ScreenshotNeo

BlogHow-to

How to screenshot a logged-in page after dismissing a OneTrust cookie banner

Dismiss a OneTrust banner without changing consent, preserve your login, and capture a page with Playwright or ScreenshotNeo.

By the ScreenshotNeo team4 October 20268 min read

To screenshot a logged-in page after dismissing a OneTrust cookie banner, keep the authenticated browser context, dismiss the banner using its actual close control, wait for the page to settle, then capture it. Closing the banner is not the same as accepting or rejecting cookies: OneTrust says its close action applies the configured default consent model. Choose Accept All or Reject All only when that is the intended consent choice. [OneTrust Web CMP methods] [OneTrust banner behavior]

This guide shows a repeatable Playwright workflow, explains how to find the right dismiss control, and covers consent persistence, screenshot scope, security, troubleshooting, and a one-call ScreenshotNeo option. No target site or account was supplied, so the example locator must be adapted to the site’s actual banner.

Use the site’s close (×) or equivalent dismiss control when your goal is to remove the overlay while leaving the configured default consent model in effect. Do not treat “close” as “accept.” OneTrust documents separate methods for closing, allowing all, and rejecting all; its close button is designed to close the banner without actively accepting or rejecting cookies. [OneTrust Web CMP methods] [OneTrust banner behavior]

Action What it means Use it when
Close or dismiss Closes the banner and leaves the configured default consent model in effect. You want the overlay gone without making a new accept/reject choice.
Accept All Actively accepts the site’s offered consent. The user intends to grant that consent.
Reject All Actively rejects optional consent as offered by the site. The user intends to reject that consent.

Site configuration determines the available controls and default. If access to the page depends on an interaction, use the real control and preserve the intended choice. Do not hide the banner with CSS as a substitute for handling consent.

2. Prepare Playwright and authenticated state

Install Playwright for Node.js and the Chromium browser it will launch:

npm install playwright
npx playwright install chromium

Sign in through a setup script or an interactive browser, then save the browser context’s storage state. Playwright can restore that state for later runs. The file can contain cookies and headers that allow someone to impersonate the account, so keep it private and out of source control. [Playwright authentication guide]

For example, after completing the site’s normal login flow in a setup script:

await page.goto('https://example.com/login');
// Complete the site's normal sign-in flow here.
await page.context().storageState({ path: 'playwright/.auth/user.json' });

Add the state directory to .gitignore:

playwright/.auth/

Protect the file with appropriate local permissions and rotate or revoke the session if it is exposed. Do not commit real account state or pass it to an untrusted build job.

3. Dismiss OneTrust and capture the page

Save this as screenshot.mjs. Replace the URL and locator with values for the target site. The button name below is illustrative; OneTrust templates and site wording vary.

import { chromium } from 'playwright';

const targetUrl = 'https://example.com/account';
const browser = await chromium.launch({ headless: true });
const context = await browser.newContext({
  storageState: 'playwright/.auth/user.json',
  viewport: { width: 1440, height: 1000 },
});
const page = await context.newPage();

try {
  await page.goto(targetUrl, { waitUntil: 'domcontentloaded', timeout: 45_000 });

  // This name is an example. Inspect the site's rendered UI and use its real
  // accessible name or a stable site-specific locator.
  const closeButton = page.getByRole('button', { name: /close/i });
  if (await closeButton.isVisible({ timeout: 5_000 }).catch(() => false)) {
    await closeButton.click();
    await closeButton.waitFor({ state: 'hidden', timeout: 10_000 }).catch(() => {});
  }

  // Replace with a meaningful page-ready condition when the site provides one.
  await page.locator('main').waitFor({ state: 'visible', timeout: 20_000 });
  await page.screenshot({ path: 'page.png', fullPage: true });
} finally {
  await context.close();
  await browser.close();
}

Run it with:

node screenshot.mjs

The script restores the login state in the same context used for navigation, clicks a rendered user-facing control if present, waits for the main content, then captures the page. The broad /close/i match may find the wrong button or none at all. Inspect the accessible names with Playwright or the browser’s accessibility tools, then use a specific locator, for example page.getByRole('button', { name: 'Close privacy banner' }) if that is the actual accessible name.

Using the documented OneTrust API

If the target deployment exposes and supports the public OneTrust API, OneTrust.Close() is documented to dismiss the banner and set the configured default consent model. The method may not be available at every point in page startup, and a site’s implementation can differ, so the actual UI control is usually the more representative automation path. Do not call OneTrust.AllowAll() or OneTrust.RejectAll() unless that choice is intended. [OneTrust JavaScript API]

await page.evaluate(() => {
  if (window.OneTrust && typeof window.OneTrust.Close === 'function') {
    window.OneTrust.Close();
  }
});

This guarded example avoids an exception when the API is absent, but it does not prove the banner was dismissed. Verify the banner is hidden and the page remains signed in before capturing.

