{"package_name":"com.cookiesextractor.app","name":"Cookie Extractor","summary":"Extract your own session cookies after a manual login","category":"Development","icon_url":"/api/icon/com.cookiesextractor.app","latest_version_code":3,"latest_version_name":"1.1.0","apk_url":"/api/apk/com.cookiesextractor.app","apk_size":4825237,"apk_sha256":"baa7f8e80d1f6481c0922f14b58df2c5056ba220a84d5b76cbfaa94efb3635da","source_kind":"fdroid-repo","repo_slug":"fdroid-main","last_updated":1791082822,"release_timestamp":1791057188,"description":"A developer tool for inspecting and verifying session information.\n\nHeadless automation is increasingly blocked by 2FA QR codes, interactive\nchallenges, and anti-bot flows. This app takes the other road: you log in\nby hand, exactly like in a normal browser, then one tap pulls the session\ncookies for the loaded domain and hands them to the Android share sheet,\nready for curl, wget, or any script that needs an authenticated session.\n\nWhat is inside:\n\n- Address bar and in-app WebView; log in with password, 2FA, OTP, or most\n  SSO-redirect flows. Passkeys for third-party sites do not work in a\n  third-party WebView (Android privilege model); the README explains why.\n- Non-http OAuth redirects are caught before an error page appears and\n  shared as one line, so relays cannot corrupt the authorization code.\n- A share template with live preview shapes the shared text: placeholders\n  for payload, URL, title, host, and date, for example a ready-to-paste\n  curl command.\n- Bookmarks with add-by-URL and entry-URL memory: what you typed, not\n  where the redirect landed.\n- A session monitor: point it at a state document on your own gateway and\n  get a native notification when a login expires.\n- An opt-in, token-gated debug channel with a versioned agent API\n  (/api/v1) to drive the app programmatically: navigate, read text and\n  cookies, fill and submit forms. Off by default; the README documents\n  every endpoint and the threat model.\n\nIt reads only the cookies of its own WebView through the public\nCookieManager API: no root, no cross-app access, no automation of other\napps. Extracted cookies are session credentials; share them only over\nchannels you trust.\n\nLicensed under the Apache License 2.0.\n","categories":["Development"]}