How to Capture a Cookie Banner Screenshot for a Website Compliance Report
Capture a cookie banner in a reproducible browser state, preserve the original, and document what a screenshot can—and cannot—prove.
To capture a cookie banner for a website compliance report, open the page in a fresh browser session, capture the banner before interacting with it, and record the URL, timestamp, browser, viewport, locale, and session state. Preserve the original image unchanged. Capture the preferences panel and post-choice state as separate files when they matter to the report. A screenshot documents what the interface looked like; it does not prove which cookies, scripts, or network requests ran.
1. Define the evidence question
Before capturing, write down the question the image should help answer. Examples include: What did a first-time visitor see? Were accept and reject controls both visible? What did the preference panel contain? What appeared after a refusal? The question determines whether an area, viewport, or full-page capture is appropriate.
Keep visual evidence separate from behavioral conclusions. A banner screenshot can show visible text, controls, prominence, layout, and state at the recorded time. It cannot establish by itself whether non-essential cookies were set before a choice, whether rejection stopped tracking, or what data left the browser. Support those claims with an authorized browser, network, storage, or other technical audit. CNIL identifies timestamped interface captures as one possible part of an evidence set, alongside code versions, audits, and timestamped consent-management configuration records (CNIL guidance on cookies and trackers).
2. Prepare a reproducible browser state
- Use a fresh browser profile, or clear the site’s consent state and relevant site data so the first-visit banner appears. Record which approach you used.
- Open the exact URL in the intended locale and region. If the report concerns a mobile experience, use a defined mobile viewport or device profile.
- Wait for the page and banner to finish rendering. Note any delay, loading behavior, or other condition that could affect what appears.
- Record the capture context before taking the image: exact URL, date and time with timezone, browser and version, viewport width and height, locale or region, and whether this was a fresh session or a session with a prior choice.
These details help another reviewer interpret and reproduce the capture. CNIL specifically describes retaining timestamped captures of the rendered interface for each site or app version; keeping the other context fields is a practical way to make the artifact interpretable.
3. Capture the initial banner with Chrome DevTools
Capture the banner before clicking accept, reject, close, or preferences. Keep the whole banner and enough surrounding page content to establish where it appeared.
- Open the page in Chrome and make sure the banner is visible.
- Open DevTools, then open the Command Menu.
- Type
screenshotand choose Capture area screenshot. - Drag around the banner and its relevant page context. Save the resulting image as the unaltered original.
For a viewport or mobile-context image, turn on Device Mode, choose the viewport or device context, then use Capture screenshot. Choose Capture a full size screenshot when the report needs the whole rendered page. Chrome documents these options in its Command Menu and Device Mode guides. Select the capture scope that answers the report question: an area is focused, a viewport shows what a visitor saw on screen, and a full-size image includes content beyond the initial viewport.
4. Capture each relevant state separately
Do not combine different interaction states into one edited screenshot. Save each meaningful state as its own image, with a filename that records the state and action. For example:
2026-10-04T14-30-00Z_initial-banner_desktop.png2026-10-04T14-31-00Z_preferences-open_desktop.png2026-10-04T14-32-00Z_after-reject_desktop.png
Use the actual capture time and timezone in filenames or in a companion evidence log. After preserving the initial banner, open the preference or details panel if it is relevant and capture it separately. Then perform the action being documented—such as reject—and capture the resulting state separately. If you also document acceptance, treat that as a distinct state. Record the exact action taken and the session state for each image.
5. Preserve the original and document it
- Keep the original file unchanged and retain an evidence identifier that connects it to the report.
- Store the capture context with the image, either in a report entry or a separate evidence log.
- If an annotated copy is useful, make a separate file. Label it as annotated and retain the original alongside it.
- For a stronger record, preserve relevant code or configuration versions and timestamped consent-management platform configuration records. A file hash can supplement the record, but it does not establish that the page state was legally compliant.
CNIL lists timestamped captures, preserved code versions, regular audits, and timestamped CMP configuration records as possible evidence approaches. Their usefulness depends on the claim being made and the context of the site or app.
6. Add technical evidence for behavior claims
If the report says trackers ran before consent or that refusing consent stopped them, collect technical evidence in addition to screenshots. An authorized browser audit can examine relevant network requests and browser storage before and after a choice. Record the test setup and the states compared so the evidence can be interpreted. Avoid presenting an image of a banner as proof of runtime behavior.
Jurisdiction matters. The ICO’s cookie guidance says non-essential cookies must not be set before consent under the guidance it describes, and explains consent as freely given, specific, informed, and indicated by an unambiguous positive action (ICO guidance on cookies and similar technologies). CNIL’s French guidance gives an example in which closing a banner, or taking an action other than explicitly accepting, is treated as refusal; it also says other methods may be used if they meet applicable requirements (CNIL compliance guidance). These sources cover UK and French contexts, not a universal checklist. Determine which rules apply to the site and report.
