How Cypress Studio AI Generates Selectors and Handles Sensitive Data
Learn Cypress Studio AI’s selector priorities, how to customize them, which DOM values it excludes, and where sensitive-data protections stop.
Cypress Studio AI chooses selectors using a configurable priority order, aiming for selectors that are unique, readable, and performant. Its default order is data-cy, data-test, data-testid, data-qa, name, id, class, tag, attributes, then nth-child. Uniqueness can make Cypress skip an available preferred attribute or combine selector parts.
For sensitive data, Cypress documents exclusions for values in password fields, certain credit-card fields identified by standard autocomplete attributes, and hidden inputs. The DOM structure and context can still inform AI recommendations. This is a specific field-based safeguard, not a guarantee that every sensitive value in an application is redacted.
How does Cypress Studio generate selectors?
Studio observes the elements a developer interacts with and the targets of assertions. It automatically chooses a unique selector for those elements, including targets in AI recommendations. The stated priorities are uniqueness, readability, and performance.
The default selector preference order is:
data-cydata-testdata-testiddata-qanameidclass- tag name
- other attributes
nth-child
This is a preference order, not a promise to always choose the first available attribute. If a candidate matches multiple elements, Cypress can skip it or combine selector parts to identify a unique target. A unique selector can still be fragile if the application generates unstable IDs, classes, or DOM structure, so review generated selectors as you would hand-written ones.
Can I change which selectors Cypress Studio prefers?
Yes. Configure Cypress.ElementSelector in your support file with Cypress.ElementSelector.defaults({ selectorPriority: [...] }). For example, a team can prioritize accessibility attributes and a stable test attribute, while deprioritizing dynamic classes and IDs:
// cypress/support/e2e.js
Cypress.ElementSelector.defaults({
selectorPriority: [
'data-cy',
'role',
'aria-label',
'data-testid',
'name',
'tag',
'attributes',
'nth-child'
]
});
Use the attribute names supported by the Cypress version in your project. The selector-priority API is documented as under active development; check the API reference for current behavior when upgrading. Cypress may still need to combine candidates to preserve uniqueness.
Choosing a project priority
- Prefer explicit test attributes when the team controls the markup and wants selectors insulated from visual redesigns.
- Consider
roleandaria-labelwhere they identify the element meaningfully and accessibly. - Avoid relying on generated IDs or styling classes if they change between builds.
- Keep uniqueness in mind: a semantic attribute shared by many controls may need another selector component.
- Review selectors after significant markup changes; configuration improves selection preferences but cannot guarantee long-term stability.
What does Studio AI use to suggest assertions?
Studio AI compares DOM changes observed across recorded interactions and proposes assertions that reflect visible UI changes. It does not inspect application source code, business logic, or backend rules. Recommendations therefore describe observed interface behavior; they do not prove that server-side validation, authorization, or business requirements are correct.
Studio recording and manual assertion authoring work without Cypress Cloud. AI recommendations require a Cypress Cloud account and a linked project.
Does Cypress Studio AI send passwords or credit card values to the AI model?
Cypress documents that values from these field types are excluded before data is sent to the AI model:
- Password inputs:
input[type="password"]. - Credit-card fields identified using standard autocomplete tokens, including cardholder name, number, expiration, security code, and card type.
- Hidden inputs:
input[type="hidden"].
The field structure and surrounding context can still be used to generate recommendations; the values are excluded. That distinction matters: an assertion may be suggested based on the presence and role of a field even though the field value is not sent.
Does Cypress Studio redact all sensitive data?
No blanket redaction guarantee is documented by these field exclusions. They do not establish that arbitrary visible text, personal information in ordinary text fields, custom secret fields, or sensitive application state is automatically removed. Avoid putting real sensitive values into test pages or AI prompts unless your data-handling process permits it.
Keep secrets out of literal cy.prompt instructions
The DOM-field exclusion is separate from the natural-language text supplied to cy.prompt. If a developer writes a secret literally into a prompt step, that text is part of the prompt and is not protected by the DOM-field rule. Cypress recommends placeholders for sensitive values and says placeholder values are not sent to the AI model.
