, displays version 25.12.0. Check the documentation matching the version deployed in your project.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Or skip the browser setup
If you do not need to run Puppeteer yourself, ScreenshotNeo offers a screenshot API and MCP server. Its one-call API example is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com/protected -o shot.webp
See the ScreenshotNeo API documentation for the request options. ScreenshotNeo’s stated differentiators are that it accepts cookie or consent banners like a visitor and removes 60+ known consent platforms, newsletter popups, and chat widgets before capture (each step can be turned off); bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, with page verdict and billing headers in responses; and an MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents. These are ScreenshotNeo product claims, not Puppeteer behavior. For HTTP-authenticated pages, check the API documentation for the supported request parameters before relying on it for a particular challenge.
Its free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots. Sign up for ScreenshotNeo’s free plan.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Frequently Asked Questions
Does Puppeteer’s authenticate method work for every authentication setup?
It is documented for HTTP authentication. The precise behavior for a particular scheme, proxy, browser, protocol mode, or redirect chain can vary, so verify it in your deployed setup.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




