About agentcookie

What agentcookie does, who maintains it, and where the code and docs live.

What it does

agentcookie is one-way, continuous, unattended replication of Chrome cookies and per-CLI secrets from the Mac you use to the Linux box or second Mac your agents run on. You browse and log in normally on your Mac. agentcookie watches Chrome's Cookies file and ships the diff to the sink the moment anything changes, so the agent's session is already there when its request hits. There is no auth login step on the sink, no Keychain prompt, and no paste-the-cookie ritual.

Everything travels encrypted over your own Tailscale tailnet. Both ends bind tailnet-private addresses only. Keys are derived per peer at pairing time (X25519 plus HKDF salted with the pairing code), every payload is sealed with AES-256-GCM, and a persistent sequence tracker rejects replays across restarts. Cookie policy filters run on both sides: the source decides what to ship and the sink independently decides what to accept, so a compromised source cannot push a domain the sink has not allowed.

On a Linux sink there is no Keychain and no Chrome SQLite rewrite. The sink attaches to Chrome's debug port and performs live CDP injection straight into the in-memory cookie store, on every sync and on every new browser context. browserUse, Puppeteer, Playwright, or any Chromium automation on that box sees the session already present. A macOS sink additionally opens Chrome Safe Storage to any cookie reader with one login-password entry at install, so unmodified tools read the real synced profile.

One source fans out to several sinks. Each sink is sealed with its own paired key, and a sink that is down fails on its own while the others still receive the payload. Alongside cookies, a per-CLI secrets bus carries bearer tokens, API keys, and KEY=VALUE auth blobs over the same encrypted push; they land on the sink at ~/.agentcookie/secrets/<cli>/secrets.env with mode 0600. Any tool can adopt the bus by dropping an agentcookie.toml manifest in its repo.

Who maintains it

agentcookie is written and maintained by Matt Van Horn (x.com/mvanhorn, GitHub mvanhorn). It is a single-maintainer project. Development happens in the open on GitHub, releases are signed with an Apple Developer ID and published with checksums on the GitHub Releases page, and the threat model is a tracked document in the same repository.

License

agentcookie is open source under the MIT license. The full source, the quickstart, the secrets bus specifications, and the threat model are all in the repository linked below. If the site and the README ever disagree, the README is the source of truth.