
Session Key Getter: a browser extension
A small Chrome extension (Manifest V3) that reads a named session cookie from your own active browser tab and copies it to the clipboard in one click — a dev and QA helper for using your session token in API tests and automation. Read-only, no network calls, no data leaves the browser.
About the project
During development and testing you often need the session token from a web app you're signed into — to replay an authenticated request in Postman, a script, or an automated test. Copying it out of the browser's dev tools by hand is fiddly. This extension puts it one click away: open the popup and it reads a named cookie from the current tab and shows it, with a Copy button.
It is deliberately tiny and self-contained — a Manifest V3 extension of about a hundred lines (a popup, a small script, and a manifest) — and privacy-conscious by design: it only reads the one cookie you ask for, only from the tab you're on, makes no network requests, and stores nothing. The token goes to your clipboard and nowhere else.
Built as an internal developer tool. The screenshots are an anonymized demo — the product name, the cookie name, and the token value shown are generic stand-ins, and no real session data appears.
Features
- One-click read: the popup fetches a named cookie from the current active tab and displays its value.
- Copy to clipboard with a brief "Copied!" confirmation.
- Clear empty state: a plain "Cookie not found" message when the tab has no such cookie.
- Tiny footprint: a popup, one script, and a manifest — nothing to configure.
Screenshots
Architecture
- Manifest V3 browser extension: a browser-action popup (
popup.html+popup.js) with no background service worker. - Reads the cookie through the
chrome.cookiesAPI for the active tab's URL (chrome.tabs.query). - Copies with the Clipboard API (
navigator.clipboard.writeText). - Permissions:
cookies,activeTab, and host access to all URLs so it works on any site. The cookie API makes no network request; nothing is sent anywhere.
Challenges & what I learned
- Reading only the one named cookie, and only from the tab you're on, with no exfiltration — the value goes to the clipboard and nowhere else.
- Making a single-purpose tool that is obvious to use — open, read, copy — with a visible empty state so it never looks broken when a cookie is simply absent.
- How Manifest V3's popup model and the
chrome.cookies/activeTabpermissions fit together for a focused utility. - Where this one could be tightened: the broad all-sites host permission could be scoped to the specific hosts it's used on, or replaced by requesting access on demand.
