@steipete/sweet-cookie
v0.4.4
Published
Inline-first browser cookie extraction for local tooling (no native addons).
Readme
@steipete/sweet-cookie
Inline-first browser cookie extraction for local tooling (no native addons).
Supports:
- Inline payloads (JSON / base64 / file) — most reliable path.
- Local browser reads (best effort): Chrome, Edge, Firefox, Safari (macOS).
- On macOS, the
chromebackend checks Chrome and Brave roots by default. - On Linux, the
chromebackend checks native and Flatpak Google Chrome roots by default. SetchromiumBrowserto target native or container roots for Chromium or Brave. - Default browser order is
chrome,safari,firefoxunlessbrowsersor env overrides it.
Install:
npm i @steipete/sweet-cookieCLI:
npx @steipete/sweet-cookie github.com
npx @steipete/sweet-cookie github.com --browser chrome --format headerUsage:
import { getCookies, toCookieHeader } from "@steipete/sweet-cookie";
const { cookies, warnings } = await getCookies({
url: "https://example.com/",
names: ["session", "csrf"],
browsers: ["chrome", "edge", "firefox", "safari"],
});
for (const w of warnings) console.warn(w);
const cookieHeader = toCookieHeader(cookies, { dedupeByName: true });macOS and Linux Chromium targeting:
await getCookies({
url: "https://example.com/",
browsers: ["chrome"],
chromiumBrowser: "brave",
});Windows Brave or other Chromium-family profiles:
await getCookies({
url: "https://example.com/",
browsers: ["chrome"],
chromeProfile: "~/.config/BraveSoftware/Brave-Browser/Default",
});Notes:
profileis a shared alias forchromeProfile/edgeProfile.chromiumBrowserpins the macOS or Linuxchromebackend tochrome,brave,arc,chromium, ordia; Arc and Dia are macOS-only.- On macOS,
chromiumBrowseralso selects the matching Keychain entry, including for custom profile paths. - Inline payloads win first; otherwise local backends run in declared order.
- Cookie results preserve
hostOnly; exact-host and domain scope remain distinct during filtering and deduplication. - Partitioned Chromium cookies and partitioned or container-scoped Firefox cookies are excluded with warnings because replay cannot preserve their isolation context.
- On Windows, Brave and other Chromium-family profiles work via an explicit
chromeProfilepath. edgeProfilefalls back toSWEET_COOKIE_CHROME_PROFILEwhenSWEET_COOKIE_EDGE_PROFILEis unset.- On Linux, safe-storage overrides support Chrome, Chromium, Edge, and Brave.
Docs + extension exporter: see the repo root README.
