ScreenshotNeo

BlogHow-to

How to Enable Cookies in Browser Screenshots

Enable the cookies your screenshot needs, verify the logged-in state, and capture reliable browser screenshots without opening every tracker.

By the ScreenshotNeo team1 October 20266 min read

Direct answer: enable the cookie permission required by the page, reload it, repeat the sign-in or consent action, verify that the expected state is visible, and only then capture the screenshot. Cookies preserve browser state such as sessions and preferences; the screenshot itself does not carry a cookie store.

How cookies affect a screenshot

A screenshot records the page after the browser renders it. If cookies are blocked, the page may show a logged-out account, an empty embedded tool, a repeated consent prompt, or a broken workflow. First-party cookies belong to the site in the address bar. Third-party cookies come from another domain embedded in the page and may be required for federated login or an embedded service.

Use the narrowest setting that fixes the page. A site-specific exception limits tracking and is easier to undo than enabling every third-party cookie globally.

Enable cookies in Chrome

  1. Open Settings.
  2. Select Privacy and security.
  3. Open Third-party cookies.
  4. If the workflow needs cross-site authentication or embedded content, select Allow third-party cookies. If only one site is involved, add a site-specific exception when available.
  5. Return to the target page, reload it, sign in again if needed, and verify the expected account or content before capturing.

Google explains that blocking third-party cookies can prevent sign-in to a third-party website and documents the exception behavior in Google Account Help.

Enable cookies in Microsoft Edge

  1. Open Settings and more (the three-dot menu), then Settings.
  2. Choose Privacy, search, and services.
  3. Open Cookies.
  4. Turn on Allow sites to save and read cookie data (recommended).
  5. For one domain, use Allowed to save cookies and select Add site.
  6. Reload the page and repeat the action that depends on cookies.

See Microsoft’s Edge cookie management guide for the global switch and per-site allow list.

Enable cookies in Firefox

  1. Open Settings and select Privacy & Security.
  2. Review Browser Privacy and the cookie controls under Custom protection.
  3. For a single website, open Manage Exceptions, enter its URL, choose Allow, and save.
  4. Reload the target page, sign in again if necessary, and confirm the personalized state.

The exception workflow is described in Microsoft’s browser-cookie guidance.

Enable cookies in Safari on macOS

  1. Open Safari settings or preferences.
  2. In Privacy, review cross-site tracking and cookie blocking.
  3. Turn off Prevent cross-site tracking when the page relies on cross-site cookies.
  4. Reload the page and complete the sign-in or consent flow.
  5. Restore stricter privacy settings after the capture if the exception was temporary.

Menu names vary by macOS release. Microsoft’s cookie guidance describes the cross-site setting and its effect.

Verify the state before taking the screenshot

  1. Reload after changing a cookie setting. Existing tabs can retain the blocked state.
  2. Repeat the action that failed: sign in, accept consent, open the embedded frame, or select the account.
  3. Check a visible indicator such as the account name, avatar, personalized content, or loaded embedded tool.
  4. Capture only after the expected state is present.

If it still fails, try a site-specific exception, clear that site’s data only when necessary, and check whether an enterprise policy controls the browser.

Automate cookies with Playwright (Node.js)

For repeatable captures, create a browser context with the required cookie policy, navigate, verify the page, and capture. Install Playwright with npm install playwright, then save this as capture.mjs:

import { chromium } from 'playwright';

const browser = await chromium.launch({ headless: true });
const context = await browser.newContext({
  // Use a persistent profile or storageState for an authenticated session.
  storageState: process.env.STATE_FILE || undefined,
  // This context allows normal cookie handling. The site may still require
  // a third-party-cookie exception in a real browser policy.
});
const page = await context.newPage();
await page.goto('https://example.com/account', { waitUntil: 'networkidle' });
await page.screenshot({ path: 'account.png', fullPage: true });
await browser.close();

To save a session after signing in, call await context.storageState({ path: 'state.json' }) after the login flow, then set STATE_FILE=state.json on later runs. Treat that file as a password: it can contain session cookies.