7. Choose the right capture method
| Method | Useful for | Limit |
|---|---|---|
| DevTools area capture | A focused banner image with surrounding context | Does not include the rest of the page outside the selected area |
| DevTools viewport capture | Showing the visible desktop or emulated mobile screen | Does not include content below the viewport |
| DevTools full-size capture | Showing the full rendered page | May make the banner small relative to the overall image |
| ScreenshotNeo API | Repeatable captures by URL, including full-page output and configurable waits or viewports | It is an image capture service; an image still does not prove which runtime requests or storage changes occurred |
For a report that depends on the first-visit state, make sure the capture starts from a session in which the banner is actually present. A screenshot service or browser automation session may have different cookies, region, or timing from a human visitor’s session; record and validate that context.
Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server from Yorker Media. One GET request can return a screenshot as PNG, JPEG, or WebP, or a PDF. It can wait for a selector, a delay, or network idle; capture a full page or an element; set viewport and device options; and pass cookies, headers, user agent, timezone, or geolocation. For compliance evidence, ensure your request preserves the banner state you intend to document: ScreenshotNeo’s consent-banner removal can be turned off for the capture. See the ScreenshotNeo API documentation for parameters and configuration.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
For a compliance capture, adapt the target URL and configure the requested output and browser state according to the documentation. Keep a record of the request settings alongside the returned file. Cookie banners, newsletter popups, and chat widgets are removed before the shot by default, and each step can be turned off; disable consent cleanup when the purpose is to preserve a visible banner. Bot checks, blank pages, timeouts, and failed loads are not billed, and cache hits are not billed; response headers identify the page verdict and whether the response was billed. An MCP server lets AI agents use take_screenshot, get_page_info, and capture_pdf. The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 screenshots.
Sign up free for 1,000 screenshots a month, with no card.
Troubleshooting
| Problem | Likely cause | Fix |
|---|---|---|
| The banner does not appear | The browser has stored a prior consent choice, or the page is being served for a different region or locale | Use a fresh profile or clear site consent state, then verify the URL, locale, and region. Record the session setup. |
| The screenshot misses part of the banner | The selected area was too small, or the banner moved during capture | Wait for rendering to settle and recapture with the full banner and enough page context. Keep the earlier original if it is part of the evidence record. |
| The page looks different on mobile | The viewport, device context, or responsive layout differs | Set and record the intended mobile viewport or device context. Capture desktop and mobile as separate artifacts when both matter. |
| The captured state is not the first-visit state | The session has a stored choice or the capture flow interacted with the banner | Start a fresh session and capture before clicking. Record any automated setup and actions. |
| The report claims trackers ran based only on the screenshot | A visual capture cannot reveal all runtime requests or storage changes | Qualify the claim and add authorized network or storage evidence from an audit. |
| An annotated image is mistaken for the original | The marked-up copy replaced or was not distinguished from the source file | Retain the unedited original, save annotations as a separate copy, and identify the annotated version in the report. |
Performance, reliability, and cost
For manual captures, the main reliability factors are reproducible session state, stable page rendering, consistent viewport, and an accurate capture timestamp. If the page or banner loads asynchronously, wait until it is visibly settled before capturing. For repeated captures, keep the setup and naming convention consistent and retain separate files for materially different states or versions.
ScreenshotNeo supports configurable waits, caching with a TTL, asynchronous jobs with signed webhooks, and bulk capture of up to 100 URLs per call. Caching can reduce repeated capture work, but evidence intended to show a changed banner or a new site version should use a fresh result rather than rely on a cached image. Its stated billing model charges only clean shots: bot checks and CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, with the page verdict and billing status in response headers.
ScreenshotNeo plans are Free: 1,000 shots per month; Starter: $5 for 3,000; Growth: $15 for 15,000; Pro: $39 for 60,000; Scale: $99 for 250,000; and Business: $249 for 1,000,000. Yearly billing gives two months free, and every feature is on every plan. For a small number of compliance captures, DevTools may be sufficient; API automation is useful when the workflow needs repeatable settings or many URLs. In either case, an image is only one part of the evidence needed for behavioral claims.
FAQ
Should a compliance screenshot include the whole page?
Only if the report question needs it. Use an area or viewport capture to make the banner legible; use full-page capture when page context below the fold matters.
Should I include the time directly on the image?
Keep the original unaltered. Put the timestamp in the evidence log or filename; if you add a visible label, save it as a separate annotated copy.
Does a screenshot prove the site complies with cookie rules?
No. It records appearance and state. Compliance conclusions depend on applicable jurisdiction and may require technical evidence about cookies, storage, and requests as well as the interface.
Do I need to capture both accept and reject?
Capture the states relevant to the report question. If comparing choices, preserve each result as a separate image and record the action and starting session state.


