Can BrowserStack Screenshots Capture Pages Behind a Login?
BrowserStack Screenshots cannot access ordinary login-protected pages. It documents support for HTTP Basic Authentication, with credentials in the URL.
Short answer: BrowserStack Screenshots cannot access pages that require ordinary login credentials, such as a page behind a conventional sign-in form. BrowserStack documents one exception: HTTP Basic Authentication, where its FAQ says to put the username and password in the URL. That exception does not establish support for form sign-in, SSO, cookies, or an already authenticated browser session. BrowserStack’s Screenshots FAQ
What kind of login does the page use?
The answer depends on the authentication mechanism. A web page that first displays a username-and-password form requires an interactive login flow. HTTP Basic Authentication is different: the server challenges the request, and the client supplies credentials as part of the HTTP request. BrowserStack’s Screenshots FAQ says ordinary pages requiring login credentials are inaccessible, while documenting Basic HTTP Authentication as supported.
| Page or workflow | What the documentation says | Practical conclusion |
|---|---|---|
| Conventional sign-in form | Pages requiring login credentials are inaccessible to BrowserStack Screenshots. | Do not expect Screenshots to fill in a form or sign into a normal account. |
| HTTP Basic Authentication | Currently supported by including credentials in the URL. | May work for a page protected by Basic Auth. |
| Cookies, SSO, or an existing session | The Screenshots FAQ does not specify support for these methods. | Check with BrowserStack for your specific setup; the FAQ does not establish support or impossibility. |
How to use the documented Basic Authentication exception
For a server that actually uses HTTP Basic Authentication, BrowserStack gives a URL pattern like http://username:password@www.xyz.com. Substitute the protected page’s host and the Basic Auth credentials required by that server. This is not an instruction to put ordinary website account credentials into a URL: the documented pattern applies to HTTP Basic Authentication only.
- Confirm with the site or its administrator that the page uses HTTP Basic Authentication, rather than a normal HTML sign-in form.
- Build the URL using the documented
scheme://username:password@host/pathpattern. - Use that URL as the target for your BrowserStack Screenshots capture.
- Check the resulting screenshot to confirm the protected content loaded, rather than an error or authentication challenge.
Security note: Credentials embedded in URLs can be exposed through browser history, logs, copied links, monitoring systems, or shell history. Use a dedicated test account, avoid sharing credential-bearing URLs, and follow your organization’s secret-handling rules. If the credentials contain reserved URL characters, URL encoding may be needed; BrowserStack’s cited FAQ does not describe encoding rules or a separate credential parameter.
Do not confuse Screenshots with other BrowserStack products
BrowserStack’s Website Scanner is a separate product with documented authentication configuration. Its guide covers form authentication, Basic Authentication, and multipage authentication. It also describes optional email OTP MFA for applicable configurations and dynamic login URLs for supported form or multipage setups. Those Website Scanner capabilities do not mean BrowserStack Screenshots supports the same login flows. Website Scanner authentication guide
Website Scanner’s troubleshooting guidance also makes an important distinction: a verification with no reported errors does not prove login succeeded. Check the final URL and resulting snapshot against the expected signed-in page. That advice applies to verifying Website Scanner’s configured flow, not as evidence of a Screenshots feature. Website Scanner authentication troubleshooting
BrowserStack Percy is another separate product. Its documentation discusses passing authentication headers for protected assets in Percy Web snapshots. That is about protected asset discovery in Percy, not a documented login feature for BrowserStack Screenshots. Percy documentation for authenticated assets
Options when a normal login form is required
- Use a product with a documented login workflow. BrowserStack Website Scanner documents configured login flows, but it is a separate product and workflow.
- Capture from an authenticated browser you control. If your application or capture tooling supports it, use a dedicated test account and manage its session securely. The cited Screenshots FAQ does not document importing or reusing such a session.
- Use a screenshot API that accepts the authentication inputs your site requires. Check its documentation for cookies, headers, scripts, or login workflows, and confirm the approach is appropriate for your application.
Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server for developers. For a page that your authorized capture request can access, call its API directly; consult the ScreenshotNeo API documentation for authentication and supported options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
timeout=90,
)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo removes cookie banners, popups, and chat widgets before the shot. Bot checks, blank pages, and failed loads are never billed. Its MCP server gives AI agents tools to take screenshots, get page information, and capture PDFs. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 shots. A screenshot API cannot grant access to a private page by itself: use only pages and authentication methods you are authorized to capture, and see the docs for supported request options.
Sign up free for 1,000 screenshots a month, no card required.
Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| The screenshot shows a sign-in form. | The destination uses conventional form authentication, which the Screenshots FAQ says is inaccessible. | Use a workflow with documented form login support, or capture through an authenticated browser setup you control. |
| The screenshot shows a Basic Auth challenge or access-denied page. | The target may not use Basic Auth, the credentials may be wrong, or the URL may not follow the expected form. | Confirm the authentication scheme and credentials with the site administrator. Keep credentials out of shared links and logs. |
| The page loads, but it is not the expected signed-in view. | A redirect, login state, or protected route may not have resolved as expected. | Inspect the destination and resulting image. The Screenshots FAQ does not describe session reuse or a form-login verification flow. |
| Website Scanner reports no verification errors, but the page is still logged out. | A clean verification result does not necessarily mean authentication succeeded. | For Website Scanner, compare the final URL and snapshot with the expected authenticated page. |
Performance, reliability, and cost considerations
The cited BrowserStack Screenshots FAQ does not provide timing, retry, reliability, or pricing details for authenticated captures. Do not assume Basic Auth changes those characteristics. For a private page, first establish that the authentication method is supported; retrying a conventional form-login capture does not add the missing login capability.
For any screenshot workflow, use a non-production test account where possible, avoid placing secrets in URLs or source control, and verify the captured page itself. For Website Scanner specifically, BrowserStack recommends sample accounts in its authentication guidance. Product scope matters: Website Scanner login configuration and Percy protected-asset headers are not evidence that Screenshots can sign into a conventional account.
FAQ
Can BrowserStack Screenshots fill out a username and password form?
The Screenshots FAQ says pages requiring login credentials are inaccessible. It documents Basic HTTP Authentication as an exception, not form filling.
Does the Basic Auth URL format work for any login page?
No. It is for HTTP Basic Authentication. Do not put normal website account credentials into the URL on the assumption that it will sign in through a page form.
Does Website Scanner’s form authentication mean Screenshots supports it?
No. Website Scanner is a separate product with separate documented login configuration.
Does BrowserStack document cookie or SSO support for Screenshots?
The cited Screenshots FAQ does not state whether cookies, SSO, or existing authenticated sessions are supported. Confirm the exact method with BrowserStack rather than inferring either support or a definitive lack of support.


