# How Cookie Authentication Works in you-get: Supported Formats and Implementation

> Learn how you-get handles cookie authentication with the -c/--cookies flag. Supports Netscape cookies.txt and SQLite cookies.sqlite formats for protected content.

- Repository: [Mort Yao/you-get](https://github.com/soimort/you-get)
- Tags: deep-dive
- Published: 2026-03-06

---

**you-get supports cookie authentication via the `-c/--cookies` flag, accepting both Netscape [`cookies.txt`](https://github.com/soimort/you-get/blob/main/cookies.txt) and SQLite `cookies.sqlite` formats to authenticate HTTP requests for protected content.**

The `soimort/you-get` downloader supports **cookie authentication** to access restricted videos and streaming content. By loading browser-exported cookie files, you-get can authenticate requests without manual header manipulation. Understanding how cookie authentication works in this tool helps users download protected content from platforms like Bilibili and YouTube.

## Command-Line Interface for Cookie Authentication

### The --cookies Argument

In [`src/you_get/common.py`](https://github.com/soimort/you-get/blob/main/src/you_get/common.py), the argument parser defines the `-c` and `--cookies` flags at lines 1604-1605:

```python
download_grp.add_argument(
    '-c', '--cookies', metavar='COOKIES_FILE',
    help='Load cookies.txt or cookies.sqlite'
)

```

When present, the application invokes `load_cookies()` at line 1722:

```python
if args.cookies:
    load_cookies(args.cookies)

```

## Supported Cookie File Formats

The `load_cookies()` function in [`common.py`](https://github.com/soimort/you-get/blob/main/common.py) recognizes two distinct storage formats for session authentication.

### Netscape cookies.txt Format

The **Netscape/Mozilla [`cookies.txt`](https://github.com/soimort/you-get/blob/main/cookies.txt)** format uses plain text where each line represents a cookie with tab-separated values:

```

domain\tflag\tpath\tsecure\texpires\tname\tvalue

```

The implementation at [`common.py`](https://github.com/soimort/you-get/blob/main/common.py) lines 1392-1405 manually parses this format to preserve `#HttpOnly_` entries and filter expired or discard-flagged cookies. This manual approach avoids limitations in Python's standard `MozillaCookieJar.load()` method.

### SQLite cookies.sqlite Format

For **Firefox and Chrome SQLite databases**, you-get handles `cookies.sqlite` or `cookies.sqlite3` files. The implementation at lines 1555-1669:

1. Copies the database to a temporary location to avoid locking issues
2. Opens the copy with `sqlite3`
3. Reads the `moz_cookies` table
4. Constructs `Cookie` objects with proper domain, path, and expiration attributes

### Format Validation

If the supplied file lacks `.txt`, `.sqlite`, or `.sqlite3` extensions, `load_cookies()` logs an error at line 1475: "unsupported cookies format".

## HTTP Request Injection

After loading, cookies reside in a global `CookieJar` instance. You-get manually constructs the `Cookie` HTTP header rather than relying on Python's automatic cookie handling, ensuring compatibility with `#HttpOnly` attributes across older Python versions.

The header construction occurs at [`common.py`](https://github.com/soimort/you-get/blob/main/common.py) lines 466-477 and 519-530:

```python
if cookies:
    cookie_strings = [c.name + '=' + c.value for c in list(cookies)]
    cookie_headers = {'Cookie': '; '.join(cookie_strings)}
    req.headers.update(cookie_headers)

```

This approach concatenates all active cookies into a single header string, attaching them to every subsequent HTTP request made by the downloader.

## Extractor Integration

Individual site extractors verify cookie presence before accessing restricted APIs. In [`src/you_get/extractors/bilibili.py`](https://github.com/soimort/you-get/blob/main/src/you_get/extractors/bilibili.py), lines 229-230 warn users: "You will need login cookies … (use --cookies to load cookies.txt.)"

Similarly, [`youtube.py`](https://github.com/soimort/you-get/blob/main/youtube.py) at line 254 emits an error when authentication cookies are missing for protected content, guiding users to supply the `--cookies` parameter.

## Practical Usage Examples

Export cookies from your browser using extensions like "Get cookies.txt" for Chrome or Firefox's native storage, then invoke you-get:

```bash

# Using Netscape format

you-get -c ~/cookies.txt "https://www.bilibili.com/video/av12345"

# Using Firefox SQLite database

you-get -c ~/.mozilla/firefox/xxx.default/cookies.sqlite "https://youtube.com/watch?v=..."

```

For programmatic usage within Python:

```python
from you_get.common import load_cookies, get_http_headers

# Load cookies into the global jar

load_cookies('cookies.txt')

# Headers now include Cookie field

headers = get_http_headers(url='https://site.com/video')

```

## Summary

- **you-get** supports cookie authentication via the `-c/--cookies` command-line flag.
- Two formats are supported: **Netscape [`cookies.txt`](https://github.com/soimort/you-get/blob/main/cookies.txt)** and **SQLite `cookies.sqlite`**.
- The `load_cookies()` function in [`src/you_get/common.py`](https://github.com/soimort/you-get/blob/main/src/you_get/common.py) handles parsing for both formats, manually processing text files and querying SQLite databases.
- Cookies are manually injected into HTTP headers at [`common.py`](https://github.com/soimort/you-get/blob/main/common.py) lines 466-477 to ensure compatibility with HttpOnly attributes.
- Extractors like Bilibili and YouTube check for cookie presence to access restricted content.

## Frequently Asked Questions

### What cookie formats does you-get support?

you-get supports two primary formats: **Netscape/Mozilla [`cookies.txt`](https://github.com/soimort/you-get/blob/main/cookies.txt)** (plain text with tab-separated values) and **SQLite `cookies.sqlite`** (the database format used by Firefox and Chrome). The tool detects the format based on file extension—`.txt` for Netscape format and `.sqlite` or `.sqlite3` for SQLite databases.

### How do I export cookies from my browser for use with you-get?

For Chrome, use extensions like "Get cookies.txt" to export in Netscape format. For Firefox, you can copy the `cookies.sqlite` file directly from your profile directory (typically located at `~/.mozilla/firefox/[profile]/cookies.sqlite`). Ensure the file has the correct extension so you-get recognizes the format.

### Why does you-get manually construct Cookie headers instead of using Python's cookiejar?

The implementation manually constructs the `Cookie` HTTP header at [`src/you_get/common.py`](https://github.com/soimort/you-get/blob/main/src/you_get/common.py) lines 466-477 to properly handle `#HttpOnly_` cookies. Older Python versions and the standard `MozillaCookieJar` class had limitations with HttpOnly attributes, so manual parsing and header construction ensures compatibility across all supported Python versions while preserving security-restricted cookies.

### Can I use you-get with cookies from Chrome or Firefox?

Yes, you-get works with cookies from both browsers. For Firefox, use the native `cookies.sqlite` file. For Chrome, export your cookies to the Netscape [`cookies.txt`](https://github.com/soimort/you-get/blob/main/cookies.txt) format using browser extensions or developer tools, then supply the file via the `-c` or `--cookies` command-line option.