How to Use an AI Agent to Capture Screenshots of Indian Bank Websites Without Exposing Account Details
Use a demo page whenever possible. If a real banking session is unavoidable, keep control of credentials, capture only what you need, mask sensitive fields, and inspect the image.
Use a synthetic or bank demonstration page whenever it can show what you need. If a real Indian banking session is unavoidable, keep the account holder in control of the login, never give credentials or OTPs to the AI agent, capture only the smallest useful page area, mask known sensitive fields, and inspect the saved image before sharing it. A screenshot mask protects pixels in the screenshot output; it does not prove that the agent or browser never had access to the underlying data.
Indian Bank classifies account numbers, banking website user IDs and passwords, card numbers and PINs, and online financial information as highly confidential. Its safety guidance recommends HTTPS, not saving passwords in the browser, and logging out and closing the browser after banking work. The RBI also advises against using public terminals for financial transactions. These are general banking safety recommendations, not an AI-agent-specific standard. Indian Bank security guidance · RBI Be Aware.
1. Choose the safest page that answers the question
Before opening a bank account, decide what the screenshot is meant to demonstrate. If the task is about layout, navigation, accessibility, or a UI bug, use a mock-up, synthetic page, or bank demo. A real customer’s account usually adds risk without adding useful evidence.
| Approach | Use it when | Privacy consideration |
|---|---|---|
| Synthetic or demo page | You need to show a design, browser, or capture behavior | Preferred: it avoids exposing live account information |
| Real session, selected element | The issue only appears after authentication and is limited to one panel | Restrict the capture area and mask known sensitive fields |
| Real session, full page | The whole page is essential to the task | May include more personal or financial information than needed; review carefully |
This is a conservative workflow inferred from bank confidentiality guidance and Playwright’s documented capture controls. The cited sources do not prescribe an AI-agent protocol for banking pages.
2. Keep the account holder in control
- Do not put a user ID, password, PIN, card number, or OTP in an agent prompt, tool argument, or chat context. If authentication is essential, the account holder should enter credentials directly in the browser.
- Use a private, trusted device and verify the bank’s HTTPS address before signing in. Do not save the banking password in the browser.
- Do not use a public terminal for banking activity.
- Limit what the agent can do to the task. Avoid asking it to navigate unrelated account pages or inspect other transactions.
- Keep screenshots and previews in a private location until you have checked them. Do not send them to an external service or shared folder before review.
These steps apply the bank’s confidentiality advice cautiously; they are not claims about the security practices of any particular AI provider or agent.
3. Capture one element and mask known sensitive fields with Playwright
Playwright can capture a selected element instead of the entire page and can apply screenshot-time masks to selected locators. The example below connects to a page that is already open in a locally controlled browser. The account holder signs in manually; the script does not enter or store credentials. Replace the example selectors with selectors for a non-production page or the exact content area you need. Confirm API details against your installed Playwright version; the cited screenshot documentation includes a Next version.
import asyncio
from pathlib import Path
from playwright.async_api import async_playwright
async def main():
async with async_playwright() as p:
# Launch a local browser. The account holder signs in manually if needed.
browser = await p.chromium.launch(headless=False)
context = await browser.new_context(accept_downloads=False)
page = await context.new_page()
# Open the bank's verified HTTPS address. Do not automate credential entry.
await page.goto("https://www.example-bank.in/", wait_until="domcontentloaded")
input("Sign in yourself if required, navigate to the target view, then press Enter...")
# Use selectors that match the page. Prefer a small, relevant capture area.
target = page.locator("main .statement-summary")
sensitive = page.locator(".account-number, .customer-name, .balance, .transaction-row")
await target.wait_for(state="visible", timeout=15000)
await target.screenshot(
path="bank-view-reviewed-before-sharing.png",
animations="disabled",
mask=[sensitive],
mask_color="#000000",
timeout=15000,
)
# Close the session when the task is finished.
await context.close()
await browser.close()
asyncio.run(main())
Install the Python package with pip install playwright, then install a browser with playwright install chromium. The code is a local-browser example, not a recommendation to give an autonomous agent control of a live banking session. Keep the account holder present and in control.
The mask option overlays the bounding boxes of the matched locators in the screenshot. Add selectors for every sensitive field visible in the target view, then open the resulting file and check the actual pixels. A selector can fail to match after a site changes, and the mask cannot identify data that you did not select.
Full-page capture, only when necessary
For a page where a full-page image is essential, apply masks at screenshot time and review the whole output. A full-page capture can include off-screen content, such as additional account or transaction details, so a smaller element capture is preferable when it answers the same question.
await page.screenshot(
path="full-page-reviewed-before-sharing.png",
full_page=True,
animations="disabled",
mask=[page.locator(".account-number, .customer-name, .balance, .transaction-row")],
mask_color="#000000",
timeout=20000,
)
Playwright documents element screenshots and screenshot-time masking in its ElementHandle screenshot API and Screenshots guide.
