The Instagram app sends noCookie request header on API traffic: 0 of
the 448 AVD capture's 34 requests and 0 of the client's 450 HAR requests
carry one. Server responses do set cookies (rur=…; domain=.instagram.com
on e.g. ZeroCampaignAPI, the content-filter lookups and the QP surface),
but those values are only informational on the wire — the app consumes the
state through its own ig-set-* response headers instead (see
applySessionHeaders). So the transport cookie store must stay off: with
cookieStore: true the Rust transport replays set-cookie (e.g. rur) as a
Cookie request header on later requests, which the app never does. The
separate JS cookieJar in createClientInternals is a different store — it
keeps snapshot state and lets webview flows build cookies explicitly — and is
unaffected by this.
Live-API transport options.
The Instagram app sends no
Cookierequest header on API traffic: 0 of the 448 AVD capture's 34 requests and 0 of the client's 450 HAR requests carry one. Server responses do set cookies (rur=…; domain=.instagram.comon e.g.ZeroCampaignAPI, the content-filter lookups and the QP surface), but those values are only informational on the wire — the app consumes the state through its ownig-set-*response headers instead (seeapplySessionHeaders). So the transport cookie store must stay off: withcookieStore: truethe Rust transport replaysset-cookie(e.g.rur) as aCookierequest header on later requests, which the app never does. The separate JScookieJarincreateClientInternalsis a different store — it keeps snapshot state and lets webview flows build cookies explicitly — and is unaffected by this.