Chrome Headless Screenshot Fails with ERR_CERT_AUTHORITY_INVALID: Fix
Fix Chrome headless certificate errors by checking the certificate chain, proxy, and trust store. Learn when a test-only bypass is appropriate.
Direct answer: ERR_CERT_AUTHORITY_INVALID means Chrome cannot validate the website’s certificate chain to a trusted certificate authority. Check the site’s certificate and your network path first, especially for an HTTPS-inspecting proxy. If the site uses a legitimate private certificate authority, establish trust through your organization’s approved process. A browser setting that accepts invalid certificates only bypasses validation for that test session; it does not repair the certificate.
Chrome’s screenshot flags control capture and viewport dimensions. They do not make an untrusted certificate valid. The same distinction applies to a longer screenshot timeout: it may allow more time for capture but cannot fix TLS trust.
1. Identify which Chrome session is failing
Before changing certificates or automation settings, record:
- The target URL and the complete browser or network error.
- Chrome version and the executable the job launches.
- Operating system or container image, including the base image where applicable.
- Automation framework and launch arguments.
- Whether a proxy, VPN, corporate network, or HTTPS inspection is involved.
- Whether ordinary Chrome on the same machine fails too.
This matters because certificate trust depends on the machine or environment running Chrome and the network path to the server. An error alone does not identify whether the cause is the site’s chain, local trust configuration, or network interception.
2. Reproduce with Chrome’s headless screenshot command
Chrome documents --headless --screenshot for command-line capture. This example saves screenshot.png in the current working directory and sets a 412 × 892 viewport:
chrome --headless --screenshot --window-size=412,892 https://example.com/
Replace chrome with the Chrome executable available in your environment, and use the affected URL. If the same authority error appears in regular Chrome, investigate the site, system trust configuration, clock, or network path rather than the screenshot command.
Chrome’s command-line reference also documents --timeout for screenshot capture. A timeout controls how long capture waits; increasing it does not repair certificate validation.
3. Check for a proxy or HTTPS inspection
On a work network, VPN, or managed machine, a proxy may intercept HTTPS and present a certificate issued by an organization-specific authority. Chrome identifies a missing or uninstalled proxy certificate as a possible cause of certificate errors.
- Ask the network or device administrator whether HTTPS inspection is enabled for this connection.
- If it is, request the approved certificate and the organization’s instructions for verifying and trusting it.
- Compare behavior on an approved alternate network, if available. A difference can help narrow the cause to the network path.
- Do not download a root certificate from an arbitrary site or install one just to silence the error.
A root CA can authorize certificates within its trust scope. Chromium warns that installing one has privacy and security consequences. Trust only a certificate whose origin and authenticity have been verified through the responsible administrator.
4. Repair trust instead of hiding the error
Choose the repair that matches the certificate you expect:
- For a website you control: configure the server to present a valid certificate chain trusted by the browsers and environments that need to access it. Check the certificate and intermediate chain with the site or hosting administrator.
- For an internal site with a private CA: obtain the organization’s approved CA certificate, verify its authenticity, then follow the administrator’s platform-specific trust-store process.
- For a managed proxy: have the administrator confirm the proxy’s certificate and provide the sanctioned trust configuration for the device or container.
There is no safe universal installation command: the correct steps depend on the operating system, container base, Chrome build, trust-store implementation, proxy, and certificate chain. Do not treat importing an unknown root as a general fix.
5. Use an invalid-certificate bypass only in an intentional test
Selenium’s WebDriver capability acceptInsecureCerts can accept invalid certificates for a browser session. Its default is false; when false, an invalid certificate produces a certificate error. This is useful when the test deliberately needs to visit an endpoint with an invalid certificate, but it weakens the TLS guarantee for that session. It does not validate or fix the server’s chain.
