How to Capture Screenshots of Competitor Pages Behind a Login
Capture a page you’re authorized to view with a normal sign-in, then save a reproducible screenshot without exposing credentials or account data.
To capture a competitor page behind a login, sign in through the site’s normal interface with an account authorized to view that page, navigate to the exact page, wait for the content to render, and capture the viewport, a selected element, or the full page. For repeatable captures, use an automated browser such as Playwright with an approved authenticated session. A screenshot tool does not grant access: stop if access is denied, and do not try to bypass login, multi-factor authentication, bot checks, or other controls.
Before capturing, confirm that your account is entitled to view the page and that the capture and intended use comply with the site’s terms and your organization’s rules. Avoid collecting unrelated account information, personal data, confidential material, or customer-specific content. Permission to view a page does not automatically mean you may republish its contents.
1. Choose the capture method and scope
For a quick reference, use your browser’s ordinary screenshot feature. For repeatable captures, Playwright can save a viewport screenshot, a full-page screenshot, or a screenshot of a selected element. For a managed browser-rendering workflow, Cloudflare Browser Run documents screenshot requests with valid session cookies, HTTP Basic Authentication, or an authorization header. Puppeteer is another browser-automation option documented by Chrome for Developers.
| Need | Approach | Record alongside the image |
|---|---|---|
| One quick reference | Browser screenshot | Date, URL, and visible viewport |
| Repeatable visual checks | Playwright or Puppeteer | Tool and browser version, viewport, wait condition, and image |
| Hosted rendering workflow | Cloudflare Browser Run screenshot endpoint | Authentication method, viewport, wait settings, and output |
| Content below the fold | Full-page screenshot | Page length and whether scrolling triggers more content |
| One component | Element or selector screenshot | Element identity and enough surrounding context to interpret it |
A viewport image records what appears at a chosen screen size. An element screenshot isolates a component. A full-page image records content across the scrollable page, though pages that load content only while scrolling may need extra handling. Playwright screenshots complement accessibility snapshots: use the image for visual layout and a structural snapshot when text and page structure matter.
2. Capture with Playwright after normal sign-in
The following Node.js example opens a persistent local browser profile so you can complete the site’s normal login flow once and reuse the authorized session for later captures. The first run opens a browser window; sign in manually, then return to the terminal. The script verifies a page-specific element before saving a full-page screenshot. Replace the example URL and selector with the page and stable element you are permitted to access.
import { chromium } from 'playwright';
const targetUrl = 'https://example.com/account/authorized-page';
const readySelector = 'main';
const profileDirectory = './authorized-browser-profile';
const context = await chromium.launchPersistentContext(profileDirectory, {
headless: false,
viewport: { width: 1440, height: 1000 },
deviceScaleFactor: 1,
});
try {
const page = context.pages()[0] ?? await context.newPage();
await page.goto(targetUrl, { waitUntil: 'domcontentloaded' });
// First run: sign in through the site's normal interface in the opened browser.
// Do not automate or bypass MFA, SSO, bot checks, or access-denied controls.
await page.waitForSelector(readySelector, { state: 'visible', timeout: 30000 });
await page.waitForLoadState('networkidle', { timeout: 15000 }).catch(() => {});
// Confirm the page is the intended authenticated page, not a login or error screen.
const currentUrl = page.url();
if (currentUrl.includes('/login') || currentUrl.includes('/sign-in')) {
throw new Error(`Still on a sign-in page: ${currentUrl}`);
}
await page.screenshot({ path: 'competitor-page.png', fullPage: true });
console.log(`Saved authorized capture of ${currentUrl}`);
} finally {
await context.close();
}
Install the dependency with npm install playwright. The persistent profile stores browser session data on disk. Keep that directory private, exclude it from version control and shared archives, and delete it when it is no longer needed. A stored session can grant account access just like a credential.
Capture a viewport or a single element
// Visible viewport only
await page.screenshot({ path: 'viewport.png' });
// One component, preserving its page context in the separate notes
await page.locator('[data-testid="pricing-panel"]').screenshot({
path: 'pricing-panel.png',
});
Choose a selector that identifies the intended component reliably. If a page has repeated matching elements, make the locator more specific and verify the selected element before capture. Include surrounding context in a separate note when an isolated component would be ambiguous.
