How to Read Cookies in Puppeteer
Read cookies from Puppeteer's default or a specific browser context with current APIs, inspect cookie fields, and fix common retrieval issues.
Use await browser.cookies() to read cookies in Puppeteer’s default browser context. If the page belongs to another context, use await context.cookies() on that context. The older page.cookies() method is deprecated; new code should use the browser or browser-context APIs.
Cookies belong to a browser context, so choose the context that owns the page and session you want to inspect. The examples below use current Puppeteer APIs. Check your installed Puppeteer version’s API reference if an example does not match your dependency.
Read cookies from the default browser context
This complete ES module example opens a page, waits for navigation, reads the default context’s cookies, prints selected fields, and closes the browser even if an operation fails.
import puppeteer from 'puppeteer';
const browser = await puppeteer.launch();
try {
const page = await browser.newPage();
await page.goto('https://example.com', { waitUntil: 'domcontentloaded' });
const cookies = await browser.cookies();
console.log(cookies);
for (const cookie of cookies) {
console.log({
name: cookie.name,
value: cookie.value,
domain: cookie.domain,
path: cookie.path,
expires: cookie.expires,
httpOnly: cookie.httpOnly,
secure: cookie.secure,
sameSite: cookie.sameSite,
});
}
} finally {
await browser.close();
}
browser.cookies() returns cookies in Puppeteer’s default BrowserContext. It is a shortcut for browser.defaultBrowserContext().cookies(). This includes browser-managed cookies; it is not limited to cookies readable by page JavaScript.
Read cookies from a specific context
Browser contexts isolate browser storage, including cookies. When a page was created in a non-default context, read cookies from that same context:
import puppeteer from 'puppeteer';
const browser = await puppeteer.launch();
try {
const context = await browser.createBrowserContext();
const page = await context.newPage();
await page.goto('https://example.com', { waitUntil: 'domcontentloaded' });
const cookies = await context.cookies();
console.log(cookies);
} finally {
await browser.close();
}
Calling browser.cookies() reads the default context, not every context you’ve created. If you have multiple isolated sessions, keep track of which context created each page and query each relevant context separately.
What cookie data you get
The result is an array of cookie records. Fields commonly useful when inspecting a session include:
nameandvalue: the cookie’s key and stored value.domainandpath: the scope used to decide which requests can receive it.expires: expiry information; session cookies may not have a persistent expiry.httpOnly: whether page JavaScript is restricted from reading the cookie.secure: whether it is restricted to secure transport.sameSite: the cookie’s cross-site sending policy as represented by the browser.
Inspect the returned objects directly when you need the exact fields exposed by your installed Puppeteer version. Avoid printing cookie values in shared logs: session cookies can grant access to an account or application.
Why document.cookie may show fewer cookies
document.cookie is a page-level JavaScript interface, not a complete view of browser cookie storage. In particular, an HttpOnly cookie is intentionally inaccessible to page JavaScript. Puppeteer’s browser and context cookie APIs are the right place to inspect browser-managed cookies.
The Puppeteer guide demonstrates assigning a cookie with page evaluation and then reading cookies with browser.cookies():
await page.evaluate(() => {
document.cookie = 'myCookie=MyCookieValue';
});
console.log(await browser.cookies());
This assignment is subject to normal browser cookie rules, including the current document’s origin and cookie attributes. A cookie set for one host or path may not appear where you expect when inspecting a different scope.
Migration from page.cookies()
page.cookies() is deprecated. Replace it with a browser or context call based on the page’s owner:
| Page ownership | Current retrieval |
|---|---|
| Default browser context | await browser.cookies() |
| Explicit browser context | await context.cookies() |
The legacy page method documented URL filtering: without URLs it returned cookies for the current page URL; with URL arguments it returned cookies for those URLs. When updating older code, first determine which page and URL scope it relied on, then use the current Browser or BrowserContext API and verify that the resulting set matches the intended context and scope.
