VerifiableThe cookie editor that can’t phone home →

Every login in
its own jar.

Save a signed-in state, then flip between admin, free and paid test accounts in one click. A fast, open-source cookie editor underneath — with no ads, no analytics and no network access.

Add to Chrome — it’s freeFirefoxEdge
MIT open sourceNo “all websites” permissionReproducible builds
Free user ⌘⇧2
Paid · Team ⌘⇧3
Flipped in 0.4s · 21 cookies
QA engineersRole-based testing without re-logins
Full-stack developersDebug auth, flags and A/B cookies
Test automationExport straight to Playwright
Security testersSession and flag audits, offline
How it works

Sign in once per role. Flip forever.

01

Sign in as a test user

Do the login, the OTP, the 2FA — one last time.

02

Save it as a jar

Every cookie for the site — HttpOnly and partitioned included — captured under a name and a color.

03

Flip in one click

Snapshot, clear, write, reload. If anything fails, it rolls back — never half signed in.

Features

A complete cookie editor. Then the parts nobody else built.

Jars & one-click flips

Named, colored sign-in states per site. Keyboard shortcuts for the first nine.

Atomic, undoable

Every flip and delete snapshots first. Undo with ⌘Z; failed writes roll back.

Partitioned cookies (CHIPS)

Seen, edited and saved with their top-level site — where most editors go blind.

Diff before you flip

See what a jar will add, remove and change versus the browser right now.

Flag audit

Missing HttpOnly, loose SameSite, oversized and immortal cookies — as a shareable report.

Encrypted team files

Bundle jars for a new teammate, AES-GCM with a passphrase. No server involved.

Trust

Don’t trust us.
Check.

Cookie extensions have been sold, cloned and turned into malware. JarFlip is built so that bad behavior would be visible — or impossible.

No network, enforced. The content policy blocks every request.
Store build = source. Reproducible builds with published hashes.
Public ownership pledge. Any acquisition offer is disclosed; 30 days’ notice before any transfer.
How to verify a release →
JarFlipTypical cookie extension
Install-time permissionNone for sitesAll websites
Network accessBlocked by CSPUnrestricted
Ads & affiliate linksNeverOften
Saved logins (profiles)Jars, one clickRare
Partitioned cookiesFull supportUsually missing
Build verifiableReproducibleNo
tests/admin.spec.ts
// Exported from JarFlip → “Playwright storageState”
test.use({ storageState: 'jars/admin.json' });

test('admin sees the audit log', async ({ page }) => {
  await page.goto('/settings/audit');
  await expect(page.getByRole('table')).toBeVisible();
});
Every format in, every format out

Bring your cookies. Take them to your tests.

Import from EditThisCookie, Cookie-Editor, cookies.txt, Playwright and Puppeteer — auto-detected. Export the same jar to your test suite, curl or yt-dlp.

JarFlip JSONEditThisCookieCookie-Editorcookies.txtPlaywrightPuppeteerCookie header
Moving from EditThisCookie? The two-minute guide →
FAQ

Questions developers ask first

Does JarFlip send my cookies anywhere?+

It can’t. The extension’s content security policy sets connect-src to none, so the browser blocks every request it might try to make. Jars live in local extension storage on your device.

Why does it ask for access site by site?+

Least privilege. Instead of “read and change all your data on all websites” at install, you grant the sites you test, and can revoke each one from the dashboard.

Will a jar keep me signed in forever?+

A jar holds whatever the site set. Short-lived sessions still expire, and sites using device-bound sessions may ask you to sign in again. JarFlip shows each jar’s health so you know before you flip.

Can I share jars with my team?+

Yes — export a bundle encrypted with a passphrase and send it through your usual channel. There is no JarFlip server, account or sync.

How is it funded?+

GitHub Sponsors. There is no paid tier, no ads and no data business. The MIT license lets anyone fork it if that ever changes.

Stop logging in and out.
Start flipping.

Free forever. Funded by developers on GitHub Sponsors — never by your data.

Add to Chrome — freeSponsor on GitHub