Use an existing authorized session carefully
You can sign in manually in the persistent profile as above. If your organization already provides an approved browser storage state, Playwright can load it for a context. Treat that file as a secret because it may contain reusable cookies. Keep it outside source control, restrict access, and do not print its contents or attach it to tickets.
import { chromium } from 'playwright';
const browser = await chromium.launch();
const context = await browser.newContext({
storageState: './private/authorized-session.json',
viewport: { width: 1440, height: 1000 },
});
try {
const page = await context.newPage();
await page.goto('https://example.com/account/authorized-page', {
waitUntil: 'domcontentloaded',
});
await page.locator('main').waitFor({ state: 'visible', timeout: 30000 });
await page.screenshot({ path: 'authorized-page.png', fullPage: true });
} finally {
await context.close();
await browser.close();
}
Use this only with session state issued for your own authorized access and an approved workflow. If the site requires an interactive step such as MFA, device approval, or SSO, complete it through the supported sign-in route. Do not try to defeat those controls.
3. Wait for the right page state
A successful navigation does not prove that the intended content loaded. Pages can display a login screen, an access-denied message, a loading skeleton, or a partially rendered view while the browser request itself succeeds. Wait for a stable page-specific element, then inspect the resulting page before saving.
- Prefer a visible, meaningful selector over a fixed sleep when the page exposes a stable element.
- Use a short delay only for a known animation or delayed component; keep it explicit and consistent across runs.
networkidlecan help with pages that settle after requests finish, but analytics, polling, or persistent connections may prevent it from occurring. A selector wait is usually a better signal for the content you need.- For lazy-loaded content, scroll through the page before a full-page capture if the site loads sections only when they approach the viewport. Do not interact with controls that could change account data or submit actions.
- Check the URL and visible page state. Do not save a login, error, or access-denied screen as if it were the target page.
4. Record context and protect the capture
For a reproducible visual record, save the capture date and time, page URL, viewport dimensions, browser and automation-tool version, and the relevant page state or account context. Keep an unmodified original when the image is being used as evidence. If sharing is appropriate, review it for personal information, account identifiers, internal notes, and secrets; redact only a separate copy and label edits clearly.
Keep credentials and session cookies out of source files, logs, issue trackers, public examples, and shared scripts. Use environment or secret-management facilities where credentials must be supplied to an approved process. Restrict access to browser profiles and session-state files, and remove them when no longer required.
5. Hosted authenticated capture options
Cloudflare’s screenshot documentation says, “Some webpages require authentication before you can view their content.” Its Browser Run documentation describes supplying valid session cookies, HTTP Basic Authentication credentials, or an authorization header to its own screenshot service. Those examples document API capabilities; they do not grant permission to access a third-party page. Use only credentials issued to you and an access method the site permits.
A normal username-and-password form is not necessarily HTTP Basic Authentication. Sites using MFA, SSO, device checks, or bot protections may require an approved interactive sign-in or vendor-supported authorization integration. Implementation depends on the site; do not infer an authentication method from the fact that a page is behind a login.
For an authorized page that your approved workflow can access without credentials, ScreenshotNeo offers a one-request screenshot API and an MCP server for AI agents. It cannot create authorization or sign in to a protected account on your behalf. Use it only for URLs you are allowed to access, such as public pages or pages made available through an approved flow. See the ScreenshotNeo API documentation.
Or skip the browser setup
For an accessible URL, ScreenshotNeo returns an image or PDF from one GET request. For example, this cURL request saves a WebP screenshot:
curl -G "https://api.screenshotneo.com/v1/shot" \
-d access_key=YOUR_API_KEY \
--data-urlencode url=https://stripe.com \
-o shot.webp
Cookie banners, popups, and chat widgets are removed before the shot. Bot checks, blank pages, and failed loads are never billed. An MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. These features do not bypass logins or access restrictions, so use an accessible, authorized URL.
Sign up free for 1,000 screenshots a month, no card required.
6. Legal and reuse boundaries
The legal sources summarized here are U.S.-specific and do not decide every situation. In Van Buren v. United States (2021), the Supreme Court interpreted the CFAA phrase “exceeds authorized access” in relation to obtaining information from computer areas off-limits to the user. The Justice Department’s current Justice Manual says a CFAA prosecution may not be brought solely on the theory that a person exceeded authorized access by violating a contractual agreement or website terms-of-service restriction. Neither point means every competitor-page capture is lawful: authorization facts, contracts, privacy, copyright, trade-secret rules, and other issues may matter.
