How Cookie Authentication Works in you-get: Supported Formats and Implementation

you-get supports cookie authentication via the -c/--cookies flag, accepting both Netscape cookies.txt and SQLite cookies.sqlite formats to authenticate HTTP requests for protected content.

The soimort/you-get downloader supports cookie authentication to access restricted videos and streaming content. By loading browser-exported cookie files, you-get can authenticate requests without manual header manipulation. Understanding how cookie authentication works in this tool helps users download protected content from platforms like Bilibili and YouTube.

The --cookies Argument

In src/you_get/common.py, the argument parser defines the -c and --cookies flags at lines 1604-1605:

download_grp.add_argument(
    '-c', '--cookies', metavar='COOKIES_FILE',
    help='Load cookies.txt or cookies.sqlite'
)

When present, the application invokes load_cookies() at line 1722:

if args.cookies:
    load_cookies(args.cookies)

The load_cookies() function in common.py recognizes two distinct storage formats for session authentication.

Netscape cookies.txt Format

The Netscape/Mozilla cookies.txt format uses plain text where each line represents a cookie with tab-separated values:


domain\tflag\tpath\tsecure\texpires\tname\tvalue

The implementation at common.py lines 1392-1405 manually parses this format to preserve #HttpOnly_ entries and filter expired or discard-flagged cookies. This manual approach avoids limitations in Python's standard MozillaCookieJar.load() method.

SQLite cookies.sqlite Format

For Firefox and Chrome SQLite databases, you-get handles cookies.sqlite or cookies.sqlite3 files. The implementation at lines 1555-1669:

  1. Copies the database to a temporary location to avoid locking issues
  2. Opens the copy with sqlite3
  3. Reads the moz_cookies table
  4. Constructs Cookie objects with proper domain, path, and expiration attributes

Format Validation

If the supplied file lacks .txt, .sqlite, or .sqlite3 extensions, load_cookies() logs an error at line 1475: "unsupported cookies format".

HTTP Request Injection

After loading, cookies reside in a global CookieJar instance. You-get manually constructs the Cookie HTTP header rather than relying on Python's automatic cookie handling, ensuring compatibility with #HttpOnly attributes across older Python versions.

The header construction occurs at common.py lines 466-477 and 519-530:

if cookies:
    cookie_strings = [c.name + '=' + c.value for c in list(cookies)]
    cookie_headers = {'Cookie': '; '.join(cookie_strings)}
    req.headers.update(cookie_headers)

This approach concatenates all active cookies into a single header string, attaching them to every subsequent HTTP request made by the downloader.

Extractor Integration

Individual site extractors verify cookie presence before accessing restricted APIs. In src/you_get/extractors/bilibili.py, lines 229-230 warn users: "You will need login cookies … (use --cookies to load cookies.txt.)"

Similarly, youtube.py at line 254 emits an error when authentication cookies are missing for protected content, guiding users to supply the --cookies parameter.

Practical Usage Examples

Export cookies from your browser using extensions like "Get cookies.txt" for Chrome or Firefox's native storage, then invoke you-get:


# Using Netscape format

you-get -c ~/cookies.txt "https://www.bilibili.com/video/av12345"

# Using Firefox SQLite database

you-get -c ~/.mozilla/firefox/xxx.default/cookies.sqlite "https://youtube.com/watch?v=..."

For programmatic usage within Python:

from you_get.common import load_cookies, get_http_headers

# Load cookies into the global jar

load_cookies('cookies.txt')

# Headers now include Cookie field

headers = get_http_headers(url='https://site.com/video')

Summary

  • you-get supports cookie authentication via the -c/--cookies command-line flag.
  • Two formats are supported: Netscape cookies.txt and SQLite cookies.sqlite.
  • The load_cookies() function in src/you_get/common.py handles parsing for both formats, manually processing text files and querying SQLite databases.
  • Cookies are manually injected into HTTP headers at common.py lines 466-477 to ensure compatibility with HttpOnly attributes.
  • Extractors like Bilibili and YouTube check for cookie presence to access restricted content.

Frequently Asked Questions

you-get supports two primary formats: Netscape/Mozilla cookies.txt (plain text with tab-separated values) and SQLite cookies.sqlite (the database format used by Firefox and Chrome). The tool detects the format based on file extension—.txt for Netscape format and .sqlite or .sqlite3 for SQLite databases.

How do I export cookies from my browser for use with you-get?

For Chrome, use extensions like "Get cookies.txt" to export in Netscape format. For Firefox, you can copy the cookies.sqlite file directly from your profile directory (typically located at ~/.mozilla/firefox/[profile]/cookies.sqlite). Ensure the file has the correct extension so you-get recognizes the format.

The implementation manually constructs the Cookie HTTP header at src/you_get/common.py lines 466-477 to properly handle #HttpOnly_ cookies. Older Python versions and the standard MozillaCookieJar class had limitations with HttpOnly attributes, so manual parsing and header construction ensures compatibility across all supported Python versions while preserving security-restricted cookies.

Can I use you-get with cookies from Chrome or Firefox?

Yes, you-get works with cookies from both browsers. For Firefox, use the native cookies.sqlite file. For Chrome, export your cookies to the Netscape cookies.txt format using browser extensions or developer tools, then supply the file via the -c or --cookies command-line option.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →