Decloak Session Capture Firefox

Decloak Session Capture

Capture your logged-in session (cookies + storage) so Decloak can run an authenticated scan, including passkey/WebAuthn logins.

Features & Capabilities

Decloak is an automated web security scanner. Paste any URL and get a free, instant report in about 15 seconds - no login required - covering HTTP/TLS posture, JavaScript vulnerabilities, third-party scripts and tag managers, and more.

Decloak's paid Enterprise tier goes further: an AI agent crawls your whole site, investigates what it finds, and produces audit-ready reports for teams tracking SOC2 or ISO 27001 compliance.

This extension is a companion for the Enterprise tier's authenticated scans - it does nothing on its own and requires a Decloak account already open to a "New scan" dialog.

Enterprise's authenticated scan mode crawls your site as a logged-in user, which means it needs your session. For most sites that's easy to script. For sites using passkeys or WebAuthn (Hanko, Face ID/Touch ID sign-in, security keys), there's no credential to script — the only way in is a session that already exists in your browser. This extension captures that session so Decloak can use it.

How it works

  1. Start a new Enterprise scan in your Decloak dashboard, choose "Authenticate as a logged-in user," and click "Get a capture code."
  2. Open the site you want scanned in a tab, log in normally, then click this extension's icon.
  3. Click "Capture session for Decloak" — it asks for permission on just that tab's site, nothing else.
  4. Paste the capture code from the dashboard and click "Send to Decloak."
What it captures

Cookies, localStorage, and sessionStorage for the one site you're currently on. Nothing else — no browsing history, no other tabs, no data from sites you haven't explicitly clicked "capture" on.

What it doesn't do

  • No install-time permissions. It asks for site access only when you click, only for that site.
  • No account or API key lives in the extension. The one-time capture code from your Decloak dashboard is the only credential involved, and it expires in 15 minutes whether you use it or not.
  • Nothing is stored by the extension itself. Closing the popup clears the capture. There's no storage permission in the manifest because there's nothing to persist.
  • The capture is single-use. Once Decloak's scan consumes it, the code is dead.
Why this needs the cookies permission

The entire purpose of this extension is capturing a session for your own authenticated security scan, scoped to the one site you click on. There's no other way to read cookies for a site from an extension. We don't request broad host permissions at install time - you grant access per-site, per-use, from the popup.

Full privacy policy: https://decloak.dev/privacy - see the "Browser extension (Session Capture)" section for exactly what's read, when it's transmitted, and how long anything is retained.

User Growth & Download Statistics

Manifest V3 Add-on
By:
Stephen Gray
Daily users:
-
Version:
0.1.0 Last updated: 2026-07-17
Version code:
6354988
Creation date:
2026-07-14
Risk:
Very low risk impact High risk likelihood
Permissions:
Size:
21.07KB
Email:
su*****@sparrowtechnology.ai
URLs:
Website ,Privacy policy
Full description:
See detailed description
Source:
Firefox Add-ons Store
Data ingested on:
2026-07-27
Compare stats and ranking:

Contact the developer

Chrome-Stats does not own this Firefox add-on. Please use these information below to contact the Firefox add-on developer.
Developed by:
Stephen Gray
Firefox Add-ons Store
https://addons.mozilla.org/firefox/addon/decloak-session-capture/
Email:
su*****@sparrowtechnology.ai
Website:
https://decloak.dev/faq

Is Decloak Session Capture Safe?

Risk impact
Risk impact measures the level of extra permissions an extension has access to. A low risk impact extension cannot do much harms, whereas a high risk impact extension can do a lot of damage like stealing your password, bypassing your security settings, and accessing your personal data. High risk impact extensions are not necessarily malicious. However, if they do turn malicious, they can be very harmful.

Decloak Session Capture does not require any sensitive permissions.

Risk impact analysis details
Risk likelihood
Risk likelihood measures the probability that a Firefox add-on may turn malicious. This is determined by the publisher and the Firefox add-on reputation on Firefox Add-ons Store, the amount of time the Firefox add-on has been around, and other signals about the Firefox add-on. Our algorithms are not perfect, and are subject to change as we discover new ways to detect malicious extensions. We recommend that you always exercise caution when installing a Firefox add-on.

Decloak Session Capture is recently added, and hasn't been around long enough for us to gather enough data to accurately assess its risk level.

Risk likelihood analysis details
  • High This extension was recently updated in the past month. New updates may not be stable or safe.
  • High **** ********* *** ******** ****** *** ********** *** *** ** ****** ** *****
  • High **** ********* *** *** **** ****** ********* ********** *** *** ** ****** ** *****
Extension Guard
Extension Guard

Discover every extension in use, analyze risks, and enforce blocking policies with Extension Guard

Secure Your Browser
Upgrade to see full risk analysis details

Best Decloak Session Capture Alternatives

Here are some Firefox add-ons that are similar to Decloak Session Capture: