ScreenshotNeo

BlogHow-to

How to Screenshot an Indian Bank Webpage That Uses OTP Login with an API

Complete an authorized OTP login in a browser, then capture the page with Playwright. Learn how to protect session data and avoid common API misunderstandings.

By the ScreenshotNeo team4 October 202610 min read

Direct answer: A screenshot API does not log you in to a bank account or complete OTP verification. For an authorized capture, open the bank’s page in a browser you control, complete the bank’s normal OTP flow, navigate to the page you are permitted to document, then capture the visible viewport or full page. Playwright can capture the page with await page.screenshot({ path: 'screenshot.png' }). Use a bank-approved sandbox and test account where available, and protect both screenshots and saved browser state as sensitive data.

The title does not identify a bank or API. Login flows, automation rules, API access, and permissions vary. The steps below are a general workflow, not confirmation that a particular bank permits automation. Do not bypass OTP, CAPTCHA, access controls, or account protections.

1. Understand what “OTP login with an API” means

There are at least three different things that phrase might mean:

  • A webpage login that asks for an OTP: You complete the bank’s expected login flow in a browser, then capture the resulting page.
  • An OTP service API: An API may generate or validate a one-time password for a particular product or integration. That does not necessarily authenticate a user to internet banking or provide access to bank account pages.
  • A bank API that requires authentication: This is a separate integration. Use its documented authentication method, approved credentials, and permitted environment. A screenshot is still a browser capture of rendered content; it does not call an API on your behalf.

For example, HDFC Bank’s API portal describes OTP generation and validation APIs in the context of customer validation with its platform and fintech partners. That example does not establish that the API is an internet-banking login API or that it can be used to capture a bank webpage. HDFC Bank API Portal.

NPCI’s BASE flow is another distinct example: it describes Aadhaar-based consent and CAPTCHA steps, OTP validation through UIDAI, and a process for finding linked bank account information. It is not a general net-banking login recipe. NPCI.

Regulatory context also does not grant automation permission. The RBI’s 2025 Authentication Mechanisms Directions state that digital payment transactions in India are required to meet two factors of authentication and list SMS OTP among potential factors. That rule does not establish a bank’s exact login flow or authorize browser automation. RBI Directions, September 25, 2025.

2. Choose an authorized capture workflow

  1. Check permission and environment. Confirm that the bank, page owner, and applicable terms allow your intended access and capture. Prefer a bank-provided sandbox and test credentials where available. If the bank does not permit your intended automation, do not automate that flow.
  2. Use the normal OTP experience. Open the expected page in a browser session you control and complete the bank’s regular verification steps. Do not intercept, replay, generate, or bypass OTPs. Do not automate a payment or account action just to produce an image.
  3. Navigate to the intended state. Reach the specific page you are authorized to document. Verify that it contains the information needed and no unnecessary personal or financial details.
  4. Reduce exposure before capture. Use test data where possible. Otherwise, use the bank’s supported controls or a permitted redaction process to mask names, account numbers, balances, transaction identifiers, OTPs, and other sensitive information. Do not share an unredacted image when a redacted one will do.
  5. Capture only what you need. Use a viewport screenshot for the visible area or a full-page screenshot for the scrollable page. Review the result before sharing or storing it.
  6. Handle session data as a credential. If your workflow saves authenticated browser state, restrict access, keep it out of version control, retain it only as long as needed, and delete it when the work is complete.

Playwright warns that saved browser state may contain sensitive cookies and headers that could impersonate you or your test account. Store it outside source control, for example under an ignored playwright/.auth directory. Playwright authentication documentation.

3. Capture a page with Playwright

Playwright’s documented screenshot call captures the current page. Add fullPage: true to capture the full scrollable page. This example assumes you have already installed Playwright and created a permitted browser session. It deliberately leaves OTP entry to the user and does not automate bank-specific authentication.

