Item logo image for CookieJab

CookieJab

ExtensionDeveloper Tools4 users
Item media 5 (screenshot) for CookieJab
Item media 1 (screenshot) for CookieJab
Item media 2 (screenshot) for CookieJab
Item media 3 (screenshot) for CookieJab
Item media 4 (screenshot) for CookieJab
Item media 5 (screenshot) for CookieJab
Item media 1 (screenshot) for CookieJab
Item media 1 (screenshot) for CookieJab
Item media 2 (screenshot) for CookieJab
Item media 3 (screenshot) for CookieJab
Item media 4 (screenshot) for CookieJab
Item media 5 (screenshot) for CookieJab

Overview

Inject request headers and cookies per match pattern. Switch each rule on and off.

CookieJab injects the request headers and cookies you define into the sites you choose, so you can test a staging environment, a feature flag, or an authentication token without touching your real browsing session. It can also inject on the way back, so you can add or override a response header such as Content-Security-Policy or X-Frame-Options. Group related rules into a bundle, toggle a whole group at once, or switch between saved identities with one click. Paste a curl command, a raw HTTP request, or anything else you captured, and pick straight from the headers and cookies it found. Smart Import reads whatever you paste with AI that runs on your device, and never sends it anywhere. One switch pauses every rule at once, and your rules follow you to your other signed-in devices. Values stay hidden by default. Open source, no analytics, and nothing sent anywhere but the sites your rules target and, if you turn on sync, your own devices. For developers and security testers who send an authentication token, a feature flag header, or a session cookie to a test environment. Features: - Match patterns with scheme, host, and path, for example *://*.example.com/*. - Header rules use declarativeNetRequest, on the request or the response, and run on all request types or only the ones you pick. - Cookie rules set a cookie for the whole site on navigation, with control over SameSite, Secure, and an expiry. - Set, append, or "only if absent" modes, so a rule can add to an existing header instead of only replacing it, or leave a cookie the site already set alone. - {{random}}, {{timestamp}}, and {{uuid}} placeholders in a value, for rate-limit and cache-busting tests. - A bundle variable: switch every rule in a bundle between named identities, like different users or environments, with one click. - A per-rule counter that shows how many times a rule has matched. - A kill switch that pauses every rule at once, badges the toolbar icon, and clears cookies already set, without touching your saved rules. - Rules sync across your devices through your Chrome sign-in, with an on-device fallback when a rule set does not fit. CookieJab sends rule values only to the sites that match your rules, and to Google's sync infrastructure for the sync itself. - Import from a curl command, or Smart Import for anything else: on a Chrome build with the on-device Prompt API, extracts headers and cookies from any pasted text using a language model that runs locally on your device. No new permission, and nothing is sent off-device. - Export and import your whole rule list as JSON, for backup or to share a rule set with a teammate. - Open source under the MIT license: https://github.com/amocsub/CookieJab

Details

  • Version
    1.1.0
  • Updated
    September 11, 2026
  • Offered by
    Matias.Busco
  • Size
    47.54KiB
  • Languages
    English
  • Developer
    Pl. de la Vila, 1 Badalona, Barcelona 08911 ES
    Email
    matias.busco@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

CookieJab has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

CookieJab handles the following:

Authentication information

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Google apps