4. Pick viewport or full-page output

By default, page.screenshot() captures the current visible viewport. Set fullPage: true to capture the full scrollable document. [Playwright Page API]

// Current viewport only
await page.screenshot({ path: 'viewport.png' });

// Entire scrollable document
await page.screenshot({ path: 'full-page.png', fullPage: true });

Set the browser context’s viewport to control the visible page dimensions. For a mobile layout, use a narrower viewport and configure a mobile device context if the target needs mobile browser behavior. Full-page images can be very tall; use a viewport capture when the useful evidence is only the visible screen. Check the output for account names, email addresses, private data, or other details before sharing.

5. Handle persistence and repeat runs

A dismissed banner can return. OneTrust describes behavior as dependent on consent cookies, tenant configuration, and browser behavior; deleting cookies or clearing browser data may cause the prompt to reappear. Its cited guidance describes a seven-day prompting interval for Safari/iOS in that context, which should not be assumed for every site or browser. [OneTrust consent persistence guidance]

  • Reuse the intended authenticated state and browser context for the capture.
  • Do not clear cookies between dismissing the banner and capturing the page.
  • Expect the banner to appear again if state expires, is cleared, or the site changes its consent setup.
  • Make the dismissal conditional so repeat runs work both when the banner appears and when it does not.
  • After any login redirect, verify the page is the expected account page before writing the screenshot.

6. Common errors and fixes

Symptom Likely cause Fix
Close button locator times out The accessible name differs, the banner has not loaded, or no banner is present. Inspect the rendered banner and accessible roles. Use its real label; make the action conditional if the banner is optional.
Click succeeds but banner remains The locator selected another control, a consent panel is still open, or the site re-renders it. Use a more specific locator, wait for the actual banner container to become hidden, and inspect whether another dialog must be closed.
Screenshot shows a login page Storage state expired, was not saved after sign-in, or the site uses session state not restored by the saved storage. Refresh the saved state through the normal sign-in flow, confirm the expected URL and account content, then capture.
OneTrust is undefined The API is not exposed, has not loaded, or is not part of this site’s integration. Prefer the rendered close control, or wait for the site’s documented API readiness condition. Do not assume every page exposes the global.
Page is blank or partially rendered Navigation completion did not mean application content was ready, or a script/resource failed. Wait for a site-specific ready element or response; inspect browser console and failed network requests.
Banner returns on later run Consent state was not persisted, browser data was cleared, or configuration/browser behavior prompts again. Preserve the same context state and handle the banner each run. Do not hard-code a universal persistence period.
Full-page image is unexpectedly large The page is long or contains expanding content. Use viewport capture, target a relevant element, or ensure lazy content is loaded before full-page capture.

7. Performance, reliability, and cost

Browser startup, navigation, authentication, and waiting for application readiness usually dominate a one-off capture. Reuse a browser process for batches of pages when appropriate, but isolate contexts and authentication states by account. Use a specific readiness condition instead of a long fixed delay; a delay can waste time and still capture too early. Keep navigation and locator timeouts bounded, and write the screenshot only after checking that the expected page is present.

For reliability, distinguish a genuine logged-in page from a login redirect, challenge, error page, or empty shell. Record the final URL and a small set of expected page signals in automation logs, while avoiding logging cookies, tokens, or private content. Retry transient navigation failures cautiously; repeated clicks on consent controls can change the intended state.

Playwright itself is browser automation software; the research sources provide no usage price or capture benchmark. Your practical costs are the compute and maintenance for the browser environment and authentication flow. Protect storage-state files as credentials and refresh them when the site’s session expires.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server. A direct screenshot call looks like this; see the API documentation for the supported parameters. Use this for pages the API can access; a private logged-in page still requires an authentication approach supported by the service and the target site.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await Bun.write('shot.webp', res);

ScreenshotNeo removes cookie and consent banners, newsletter popups, and chat widgets before capture; each cleanup step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status. Its MCP server offers take_screenshot, get_page_info, and capture_pdf for AI agents. The free plan includes 1,000 screenshots monthly with no card; paid plans start at $5 for 3,000 screenshots. Every feature is on every plan. A simple URL call does not itself restore a private browser login, so confirm the available authentication options in the docs for a protected target.

Sign up for 1,000 free screenshots a month, with no card.

FAQ

Does dismissing the OneTrust banner accept cookies?

No. OneTrust’s close method dismisses the banner and applies the configured default consent model; accepting and rejecting are separate actions. [OneTrust API documentation]

Will the page stay logged in after I close the banner?

It should if you keep the authenticated browser context and do not clear or replace its session state. Verify the expected account page before capturing.

Why did the banner come back after I dismissed it?

Consent persistence varies with browser storage, site configuration, and browser behavior. Clearing data or using a fresh context can bring it back; handle the control when it appears.

Can I capture the page without accepting cookies?

Use the site’s close or dismiss control if that matches the intended choice. The site’s configured default consent model still applies.

Sources