Install

npm init -y
npm install playwright
npx playwright install chromium

Capture after you complete login manually

Save this as capture.mjs. It opens the target URL, lets you complete the normal login in the visible browser, waits for you to confirm that the target page is ready, and then saves a full-page PNG. Replace the placeholder URL only with an authorized target.

import { chromium } from 'playwright';
import { createInterface } from 'node:readline/promises';
import { stdin as input, stdout as output } from 'node:process';

const targetUrl = process.env.TARGET_URL;
if (!targetUrl) throw new Error('Set TARGET_URL to an authorized page URL.');

const browser = await chromium.launch({ headless: false });
const context = await browser.newContext();
const page = await context.newPage();

try {
  await page.goto(targetUrl, { waitUntil: 'domcontentloaded', timeout: 60_000 });
  const terminal = createInterface({ input, output });
  await terminal.question(
    'Complete the normal authorized login and navigate to the page to capture. Press Enter when it is ready. '
  );
  terminal.close();

  await page.screenshot({ path: 'bank-page.png', fullPage: true });
  console.log('Saved bank-page.png. Review it for sensitive information before sharing.');
} finally {
  await context.close();
  await browser.close();
}

Run it with an authorized URL, for example:

TARGET_URL='https://example.com/' node capture.mjs

The placeholder domain above is not a bank. Use only a URL and account you are authorized to access. The script waits for a person to finish the login rather than attempting to automate OTP entry.

Viewport and full-page options

// Capture the current viewport only
await page.screenshot({ path: 'viewport.png' });

// Capture the entire scrollable page
await page.screenshot({ path: 'full-page.png', fullPage: true });

For full-page captures, review the entire output: it may include content below the initially visible area. Playwright documents fullPage as capturing the full scrollable page. Playwright screenshot documentation.

4. Save authenticated state only when necessary

For repeated approved test runs, Playwright can save browser storage state and use it to create a context. This can avoid repeating setup, but the state file is sensitive and can contain cookies or headers that grant access. Use a test account, restrict the file, exclude it from Git, and remove it when it is no longer needed. Do not use this technique to evade a bank’s login controls or session policy.

// After a permitted login in a browser context:
await context.storageState({ path: 'playwright/.auth/test-state.json' });

// In a later approved test run:
const context = await browser.newContext({
  storageState: 'playwright/.auth/test-state.json'
});

Add the auth directory to .gitignore, set filesystem permissions appropriate to your environment, and avoid copying state files into build artifacts, logs, or shared folders. See Playwright’s guidance on authentication state.

5. Screenshot choices and sensitive-data handling

Choice Use it when Consider
Viewport capture You need only the currently visible section. It reduces the amount of page content included, but may omit information lower on the page.
Full-page capture You need the whole scrollable page in one image. It may include off-screen personal or financial information. Inspect the complete image.
Manual login each run You want the shortest-lived saved credentials and the flow permits this approach. Requires a person to complete OTP each time.
Saved test state An approved test workflow needs repeatable sessions. The file can act like a credential; restrict and delete it carefully.
Bank sandbox The bank provides a test environment suitable for your use. Confirm that its page and data reflect what you need to document.
Production page Your purpose and access are authorized for the real site. Use extra care with personal data, account actions, storage, and sharing.
  • Capture the least content needed for the task.
  • Do not include OTPs, account numbers, balances, names, or transaction references unless strictly necessary and authorized.
  • Keep screenshots in access-controlled storage; apply an appropriate retention period.
  • Before sending an image to a ticket, chat, cloud service, or AI tool, check its data-handling rules and remove sensitive details where possible.
  • Remember that a screenshot and an authentication-state file are separate sensitive artifacts; protect both.

