NVX Session
Install
Per-tab sessions for Chrome

Every account, its own tab.

Signed into work and personal Google in one window, the browser quietly treats one as /u/0, and work links start opening as your personal address. Give each account a session where it is the only account, and there is no default left to get wrong.

~0 MB
memory per session
Unlimited
sessions, free
GPL-3.0
open source
6
browsers, Opera GX included
What it is for

Multiple accounts on the same site, in one window

Containers for Chrome, in practice: each tab carries its own session, so two accounts on one site never see each other.

Work and personal Google

Keep both signed in without the /u/0 wrong-account trap.

Google numbers your accounts in the order you signed in, and a shared link opens as /u/0, whichever account that happens to be. Inside a session the work account is the only one there, so a work link opens as work.
Testing roles

Test a site as admin, user and guest at the same time.

Give each role its own session and its own tab colour, sign in once per role, and watch a permission change land in all three without logging out and back in.
Coming from SessionBox

If your SessionBox extension stopped working, here is how this one differs.

Moving from SessionBox
Trust

What you are installing

An extension that touches every site you put in a session should be checkable. These are the commitments, and each one can be verified.

Read the source
  1. 01

    Open source

    The free extension is GPL-3.0 and public. The code this site describes is the code that ships: github.com/Envxsion/nvx_session.

  2. 02

    No remote code

    Everything it runs is inside the package. It never downloads code to run later, so what the Web Store reviews is what runs in your browser.

  3. 03

    No account

    There is nothing to sign up for. The free extension needs no account at all, and Pro is a licence key you paste in, not a login.

  4. 04

    Not for sale

    Popular extensions get offers from buyers who then ship tracking or ads in an update. This one will never change hands.

  5. 05

    What leaves your machine

    No browsing data. The full list of network calls:

    • Anonymous usage stats, off by default, sent only if you turn them on.
    • Favicon fetches for the sites in your own sessions, sent without cookies.
    • Pro only: the licence check (your key, a random device id and a label such as “Windows, Chrome”), and encrypted sync if you turn it on.
How it compares

What you get free here, and what it costs elsewhere.

Five alternatives, checked against their published plans and their own documentation. Every row below is included free in NVX Session; the marks show which of the others charge for it, do it partly, or do not do it.

25/25

NVX Session covers every capability below, free. The closest alternative, Firefox Containers, fully covers 13. On 11 of them, none of the five has it in full.

