Stealth LabsStart a conversation
All portfolio
01 / Insurance·~250-agent life-insurance agency (12 carriers)

Session-Bridge Carrier Scrapers

Carriers offer no APIs, so getting to the truth means replaying the operator's own authenticated sessions. A Manifest V3 Chrome extension captures authenticated carrier sessions, AES-256-GCM-encrypts them, and pushes them to a self-hosted stack where a scraper replays each carrier's internal API server-side to pull the whole book, handling hard auth like gateway tokens, partitioned cookie JWTs, and localStorage tokens.

The problem

No carrier exposes an API, and carrier portals change without warning. Getting real-time book truth means safely capturing and replaying authenticated sessions across twelve very different auth schemes, without ever letting credentials sit in the clear.

What we built
01

Encrypted session capture

The extension captures cookies and hard-to-reach secrets from authenticated carrier sessions and AES-256-GCM-encrypts them before anything leaves the browser.

02

Server-side API replay

The scraper replays each carrier's own internal API server-side to pull the entire book, rather than fragile screen-scraping.

03

Hard-auth coverage

Purpose-built handling for gateway tokens, partitioned cookie JWTs, and localStorage tokens across a dozen carriers.

Outcomes
12
Carriers, 9 scrapers built
~94s
Full-book reconciliation
0
Credentials stored in clear

Have a system like this to build?