Example: Downloading Behind a Login Cookie
curl -L -b 'session=abc123' -o invoice.pdf \
'https://portal.example.com/billing/invoice/9812/download'
-bsends a cookie read-style;-cwrites the jar. For flows that need two hops (login then download), use-c jar.txtthen-b jar.txt.-Lmatters more here than anywhere: download endpoints are usually one redirect from the page URL you copied.- The gotcha: if the server re-issues
Set-Cookieduring the redirect and you didn't use a jar, hop two is unauthenticated and you silently download the login page named invoice.pdf. Converted code needs a session/cookie-jar object for the same behavior —requests.Session()in Python, aCookieJarin Node fetch is manual.
Check what you actually downloaded before opening it: file invoice.pdf will tell you it's an HTML document in one keystroke.
FAQ
How do I find the right cookie to copy? DevTools → Application → Cookies, or run curl -i on the page and read the Set-Cookie headers. Send only the session cookie, not analytics noise.
Why did -o save an HTML login page instead of the PDF? You hit the redirect without the re-issued cookie. Use a jar: curl -c jar.txt -b jar.txt -L ... so both hops share cookie state.
Is exporting cookies from DevTools safe? The value is your session — treat it like a password. Paste it only where you need it and rotate the session afterwards if the machine isn't yours.