  1. NVX Session25/25
  2. Firefox Containers13/25
  3. SessionBox3/25
  4. Ghost Browser4/25
  5. Multi-profile browsers4/25
  6. Chrome profiles6/25
  • NVX has it, free
  • They have it too
  • Partly
  • Paid plans only
  • Does not
  • Not applicable
NVX Session against five alternatives, capability by capability.
CapabilityNVX Session25/25Firefox Containers13/25SessionBox3/25Ghost Browser4/25Multi-profile browsers4/25Chrome profiles6/25
How it separates accounts5
The mechanism decides everything downstream. Swapping a shared cookie jar has a window where requests are already in flight under the old identity; rewriting the request does not.
MechanismAhead of 1 of 5Yes (Yes, included)Rewrites the outgoing Cookie header per tab. The browser jar is bypassed, never swappedYes (Yes)Origin attributes inside the storage enginePartly (Partly)Swaps the one real cookie jar per tabYes (Yes)A separate Chromium profile per identityYes (Yes)A patched browser instance per profileYes (Yes)An OS-level browser profile
Many tabs loading at onceAhead of 1 of 5Yes (Yes, included)Rules are matched in C++ per request, so every tab is correct simultaneouslyYes (Yes)Engine levelNo (No)A swap can only be right for one tab at a time; background tabs desyncYes (Yes)Separate profilesYes (Yes)Separate instancesYes (Yes)Separate profiles
Leaves your real cookie jar untouchedAhead of 1 of 5Yes (Yes, included)Cookies are copied into a private vault, never moved or deletedYes (Yes)Separate storageNo (No)Writes into the real profile jarYes (Yes)Separate profileYes (Yes)Separate profileYes (Yes)Separate profile
localStorage and sessionStorageAhead of 1 of 5Yes (Yes, included)Virtualised per session by a content-script shimYes (Yes)Partitioned by origin attributesNo (No)Shared across sessionsYes (Yes)Profile levelYes (Yes)Profile levelYes (Yes)Profile level
Half-finished sign-in protectionAhead of 1 of 5Yes (Yes, included)A loop detector releases the site, because a partial cookie set reads as a hijackn/a (Not applicable)No swap to go wrongNo (No)Nonen/a (Not applicable)n/a (Not applicable)n/a (Not applicable)
What it costs you to run5
An identity in a multi-profile browser is a whole browser process. Here it is a tab.
Memory per identityAhead of 3 of 5Yes (Yes, included)About 0 MB. It is a rule, not a processYes (Yes)About 0 MBYes (Yes)LowPartly (Partly)ModerateNo (No)300 to 800 MB, per profileNo (No)About 250 MB, per profile
Cost of adding one more identityAhead of 3 of 5Yes (Yes, included)A tabYes (Yes)A tabYes (Yes)A tabPartly (Partly)A profileNo (No)A whole browser instanceNo (No)A window and a profile
How many at onceAhead of 4 of 5Yes (Yes, included)Hundreds. Measured, bounded by a 5,000 rule budgetYes (Yes)HighPartly (Partly)ModeratePartly (Partly)Bounded by memoryNo (No)Bounded by memory, expensivelyNo (No)Bounded by memory
Stays in the browser you already useAhead of 4 of 5Yes (Yes, included)Chrome, Edge, Brave, Vivaldi, Arc, Opera GXPartly (Partly)Only if you already live in FirefoxYes (Yes)ChromiumNo (No)A different browserNo (No)A different browserPartly (Partly)Separate windows
Opera GXAhead of 4 of 5Yes (Yes, included)A first-class target with its own MV2 backend. Nobody else does thisNo (No)No (No)No (No)No (No)n/a (Not applicable)
Whether you can trust it3
Isolating cookies on every site needs access to every site, so the permission list cannot be the proof. What can be checked is the code, which is open source: no remote code, no account, and a short, published list of what it sends.
Keeps your browsing data on your machineAhead of 4 of 5Yes (Yes, included)Yes. Network calls are opt-in stats, cookie-free favicon fetches, and with Pro the licence check and opt-in encrypted syncYes (Yes)YesNo (No)Cloud profiles are stored on its serversPartly (Partly)LocalNo (No)Cloud connected by designPartly (Partly)Unless browser sync is on
Analytics you can read in fullAhead of 4 of 5Yes (Yes, included)Opt in, anonymous, a closed allowlist with no free-form field, erasableYes (Yes)None collectedNo (No)Vendor definedNo (No)Vendor definedNo (No)Vendor definedPartly (Partly)Browser vendor
States its own limits in publicAhead of 3 of 5Yes (Yes, included)Named on this page and on the Pro page, including the ones it losesn/a (Not applicable)No (No)No (No)No (No)n/a (Not applicable)
Living with it every day6
The parts you touch constantly, which is usually what decides whether a tool survives a week.
Tabs coloured by identityAhead of 3 of 5Yes (Yes, included)Per session, at a glanceYes (Yes)Container coloursPartly (Partly)Partly (Partly)n/a (Not applicable)One identity per windowNo (No)
Move several tabs at once, and undo itAhead of 4 of 5Yes (Yes, included)One guarded operation, so nothing leaks mid-moveNo (No)No (No)No (No)n/a (Not applicable)No (No)
Keyboard shortcut to move a tabAhead of 4 of 5Yes (Yes, included)Alt and 1 to 3No (No)No (No)No (No)n/a (Not applicable)No (No)
Right-click a link into an identityAhead of 3 of 5Yes (Yes, included)Yes (Yes)Open in containerPartly (Partly)No (No)n/a (Not applicable)No (No)
Tells you which account a site thinks is defaultAhead of 4 of 5Yes (Yes, included)The whole reason the product existsNo (No)No (No)No (No)n/a (Not applicable)No (No)
Turn it off without uninstallingAhead of 1 of 5Yes (Yes, included)One switch, behaves exactly as if it were not installedn/a (Not applicable)No (No)n/a (Not applicable)n/a (Not applicable)n/a (Not applicable)
Fingerprinting, and what it costs to get it4
This is the row where the money usually is. SessionBox puts fingerprint protection on its $21.99 a month plan. Multi-profile browsers are subscription-only and start higher. Here Mirror and Standardize are free, and Persona is part of Pro.
Fingerprint control at allOnly NVXYes (Yes, included)Mirror and Standardize free, no account, no limit. Persona is ProNo (No)None. Containers separate storage, not identityPaid (Only on a paid plan)Professional plan, $21.99 a monthPartly (Partly)MinimalPaid (Only on a paid plan)Subscription only, the deepest availableNo (No)None
Checks the disguise is coherentAhead of 3 of 5Yes (Yes, included)A consistency validator. Incoherence is what flags you, not similarityn/a (Not applicable)No (No)Lets you build a machine that contradicts itselfNo (No)Partly (Partly)Vendor managed, not shown to youn/a (Not applicable)
A default that fabricates nothingAhead of 3 of 5Yes (Yes, included)Mirror ships as the default: real fingerprint, only storage partitionedn/a (Not applicable)No (No)No (No)No (No)Fabrication is the productn/a (Not applicable)
Tells you what each setting costs your detectabilityAhead of 4 of 5Yes (Yes, included)A generated manual inside the extensionNo (No)Docs onlyNo (No)Docs onlyNo (No)Docs onlyPartly (Partly)Partlyn/a (Not applicable)
Price2
Unlimited sessions, free, is the shipped product. Nothing here is metered on how many accounts you have.
Cost to use it properlyAhead of 3 of 5Yes (Yes, included)Free. Unlimited sessions, with Mirror and Standardize includedYes (Yes)FreePaid (Only on a paid plan)Free tier is local profiles only. $4.99 to $44.99 a monthPaid (Only on a paid plan)Limited free, then subscriptionPaid (Only on a paid plan)Subscription only, the most expensive categoryYes (Yes)Free
Metered on how many identities you haveAhead of 3 of 5Yes (Yes, included)No, and it never will beYes (Yes)NoNo (No)Yes, cloud profiles are capped by planNo (No)YesNo (No)Yes, this is the pricing modelYes (Yes)No
Against

