Every login in
its own jar.
Save a signed-in state, then flip between admin, free and paid test accounts in one click. A fast, open-source cookie editor underneath — with no ads, no analytics and no network access.
Sign in once per role. Flip forever.
Sign in as a test user
Do the login, the OTP, the 2FA — one last time.
Save it as a jar
Every cookie for the site — HttpOnly and partitioned included — captured under a name and a color.
Flip in one click
Snapshot, clear, write, reload. If anything fails, it rolls back — never half signed in.
A complete cookie editor. Then the parts nobody else built.
Jars & one-click flips
Named, colored sign-in states per site. Keyboard shortcuts for the first nine.
Atomic, undoable
Every flip and delete snapshots first. Undo with ⌘Z; failed writes roll back.
Partitioned cookies (CHIPS)
Seen, edited and saved with their top-level site — where most editors go blind.
Diff before you flip
See what a jar will add, remove and change versus the browser right now.
Flag audit
Missing HttpOnly, loose SameSite, oversized and immortal cookies — as a shareable report.
Encrypted team files
Bundle jars for a new teammate, AES-GCM with a passphrase. No server involved.
Don’t trust us.
Check.
Cookie extensions have been sold, cloned and turned into malware. JarFlip is built so that bad behavior would be visible — or impossible.
// Exported from JarFlip → “Playwright storageState” test.use({ storageState: 'jars/admin.json' }); test('admin sees the audit log', async ({ page }) => { await page.goto('/settings/audit'); await expect(page.getByRole('table')).toBeVisible(); });
Bring your cookies. Take them to your tests.
Import from EditThisCookie, Cookie-Editor, cookies.txt, Playwright and Puppeteer — auto-detected. Export the same jar to your test suite, curl or yt-dlp.
Questions developers ask first
Does JarFlip send my cookies anywhere?+
It can’t. The extension’s content security policy sets connect-src to none, so the browser blocks every request it might try to make. Jars live in local extension storage on your device.
Why does it ask for access site by site?+
Least privilege. Instead of “read and change all your data on all websites” at install, you grant the sites you test, and can revoke each one from the dashboard.
Will a jar keep me signed in forever?+
A jar holds whatever the site set. Short-lived sessions still expire, and sites using device-bound sessions may ask you to sign in again. JarFlip shows each jar’s health so you know before you flip.
Can I share jars with my team?+
Yes — export a bundle encrypted with a passphrase and send it through your usual channel. There is no JarFlip server, account or sync.
How is it funded?+
GitHub Sponsors. There is no paid tier, no ads and no data business. The MIT license lets anyone fork it if that ever changes.
Stop logging in and out.
Start flipping.
Free forever. Funded by developers on GitHub Sponsors — never by your data.