6. Common errors and fixes

Symptom Likely cause What to do
Screenshot shows the login page The OTP flow is incomplete, the session expired, or navigation did not reach the intended page. Complete the normal login manually, verify the visible page, and capture only after it is ready. Do not try to bypass the challenge.
Navigation times out The site is slow, a redirect is still in progress, or the selected wait condition is too strict. Use a reasonable timeout and wait for the page state you need. The example waits for domcontentloaded, then leaves the interactive login and readiness check to you.
Browser closes before capture An error occurred before the screenshot call or cleanup ran. Keep the capture inside a try block and inspect the thrown error. Close the browser in finally so failures do not leave sessions running.
Image is blank or incomplete The target content has not rendered, the page is still loading, or the wrong tab/page was captured. Confirm the correct page is open and visually ready before pressing Enter. Avoid assuming a fixed delay means the content is ready.
Full-page image contains unexpected data Content below the viewport was included. Use viewport capture if sufficient, or inspect and redact the full image before sharing.
Saved state does not restore the session The session expired, required state is not in storage state, or the bank requires fresh authentication. Follow the bank’s normal login process again. Do not use stored state to defeat session expiration or authentication requirements.
Git or a shared artifact contains auth data The state file was not excluded or was copied into a build/share location. Remove it from the repository and shared artifacts, restrict access, and follow your organization’s incident process if a live credential was exposed. Deleting a local copy alone may not remove repository history.
Automation is blocked or disallowed The site’s policy, security controls, or environment does not allow the attempted automation. Stop. Ask the bank or system owner for an approved method or sandbox. Do not defeat CAPTCHA, bot checks, access controls, or other protections.

7. Performance, reliability, and cost

For a single capture, the main work is opening the page, completing its permitted authentication flow, waiting for the intended state, and encoding the image. A full-page image can include substantially more content than a viewport image, so choose the smallest capture that answers the documentation need. No bank-specific speed or reliability figures are available here.

Reliability depends on the bank’s page, redirects, session lifetime, browser support, and the state of the authorized test environment. Prefer a human readiness check or a documented stable page condition over an arbitrary sleep. Re-authenticate through the normal flow when the session expires. Keep capture scripts focused on screenshots; do not add payment or account actions to make a capture happen.

Playwright is an open-source browser automation library; browser execution and storage have infrastructure costs in hosted environments, while local runs use your own machine. The research does not provide a cost benchmark. If the task is simply to capture a public page without bank authentication, a screenshot API can avoid operating a browser yourself. It cannot provide access to a private bank session or replace the bank’s OTP flow.

8. Or skip the browser setup

For a public page that does not require a private logged-in session, ScreenshotNeo is a website screenshot API and MCP server. A single GET request returns an image or PDF. It does not log you into a bank account, handle a private OTP flow, or grant access to authenticated pages. Use it only for URLs and content you are authorized to capture. See the ScreenshotNeo documentation for request options.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Replace the example target with a public URL you are permitted to capture. ScreenshotNeo can remove cookie banners, popups, and chat widgets before the shot; bot checks, blank pages, and failed loads are never billed; its MCP server lets AI agents take screenshots; and the free plan includes 1,000 screenshots per month with no card, with paid plans starting at $5 for 3,000. Sign up for free.

9. FAQ

Can a screenshot API complete my bank’s OTP login?

No. A screenshot API captures a page it can access. It does not authenticate you to a private bank session or bypass OTP.

Can I automate OTP entry for a real bank account?

This guide does not establish that any bank permits that. Follow the bank’s rules and use an approved sandbox and test account when available. Do not bypass or defeat authentication protections.

Does an OTP validation API give me access to an internet-banking page?

Not necessarily. An OTP product can serve a specific integration or validation purpose. Confirm the API’s official documentation, intended audience, and authorization model.

Should I save browser state to avoid OTP every time?

Only if that reuse is permitted in your environment. Saved state can contain session credentials, so use a test account, restrict access, exclude it from version control, and remove it when no longer needed.

What should I do if the page contains real financial information?

Capture only what is necessary, redact sensitive details before sharing, and store the image with access controls and a limited retention period.