# Decloak Session Capture

> Capture your logged-in session (cookies + storage) so Decloak can run an authenticated scan, including passkey/WebAuthn logins.

Canonical page: [https://chrome-stats.com/d/decloak-session-capture](https://chrome-stats.com/d/decloak-session-capture)

## Overview

- **ID:** `decloak-session-capture`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** Stephen Gray
- **Category:** web-development,privacy-security
- **Version:** 0.1.0
- **Last updated:** 2026-07-17
- **First published:** 2026-07-14
- **Size:** 21 KB
- **Data as of:** 2026-09-09
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/decloak-session-capture/)
- **Website:** [https://decloak.dev/faq](https://decloak.dev/faq)
- **Privacy policy:** [https://addons.mozilla.org/firefox/addon/decloak-session-capture/privacy/](https://addons.mozilla.org/firefox/addon/decloak-session-capture/privacy/)

## Description

Decloak is an automated web security scanner. Paste any URL and get a free, instant report in about 15 seconds - no login required - covering HTTP/TLS posture, JavaScript vulnerabilities, third-party scripts and tag managers, and more.

Decloak's paid Enterprise tier goes further: an AI agent crawls your whole site, investigates what it finds, and produces audit-ready reports for teams tracking SOC2 or ISO 27001 compliance.

This extension is a companion for the Enterprise tier's authenticated scans - it does nothing on its own and requires a Decloak account already open to a "New scan" dialog.

Enterprise's authenticated scan mode crawls your site as a logged-in user, which means it needs your session. For most sites that's easy to script. For sites using passkeys or WebAuthn (Hanko, Face ID/Touch ID sign-in, security keys), there's no credential to script — the only way in is a session that already exists in your browser. This extension captures that session so Decloak can use it.

How it works
<ol><li>Start a new Enterprise scan in your Decloak dashboard, choose "Authenticate as a logged-in user," and click "Get a capture code."</li><li>Open the site you want scanned in a tab, log in normally, then click this extension's icon.</li><li>Click "Capture session for Decloak" — it asks for permission on just that tab's site, nothing else.</li><li>Paste the capture code from the dashboard and click "Send to Decloak."</li></ol>
What it captures

Cookies, localStorage, and sessionStorage for the one site you're currently on. Nothing else — no browsing history, no other tabs, no data from sites you haven't explicitly clicked "capture" on.

What it doesn't do
<ul><li>No install-time permissions. It asks for site access only when you click, only for that site.</li><li>No account or API key lives in the extension. The one-time capture code from your Decloak dashboard is the only credential involved, and it expires in 15 minutes whether you use it or not.</li><li>Nothing is stored by the extension itself. Closing the popup clears the capture. There's no storage permission in the manifest because there's nothing to persist.</li><li>The capture is single-use. Once Decloak's scan consumes it, the code is dead.</li></ul>
Why this needs the cookies permission

The entire purpose of this extension is capturing a session for your own authenticated security scan, scoped to the one site you click on. There's no other way to read cookies for a site from an extension. We don't request broad host permissions at install time - you grant access per-site, per-use, from the popup.

Full privacy policy: <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/53db09c0d3a06a7ffbcf5ec59633fd9f5640f80f6c74ea9c0061a2ca10f6a747/https%3A//decloak.dev/privacy" rel="nofollow">https://decloak.dev/privacy</a> - see the "Browser extension (Session Capture)" section for exactly what's read, when it's transmitted, and how long anything is retained.

## Rankings

- #137,898 — Overall

## Permissions and access

### Permissions

- `cookies`
- `activeTab`
- `scripting`

## Safety

- **Risk impact:** Very low risk impact
- **Risk likelihood:** High risk likelihood

### Analysis details

- This extension has low user count. Unpopular extensions may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Similar extensions and apps

- [Session Hijack Guard](https://chrome-stats.com/d/session-hijack-guard) — 4 users
- [Secret Scanner](https://chrome-stats.com/d/secret-scanner) — 2 users
- [Secret Scanner](https://chrome-stats.com/d/secret_scanner) — 37 users
- [JS Recon & Secret Scanner](https://chrome-stats.com/d/js-recon-secret-scanner) — 5 users
- [Komodo Scout Pro](https://chrome-stats.com/d/komodo-browser-agent)
- [Cloudeagle](https://chrome-stats.com/d/cloudeagle) — 1 users
- [CredScanner](https://chrome-stats.com/d/credscanner) — 1 users
- [Simple Request Capture](https://chrome-stats.com/d/simple-request-capture) — 14 users
- [AppScan Activity Recorder](https://chrome-stats.com/d/appscan-activity-recorder) — 4 users
- [Secret Scanner](https://chrome-stats.com/d/secretscanner) — 35 users
- [ReconLens - Passive Security Scanner](https://chrome-stats.com/d/reconlens) — 1 users
- [YetAnotherBrowserExtension](https://chrome-stats.com/d/yetanotherbrowserextension) — 2 users

---

Source: [Chrome-Stats](https://chrome-stats.com/d/decloak-session-capture)
