MASAKA / Browser / Profiles
Reuse login state,
not secrets.
A profile carries encrypted, account-bound cookies and supported browser storage into a later session.
Profile lifecycle
POST
/api/profilesCreate a named profileGET
/api/profilesList owned metadataDELETE
/api/profiles/:idDelete and queue storage cleanupAttach a profile with profile_id at session creation. Current retained login state expires after 24 hours.
Capture and restore
- 1Launch with the profile
The worker restores native and portable state before task navigation.
- 2Complete human login if required
Credentials never enter the model prompt.
- 3Stop normally
The worker captures changed cookie and storage state before settlement.
Security properties
- Profiles are account-owned and project references are checked.
- List APIs never return archive bytes.
- Portable state is restored only at its saved origin.
- Authoritative empty state can delete stale storage from an older archive.