How to Use Instagram Cookies in Your Browser and Automation Tools
A cookie file decides whether your first login reads as the account owner coming back or a stranger walking in. Here's how to load one properly, in an antidetect browser and in Playwright or Selenium.
Key Takeaways
- Instagram cookies arrive as Netscape/cookies.txt or JSON. The one that carries the login is sessionid.
- Import the cookie into an isolated browser profile before you open Instagram, then refresh. You should land on the feed already signed in.
- In Playwright, cookies go into the context before you navigate. Selenium needs the domain loaded first, then a refresh.
- Pair the cookie with a proxy in the region the account normally uses. An IP mismatch invalidates sessions fast.
- One account, one environment. Never reuse a cookie across browser profiles or IP addresses.
Your order lands with a password, an email login, and a file full of cookie data. Most buyers open the first two and ignore the third. That file decides whether your first login reads as the account owner coming back, or a stranger walking in.
So here's how to actually use it. Antidetect browsers first, then Playwright and Selenium. In that order.
What Format Does the Cookie Come In?
Two formats cover almost everything you'll run into. Netscape/cookies.txt format is a flat text file, and most automation tools read it natively. JSON format is what browser extensions and newer tools tend to expect. We ship cookies in whichever one plays nicest with mainstream tooling, and every Instagram softreg listing spells out what's bundled: cookie + mail, cookie + 2FA, and so on.
Open the file and find sessionid. That's Instagram's primary session identifier and the line that carries the login. Valid cookie, session nobody has disturbed, and you're authenticated. Everything else in there is supporting cast.
Using Cookies in Antidetect Browsers
Multilogin, AdsPower, Dolphin Anty, GoLogin. They all import cookies, and the sequence barely changes between them:
- Make a fresh browser profile for this account and nothing else
- Attach the dedicated residential or mobile proxy first, before anything loads
- Import the cookie file through the profile's cookie manager, usually buried in profile settings
- Now open the profile and go to instagram.com. You should land on the feed, already signed in
- Never press log out. That kills the session cookie permanently
A login form instead of a feed means the cookie is dead, or something invalidated it. Not a disaster. Use the credentials and the email access to sign in normally, and the fresh session you create becomes your new cookie.
Using Cookies in Playwright
Playwright lets you push cookies into a browser context before the first request ever goes out. That ordering is the whole point:
const context = await browser.newContext();
await context.addCookies([
{
name: 'sessionid',
value: 'YOUR_SESSION_ID_HERE',
domain: '.instagram.com',
path: '/'
}
]);
const page = await context.newPage();
await page.goto('https://www.instagram.com/');
Working from a full JSON cookie file? Parse the whole array and pass all of it rather than cherry-picking the session. Some flows want csrftoken and ds_user_id present as well, and if they're missing you won't get a clean error for it, just a session that half works and then drops you back to the login screen an hour later.
Using Cookies in Selenium
Selenium flips the order on you. It won't accept a cookie for a domain until the driver is already sitting on that domain:
driver.get("https://www.instagram.com/")
for cookie in cookie_list:
driver.add_cookie(cookie)
driver.refresh()
Don't skip the driver.refresh() call. Leave it out and the cookies just sit there while the page keeps showing you a logged-out view.
Common Issues and Fixes
| Issue | Likely cause | Fix |
|---|---|---|
| Login page still showing after cookie import | Cookie expired or invalidated | Sign in fresh, save the new session |
| Verification prompt straight away | IP mismatch or flagged proxy | Move to a cleaner residential proxy |
| Account asks to confirm phone number | Instagram security checkpoint | Handle by hand; use email 2FA if available |
| Session drops after a few hours | Cookie format issue or missing cookies | Import the full cookie set, not just sessionid |
One Rule That Matters Most
One session cookie, one IP address. Ever.
Instagram ties sessions to device and network fingerprints, so the same cookie appearing on two addresses at once reads as exactly what it looks like from outside: a stolen session. And it usually happens through convenience, not carelessness. Someone opens the account on their own laptop for ten seconds, just to confirm the order was fine. That single request from a home connection starts the checkpoint.
One account, one proxy, one browser profile. Keep them married and cookies do their job for months.