Read cookies with cURL, Python, or Node.js
Puppeteer is a Node.js browser automation library, so the primary examples above use JavaScript. For an existing browser session, retrieve cookies through Puppeteer and then pass only the required cookie data to another tool. cURL and Python do not directly inspect Puppeteer’s in-memory browser context.
cURL after exporting a cookie
If you already have a cookie value and are authorized to use it, cURL can send it in an HTTP request. This does not read cookies from Puppeteer:
curl --cookie 'session=YOUR_COOKIE_VALUE' https://example.com/
Python after exporting a cookie
Likewise, Python’s requests library can send a cookie that you obtained separately:
import requests
response = requests.get(
'https://example.com/',
cookies={'session': 'YOUR_COOKIE_VALUE'},
timeout=30,
)
print(response.status_code)
print(response.text[:500])
Node.js request after reading with Puppeteer
In Node.js, read from Puppeteer first, then construct a cookie header for a request only when you have a valid reason to reuse that session. A minimal example for one cookie is:
const cookies = await browser.cookies();
const session = cookies.find((cookie) => cookie.name === 'session');
if (!session) {
throw new Error('The session cookie was not found in the default context');
}
const response = await fetch('https://example.com/', {
headers: { Cookie: `session=${session.value}` },
});
console.log(response.status);
Cookie domain, path, expiry, secure, and same-site rules affect whether a browser would send a cookie. Manually copying a value into a request does not automatically reproduce those browser checks.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| The returned array is empty | The page has not set cookies yet, the request has not reached the relevant origin, or you queried a different context. | Navigate to the intended site, wait for the action that establishes the session, and call cookies() on the owning context. |
A cookie visible in the browser is missing from document.cookie |
It may be HttpOnly, or its domain/path may not match the current document. |
Inspect with browser.cookies() or context.cookies() and check the cookie scope fields. |
| Cookies from one page appear missing in another context | Browser contexts have isolated storage. | Retain the context reference and read from that context rather than the default browser context. |
page.cookies is not a function or a deprecation warning appears |
The code uses a deprecated API or a Puppeteer version whose API surface differs. | Use browser.cookies() or context.cookies(); consult the API documentation matching the installed version. |
The cookie created through document.cookie does not appear |
The assignment may have run on the wrong origin or used attributes the browser rejects. | Run it after navigating to the intended site and inspect browser cookie storage; check domain, path, and secure requirements. |
| The session disappears after closing the browser | A session cookie or non-persistent browser context was used. | Do not assume a transient automation context persists between runs. If persistence is required, explicitly design storage and lifecycle handling appropriate to your application. |
Performance, reliability, and security
Cookie retrieval is a browser-storage operation and usually is not the expensive part of an automation workflow; navigation, page scripts, and network waits tend to dominate. Read cookies after the interaction that establishes the state, and avoid polling repeatedly when one read after a known event is sufficient.
- Reliability: keep the BrowserContext associated with each page/session. This prevents accidentally inspecting the default context while the page lives elsewhere.
- Timing: choose a navigation or application-state wait that reflects when the site sets its cookie. A completed document load does not guarantee that a later login or consent interaction has run.
- Security: treat cookie values as credentials. Do not commit them, include them in public bug reports, or emit them into broadly accessible logs.
- Cost: Puppeteer itself has no per-cookie API charge described by these sources. Your runtime, browser infrastructure, and network usage determine the operating cost.
Or skip the browser setup
If your goal is to capture a page rather than inspect its cookie values, ScreenshotNeo is a website screenshot API and MCP server. A single GET request returns a PNG, JPEG, WebP, or PDF. Its capture flow accepts cookie and consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before the shot; each step can be turned off. Bot checks and CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status.
See the ScreenshotNeo API documentation. This cURL example captures a page as WebP:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
timeout=90,
)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await import('node:fs/promises').then(({ writeFile }) => writeFile('shot.webp', Buffer.from(await res.arrayBuffer())));
- Cookie banners, popups, and chat widgets are removed before the shot.
- Bot checks, blank pages, and failed loads are never billed.
- An MCP server lets AI agents use
take_screenshot,get_page_info, andcapture_pdf. - 1,000 screenshots a month are free with no card; paid plans start at $5 for 3,000 screenshots.
ScreenshotNeo is for producing a page capture; it does not return the target site’s cookie values. Sign up free for 1,000 screenshots a month with no card.
FAQ
Does browser.cookies() read cookies from every open page?
It reads cookies in the default BrowserContext. For a page in another context, call that context’s cookies() method.
Can Puppeteer read HttpOnly cookies?
Use Puppeteer’s browser or context cookie APIs to inspect browser-managed cookies. Page JavaScript’s document.cookie does not expose HttpOnly cookies.
Should I keep using page.cookies()?
No for new code: the Page API marks it deprecated and points to Browser or BrowserContext cookie methods.
Does ScreenshotNeo show me a site’s cookie values?
No. ScreenshotNeo captures a rendered page and cleans certain overlays; it is not a cookie-inspection API.


