ScreenshotNeo

BlogHow-to

URL2PNG Cannot Capture a Page Behind a Login: What to Do

A screenshot service needs an authorized session to see protected content. Here’s how to capture it safely with your browser, Playwright, or a screenshot API.

By the ScreenshotNeo team4 October 20268 min read

A screenshot service can capture a page behind a login only if its browser has an authorized way to access that page. If URL2PNG returns the login screen, its remote browser did not arrive with the authenticated session the site requires. For a one-off image, sign in in a browser you control and capture the page there. For recurring captures, use authorized browser automation such as Playwright and sign in through the site’s approved flow.

URL2PNG’s reviewed Quickstart Guide describes controls such as viewport size, full-page capture, custom CSS, user agent, delay, cache TTL, and a readiness marker. It does not document interactive sign-in or saved browser-session reuse. That is a statement about the documentation reviewed, not proof that every account or configuration lacks an authentication capability. Check with URL2PNG for your specific setup.

Why the capture shows a login page

A remote screenshot service makes its own request or opens its own browser. Your local browser’s cookies and signed-in state are not automatically transferred to it. When the remote browser reaches a protected route without a valid authorized session, the website serves a login page, redirects to sign-in, or displays an access-denied response.

Authentication and rendering readiness solve different problems. A delay or selector wait can give an already-authorized page more time to render; a custom user agent changes the browser’s identity string. Neither creates a signed-in session. URL2PNG documents delay, readiness, and user-agent settings, but those settings should not be mistaken for login support. URL2PNG Quickstart Guide

Choose a safe capture method

Method Best for Authentication context Trade-off
Capture from your browser One-off image or PDF Your existing signed-in browser Simple and keeps the session local, but manual
Playwright automation Recurring captures you control An authorized browser session established by the script or a protected saved session Repeatable, but requires setup and careful secret handling
Screenshot API with documented HTTP Basic Auth A page protected specifically by Basic Auth Credentials sent using the provider’s documented mechanism Can be convenient for Basic Auth, but does not imply support for web forms, SSO, or MFA

Use only an account and access route you are authorized to use. Treat passwords, cookies, and saved session state as credentials. Prefer a least-privilege test account for recurring captures, and do not put secrets in public URLs, source control, logs, or shared artifacts.

One-off capture after manual sign-in

  1. Open the protected page in your normal browser and complete the site’s approved sign-in process.
  2. Navigate to the exact page you want, and confirm the protected content is visible.
  3. Use the browser’s screenshot or print-to-PDF feature. For a long page, select a full-page capture if available; for a partial capture, select the relevant visible area or element.
  4. Store the result somewhere appropriate for the page’s sensitivity. Avoid sharing a capture that exposes private account data.

This is usually the fastest route for a one-time image because it uses the session you already established. It does not make the capture repeatable, and a browser screenshot only contains what the browser can render at the time you take it.

Repeatable captures with Playwright

Playwright supports viewport screenshots, screenshots of a selected element, and full-page screenshots. Its Page API provides navigation and screenshot methods. Playwright screenshot documentation · Playwright Page API

The following Node.js example is a starting point for an authorized site that permits automated sign-in. Replace the example selectors and URL with the site’s actual login form and a test account. Install Playwright with npm install playwright and install its browser with npx playwright install chromium. Keep credentials in environment variables, not in the script.

import { chromium } from 'playwright';

const { TEST_USERNAME, TEST_PASSWORD } = process.env;
if (!TEST_USERNAME || !TEST_PASSWORD) {
  throw new Error('Set TEST_USERNAME and TEST_PASSWORD first');
}

const browser = await chromium.launch({ headless: true });
const page = await browser.newPage({ viewport: { width: 1440, height: 1000 } });

try {
  await page.goto('https://example.com/login', { waitUntil: 'domcontentloaded' });
  await page.getByLabel('Email').fill(TEST_USERNAME);
  await page.getByLabel('Password').fill(TEST_PASSWORD);
  await page.getByRole('button', { name: 'Sign in' }).click();

  // Wait for a reliable signal that authentication succeeded.
  await page.waitForURL('**/account/**', { timeout: 15000 });
  await page.goto('https://example.com/account/report', { waitUntil: 'domcontentloaded' });
  await page.locator('main').waitFor({ state: 'visible', timeout: 15000 });
  await page.screenshot({ path: 'protected-page.png', fullPage: true });
} finally {
  await browser.close();
}

The example assumes a conventional form, accessible labels, and a post-login URL pattern. Adapt the selectors and success condition to the application. A visible account-specific element or an expected URL is generally a better readiness check than an arbitrary sleep. If the site renders data asynchronously, wait for the specific content needed in the screenshot.

Reusing an authorized browser session

Some workflows need a human to complete an interactive sign-in once, then reuse browser state for later captures. Playwright supports storage state; its contents can include cookies and other credentials, so protect the file as a secret, keep it out of version control, and limit its lifetime and access. Follow the site’s policies and your organization’s handling rules.

