Cookie Parser

Parse Set-Cookie headers and document.cookie strings into structured data. All processing is done in your browser for maximum security and privacy.

Multiple Formats Security Flags Cookie Statistics

How to Use Cookie Parser

1

Choose Mode

Select Set-Cookie header mode for HTTP headers or document.cookie mode for browser cookie strings

2

Paste Data

Paste your Set-Cookie headers (one per line) or a document.cookie string into the input field

3

Inspect Results

View parsed cookies in a structured table with statistics on security flags

What are HTTP Cookies?

HTTP cookies are small pieces of data stored by the browser on behalf of websites. They are sent via the Set-Cookie HTTP response header and attached to subsequent requests via the Cookie header. Cookies are used for session management, personalization, and tracking. Security flags like HttpOnly, Secure, and SameSite help protect cookies from cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.

HttpOnly

Prevents client-side scripts from accessing the cookie, mitigating XSS attacks

Secure

Ensures the cookie is only sent over HTTPS connections

SameSite

Controls cross-site cookie sending: Strict, Lax, or None to prevent CSRF attacks

Frequently Asked Questions

What cookie formats are supported?

The tool parses Set-Cookie HTTP headers and document.cookie JavaScript strings. Multiple cookies can be parsed at once.

Does it show security flags?

Yes. HttpOnly, Secure, SameSite (Strict/Lax/None), Path, and Domain attributes are all displayed for each cookie.

Can I parse multiple cookies at once?

Yes. In Set-Cookie mode, paste one header per line. In document.cookie mode, all cookies in the string are parsed.

What do the SameSite attribute values mean?

SameSite=Strict sends the cookie only on same-site navigations - full CSRF protection but no cookie on inbound links from elsewhere. Lax (the browser default) allows top-level GET navigations to carry it, which keeps login sessions working from external links while blocking most CSRF. None disables the restriction but requires Secure, or browsers reject it - that combination is what cross-site iframes and payment flows need.

What is the difference between session and persistent cookies?

A cookie without Expires or Max-Age is a session cookie: it lives only in memory and disappears with the browser session (modern browsers may restore it after a crash, though). Expires sets an absolute deadline, Max-Age a relative one in seconds, and Max-Age wins when both are present. Persistent cookies are how remember-me logins and long-lived analytics IDs survive restarts.

What do the __Secure- and __Host- cookie prefixes do?

They are name-level guarantees that browsers enforce. __Secure- requires an https origin and the Secure attribute. __Host- is stricter: Secure, no Domain attribute (host-only), and Path=/ - so a __Host-prefixed cookie cannot be overwritten by a subdomain, which pins it to the exact site. Unsupported browsers just treat the prefixes as ordinary name characters.

How large can cookies be, and how many fit per domain?

RFC 6265 requires browsers to accept at least 4096 bytes per cookie and at least 50 cookies per domain. Chrome caps around 180 cookies per domain and a few thousand overall; Safari is stricter in practice. Since cookies ride along with every request to the domain, heavy cookie storage measurably slows traffic - the reason large sites move state into localStorage or server-side sessions.

How do HttpOnly and Secure protect a cookie?

HttpOnly hides the cookie from document.cookie in JavaScript, so injected XSS scripts cannot read it - set it on session cookies always. Secure restricts transmission to HTTPS connections, preventing leakage over plain HTTP. Neither encrypts the cookie at rest; both are one-line hardening in the Set-Cookie header.

{-- * External Resources Component(#18 Phase 3b 内容佐证工程) * 工具页「权威引用」区块:RFC / W3C / WHATWG / ECMA / IANA / 官方规范站 / Wikipedia。 * * - 接受 :slug 属性 → 经 config/tool-sources.php 家族矩阵渲染该工具的权威引用 * - slug 未命中映射时不渲染(无权威来源的工具静默跳过) * - 链接 title 保持英文(引用源专名);description 经 * common.resources.descriptions.{key} 本地化,lang 未命中回退英文(线上不裸奔) * - 链接保持 dofollow(rel="noopener noreferrer") * * @param string|null $slug --}}