Login sessions
For apps behind a form login, shotsweep login drives the actual login form once in a real
browser and saves the resulting session (cookies and local storage) to disk.
terminal
shotsweep login \
--login-url https://example.com/login \
--email-selector "#email" \
--password-selector "#password" \
--submit-selector "button[type=submit]" \
--email [email protected] \
--password $APP_PASSWORD \
--session-out auth.jsonThen reuse it on any capture run:
terminal
shotsweep capture --sitemap https://example.com/sitemap.xml --session auth.jsonLogin
↓
auth.json
↓
ShotSweep capture
↓
authenticated screenshotsRequired flags
login requires --login-url, --email-selector, --password-selector, and
--submit-selector — all four are CSS selectors ShotSweep uses to fill and submit the form.
Credentials from the environment
Instead of passing --email / --password on the command line, you can set:
terminal
export SHOTSWEEP_EMAIL=[email protected]
export SHOTSWEEP_PASSWORD=your-passwordshotsweep login saves the file readable by your user only (on macOS and Linux).
Don’t commit your session file
auth.json contains real cookies and storage state for an authenticated account. Treat it like a
credential:
- add it to
.gitignore - don’t commit it, even to a private repo
- regenerate it if it ever leaks
Last updated on