// Avoid embedding a real secret in the instruction string.
cy.prompt([
'Enter the account password: {{accountPassword}}'
]);
Use the placeholder mechanism supported by your Cypress version and supply its value through your test setup. Keep credentials in your normal secret-management path, and do not print them in logs or screenshots.
Controls, requirements, and limitations
- Session control: a user can disable Studio AI for an individual session.
- Organization control: Cloud admins and owners can disable AI capabilities in Cloud settings.
- Version: the Studio AI guide lists Cypress 15.11.0 or later as a requirement; verify the current requirement for the version you install.
- Scope: Studio AI is for end-to-end testing. Component testing, Cucumber-style tests, multi-origin recording, iFrames, and Shadow DOM are listed as unsupported.
- Recommendation quality: animations and transitions can create intermediate DOM changes; large pages may exceed context limits. Studio AI does not crawl an application automatically.
Practical workflow
- Add stable test attributes or meaningful accessibility attributes to important controls.
- Set a project selector priority if the default does not fit the application’s markup.
- Record a representative end-to-end flow with Studio and inspect the generated selectors.
- Review AI-proposed assertions against the intended user-visible behavior and add checks for backend rules separately.
- Use synthetic test data where possible, keep literal secrets out of prompt strings, and verify organizational AI settings.
- Revisit selector quality and unsupported-feature constraints when the UI or Cypress version changes.
Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| Studio chooses a class or positional selector instead of a test attribute | The preferred attribute may be absent, unsupported in the current configuration, or insufficient to identify one element. | Inspect the element’s attributes, ensure the test attribute is present and unique, and confirm the configured priority. |
| A generated selector changes between runs | The application may generate dynamic IDs/classes or alter DOM order. | Add a stable test attribute or meaningful accessible name and adjust selector priority. |
| AI recommendations are unavailable | AI suggestions require Cypress Cloud and a linked project; the version or project setup may also be unsupported. | Check Cloud linkage and the documented Cypress version requirement. Manual recording and assertions do not require Cloud. |
| A sensitive value appears in prompt content or logs | The value may have been typed literally into a prompt, printed by the test, or rendered as ordinary visible text rather than a protected field type. | Remove the literal, use a supported placeholder, and avoid logging or capturing real secrets. |
| Suggestions are poor around transitions or complex pages | Intermediate DOM states or context limits can affect recommendations. | Record after the interface settles, reduce the flow to a focused case, or author the assertion manually. |
| Studio cannot record an iframe, Shadow DOM, multi-origin, or component-testing case | These scenarios are listed among Studio AI limitations. | Use a supported end-to-end flow or write and maintain the relevant test directly. |
Performance, reliability, and cost notes
Selector priority affects the selector Cypress tries to produce, but it does not make an unstable page structure stable. Stable attributes and focused recordings reduce avoidable selector churn. Treat AI assertions as proposed test code and review them for the actual behavior the test must protect.
AI recommendations add a Cloud dependency; manual Studio recording and assertions remain available without Cloud. The research sources do not establish pricing, latency, or independent reliability benchmarks for Studio AI, so check Cypress’s current product and account documentation for those details rather than assuming a fixed cost or response time.
Or skip the browser setup
If the task is capturing the page itself for a test artifact, report, or agent workflow, ScreenshotNeo is a website screenshot API and MCP server. A single GET request returns a PNG, JPEG, WebP, or PDF. The API accepts common screenshot parameter names, which can make switching straightforward. See the ScreenshotNeo API documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo accepts cookie and consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers indicate the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for AI agents. The free plan includes 1,000 screenshots monthly with no card; paid plans start at $5 for 3,000 shots. Sign up for 1,000 free screenshots a month with no card.
FAQ
Does Studio AI understand what the application is supposed to do?
It uses observed DOM changes, not application source code, business logic, or backend rules. Validate recommendations against the intended behavior.
Will a selector priority override uniqueness?
No. Priority guides candidate preference; Cypress may skip or combine candidates to identify a unique element.
Can I use Studio without enabling AI?
Yes. Studio recording and manual assertions work without Cloud AI recommendations.