How it separates accounts5

The mechanism decides everything downstream. Swapping a shared cookie jar has a window where requests are already in flight under the old identity; rewriting the request does not.

Mechanism

Ahead of 1 of 5
NVX SessionYes (Yes, included)Rewrites the outgoing Cookie header per tab. The browser jar is bypassed, never swapped
  • Firefox ContainersYes (Yes)Origin attributes inside the storage engine
  • SessionBoxPartly (Partly)Swaps the one real cookie jar per tab
  • Ghost BrowserYes (Yes)A separate Chromium profile per identity
  • Multi-profile browsersYes (Yes)A patched browser instance per profile
  • Chrome profilesYes (Yes)An OS-level browser profile

Many tabs loading at once

Ahead of 1 of 5
NVX SessionYes (Yes, included)Rules are matched in C++ per request, so every tab is correct simultaneously
  • Firefox ContainersYes (Yes)Engine level
  • SessionBoxNo (No)A swap can only be right for one tab at a time; background tabs desync
  • Ghost BrowserYes (Yes)Separate profiles
  • Multi-profile browsersYes (Yes)Separate instances
  • Chrome profilesYes (Yes)Separate profiles

Leaves your real cookie jar untouched

Ahead of 1 of 5
NVX SessionYes (Yes, included)Cookies are copied into a private vault, never moved or deleted
  • Firefox ContainersYes (Yes)Separate storage
  • SessionBoxNo (No)Writes into the real profile jar
  • Ghost BrowserYes (Yes)Separate profile
  • Multi-profile browsersYes (Yes)Separate profile
  • Chrome profilesYes (Yes)Separate profile

localStorage and sessionStorage

Ahead of 1 of 5
NVX SessionYes (Yes, included)Virtualised per session by a content-script shim
  • Firefox ContainersYes (Yes)Partitioned by origin attributes
  • SessionBoxNo (No)Shared across sessions
  • Ghost BrowserYes (Yes)Profile level
  • Multi-profile browsersYes (Yes)Profile level
  • Chrome profilesYes (Yes)Profile level

