ScreenshotNeo

BlogHow-to

Puppeteer screenshot gives net::ERR_CERT_AUTHORITY_INVALID: fix certificate errors

Fix Puppeteer’s ERR_CERT_AUTHORITY_INVALID navigation error with acceptInsecureCerts, or correct the certificate trust problem. Includes launch, connect, and troubleshooting guidance.

By the ScreenshotNeo team4 October 20266 min read

net::ERR_CERT_AUTHORITY_INVALID usually means Chromium does not trust the certificate authority that issued the site’s HTTPS certificate. If an automated test must proceed against a known test certificate problem, set Puppeteer’s acceptInsecureCerts: true on launch() or connect(). This bypass lets navigation continue; it does not repair the certificate or verify the server’s identity.

If the site should be trusted, fix its certificate chain or configure the intended private CA as trusted in the environment running Chrome. The error alone does not establish which part of a particular deployment is misconfigured.

Use acceptInsecureCerts for a controlled test

In current Puppeteer, acceptInsecureCerts defaults to false. Set it in browser options when launching Chromium. Then navigate and capture the page as separate steps:

import puppeteer from 'puppeteer';

const browser = await puppeteer.launch({
  acceptInsecureCerts: true,
});

try {
  const page = await browser.newPage();
  await page.goto('https://your-test-host.example', {
    waitUntil: 'networkidle2',
  });
  await page.screenshot({ path: 'page.png', fullPage: true });
} finally {
  await browser.close();
}

The option affects HTTPS errors during navigation. It is not a page.screenshot() option. Puppeteer’s [API docs](https://pptr.dev/api/puppeteer.connectoptions) describe this setting, and its [screenshots guide](https://pptr.dev/guides/screenshots) shows the navigation-then-capture sequence.

Attach to an existing browser

If another process or service started Chromium and Puppeteer connects to it, pass the same option to puppeteer.connect(). For example, with a browser WebSocket endpoint supplied by your environment:

import puppeteer from 'puppeteer';

const browser = await puppeteer.connect({
  browserWSEndpoint: process.env.BROWSER_WS_ENDPOINT,
  acceptInsecureCerts: true,
});

try {
  const page = await browser.newPage();
  await page.goto('https://your-test-host.example', {
    waitUntil: 'networkidle2',
  });
  await page.screenshot({ path: 'page.png', fullPage: true });
} finally {
  await browser.disconnect();
}

disconnect() detaches Puppeteer without closing a browser owned by another process. LaunchOptions extends ConnectOptions, so the setting is available for either approach. See the [Puppeteer launch options](https://pptr.dev/api/puppeteer.launchoptions) and [connect options](https://pptr.dev/api/puppeteer.connectoptions).

Choose between a test bypass and fixing trust

Approach Use it when What it means
acceptInsecureCerts: true A controlled automated run must access a known test host despite a certificate problem. Navigation proceeds without ordinary HTTPS certificate validation. Keep the bypass scoped to that run.
Correct the certificate chain or browser trust configuration The connection should be trusted, including for an internal site using a private CA. Fix the certificate served by the site, or configure the appropriate CA as trusted where Chrome runs.

Chrome checks whether a certificate chains to a recognized CA and can use local trust settings. A self-signed certificate’s issuing CA may need to be installed as a local trust root on each device that accesses the site; the precise steps depend on the platform and deployment. Consult the [Chrome Root Program Policy](https://www.chromium.org/Home/chromium-security/root-ca-policy/) and relevant platform guidance. A [Chromium issue discussion](https://issues.chromium.org/issues/402520952) also discusses installing a self-signed certificate’s issuing CA locally.

Check Puppeteer version and option spelling

Use acceptInsecureCerts with current Puppeteer. The old spelling, ignoreHttpsErrors, appears in older examples because Puppeteer renamed the option in version 23.0.0. Check the [Puppeteer changelog](https://pptr.dev/CHANGELOG) and the API docs that match the version installed in your project before copying version-specific advice.

Browser compatibility can matter too. Puppeteer publishes a [Puppeteer-to-Chrome for Testing version mapping](https://pptr.dev/chromium-support). When using a custom browser executable, check that mapping: Puppeteer says it is only guaranteed to work with its bundled browser when a custom executable path is used. Also verify the installed release’s [system requirements](https://pptr.dev/guides/system-requirements), since supported Node.js versions change.

Troubleshoot the failure

Symptom Likely cause What to check or change
net::ERR_CERT_AUTHORITY_INVALID still appears after setting the option The option may be on the wrong object, or the code may be using an old or mismatched Puppeteer setup. Set acceptInsecureCerts: true directly in the options passed to launch() or connect(). Confirm you are running the updated code and check the installed Puppeteer version’s API.
Navigation succeeds but the screenshot is blank or shows an error page Certificate bypass only addresses HTTPS validation; the target may still fail to render or the screenshot may capture an error page. Inspect the loaded page and navigation result before capture. Confirm that the intended content rendered and that the URL is the expected one.
Works locally but fails in CI or a container The browser environment, browser binary, or trust configuration differs. Confirm the same option reaches the browser used in CI. If the site should be trusted, configure the intended CA in that runtime and verify its served chain. Check Puppeteer’s supported browser mapping if using a separate executable.
ignoreHttpsErrors has no effect The example uses the pre-23.0.0 option name, while current Puppeteer uses acceptInsecureCerts. Use the spelling documented for your installed version; current API examples use acceptInsecureCerts.
The site still cannot be reached A certificate bypass cannot fix DNS, connection refusal, proxy, timeout, or other navigation failures. Read the actual navigation error and diagnose the network or server issue separately. Do not assume every failed screenshot is a certificate problem.

Performance, reliability, and cost considerations

The certificate option changes whether HTTPS errors block navigation; it does not make page rendering faster, guarantee the page will load, or ensure that the captured page is the intended one. Choose a navigation wait condition that fits the site, and verify the page content before relying on a screenshot in a test pipeline. The example uses networkidle2, but pages with ongoing network activity may need a different readiness condition.

For repeatable automation, keep the browser and Puppeteer versions aligned using Puppeteer’s browser support information, and keep certificate bypasses limited to the known test target and run. If a site is supposed to have valid HTTPS, fixing the served chain or configuring the correct CA gives the browser a trusted connection rather than suppressing the check.

No product-specific cost estimate follows from the certificate error itself. The relevant cost is your own browser runtime and infrastructure; measure it in the environment and at the capture volume you actually use.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server for developers. Its one-call API can return a screenshot without setting up Puppeteer in your project. See the [API documentation](https://screenshotneo.com/docs/) for request options.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await import('node:fs/promises').then(fs => fs.writeFile('shot.webp', Buffer.from(await res.arrayBuffer())));

ScreenshotNeo accepts cookie and consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each of those steps can be turned off. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers report the page verdict and billing status. Its MCP server lets AI agents use take_screenshot, get_page_info, and capture_pdf. The free plan includes 1,000 shots a month with no card; paid plans start at $5 for 3,000 shots.

Sign up for free: 1,000 screenshots a month, no card required.

FAQ

Does this option fix the website’s certificate?

No. It lets the browser continue despite HTTPS errors. Fix the certificate chain or trust configuration when the connection should be trusted.

Can I set this on page.screenshot()?

No. Set it in the options for puppeteer.launch() or puppeteer.connect(); the screenshot call happens after navigation.

Should I use ignoreHTTPSErrors?

Current Puppeteer documentation uses acceptInsecureCerts. The option was renamed in Puppeteer 23.0.0, so check the docs for your installed version.