Automate cookies with Selenium (Python)

from selenium import webdriver
from selenium.webdriver.chrome.options import Options
from selenium.webdriver.support.ui import WebDriverWait

options = Options()
options.add_argument('--headless=new')
options.add_argument('--window-size=1440,1000')
driver = webdriver.Chrome(options=options)
try:
    driver.get('https://example.com/account')
    WebDriverWait(driver, 30).until(
        lambda d: 'Sign in' not in d.title
    )
    driver.save_screenshot('account.png')
finally:
    driver.quit()

For an existing authenticated session, add cookies with driver.add_cookie after first opening the same domain, then reload. Never put live session values in source control or logs.

Choice Coverage Use when Trade-off
First-party cookies The site in the address bar Login, preferences, or site sessions are missing Usually the smallest change
Third-party cookies Embedded or cross-site domains Federated login or an embedded application needs them More tracking and broader access
Per-site exception One approved domain A single capture workflow needs cookies Requires maintaining an allow list
Global allow All sites Temporary diagnosis only Largest privacy impact

On managed devices, an administrator can control whether websites create cookies. Edge documents the policy in DefaultCookiesSetting. Contact IT if the setting is locked.

Troubleshooting

Symptom Likely cause Fix
Screenshot is logged out Session cookie was blocked or expired Allow cookies for the site, sign in again, reload, and verify the account indicator.
Embedded frame is blank It uses third-party cookies Allow third-party cookies or add an exception for the embedded domain.
Consent prompt appears every time Consent cookie cannot be written Allow first-party cookies and complete consent before capture.
Setting changed but page is unchanged Old tab or cached state Reload; if needed, clear data for that site and repeat the flow.
Cookies work manually but not in automation Automation starts with a fresh context Persist and reuse Playwright storage state or add Selenium cookies after opening the domain.
Login redirects repeatedly Cross-site authentication cookies are blocked Allow the identity provider’s cookies and the target site’s cookies, then retry.
Cookie controls are unavailable Enterprise policy or managed browser Check policy settings and ask the administrator for a scoped exception.
Capture shows a bot check or blank page The target did not render a usable page Wait for the page, reduce automation speed, and inspect network and console errors before retrying.

Performance, reliability, and security

  • Wait for state, not just navigation. Use a selector that proves the account or embedded content is visible; network idle alone can finish too early.
  • Keep sessions short-lived. Reuse a stored state for speed, but rotate it and restrict file permissions.
  • Prefer scoped exceptions. They reduce unwanted tracking and make failures easier to reproduce.
  • Expect differences between browsers. Cookie partitioning, tracking protection, extensions, and enterprise policies can change the result.
  • Capture deterministically. Set a fixed viewport, timezone, locale, and wait condition when comparing screenshots.
  • Do not log secrets. Cookie headers, storage-state files, and authorization values can grant account access.

Or skip the browser setup

ScreenshotNeo provides a website screenshot API and MCP server. Its capture flow accepts cookie and consent banners before the shot and removes more than 60 known consent platforms, newsletter popups, and chat widgets. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed; the response identifies the result with X-Page-Verdict and X-Billed headers. An MCP server lets Claude, Cursor, and other MCP clients call take_screenshot, get_page_info, and capture_pdf.

See the ScreenshotNeo API documentation for all options, including custom cookies, headers, user agents, waits, JavaScript, CSS, device presets, caching, signed links, async jobs, and bulk capture.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 screenshots, and every feature is available on every plan. Create a free ScreenshotNeo account.

FAQ

Do screenshots contain cookies?

No. Cookies affect how the browser renders the page; the image contains rendered pixels, not the browser cookie store.

Should I allow all third-party cookies?

Only when the workflow requires them. A per-site exception is narrower and easier to revert.

Why does a private window show a different page?

Private windows start with a separate, usually empty cookie store. Sign in and complete consent again, or use a controlled persistent profile.

Yes. Browser automation can click the consent control and save the resulting state; verify that the banner is gone before capture.

How do I capture a logged-in page safely?

Use a short-lived test account, keep storage-state files private, and never commit cookies or authorization headers.