Half-finished sign-in protection

Ahead of 1 of 5
NVX SessionYes (Yes, included)A loop detector releases the site, because a partial cookie set reads as a hijack
  • Firefox Containersn/a (Not applicable)No swap to go wrong
  • SessionBoxNo (No)None
  • Ghost Browsern/a (Not applicable)
  • Multi-profile browsersn/a (Not applicable)
  • Chrome profilesn/a (Not applicable)

What it costs you to run5

An identity in a multi-profile browser is a whole browser process. Here it is a tab.

Memory per identity

Ahead of 3 of 5
NVX SessionYes (Yes, included)About 0 MB. It is a rule, not a process
  • Firefox ContainersYes (Yes)About 0 MB
  • SessionBoxYes (Yes)Low
  • Ghost BrowserPartly (Partly)Moderate
  • Multi-profile browsersNo (No)300 to 800 MB, per profile
  • Chrome profilesNo (No)About 250 MB, per profile

Cost of adding one more identity

Ahead of 3 of 5
NVX SessionYes (Yes, included)A tab
  • Firefox ContainersYes (Yes)A tab
  • SessionBoxYes (Yes)A tab
  • Ghost BrowserPartly (Partly)A profile
  • Multi-profile browsersNo (No)A whole browser instance
  • Chrome profilesNo (No)A window and a profile

How many at once

Ahead of 4 of 5
NVX SessionYes (Yes, included)Hundreds. Measured, bounded by a 5,000 rule budget
  • Firefox ContainersYes (Yes)High
  • SessionBoxPartly (Partly)Moderate
  • Ghost BrowserPartly (Partly)Bounded by memory
  • Multi-profile browsersNo (No)Bounded by memory, expensively
  • Chrome profilesNo (No)Bounded by memory

Stays in the browser you already use

Ahead of 4 of 5
NVX SessionYes (Yes, included)Chrome, Edge, Brave, Vivaldi, Arc, Opera GX
  • Firefox ContainersPartly (Partly)Only if you already live in Firefox
  • SessionBoxYes (Yes)Chromium
  • Ghost BrowserNo (No)A different browser
  • Multi-profile browsersNo (No)A different browser
  • Chrome profilesPartly (Partly)Separate windows

Opera GX

Ahead of 4 of 5
NVX SessionYes (Yes, included)A first-class target with its own MV2 backend. Nobody else does this
  • Firefox ContainersNo (No)
  • SessionBoxNo (No)
  • Ghost BrowserNo (No)
  • Multi-profile browsersNo (No)
  • Chrome profilesn/a (Not applicable)

Whether you can trust it3

Isolating cookies on every site needs access to every site, so the permission list cannot be the proof. What can be checked is the code, which is open source: no remote code, no account, and a short, published list of what it sends.

Keeps your browsing data on your machine

Ahead of 4 of 5
NVX SessionYes (Yes, included)Yes. Network calls are opt-in stats, cookie-free favicon fetches, and with Pro the licence check and opt-in encrypted sync
  • Firefox ContainersYes (Yes)Yes
  • SessionBoxNo (No)Cloud profiles are stored on its servers
  • Ghost BrowserPartly (Partly)Local
  • Multi-profile browsersNo (No)Cloud connected by design
  • Chrome profilesPartly (Partly)Unless browser sync is on

Analytics you can read in full

Ahead of 4 of 5
NVX SessionYes (Yes, included)Opt in, anonymous, a closed allowlist with no free-form field, erasable
  • Firefox ContainersYes (Yes)None collected
  • SessionBoxNo (No)Vendor defined
  • Ghost BrowserNo (No)Vendor defined
  • Multi-profile browsersNo (No)Vendor defined
  • Chrome profilesPartly (Partly)Browser vendor

States its own limits in public

Ahead of 3 of 5
NVX SessionYes (Yes, included)Named on this page and on the Pro page, including the ones it loses
  • Firefox Containersn/a (Not applicable)
  • SessionBoxNo (No)
  • Ghost BrowserNo (No)
  • Multi-profile browsersNo (No)
  • Chrome profilesn/a (Not applicable)

Living with it every day6

The parts you touch constantly, which is usually what decides whether a tool survives a week.

