How Agent Reach Browser Cookie Extraction Works for Chrome and Firefox
Agent Reach extracts authentication cookies from Chrome and Firefox using a dual-backend approach that reads browser SQLite stores directly and filters them against platform-specific requirements.
The Agent Reach project (Panniantong/Agent-Reach) automates the extraction of session cookies from local browsers to authenticate with platforms like Twitter/X, XiaoHongShu, Bilibili, and Xueqiu. This Agent Reach browser cookie extraction capability enables downstream commands to execute API operations on behalf of the logged-in user without manual token copying.
The Extraction Workflow
The cookie extraction logic resides in agent_reach/cookie_extract.py and follows a seven-step pipeline when invoked via the CLI (agent-reach configure --from-browser chrome) or programmatically through extract_all(browser):
- Library Selection – The code attempts to import
rookiepyfirst; if unavailable, it falls back tobrowser_cookie3. - Browser Validation – Only
chrome,firefox,edge,brave, oroperaare accepted, raisingValueErrorfor unsupported browsers. - Raw Cookie Reading – The selected backend reads the browser's SQLite cookie store and returns an iterable of cookie objects.
- Object Normalization – When using
rookiepy, raw dictionaries are wrapped in a_Cookieclass to provide uniform.name,.value, and.domainattributes. - Domain Filtering – Cookies are matched against the
PLATFORM_SPECStable (lines 15-41) which declares required domains for each service. - Name Extraction – The code either extracts specific named cookies (e.g.,
auth_token,ct0,SESSDATA) or builds a complete header string whencookiesisNone. - Result Mapping – Returns a dictionary mapping platform keys to their respective cookie data structures.
Dual-Backend Architecture
The extraction engine implements a resilient fallback mechanism to ensure cross-platform compatibility:
rookiepy (Primary) – A Rust-based library that reads Chromium and Firefox SQLite cookie stores directly without requiring OS keychain access on macOS. This backend offers superior speed and stability by bypassing native security prompts.
browser_cookie3 (Fallback) – A pure-Python alternative that functions on all platforms but may trigger permission dialogs (e.g., macOS keychain access) depending on the system's security configuration.
The selection logic at lines 55-63 attempts rookiepy first, catching ImportError to transparently switch to browser_cookie3 when the former is not installed.
Platform-Specific Cookie Mapping
The PLATFORM_SPECS dictionary defines extraction rules for each supported service:
| Platform | Required Domain | Cookie Names | Config Output |
|---|---|---|---|
| Twitter/X | .twitter.com, .x.com |
auth_token, ct0 |
Individual key-value pairs |
| XiaoHongShu | .xiaohongshu.com |
All cookies | Concatenated header string |
| Bilibili | .bilibili.com |
SESSDATA, bili_jct |
Individual key-value pairs |
| Xueqiu | .xueqiu.com |
xq_a_token (filtered) |
Header string if present |
When processing XiaoHongShu, the algorithm iterates through all matching domain cookies and constructs a semicolon-delimited string (name=value; name2=value2) suitable for direct HTTP header injection.
CLI Integration and Secure Storage
The configure_from_browser function (also in cookie_extract.py) bridges extraction with persistent configuration:
- Calls
extract_all(browser)to retrieve the cookie dictionary - Persists values via the
Configclass inagent_reach/config.pyto~/.agent-reach/config.yaml - Synchronizes legacy formats for external tools (e.g., writes
~/.config/xfetch/session.jsonfor Twitter/X integration)
Security Implementation – When writing auxiliary credential files, the helper _open_owner_only creates files with mode 0o600 (read/write owner only) at lines 51-68, preventing exposure through permission inheritance or race conditions. The CLI entry point in agent_reach/cli.py (lines 96-104) handles the --from-browser flag, displaying per-platform success indicators without echoing sensitive values to stdout.
Practical Usage Examples
Extract cookies from Chrome via command line:
agent-reach configure --from-browser chrome
Expected output:
Extracting cookies from chrome…
✅ Twitter/X: auth_token + ct0
✅ XiaoHongShu: 12 cookies
✅ Bilibili: SESSDATA + bili_jct
✅ Xueqiu: 8 cookies (含 xq_a_token)
Programmatic extraction in Python:
from agent_reach.cookie_extract import extract_all
# Extract from Firefox
cookies = extract_all('firefox')
# Access Twitter authentication tokens
auth_token = cookies['twitter']['auth_token']
ct0 = cookies['twitter']['ct0']
# Use XiaoHongShu cookie string directly
xhs_header = cookies['xhs']['cookie_string']
Manual configuration persistence:
from agent_reach.config import Config
cfg = Config()
cfg.set('xhs_cookie', 'auth=abc; sess=def')
Summary
- Agent Reach browser cookie extraction relies on
agent_reach/cookie_extract.pyto read Chrome and Firefox SQLite stores using eitherrookiepy(Rust) orbrowser_cookie3(Python). - The system validates browser names, normalizes cookie objects, and filters against
PLATFORM_SPECSto extract platform-specific authentication tokens. - Extracted credentials are stored in
~/.agent-reach/config.yamlwith strict0o600file permissions, and the CLI provides aconfigure --from-browserinterface for non-interactive setup. - Supported platforms include Twitter/X, XiaoHongShu, Bilibili, and Xueqiu, each with distinct cookie naming and domain requirements.
Frequently Asked Questions
How does Agent Reach handle browsers that are currently running?
Agent Reach reads the SQLite cookie files directly from disk. While this generally works even when browsers are active, file locking on some operating systems may cause permission errors. The CLI catches these exceptions and displays helpful guidance without aborting the overall configuration process.
What is the difference between rookiepy and browser_cookie3 in Agent Reach?
rookiepy is a compiled Rust library preferred for its speed and ability to bypass macOS keychain prompts, while browser_cookie3 serves as a pure-Python fallback that works universally but may require additional OS permissions. The code automatically attempts rookiepy first and falls back to browser_cookie3 if the former is not installed.
Which specific cookies does Agent Reach extract for Twitter/X authentication?
For Twitter/X, Agent Reach specifically looks for auth_token and ct0 cookies from domains ending in .twitter.com or .x.com. These values are extracted individually rather than as a concatenated string, allowing them to be written to both the internal config and legacy formats like xfetch session files.
Is it safe to use Agent Reach's cookie extraction on shared computers?
The extraction itself reads only from the current user's browser profile. However, the security depends on the file permissions of ~/.agent-reach/config.yaml. Agent Reach enforces 0o600 permissions (owner read/write only) on all credential files to prevent other system users from accessing the extracted cookies.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →