Aar318's Session Vault by Aar318
Session Vault lets a user manually save multiple named login-session snapshots for a website, restore a selected snapshot, clear the current local session for re-authentication, and import or export vault data.
Available on Firefox for Android™Available on Firefox for Android™
Scan the QR code to open this extension in Firefox for Android
Extension Metadata
Screenshots
About this extension
Aar318's Session Vault
Save multiple named login sessions for a website and load them from one compact toolbar vault. Session Vault is designed for people who regularly move among personal, work, family, test, or media-service accounts without maintaining a separate browser profile for every account.
Getting Started
Key Features
New Features (v1.0.0.5)
Permissions
Privacy and Security
Session Vault has no analytics, advertising, telemetry, remote code, or automatic network service. Vault data remains in the local browser profile unless you explicitly export it. Ko-fi and Donate open only when selected.
Saved sessions are credentials: anyone with access to them may gain access to the associated accounts. Optional master-password protection encrypts saved profile records at rest and relocks the vault after the configured timer; index metadata and settings remain visible. Without it, extension storage is not passphrase-encrypted at rest. Profile exports offer AES-GCM protection and enable it by default; treat every unencrypted export like a password.
Limitations
Session Vault captures cookies, localStorage, and sessionStorage. It does not capture IndexedDB, Cache Storage, service-worker state, passkeys, device-bound tokens, HTTP authentication, or server-side session state. Some services may invalidate restored sessions or require re-authentication, especially after password, security, device, or location changes. Selecting Sign out on a website can revoke the saved token on its server, which local restoration cannot undo. Profiles are isolated by exact website origin, so related subdomains may need separate profiles. Parent-domain cookies applicable to the saved host retain their cookie scope; web storage remains specific to the saved origin.
Save multiple named login sessions for a website and load them from one compact toolbar vault. Session Vault is designed for people who regularly move among personal, work, family, test, or media-service accounts without maintaining a separate browser profile for every account.
Getting Started
- Pin Session Vault to the browser toolbar.
- Open a supported website and sign in to an account.
- Select Session Vault, choose Save current, and name the profile.
- Use Re-auth to clear the current session locally, sign in to another account, and save it as another profile. Avoid the site's own Sign out command because it may revoke the saved token server-side.
- Select Load on a saved profile. The current site session is replaced and the tab reloads.
Key Features
- Multiple Profiles Per Site: Save, name, annotate, color-label, update, rename, export, and delete multiple sessions for each website origin.
- Complete Session Capture: Capture cookies, including HttpOnly cookies, plus selected localStorage and sessionStorage data.
- Fast Account Switching: Replace the active site's cookies and selected web storage, then reload to apply the chosen profile.
- Safe Re-authentication: Clear the site's local session without invoking its normal sign-out flow, then reload and sign in again when adding another account.
- Manual-Only Profiles: Every completed capture creates exactly one profile. Loading and re-authentication never create automatic profiles or backups.
- Global Session Manager: Use a grouped, collapsible All Sites overview with search, alphabetical website groups, and favorites-first sorting within each site to manage sessions from every saved website.
- Clean Transfer Workflows: Automatically preview profile names, websites, site count, profile count, estimated size, encryption status, and complete-vault master-lock state before export. Imports restore valid included preferences and automatically show what will be added, updated, or skipped before a single Import click changes the vault.
- Verified Encrypted Backups: Export one profile, the current site, the active profile, or the complete vault. All Sites exports refresh directly from current vault storage, verify every selected profile, and decrypt protected output in memory before downloading. Encrypted complete-vault backups can also preserve and restore enabled master-password protection. Exports use unique timestamps and offer AES-GCM protection with a four-character passphrase or PIN minimum.
- Password Tools: Generate ambiguity-free random characters or memorable real-word combinations, then preview, refresh, reveal, copy, and apply the result with clear password controls.
- Controlled Import: See exactly which profiles will be added, updated, or skipped before restoring, with origin, cookie, schema, and size validation plus visible success or failure feedback.