Tabs coloured by identity

Ahead of 3 of 5
NVX SessionYes (Yes, included)Per session, at a glance
  • Firefox ContainersYes (Yes)Container colours
  • SessionBoxPartly (Partly)
  • Ghost BrowserPartly (Partly)
  • Multi-profile browsersn/a (Not applicable)One identity per window
  • Chrome profilesNo (No)

Move several tabs at once, and undo it

Ahead of 4 of 5
NVX SessionYes (Yes, included)One guarded operation, so nothing leaks mid-move
  • Firefox ContainersNo (No)
  • SessionBoxNo (No)
  • Ghost BrowserNo (No)
  • Multi-profile browsersn/a (Not applicable)
  • Chrome profilesNo (No)

Keyboard shortcut to move a tab

Ahead of 4 of 5
NVX SessionYes (Yes, included)Alt and 1 to 3
  • Firefox ContainersNo (No)
  • SessionBoxNo (No)
  • Ghost BrowserNo (No)
  • Multi-profile browsersn/a (Not applicable)
  • Chrome profilesNo (No)

Right-click a link into an identity

Ahead of 3 of 5
NVX SessionYes (Yes, included)
  • Firefox ContainersYes (Yes)Open in container
  • SessionBoxPartly (Partly)
  • Ghost BrowserNo (No)
  • Multi-profile browsersn/a (Not applicable)
  • Chrome profilesNo (No)

Tells you which account a site thinks is default

Ahead of 4 of 5
NVX SessionYes (Yes, included)The whole reason the product exists
  • Firefox ContainersNo (No)
  • SessionBoxNo (No)
  • Ghost BrowserNo (No)
  • Multi-profile browsersn/a (Not applicable)
  • Chrome profilesNo (No)

Turn it off without uninstalling

Ahead of 1 of 5
NVX SessionYes (Yes, included)One switch, behaves exactly as if it were not installed
  • Firefox Containersn/a (Not applicable)
  • SessionBoxNo (No)
  • Ghost Browsern/a (Not applicable)
  • Multi-profile browsersn/a (Not applicable)
  • Chrome profilesn/a (Not applicable)

Fingerprinting, and what it costs to get it4

This is the row where the money usually is. SessionBox puts fingerprint protection on its $21.99 a month plan. Multi-profile browsers are subscription-only and start higher. Here Mirror and Standardize are free, and Persona is part of Pro.

Fingerprint control at all

Only NVX
NVX SessionYes (Yes, included)Mirror and Standardize free, no account, no limit. Persona is Pro
  • Firefox ContainersNo (No)None. Containers separate storage, not identity
  • SessionBoxPaid (Only on a paid plan)Professional plan, $21.99 a month
  • Ghost BrowserPartly (Partly)Minimal
  • Multi-profile browsersPaid (Only on a paid plan)Subscription only, the deepest available
  • Chrome profilesNo (No)None

Checks the disguise is coherent

Ahead of 3 of 5
NVX SessionYes (Yes, included)A consistency validator. Incoherence is what flags you, not similarity
  • Firefox Containersn/a (Not applicable)
  • SessionBoxNo (No)Lets you build a machine that contradicts itself
  • Ghost BrowserNo (No)
  • Multi-profile browsersPartly (Partly)Vendor managed, not shown to you
  • Chrome profilesn/a (Not applicable)

A default that fabricates nothing

Ahead of 3 of 5
NVX SessionYes (Yes, included)Mirror ships as the default: real fingerprint, only storage partitioned
  • Firefox Containersn/a (Not applicable)
  • SessionBoxNo (No)
  • Ghost BrowserNo (No)
  • Multi-profile browsersNo (No)Fabrication is the product
  • Chrome profilesn/a (Not applicable)

Tells you what each setting costs your detectability

Ahead of 4 of 5
NVX SessionYes (Yes, included)A generated manual inside the extension
  • Firefox ContainersNo (No)Docs only
  • SessionBoxNo (No)Docs only
  • Ghost BrowserNo (No)Docs only
  • Multi-profile browsersPartly (Partly)Partly
  • Chrome profilesn/a (Not applicable)

Price2

Unlimited sessions, free, is the shipped product. Nothing here is metered on how many accounts you have.

