Skip to Content
🎉 ShotSweep is live! Launched on NFSFU234 Open Source Day.
DocsAuthenticationLogin Sessions

Login sessions

For apps behind a form login, shotsweep login drives the actual login form once in a real browser and saves the resulting session (cookies and local storage) to disk.

terminal
shotsweep login \ --login-url https://example.com/login \ --email-selector "#email" \ --password-selector "#password" \ --submit-selector "button[type=submit]" \ --email [email protected] \ --password $APP_PASSWORD \ --session-out auth.json

Then reuse it on any capture run:

terminal
shotsweep capture --sitemap https://example.com/sitemap.xml --session auth.json
Login ↓ auth.json ↓ ShotSweep capture ↓ authenticated screenshots

Required flags

login requires --login-url, --email-selector, --password-selector, and --submit-selector — all four are CSS selectors ShotSweep uses to fill and submit the form.

Credentials from the environment

Instead of passing --email / --password on the command line, you can set:

terminal
export SHOTSWEEP_EMAIL=[email protected] export SHOTSWEEP_PASSWORD=your-password

shotsweep login saves the file readable by your user only (on macOS and Linux).

Don’t commit your session file

auth.json contains real cookies and storage state for an authenticated account. Treat it like a credential:

  • add it to .gitignore
  • don’t commit it, even to a private repo
  • regenerate it if it ever leaks
Last updated on