Tell CookieJar exactly which sites to sync. No more, no less.
Pick domains. Encrypt locally. Sync via your private GitHub Gist. No servers. No trackers. Cross-device convenience with end-to-end encryption.
CookieJar uses your GitHub Gist as an encrypted vault. Cookies never leave your device unencrypted.
Tell CookieJar exactly which sites to sync. No more, no less.
Data is encrypted on-device using AES-256-GCM with a key derived from your passphrase (PBKDF2/Argon2).
Encrypted blobs are stored in your private GitHub Gist with your PAT (gist scope). Pull & decrypt on any device.
gist
scope.Tip: keep the same passphrase on every device you sync with.
As encrypted blobs inside your private GitHub Gist. No plaintext cookies are stored by CookieJar.
No. Cookies are encrypted locally before upload. Without your passphrase, the data is useless.
Minimal permissions to read/write cookies for the domains you select, store settings locally, and schedule periodic syncs.
Most sites work. Some services bind sessions to device/IP or add integrity checks; those might require re-login.
It cannot be recovered. Revoke your PAT, clear the Gist, set a new passphrase, and re-sync from a logged-in device.