Cost to use it properly

Ahead of 3 of 5
NVX SessionYes (Yes, included)Free. Unlimited sessions, with Mirror and Standardize included
  • Firefox ContainersYes (Yes)Free
  • SessionBoxPaid (Only on a paid plan)Free tier is local profiles only. $4.99 to $44.99 a month
  • Ghost BrowserPaid (Only on a paid plan)Limited free, then subscription
  • Multi-profile browsersPaid (Only on a paid plan)Subscription only, the most expensive category
  • Chrome profilesYes (Yes)Free

Metered on how many identities you have

Ahead of 3 of 5
NVX SessionYes (Yes, included)No, and it never will be
  • Firefox ContainersYes (Yes)No
  • SessionBoxNo (No)Yes, cloud profiles are capped by plan
  • Ghost BrowserNo (No)Yes
  • Multi-profile browsersNo (No)Yes, this is the pricing model
  • Chrome profilesYes (Yes)No

Competitor capabilities from their own documentation, pricing from published plans, August 2026. NVX Session has real limits too, and they are named on this page rather than hidden: see the questions below and the Pro page.

The default account trap

Why the wrong account opens

A browser keeps one cookie jar per profile, and a site can only treat one account in it as the default. Every link you open resolves against that choice, which is how a work document ends up opening as your personal address without anything warning you.

One shared jarAny browser, no extension
Work doc
Personal mail
Client admin
One jarenvxsion@personal

Every tab resolves to whichever account is default. The work doc opens as personal.

A jar per tabWith NVX Session
Work doc
Personal mail
Client admin
envxsion@work
envxsion@personal
ops@client

Each tab resolves to its own account. There is no default left to get wrong.

How it works

Three steps, nothing deleted

01Isolate

Each tab gets its own cookie jar.

Identity is substituted request-side, through declarative rule bands, rather than by swapping the browser's cookie jar in and out. A swap has a window in which some requests are already in flight under the old identity. Rules do not: every request is resolved against the rule that is live when it leaves.
02Sign in fresh

Put an account in a session by signing in there, so it is the only account and therefore the default.

The tab is bound and its rules are live before the first request leaves. That ordering is the point: a federated provider never sees a half-finished login, which is the state they punish hardest.
03Switch

Switch accounts by switching sessions.

Identity is per tab and resolved per request, so there is no account menu to fight and no global default to lose track of.

Throughout, cookies are copied, never moved. Nothing is deleted. The browser's own jar is left exactly as it was, so the worst case is that you turn the extension off and everything is where you left it.

Engineering

What it does underneath

Each one states the plain version first. Open any of them for the architecture.

Request-side substitution

Identity is rewritten at the network layer, not by swapping cookies.

Sessions are expressed as declarative rule bands: a posture band, a guard band, and a per-session id band. Because the rules are evaluated per request rather than applied as a state change, there is no window in which a request can leave under the wrong identity. The measured ceiling is hundreds of concurrent sessions, bound by the rule budget rather than by memory.
Moves that cannot leak

Every move is one guarded operation.

Before any rebind, a declarative block naming every moving tab is installed. It is lifted only once the new rules are live. Bulk moves, keyboard moves, right-click moves and undo all run through the same guard, so there is no path where a request escapes mid-change.
Survives the service worker

MV3 can stop the extension at any moment. Sessions come back correct.

Every wake reconciles the slot map, clears stale rules and rebuilds from the persisted session state rather than trusting whatever was in memory. The App-Bound Encryption work sits here too.
Per-session web storage

localStorage and sessionStorage are virtualised per session, and the rest is disclosed.

A content-script shim virtualises both per session. IndexedDB is detected and disclosed rather than silently shared, because a tool quietly leaving a hole is worse than one naming it.
Sign-in loop detection

It notices when a login is looping and stops fighting the site.

