your agent's
session state, synced

cookies, bearer tokens, and per-CLI auth blobs replicated continuously from your laptop to the Linux box or second Mac your agent runs on. encrypted over Tailscale, zero per-site auth ceremony.

you@laptop:~
$ssh sink 'instacart-pp-cli carts'
Costco · slug=costco · cart=757109404 · 5 items
Safeway · slug=safeway · cart=3190 · 1 item
$ssh sink 'ebay-pp-cli auctions watch --ending-within 1h'
$352 · 23 bids · 1m left · Apple Watch Ultra 2 49mm
$ssh sink 'table-reservation-goat goat "omakase"'
✓ 12 results · OpenTable + Tock · already signed in

no auth login, no Keychain prompt, no paste-the-cookie ritual. cookies were already there.

stripe-pp-cli/agentcookie.toml
# adoption manifest v2
schema_version = 2
name = "stripe-pp-cli"
display_name = "Stripe"
[secrets.file]
path = "~/.config/stripe-pp-cli/config.toml"
[sync.keys]
STRIPE_SECRET_KEY = true
# arrives on the sink at mode 0600
$ cat ~/.agentcookie/secrets/stripe-pp-cli/secrets.env
STRIPE_SECRET_KEY=sk_live_...

per-CLI bearer tokens and API keys, declared once, synced across the wire. read by every PP CLI; readable by 1Password or whatever else fills the bus.

two surfaces, one encrypted push. cookies for browser-driving agents and adapter-equipped CLIs; secrets bus for everything with bearer auth.

what's working today

continuous laptop -> sink sync

fsnotify on Chrome's Cookies file, debounced, allowlist + blocklist filtered, AES-256-GCM over Tailscale.

live CDP injection on Linux

the Linux sink attaches to Chrome's debug port and sets cookies straight into the in-memory store, on every sync and every new browser context. no Keychain, no SQLite rewrite; browserUse, Puppeteer, and Playwright see the session already there.

fan out to multiple sinks

one source pushes the same cookies and secrets to several sinks, each sealed with that sink's own paired key. a sink that is down fails on its own while the others still receive the payload.

universal cookie delivery

one login-password entry at install (no GUI click) opens Chrome Safe Storage to any cookie reader, so unmodified tools - yt-dlp, gallery-dl, browser-driving agents, the Printing Press CLIs - read the real synced Default Chrome profile. verified live on macOS 15.x.

three cookie delivery surfaces

universal (the real Default profile + one-password keychain open) is the default; the plaintext sidecar at ~/.agentcookie/cookies-plain.db and per-CLI adapter session files are the agentcookie-aware paths that also work in degraded mode.

works with Printing Press CLIs like

Stripe, Linear, Notion, Granola, Slack, Kalshi, ElevenLabs, Mercury, and dozens more - anything with a bearer token or API key reads the secrets bus. Five (instacart, airbnb, ebay, pagliacci, table-reservation-goat) additionally get a bespoke cookie adapter.

per-CLI secrets bus

bearer tokens, API keys, KEY=VALUE auth blobs ride the same encrypted push and land at ~/.agentcookie/secrets/<cli>/secrets.env (mode 0600) with an optional sealed twin.

v2 adoption standard

drop an agentcookie.toml in your repo and agentcookie discover auto-detects it. three integration tiers (explicit, pp-cli-derived, legacy v1) coexist.

tailnet-only listeners

both ends bind tailnet-private addresses. pair endpoint is rate-limited with a 64-bit code.

replay defense, per-peer keys

persistent replay defense and pairing-derived per-peer keys; pairing-code rotation re-derives both ends.

Apple Developer ID signed

every release binary signed and timestamped. the sink daemon reads Chrome Safe Storage via the teamid: partition - no per-binary trust list, no recreate of the key value, no AllowAlways prompt after install.

headless install over SSH

one login-password entry, no GUI SecurityAgent click. a box with no password lands in degraded mode (sidecar + adapters) and prints the one-line upgrade command.

fifteen-category doctor

cookie delivery (universal vs degraded, with duplicate-keychain-item race detection), binary signature + install, Tailscale, config, keystore, listener bind, sink/source state, sealing posture, adapter coverage, CDP injector health, secrets-bus + secret coverage, and DBSC-suspect cookies.

the source is a Mac. the sink is a Linux box (live CDP injection into Chrome's in-memory store) or a second Mac, and one source fans out to several sinks. 520+ unit tests across 26 packages.

frequently asked

Does Chrome's device-bound cookie protection (DBSC) break agentcookie?

No, not for the sites you use today. DBSC is opt-in per site: a cookie is device-bound only when the site's own backend asks for it. As of August 2026 the one broad adopter is Google's own account and Workspace cookies. Almost every other site, and every Printing Press CLI agentcookie feeds, is unaffected and syncs as before.

The secrets bus is untouched. DBSC is a cookie protocol, so bearer tokens, API keys, and OAuth refresh tokens that ride the bus replicate normally.

For a site that has adopted DBSC, a copied cookie works on the sink only until its short-lived window of minutes lapses, because the sink cannot sign the refresh challenge held in the source Mac's Secure Enclave. agentcookie flags these in agentcookie doctor and ships them with a warning by default; pass --skip-dbsc-suspect to drop them instead. For Google sessions, sign the sink's Chrome into the same account once and it establishes its own device-bound session locally, no copy needed.