cypress cy.visit() basic auth not working: how to fix
Shows the supported way to pass HTTP basic auth credentials to cy.visit(). Use when visits hit a 401 or a browser login prompt appears. Not for OAuth flows, form logins, or auth handled inside the app.
TL;DR
Pass credentials through the auth option of cy.visit(), like cy.visit('/page', { auth: { username: YOURUSER, password value YOURPASSWORD } }), because embedding credentials in the URL is blocked by modern browsers. Put it in a beforeEach or a custom command so every visit in the spec uses it.
The query
cypress cy.visit() basic auth not working: how to fixUse this when
- cy.visit returns a 401
- a browser login prompt blocks the spec
- credentials embedded in the URL stopped working
Not for
- OAuth or SSO logins (use cy.session with the sign-in flow)
- in-app login forms
- setting API authorization headers
Steps
- Confirm the failure is basic auth: open the Cypress runner network tab and look for a 401 on the document request. Expected output: a 401 response on the initial page load.
- Add the auth option to cy.visit with the username and password from test config or env vars, never hardcoded secrets in the spec. Expected output: the visit options include an auth object with both fields.
- If only some visits pass auth, wrap cy.visit in a custom command or set it in beforeEach. Expected output: every visit in the spec sends credentials consistently.
- For cross-origin visits, pass the auth option on each cy.visit call since Cypress does not carry it across origins automatically. Expected output: cross-origin pages load without a login prompt.
- Re-run the spec and confirm no browser auth dialog appears. Expected output: the page loads authenticated and the test proceeds.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_mkJ-yOjVlB2QJ1c1Tzo-Tg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.