Best Practices for Maintaining Cookie Sessions for Long-Running Agent Reach Agents
Store browser cookies in atomic, owner-only files with 0o600 permissions, extract only from closed browsers using rookiepy with browser-cookie3 fallback, and schedule periodic refreshes via cron to prevent authentication timeouts in long-running deployments.
Maintaining cookie sessions for long-running Agent Reach agents requires a security-first approach that prevents credential leakage while ensuring continuous authentication against platforms like Twitter/X, XiaoHongShu, Bilibili, and Xueqiu. The Agent Reach repository implements robust patterns for browser cookie extraction, atomic file storage, and graceful degradation that you should follow in production deployments.
Secure Cookie Extraction from Browser Profiles
Extract from Closed Browsers Only
The extract_all() function in agent_reach/cookie_extract.py enforces a critical safety rule: it attempts extraction only when the target browser is not running. The implementation first tries rookiepy (a Rust-based extractor) and falls back to browser-cookie3, validating the browser state before proceeding (lines 44-61). This prevents partial reads and permission errors that could corrupt the cookie jar or return incomplete session data.
Validation and Graceful Degradation
When extraction fails, the configure_from_browser() function catches exceptions and returns a user-friendly status tuple rather than crashing: except Exception as e: return [("Browser", False, str(e))] (lines 40-44). This allows long-running agents to continue operating with reduced functionality instead of failing completely when browser cookies are temporarily unavailable.
Atomic File Operations with Strict Permissions
Private File Creation
The repository uses _open_owner_only() in agent_reach/cookie_extract.py to create cookie storage files with atomic, secure defaults. The function opens the target file with os.O_CREAT|os.O_WRONLY|os.O_TRUNC and forces mode 0o600 (owner-only) before any data is written (lines 50-68). This guarantees that credentials never become world-readable, even briefly during file creation.
Secure Configuration Directory
Before writing any configuration, Config._ensure_dir() calls make_private_dir() (found in agent_reach/utils/paths.py) to create the ~/.agent-reach folder with 0o700 permissions (lines 39-42 in agent_reach/config.py). This shields all stored secrets from other users on the system, establishing a secure root for all subsequent cookie operations.
Credential Masking and Safe Serialization
When serializing configuration for logging or diagnostics, Config.to_dict() automatically redacts sensitive values. The method replaces any key containing words like "token", "cookie", or "auth" with a short, redacted preview (lines 108-128 in agent_reach/config.py). This prevents accidental leakage of authentication credentials in application logs or error reports.
Platform-Specific Cookie Handling
Twitter/X Authentication
For Twitter/X integration, the code synchronizes extracted tokens to legacy tool locations while maintaining security boundaries. The _sync_xfetch_session() and _sync_bird_env() functions write auth tokens to the locations expected by xfetch and bird CLIs while still respecting private-file semantics (lines 76-99 in agent_reach/cookie_extract.py). This ensures compatibility without exposing credentials to broader filesystem access.
XiaoHongShu and Xueqiu Validation
Before persisting platform-specific cookies, the code validates the presence of required authentication tokens. When configuring Xueqiu, the implementation checks that xq_a_token is present: if cookie_str and "xq_a_token" in cookie_str: (lines 86-90). This avoids persisting anonymous cookie batches that would fail during subsequent API calls.
Automated Refresh Strategies for Long-Running Agents
Dry-Run Testing
The CLI in agent_reach/cli.py supports a --dry-run flag that prints "Would try to import cookies ..." without touching the browser or filesystem (lines 285-311). Use this to verify import flows before executing them in production:
# Verify what would happen without extraction
agent-reach configure --from-browser chrome --dry-run
# Actually import the cookies
agent-reach configure --from-browser chrome
Scheduled Refresh via Cron
While the library does not automate refreshes internally, the extraction code is idempotent and safe to run periodically. Schedule a cron entry to prevent authentication timeouts:
0 2 * * * /opt/agent-reach/venv/bin/python -m agent_reach.cli configure --from-browser chrome >/dev/null 2>&1
This daily refresh at 02:00 UTC ensures cookies remain valid without manual intervention.
Programmatic Access Patterns
In your long-running agent code, access persisted cookies through the Config class, which automatically handles the secure file permissions:
from agent_reach.config import Config
from agent_reach.cookie_extract import configure_from_browser
cfg = Config()
# Optional: Refresh on startup
configure_from_browser("chrome", cfg)
# Retrieve platform-specific cookies
twitter_token = cfg.get("twitter_auth_token")
xhs_cookie = cfg.get("xhs_cookie")
xueqiu_cookie = cfg.get("xueqiu_cookie") # Contains validated xq_a_token
# Use with HTTP clients
import requests
headers = {"Cookie": xhs_cookie}
resp = requests.get("https://www.xiaohongshu.com/api/v1/endpoint", headers=headers)
To manually set cookies while maintaining security:
from agent_reach.config import Config
cfg = Config()
cfg.set("xhs_cookie", "a=1; b=2; c=3") # Automatically saved with 0o600 permissions
Summary
- Extract from closed browsers only using the
extract_all()implementation inagent_reach/cookie_extract.pyto prevent corruption. - Enforce 0o600 file permissions via
_open_owner_only()and 0o700 directory permissions viamake_private_dir()to protect credentials. - Mask sensitive values in logs using
Config.to_dict()to prevent accidental exposure of tokens and cookies. - Validate required cookies (like
xq_a_token) before persistence to ensure functional authentication. - Schedule periodic refreshes using cron and the idempotent CLI commands to maintain session continuity.
Frequently Asked Questions
How often should I refresh cookies for long-running Agent Reach agents?
While the code does not enforce automatic refresh intervals, you should run agent-reach configure --from-browser <browser> daily or every few days via cron. Platform cookies typically expire after short periods, and the idempotent extraction process in agent_reach/cookie_extract.py safely overwrites existing files with atomic operations.
What permissions should cookie files have?
All cookie storage files must have 0o600 (owner-only) permissions, created via the _open_owner_only() function. The configuration directory requires 0o700 permissions via make_private_dir(). These restrictions ensure that only the agent process owner can read authentication credentials.
Can I extract cookies while the browser is running?
No. The extract_all() function specifically validates that the browser is closed before attempting extraction (lines 44-61). Extracting from a running browser causes partial reads and permission errors that could corrupt your session data or return incomplete cookies.
How does Agent Reach prevent credential leakage in logs?
The Config.to_dict() method in agent_reach/config.py automatically detects keys containing "token", "cookie", or "auth" and replaces their values with redacted previews (lines 108-128). This ensures that even if you log the entire configuration object, sensitive authentication materials remain masked.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →