Web cookie providers
Copy the correct browser session value, check provider support, and recover expired sessions.
A web cookie provider reuses the session your browser already has with a chat website. There is no API key. You copy the cookie the site sets after you sign in, paste it into DurinDoor, and DurinDoor sends it the way the web app would.
On Providers, web-session connections have their own group. Some cards can store credentials before their request executor is available; check the supported status below before configuring a client.
A session cookie is a full login for that account. Anyone who can send requests through your gateway can spend that session. Keep cookie providers on a personal install, or put them behind scoped DurinDoor keys. See API key scoping.
Sign in from the dashboard
For Grok Web (grok-web), Perplexity Web (perplexity-web), ChatGPT Web (chatgpt-web), HuggingChat (huggingchat), and Muse Spark Web (muse-spark-web), the Add dialog offers Sign in in-page alongside manual cookie paste.
Sign in inside the embedded page, or choose Open in popup if embedding fails. Each popup receives a fresh, one-time bootstrap grant for the same login session; it does not reuse the iframe's grant. The dashboard polls every two seconds and displays captured cookie names, never their values. Once the session is ready, enter a connection name and choose Save connection. Cancel, closing the modal, or leaving the page discards the login session. Sessions expire after 15 minutes. Signing in does not add an executor for a provider that is not yet runnable.
Saving rechecks the exact provider/operator-bound session after readiness and immediately before the database commit. Cancellation, expiry, or a replacement login before that commit prevents an in-flight save from storing cookies.
Isolated login origin
The operator must configure DURINDOOR_WEB_LOGIN_ORIGIN, for example https://login.gateway.example, and route that hostname to the same DurinDoor server. Use a dedicated hostname different from the dashboard's hostname: a different port alone does not isolate cookies. The flow fails closed if the origin is missing, invalid, or shares the dashboard cookie hostname; there is no same-origin fallback.
The dedicated origin keeps login cookies separate from dashboard authentication and serves only sign-in traffic. Use HTTPS. If browser cookie rules or a provider login block the embedded page, use the popup or manual paste. MiMo keeps its existing login flow.
Cloudflare Turnstile, Google SSO, third-party cookies, cross-origin redirects, or other site protections may reject reverse-proxied login, including in a popup. Use manual cookie paste in that case. The flow captures upstream HTTP cookies, not localStorage tokens; only the five providers listed above support this dashboard login. Cookie capture and readiness are not a guarantee that the provider will accept every later chat request.
Copy the cookie
Copy from a live request, not from the cookie storage view. The storage view can show stale values, and it can miss cookies the site only sends on signed-in requests.
Sign in to the site in a normal browser window and open a chat so the session is active.
Open developer tools, then the Network tab. Reload the page and click a request to the site's own domain.
Under Request Headers, copy the Cookie value. Some providers only want one named cookie from that header; the table below says which.
In DurinDoor open Providers, pick the cookie provider, and click Add. The field is labelled Cookie Value. The hint under it is the provider's authHint.
Paste and save. Model chat probes for web-cookie LLM providers are skipped and shown as "Skipped", not failed. Validate and Test Connection also skip grok-web, copilot-web and zenmux-free: their chat endpoints create a real conversation per probe, risking account restrictions . Saving or editing those cookies leaves connection status unknown until a real request runs; batch results count skips separately from passes. ZenMux still checks for ctoken locally before skipping. perplexity-web uses a read-only session check.
You can paste the whole header or just the value. DurinDoor strips a leading Cookie: or Bearer , and pulls a single named cookie out of a full header when the provider only needs one.
The field is plain text, not a password field, so the cookie is visible on screen while you type. Once saved, the value is stored in the connection's encrypted apiKey column like any other secret.
What each provider expects
| Provider | Id | Paste |
|---|---|---|
| Grok Web | grok-web | The sso= cookie value (the prefix is optional) |
| Perplexity Web | perplexity-web | The __Secure-next-auth.session-token value; chunked .0, .1 cookies are accepted |
| Copilot Web | copilot-web | An access_token, or a HAR from a signed-in browser |
| Microsoft 365 Copilot Web | copilot-m365-web | The chathub WebSocket path and access_token |
| ZenMux Free | zenmux-free | The full Cookie header; it must include ctoken= |
| Kimi Web | kimi-web | Not a cookie: access_token and refresh_token JSON from localStorage, copied with the dialog's console snippet. See Kimi Web |
| ChatGPT Web | chatgpt-web | The whole Cookie header from a chatgpt.com request, or the __Secure-next-auth.session-token value. Chunked .0, .1 cookies are accepted |
| HuggingChat | huggingchat | The full Cookie header from huggingface.co/chat |
| T3 Chat Web | t3-web | convex-session-id plus the Cookie header |
| Muse Spark Web | muse-spark-web | The ecto_1_sess value or the full header from meta.ai |
| Adapta Web | adapta-web | The __client cookie from agent.adapta.one |
| Tencent Yuanbao Web | yuanbao-web | The Yuanbao session cookie |
| Suno | suno | The Suno session cookie |
| Udio | udio | The Udio session cookie |
Chunked session cookies
chatgpt.com and perplexity.ai keep their session in a NextAuth cookie, __Secure-next-auth.session-token. When the session grows past about 4KB, NextAuth splits it into __Secure-next-auth.session-token.0, .1, and so on, each holding a different part. Copy every chunk: pasting the whole Cookie header from the Network tab is the easy way. DurinDoor sends the chunks back under their own names in index order, never joined into one value, and drops a stale unchunked cookie if the header has both. Other cookies in the paste, such as cf_clearance, are kept.
These cookies are HttpOnly, so no page script can read them. For ChatGPT Web the add dialog also offers a console snippet that prompts for each chunk value you copy from Application, Cookies, and puts the joined name=value string on your clipboard.
Some of these ids exist in the registry before their executor does. A request to one of them returns HTTP 501 with type: "provider_port_pending" and names the missing piece. In this build that covers adapta-web, huggingchat, muse-spark-web, suno, t3-web, udio, and yuanbao-web. ChatGPT Web has a working browser transport with an HTTP fallback; see its setup guide. See Hidden and retired providers for unsupported entries. You can save a connection for them, but no request will run until the executor ships.
Validation
Validate posts to /api/providers/validate with a 10 second limit. Grok Web, Copilot Web and ZenMux Free skip network validation rather than creating a conversation; this does not prove the cookie works. ZenMux Free still rejects a pasted cookie missing ctoken locally. Perplexity Web and ChatGPT Web use read-only session requests; an expired or incomplete ChatGPT Web cookie (such as a missing .1 chunk) fails with a message asking for every chunk. Microsoft 365 Copilot Web checks that both fields are present. Kimi Web calls the site's model list endpoint with the access token. A provider with no probe answers Provider validation not supported.
A passing probe means the site accepted the cookie at that moment. It does not keep the session alive.
Limits
- Tool calling is usually off. Kimi Web, for example, declares
tools: falsefor every model. Use an API or OAuth provider when your client needs tools. - The model list is whatever the registry declares for that site, and the site can change or drop models without notice.
- These providers do not report quota to the Quota Tracker, except Grok Web, which has a usage fetcher but no preflight config.
When the session ends
Most cookie sessions have no proactive refresh or expiry tracking. ChatGPT Web can save cookies rotated by the site, but rotation does not prevent expiry or revocation. The temporary dashboard-login jar discards expired cookies before saving. Kimi Web is the exception: with a refresh token in the paste, it renews its access token on a 401 (see Kimi Web). A 401 or 403 from upstream puts that connection on the normal two minute cooldown and the request moves to the next connection or combo member. The connection stays active, so the same rejection repeats after the cooldown.
If automatic recovery fails, sign in to the site again, copy a fresh cookie, and paste it over the old one with Edit. Signing out of the site in your browser usually kills the session DurinDoor holds too.
Keep one browser profile for the account you hand to DurinDoor, and avoid signing out of it.
After saving a supported session, send one short request and check Usage. A skipped validation is not a successful probe. HTTP 501 provider_port_pending means no credential change can enable that provider in this build.