For publication or reuse, the U.S. Copyright Office describes fair use as a case-specific assessment involving purpose and character, the nature of the work, the amount used, and market effect. Capturing a page for internal reference does not automatically permit publishing its screenshot. Check the relevant permissions and rules, minimize what you reproduce, and seek legal advice when commercial publication or sensitive material is involved. This guide is not legal advice.
7. Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| The screenshot shows a login page | The browser has no valid session, the session expired, or navigation redirected to sign-in. | Sign in through the normal route in the authorized profile, confirm the target page is visible, and retry. Do not attempt to evade authentication. |
| The page shows access denied or a bot check | The account lacks access, the site blocked the request, or the page requires a supported interactive check. | Stop and use the site’s approved access process. Do not bypass the denial or bot controls. |
| The selector wait times out | The selector is wrong, the element is hidden, the page is still loading, or the target content differs from expectation. | Inspect the page manually, choose a stable selector that exists on the authorized target page, and distinguish login/error states from the intended content. |
| The full-page screenshot misses lower sections | Content may load only after scrolling or expanding an allowed section. | Scroll through the page in a controlled way and wait for the relevant content. Avoid actions that submit forms or alter account data. |
networkidle never arrives |
Long polling, analytics, or persistent connections keep network activity open. | Use a page-specific visible selector as the readiness condition; use a bounded timeout for any secondary wait. |
| The saved session stops working | Sessions expire or are revoked, or the site requires a fresh interactive check. | Repeat the approved sign-in process and update the private session state. Never share or log cookie values. |
| The image contains unrelated account data | The viewport or full-page scope includes profile details, notices, or other private content. | Choose a narrower element or viewport, navigate to a properly scoped page, and review the image before sharing. |
8. Performance, reliability, and cost
Local browser automation runs a browser and loads the target page, so completion time depends on the site, assets, authentication flow, and chosen wait condition. Avoid arbitrary long sleeps: they add delay without proving that the content is ready. Use a stable selector and bounded timeouts so failures are visible and repeatable. Full-page captures can take longer and produce larger files than viewport or element captures.
For repeatable comparisons, hold the viewport, device scale, browser version, wait condition, and capture scope steady, and record them with each image. Dynamic content, personalized account data, experiments, and time-sensitive notices can change between runs; record the capture time and page context. No approach guarantees identical output across changing pages.
Playwright and a locally run browser have no per-screenshot API charge described by the cited sources, but they use compute, storage, and maintenance. A hosted rendering service may have its own pricing and credential-handling considerations; check its current official documentation and plan details. ScreenshotNeo’s published plan options are Free: 1,000 shots/month; Starter: $5 for 3,000; Growth: $15 for 15,000; Pro: $39 for 60,000; Scale: $99 for 250,000; Business: $249 for 1,000,000. Yearly billing gives two months free, and every feature is on every plan. Only clean shots are billed; responses identify page verdict and billing status in headers. Don’t send protected-page credentials to a hosted service unless the site and your organization permit that handling.
FAQ
Can I use a screenshot as proof that the competitor’s page said something?
A screenshot records a visual state at a point in time, but it does not by itself establish permission to access, publish, or rely on the material. Keep the original and record the URL, date, viewport, and capture context.
Should I save a screenshot or an accessibility snapshot?
Use a screenshot for appearance and layout. A structural or accessibility snapshot can help when the question concerns page text and structure; the two can complement each other.
Does an authorized login mean I can publish the captured page?
No. Access and reuse are separate questions. Consider permission, applicable terms, privacy, copyright, and the intended publication context.
Can ScreenshotNeo capture a page that requires my competitor account?
ScreenshotNeo does not grant account access or bypass a login. Use an authorized browser session for protected pages, or use ScreenshotNeo for URLs accessible through an approved workflow.
Sources
- Playwright: Screenshots — viewport, full-page, and element capture.
- Cloudflare Browser Rendering documentation — hosted rendering and authenticated capture documentation.
- Chrome for Developers: Puppeteer — browser automation documentation.
- Playwright: ARIA snapshots — structural snapshots.
- Van Buren v. United States (2021) — Supreme Court opinion.
- U.S. Department of Justice, Justice Manual: Computer Fraud.
- U.S. Copyright Office: Fair Use.