// After an authorized interactive sign-in, save state to a private path:
await page.context().storageState({ path: '/secure/path/auth-state.json' });

// In a later run, create a context using that state:
const context = await browser.newContext({
  storageState: '/secure/path/auth-state.json',
  viewport: { width: 1440, height: 1000 }
});
const page = await context.newPage();
await page.goto('https://example.com/account/report');
await page.locator('main').waitFor({ state: 'visible' });
await page.screenshot({ path: 'protected-page.png', fullPage: true });

Session state expires or can be revoked. If the site uses MFA, SSO, anti-bot controls, or short-lived sessions, arrange an owner-approved test account or testing route. Do not try to bypass those controls.

Screenshot a specific element or viewport

For a smaller artifact, capture one element instead of the full page. For the current viewport, omit fullPage.

const report = page.locator('[data-testid="report"]');
await report.waitFor({ state: 'visible' });
await report.screenshot({ path: 'report.png' });

// Current viewport only:
await page.screenshot({ path: 'viewport.png' });

HTTP Basic Auth is not an ordinary login form

HTTP Basic Auth is a browser/server authentication mechanism, not the same as signing in through a web form. Some screenshot APIs document credential parameters for Basic Auth: Capture documents an httpAuth parameter, and URL2IMG documents username/password options. These provider-specific examples do not establish support for interactive JavaScript login, saved browser sessions, MFA, SSO, or CAPTCHA. Verify the provider’s current documentation and credential handling before sending secrets. Capture authentication documentation · URL2IMG documentation

Do not assume URL2PNG’s custom user-agent option or delay setting authenticates a request. If your site uses Basic Auth, check directly whether the chosen provider supports that exact mechanism. Avoid credentials in query strings unless the provider explicitly documents a secure approach; URLs can be recorded in logs and histories.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server. It does not document a mechanism for signing into arbitrary protected web applications or importing your logged-in browser session, so do not send it cookies, passwords, or session tokens for that purpose. It can capture pages that are publicly reachable to its browser. One GET request returns an image or PDF; see the API documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`ScreenshotNeo returned HTTP ${res.status}`);
await Bun.write('shot.webp', res);

ScreenshotNeo removes cookie and consent banners, newsletter popups, and chat widgets before capture; each cleanup step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status. Its MCP server lets AI agents use take_screenshot, get_page_info, and capture_pdf. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 shots. Sign up free for 1,000 screenshots a month, with no card required.

Troubleshooting

Symptom Likely cause What to do
The result is the login page The remote browser has no valid authorized session, or the session expired. Capture in your signed-in browser or use approved automation that signs in and verifies success before capture.
The result is blank or still loading The page has not finished rendering, or the expected content is delayed. After confirming authentication, wait for a meaningful selector or content signal. A delay can help with timing; it cannot provide access.
It works locally but not through an API Your local session, network access, or authentication context differs from the service’s environment. Check whether the service can reach the host and supports the exact auth type. URL2PNG’s reviewed public guide does not settle account-specific capabilities; ask its support about your setup.
Basic Auth credentials do not work The target may use a form login, or the provider’s parameter format may differ. Confirm the site actually uses HTTP Basic Auth and follow the provider’s current documentation. Do not treat Basic Auth as SSO or form-login support.
Playwright times out waiting for sign-in The selectors, redirect pattern, or sign-in success condition do not match the site; an additional verification step may be required. Inspect the flow in an authorized test account, update selectors and the success condition, and follow the site’s approved MFA/SSO testing process.
Automation succeeds once and then fails Saved state expired, was revoked, or is not being loaded into the intended browser context. Refresh state through the approved sign-in flow, verify the context configuration, and protect the state file as a credential.

Reliability, performance, and cost considerations

  • Reliability: Check an authentication success signal and the target content before saving. A screenshot of a login page can look like a successful image response while still being the wrong result.
  • Performance: Reuse a browser process for batches where appropriate, use a viewport or element capture when full-page output is unnecessary, and wait for the specific content rather than a long fixed delay. Full-page screenshots may require more rendering and memory for long pages.
  • Session maintenance: Interactive sign-in, MFA, session expiry, and revocation can make scheduled jobs require human or owner-supported maintenance. Keep session state private and out of logs and artifacts.
  • Cost: A local Playwright workflow uses browser compute and storage that you operate. A third-party API may charge according to its own terms and may receive the URL and any credentials you submit. Compare the provider’s documented authentication support, billing rules, and secret handling before adopting it.
  • Scope: No statistic or benchmark is needed to choose the method; fit the method to whether the capture is one-off or recurring and to the site’s approved authentication route.

FAQ

Can I pass my browser cookies to URL2PNG?

The reviewed URL2PNG guide does not document a saved-session or cookie-import workflow. Ask URL2PNG support about your account and exact configuration before sending session credentials.

Will waiting longer make a protected page appear?

No. Waiting can help content render after access is granted, but it does not authenticate the browser.

Can I automate MFA?

Use an owner-approved test account or testing route. MFA and SSO are site-specific, and automation should follow the site’s approved process rather than bypass access controls.

Can ScreenshotNeo capture my signed-in page?

The ScreenshotNeo facts provided here do not include arbitrary login or browser-session import. Use your own authorized browser for protected pages; use ScreenshotNeo for pages its browser can access without private session credentials.

Sources: URL2PNG Quickstart Guide; Playwright screenshot documentation; Playwright Page API; Capture authentication documentation; URL2IMG documentation.