Python Selenium example for a deliberately isolated test:
from selenium import webdriver
from selenium.webdriver.chrome.options import Options
options = Options()
options.accept_insecure_certs = True
# Keep this session scoped to a controlled test target.
driver = webdriver.Chrome(options=options)
try:
driver.get("https://example.test")
driver.save_screenshot("screenshot.png")
finally:
driver.quit()
Use this only when accepting the invalid certificate is part of the test’s purpose. Do not use it to make production screenshots appear successful or to claim that the connection is trustworthy.
6. Check which Headless implementation is running
Current Chrome Headless is unified with regular Chrome. The updated mode shipped in Chrome 112. Starting with Chrome 132, the earlier Headless implementation is available as the separate chrome-headless-shell binary. When a failure seems specific to Headless, establish whether the job launches Chrome with --headless, Puppeteer’s headless: 'shell', or the standalone shell executable. That distinction helps identify which browser build and environment to inspect; it does not change what the certificate error means.
7. Troubleshoot common symptoms
| Symptom | Likely explanation | What to do |
|---|---|---|
| Regular Chrome and headless Chrome both show the error | The certificate chain, local trust configuration, clock, or network interception may be involved. | Inspect the site and network path; ask the site or network administrator to verify the expected chain. |
| Only a work network or VPN fails | An HTTPS-inspecting proxy may present a certificate from a private CA that this environment does not trust. | Ask the administrator whether inspection is enabled and follow the approved certificate verification and installation process. |
| It works on a workstation but fails in a container | The container may have a different trust configuration or network path. | Record the container base image and Chrome executable, then configure trust using the container environment’s approved process. |
| A longer timeout does not help | Timeouts affect waiting for capture, not certificate authority validation. | Diagnose the trust chain and proxy instead of increasing the capture timeout. |
| A bypass makes the screenshot work | The session accepted an invalid certificate; the underlying trust problem remains. | Keep the bypass limited to an isolated test, or repair trust if the certificate is meant to be trusted. |
| The error appears after changing headless mode | The job may use a different Chrome implementation or executable. | Check the Chrome version and executable, including whether it is regular Chrome or chrome-headless-shell. |
8. Performance, reliability, and cost considerations
Certificate repair is a reliability issue as much as a capture issue. A screenshot from a session that accepted an invalid certificate does not establish that the page was served by the expected, authenticated endpoint. For repeatable captures, use a verified trust configuration in the actual machine or container that runs the job.
Changing viewport size or capture timeout may affect the screenshot output or wait duration, but neither addresses the cause of this error. The research sources do not establish a universal performance or cost impact for certificate repair; those depend on the environment and capture workload.
Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server. Its API can return an image or PDF with one GET request, so you do not need to configure a local Chrome session for the capture. See the ScreenshotNeo API documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await Bun.write('shot.webp', res);
- Cookie banners, newsletter popups, and chat widgets are removed before the shot; each cleanup step can be turned off.
- Bot checks, blank pages, timeouts, and failed loads are never billed. Response headers report the page verdict and billing status; cache hits also cost nothing.
- An MCP server lets AI agents, including Claude and Cursor, take screenshots with its tools.
- 1,000 screenshots a month are free with no card. Paid plans start at $5 for 3,000 screenshots.
Sign up for ScreenshotNeo’s free 1,000 screenshots a month, with no card required.
FAQ
Does --headless cause this certificate error?
The error means Chrome could not validate the certificate authority chain. Compare headless and ordinary Chrome to see whether the failure is specific to the automation environment.
Does a self-signed certificate always mean the site is unsafe?
The error by itself does not establish the exact cause or the site’s intent. For a private or self-signed certificate, verify its origin and authenticity with the site or organization responsible before trusting it.
Can I fix this by setting acceptInsecureCerts?
That capability accepts invalid certificates for a WebDriver session. It bypasses validation; it does not repair the certificate chain.
Will changing screenshot dimensions fix the error?
No. --window-size sets the capture viewport. It does not change certificate trust.


