SessionCourier join waitlist

session infrastructure for dev · qa · automation

Login sessions, delivered.

SessionCourier is the cookie & session manager for developers and QA: edit cookies, capture login state, and move it safely into Playwright, CI pipelines, and your team's staging setup — from an EU operator you can actually trust with credentials.

  • identified EU operator
  • zero-knowledge E2E
  • reproducible build
  • ad-free forever
auth.setup.ts
// 1. Log in once, in your normal browser.
// 2. Export → Playwright storageState.
// 3. Point your tests at it:

export default defineConfig({
  use: { storageState: 'e2e/.auth/staging.json' },
});
$ npx playwright test
  ✓ 42 passed — no login flow, no OTP, no flakes

features

From browser tab to CI pipeline.

The free editor covers everything the daily dev/QA workflow needs. Pro adds the infrastructure around it: profiles, encrypted sync, and headless access.

free · flagship

Playwright storageState, one click

Log in once in your normal browser — where SSO, 2FA and passkeys actually work — then export storageState.json and run your E2E suite authenticated. No scripted login flows, no OTP dances; when the session expires mid-pipeline, re-export in one click.

The SessionCourier side panel with the Export menu open on a staging session — a one-click Playwright storageState export (with an “Include this tab’s localStorage” option), alongside JSON, Netscape cookies.txt, curl and header-string exports.
free

An editor that keeps up

List, search, filter, edit — single cookies or in bulk. Built and performance-tested against 1,000+ cookie jars, because reliability is where the incumbents fall over.

free

Every format your tools speak

Import and export JSON, Netscape cookies.txt (curl, wget, yt-dlp) and raw header strings.

free

Inline JWT decoder

Token cookies decode in place — header, payload, expiry — without pasting credentials into some website.

free

Cookie protect

Pin a cookie read-only and SessionCourier restores it the moment anything overwrites it. Your debugging session survives the app’s own writes.

free

Session recorder, not archaeology

Start the recorder, run a login, logout or checkout flow, and watch the diff fill in live: what was added, what was refreshed — before → after, flags and expiry included — what was cleared, plus the transient cookies a before/after snapshot never sees. Captured changes stay in memory and are gone when the browser closes.

How the recorder works →

What changed on checkout.acme.dev
  • Added sc_session7f3c…9ab
  • Changed csrf4c1e… → b90d…
  • SecureOff → On
  • Removed guest_cart112a…
  • Transient ab_bucketset, then cleared
pro · waitlist

Profiles, sync & headless CLI

Named session profiles per domain, end-to-end-encrypted sync, and npx sessioncourier pull to fetch a profile in CI — no browser required. Team vaults for shared staging sessions follow.

trust

Session cookies are credentials.
We treat them that way.

Would you paste your production session into a random free extension? Neither would we. A competitor can copy any one of these; the bundle — an identified EU operator, a reproducible build, a browser-to-CI session bridge and zero-knowledge storage in one tool — is what they can’t. Every claim below is verifiable, not marketing.

Identified EU operator

Full imprint, DSA trader verification in the Chrome Web Store, German jurisdiction. This niche has been burned by anonymous operators twice — we put a name on it.

Reproducible build

“Open source” is a claim. A CI job proving the store build is byte-identical to the public repo is evidence. GPL-3.0 client, verifiable by anyone.

Zero-knowledge by architecture

Everything stored is encrypted on your device — Argon2id key derivation, libsodium secretbox. The server only ever sees ciphertext. We can’t read your sessions, by design.

Minimal permissions

Five at install: cookies, storage, activeTab, scripting, sidePanel — not one of them shows a host-access warning. Broad host access stays optional and off by default. No ads, no trackers, GDPR-compliant, EU hosting.

pricing

Cheaper than one broken staging login.

The editor and every export format stay free — no export paywall, no ads in a tool that touches your credentials. You pay for the workflow around it.

Free

$0 forever, ad-free

  • Full cookie editor, no limits
  • All exports — incl. Playwright storageState
  • JSON · cookies.txt · header string
  • Inline JWT decoder
  • Cookie protect
  • No account, no sign-up
join waitlist

Pro

$4 per month · $36/year

  • Everything in Free
  • Named session profiles per domain
  • End-to-end-encrypted sync
  • CLI + token API for CI (npx sessioncourier pull)
  • Printable recovery kit
  • Revoke any device, any time
get launch access

Team

$8 per seat / month

  • Everything in Pro
  • Shared encrypted vaults for staging & test sessions
  • Roles: read-only / admin
  • Audit log
  • Email support from the maintainers
  • Self-service — credit card, no sales call
join waitlist

waitlist

Launching on the Chrome Web Store, September 2026.

One email when Pro ships, one when Teams is ready. No newsletter, no drip campaign.