4. Review the output before it leaves the device
- Open the saved image locally after capture.
- Check names, account identifiers, balances, transaction descriptions, and other personal details visible in that particular view.
- Confirm each mask covered the rendered field and that no sensitive content remains around the capture boundary.
- Discard and recapture if a field was missed. Do not treat a mask as proof the browser, agent context, logs, or another capture path never accessed the original value.
- Share only the reviewed image, through the destination appropriate for the task.
Playwright can return screenshot bytes or save them to a file. Keeping the file local until review is a handling recommendation for this sensitive use case, not a guarantee supplied by the screenshot API.
5. Sign out and close the session
When finished, log out of the bank site and close the browser context and browser. Indian Bank’s safety advice recommends logging out and closing the browser after banking work. Avoid leaving the account open in a shared session.
Or skip the browser setup
For public pages that do not require a banking login, ScreenshotNeo offers a one-request website screenshot API. Do not send bank credentials, session cookies, account URLs behind authentication, or private account pages to a third-party capture service. The API is appropriate here for public or synthetic pages only.
curl -G "https://api.screenshotneo.com/v1/shot" \
-d access_key=YOUR_API_KEY \
--data-urlencode url=https://stripe.com \
-o shot.webp
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await Bun.write('shot.webp', new Uint8Array(await res.arrayBuffer()));
See the ScreenshotNeo API documentation for request options. Before a capture, ScreenshotNeo can accept the cookie or consent banner like a visitor and remove 60+ known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify the page verdict and billing status in headers. Its MCP server gives AI agents tools named take_screenshot, get_page_info, and capture_pdf. The free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. These features do not make it suitable for private authenticated bank pages: use it only with public or synthetic content.
Create a free ScreenshotNeo account for 1,000 screenshots per month with no card.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Playwright cannot find the target element | The selector is wrong, the page has not finished rendering, or the view differs from the expected page | Inspect the page locally, update the selector, and wait for the target to be visible. Do not broaden to a full-page capture just to make the script succeed. |
| A sensitive value is visible in the image | The mask selector missed it, the field uses a different element, or the page changed | Do not share the image. Add the correct locator, recapture, and inspect the new output. |
| The screenshot is blank or incomplete | The target was not visible or finished rendering, or navigation is still in progress | Wait for the exact target with a bounded timeout, verify the view manually, then capture again. |
| A mask hides too much or too little | The selected locator’s bounding box is larger or smaller than expected | Choose a more precise locator, use a smaller target region, and check the rendered result. The overlay follows the matched element’s bounds. |
| Capture fails after browser or package updates | Installed Playwright and browser versions or API documentation may differ | Use documentation matching the installed version and install its supported browser build. |
| Authentication expires during the task | The banking session timed out | Stop the agent, handle reauthentication yourself in the trusted browser, and repeat only the minimum capture. Never pass credentials or OTPs through the agent. |
Performance, reliability, and cost
- Performance: Capturing one element generally means producing a smaller image than a full-page screenshot. Wait for the specific target rather than adding long fixed delays. Keep timeouts bounded.
- Reliability: Bank layouts and selectors can change. A successful screenshot does not mean a mask matched every sensitive field; inspect the artifact each time, especially after page changes.
- Data handling: Treat the browser page, screenshot, and any preview as sensitive until checked. Screenshot masking only affects screenshot output; it does not establish what an agent, browser context, logs, or external service could access.
- Cost: A local Playwright run does not require a screenshot API request, but it does require maintaining the script and browser setup. A capture API may simplify public-page capture, but never send private banking session data to it. ScreenshotNeo’s listed free allowance and paid tiers apply to eligible captures; consult its docs for options and account details.
Frequently asked questions
Can an AI agent safely log in to my bank for me?
This workflow does not recommend giving an agent credentials or OTPs. Keep authentication under the account holder’s control, and prefer a demonstration page whenever possible.
Does a screenshot mask remove the original account data?
No. It overlays selected regions in screenshot output. It does not prove that the underlying page data was inaccessible to the browser or agent, nor that another system did not record it.
Should I use a public screenshot API for a logged-in bank page?
No. Use a local, account-holder-controlled workflow for any necessary real session. A hosted screenshot API is for public or synthetic pages in this guide.
What if I cannot mask every sensitive field?
Do not share the image. Use a synthetic page or choose a smaller capture that avoids the sensitive information, then review the result again.