A partial cookie set is worse than none: a federated provider reads it as a hijacked session and can invalidate the account everywhere, not just in that tab. When the detector sees the loop it releases the site instead of retrying into that outcome.
Blast-radius guard

One bad session cannot spend the whole rule budget.

Each session owns its own id band, and overflow is journalled rather than silently dropped, so a runaway session is visible instead of degrading everything else.
Two backends, one kernel

MV3 for Chromium, a blocking backend for Opera GX.

The backend is chosen at runtime and both sit under the same kernel, so Opera GX is a first-class target rather than a port that lags behind.
Fingerprint posture

Set per session. Mirror and Standardize are free; Persona is Pro.

Mirror is the default and fabricates nothing, because incoherence is what flags you, not similarity. Standardize presents one shared machine. Persona, part of Pro, is a stable per-session machine on your real operating system, seeded per origin, delivered at document_start from the page world. A consistency validator checks the result, which matters because the usual failure is a persona that contradicts itself while the tool says nothing.
Privacy

It cannot leak, including into our own analytics

No browsing data leaves your machine. Usage stats are off until you switch them on, two independent gates hold them shut, and what they can carry is a closed list with no free-form field in it.

Telemetry

Opt in, anonymous, and built so it cannot carry anything.

The format is a closed allowlist, not a blocklist. Every field is an enum or a bounded integer and there is no free-form string anywhere in it, so a URL, a domain, a cookie or an account name cannot be transmitted even in principle. Counts are buckets, never exact numbers. The install id is a random UUID tied to no identity and erased when you opt out.
Never collected

No fingerprinting vectors, even in the analytics.

No screen size or pixel ratio, no canvas or WebGL, no font list, no full user agent, no named timezone, no geolocation, no exact install date, no exact counts, no URLs, no cookies, no accounts. The one named site is a major sign-in provider that had trouble, from a fixed list.
Everyday controls

The parts you touch constantly

Which is usually what decides whether a tool survives a week. Hover or focus any of them to see it work.

Colour-coded tabs

Every tab wears its session colour, so you can see which account you are in without clicking anything.

Bulk move, with undo

Select several tabs and move them together. It runs as one guarded operation, and undo puts them back.

Keyboard moves

Alt and a number sends the current tab to that session. No menu, no dragging.

Right-click into a session

Open any link or page directly in the session it belongs to, from the context menu.

Default-account hint

It tells you which account a site is treating as default, which is the thing nothing else surfaces.

One-switch pause

Turn it off and the browser behaves exactly as if the extension were not installed. Nothing is lost.

FAQ

Common questions

The short answers. The help pages have the long ones.

Is this a VPN or a proxy?

No. It separates cookies per tab. Your network connection is unchanged, your IP is the same in every session, and nothing is routed anywhere.

Will it sign me out of things?

It can, in one specific case. If a sign-in ends up half finished, a federated provider like Google can read that as a hijacked session and invalidate it everywhere. That is why signing in fresh inside a session is the recommended path, and why a loop detector releases a site rather than retrying into that outcome. Cookies are copied and never moved, so your original session stays intact.

Does it work with Google, Microsoft, Okta?

Yes. It is domain agnostic and does not special-case any provider. For federated logins, sign in fresh inside the session rather than importing an existing one.

Is it free?

Yes, with unlimited sessions. A Pro tier is planned later for deeper isolation, and it will never meter how many sessions you can have.

What do you collect?

Nothing unless you opt in, and then only anonymous, bucketed counts from a closed allowlist. The full list is on the telemetry page.

How is this different from Chrome profiles or Firefox Containers?

Profiles cost a window and about 250 MB each. Containers are deeper but Firefox only. This is the closest thing to Containers for Chrome: per-tab sessions, in the browser you already use, at roughly no memory per session. Firefox Containers still isolate more, including the cache.

Can I test a site as several users at once?

Yes. Put each role in its own session, for example admin, user and guest, and keep the tabs side by side. Each tab sends only its own session's cookies, so the roles do not mix.

My SessionBox extension stopped working. Is this a replacement?

It does the same core job, multiple accounts on the same site in one window, with a different mechanism and a few differences worth knowing first. They are set out on the page for SessionBox users.

Stop opening the wrong account.

Free, unlimited sessions, and it stays in the browser you already use.