Cookie Parser
Parse Set-Cookie headers and document.cookie strings into structured data. All processing is done in your browser for maximum security and privacy.
0
Total Cookies
0
Secure Cookies
0
HttpOnly Cookies
Parsed Cookies
| Name | Value | Domain | Path | Expires | Max-Age | Flags |
|---|
How to Use Cookie Parser
Choose Mode
Select Set-Cookie header mode for HTTP headers or document.cookie mode for browser cookie strings
Paste Data
Paste your Set-Cookie headers (one per line) or a document.cookie string into the input field
Inspect Results
View parsed cookies in a structured table with statistics on security flags
What are HTTP Cookies?
HTTP cookies are small pieces of data stored by the browser on behalf of websites. They are sent via the Set-Cookie HTTP response header and attached to subsequent requests via the Cookie header. Cookies are used for session management, personalization, and tracking. Security flags like HttpOnly, Secure, and SameSite help protect cookies from cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.
HttpOnly
Prevents client-side scripts from accessing the cookie, mitigating XSS attacks
Secure
Ensures the cookie is only sent over HTTPS connections
SameSite
Controls cross-site cookie sending: Strict, Lax, or None to prevent CSRF attacks
Frequently Asked Questions
The tool parses Set-Cookie HTTP headers and document.cookie JavaScript strings. Multiple cookies can be parsed at once.
Yes. HttpOnly, Secure, SameSite (Strict/Lax/None), Path, and Domain attributes are all displayed for each cookie.
Yes. In Set-Cookie mode, paste one header per line. In document.cookie mode, all cookies in the string are parsed.
SameSite=Strict sends the cookie only on same-site navigations - full CSRF protection but no cookie on inbound links from elsewhere. Lax (the browser default) allows top-level GET navigations to carry it, which keeps login sessions working from external links while blocking most CSRF. None disables the restriction but requires Secure, or browsers reject it - that combination is what cross-site iframes and payment flows need.
A cookie without Expires or Max-Age is a session cookie: it lives only in memory and disappears with the browser session (modern browsers may restore it after a crash, though). Expires sets an absolute deadline, Max-Age a relative one in seconds, and Max-Age wins when both are present. Persistent cookies are how remember-me logins and long-lived analytics IDs survive restarts.
They are name-level guarantees that browsers enforce. __Secure- requires an https origin and the Secure attribute. __Host- is stricter: Secure, no Domain attribute (host-only), and Path=/ - so a __Host-prefixed cookie cannot be overwritten by a subdomain, which pins it to the exact site. Unsupported browsers just treat the prefixes as ordinary name characters.
RFC 6265 requires browsers to accept at least 4096 bytes per cookie and at least 50 cookies per domain. Chrome caps around 180 cookies per domain and a few thousand overall; Safari is stricter in practice. Since cookies ride along with every request to the domain, heavy cookie storage measurably slows traffic - the reason large sites move state into localStorage or server-side sessions.
HttpOnly hides the cookie from document.cookie in JavaScript, so injected XSS scripts cannot read it - set it on session cookies always. Secure restricts transmission to HTTPS connections, preventing leakage over plain HTTP. Neither encrypts the cookie at rest; both are one-line hardening in the Set-Cookie header.
Related Tools
JWT Parser
Decode and verify JSON Web Tokens (JWT) instantly. View header, payload, and signature information with human-readable time display
HTTP Header Parser
Parse raw HTTP headers into a structured table with cookie extraction
URL Parser
Parse any URL into its components — scheme, host, port, path, query parameters, and fragment
Authoritative References
Primary sources behind this tool - official standards and specifications, not secondhand summaries.
RFC 6265 - HTTP State Management Mechanism
The IETF HTTP State Management Mechanism standard that defines cookies and their attributes.
MDN Web Docs - Set-Cookie
Mozilla reference for the Set-Cookie header: attributes, prefixes, and security flags.
HTTP cookie - Wikipedia
How HTTP cookies carry state: sessions, attributes, and same-site rules.