- Duplicate Protection: Optionally prevent exact duplicate captures and skip duplicate sessions during normal restore. Choose Overwrite existing IDs to replace same-origin matches, or Always add as new to keep copies.
- Optional Timed Vault Lock: Encrypt saved profile records at rest and require the master password to unlock the vault temporarily. Choose a 15-minute, 30-minute, 1-hour, 4-hour, or 8-hour timer; one hour is the default. Each protected export can use the unlocked master password without displaying it, or use a separate generated/custom password. Complete-vault restore safely reapplies the backed-up lock state to every resulting profile.
- Safer Changes: Load confirmations are enabled by default and can be replaced with optional One-click Load. Separate confirmations protect overwrites and other destructive actions. Imported and restored profiles remain locked to their exact website origin.
- Complete Settings Tools: Export, import, reset, or clear settings separately from saved profiles.
- Personalized Interface: Choose dark, light, or system appearance plus Emerald, Blue, Purple, Amber, or Rose accents.
- Accessible Controls and Shortcuts: Use the toolbar action, Alt+Shift+V, or right-click commands for opening, saving, re-authentication, Ko-fi, and Donate. Responsive, keyboard-accessible controls include explanatory tooltips, a fully visible title with the active website shown compactly on its right, and consistent project-icon branding throughout Profiles, Settings, and About.
- Site-Access Recovery: Session actions request access only for the active website when needed. Settings also provides an explicit one-time option to approve ordinary websites together.
New Features (v1.0.0.5)
- Improvement: Request current-site access only when Save, Load, Update, or Re-auth needs it, while leaving profile management and settings available without repeated prompts.
- New Feature: Add an explicit Settings action to approve ordinary websites together when preferred.
- Bug Fix: Keep individual-profile export available in the toolbar when the active page cannot host the larger persistent export view.
Permissions
- Cookies: Reads, creates, and removes cookies only to capture, restore, or clear sessions at your request.
- Website Access: Allows session work on the website open in the active tab and supports cookies belonging to that site.
- Access Requests: Missing access is requested only from an explicit session action or the optional all-websites Settings command; ordinary page loads never trigger a prompt.
- Scripting: Reads and restores localStorage and sessionStorage in the active tab after the user opens or invokes the extension.
- Storage: Keeps settings and saved session profiles inside the local browser profile.
- Context Menus: Adds user-invoked toolbar-menu shortcuts and support links.
Privacy and Security
Session Vault has no analytics, advertising, telemetry, remote code, or automatic network service. Vault data remains in the local browser profile unless you explicitly export it. Ko-fi and Donate open only when selected.
Saved sessions are credentials: anyone with access to them may gain access to the associated accounts. Optional master-password protection encrypts saved profile records at rest and relocks the vault after the configured timer; index metadata and settings remain visible. Without it, extension storage is not passphrase-encrypted at rest. Profile exports offer AES-GCM protection and enable it by default; treat every unencrypted export like a password.
- Privacy policy: https://gist.github.com/aar318/9d4fc167a12546f162bcef3b91322aad
Limitations
Session Vault captures cookies, localStorage, and sessionStorage. It does not capture IndexedDB, Cache Storage, service-worker state, passkeys, device-bound tokens, HTTP authentication, or server-side session state. Some services may invalidate restored sessions or require re-authentication, especially after password, security, device, or location changes. Selecting Sign out on a website can revoke the saved token on its server, which local restoration cannot undo. Profiles are isolated by exact website origin, so related subdomains may need separate profiles. Parent-domain cookies applicable to the saved host retain their cookie scope; web storage remains specific to the saved origin.
Rated 5 by 1 reviewer
Permissions and data
Optional permissions:
- Access your data for all websites
Data collection:
- The developer says this extension doesn't require data collection.
More information
- Add-on Links
- Version
- 1.0.0.5
- Size
- 94.86 KB
- Last updated
- 13 days ago (Sep 14, 2026)
- Related Categories
- License
- MIT License
- Privacy Policy
- Read the privacy policy for this add-on
- Version History
- Add to collection