DEVELOPER WORKBENCH

HTTP Cookie Inspector

Inspect pasted Set-Cookie fields, domain and path scope, lifetime, cookie prefixes and attribute conflicts. Masked JSON and CSV reports help review cookie configurations.

Local processingEditable exampleCopy + file exports

Settings

Try the example or enter your own settings.

Static review only: no cookie store access or requests. Values stay masked. Browser policies, public suffixes and SameSite context are not simulated. Expires parsing supports IMF-fixdate only; legacy date parsing may differ. Use synthetic examples: advertising scripts can technically access page inputs.

Using HTTP Cookie Inspector

Inspect pasted Set-Cookie fields, domain and path scope, lifetime, cookie prefixes and attribute conflicts. Masked JSON and CSV reports help review cookie configurations.

  1. Paste individual Set-Cookie fields, one per line. Do not join multiple cookies with commas or paste a request Cookie header.
  2. Enter the URL that sets the cookies and an optional UTC reference time for repeatable expiry calculations. Inspect the table and JSON details.
  3. Review conflicts, prefix requirements and unresolved scope. Copy or export the masked report; confirm actual behavior in browser developer tools.

Example

Try the included editable example.
Enter the URL that sets the cookies and an optional UTC reference time for repeatable expiry calculations. Inspect the table and JSON details.

Questions & answers

Does this tool read my browser cookies?

No. It only reviews pasted text in a local worker. It neither reads document.cookie nor writes cookies or makes requests to the setting URL.

Are cookie values included in exports?

No. JSON always masks cookie values and CSV does not include them. Unknown attribute values are omitted. This does not prevent third-party advertising scripts from accessing raw page input; paste synthetic data.

Which lifetime takes precedence?

A supported valid Max-Age takes precedence over a supported Expires date. Zero or negative Max-Age means immediate deletion. Relative expiry uses the chosen reference time; browser caps, eviction and clock-skew adjustments are not simulated.

What do the prefix checks cover?

Case-sensitive __Secure-, __Host-, __Http- and __Host-Http- requirements for Secure, HTTPS, explicit Path=/, no Domain, and HttpOnly where applicable. Prefix enforcement depends on browser support.

Can this prove a cookie will be accepted?

No. It reviews supported syntax and configuration. It does not check the Public Suffix List, browser policy, SameSite navigation context, partition keys or credentials modes. Domain-match and default-path checks need a setting URL.

What input limits apply?

Up to 100,000 characters and 200 nonempty cookie lines. Expires supports English IMF-fixdate with a valid year from1601 onward. Legacy date formats may be accepted by browsers but are not modeled here. Request Cookie headers and comma-joined cookies are unsupported.

Help improve this tool

Report a problem or suggest an improvement

Describe the issue without pasting private tool input. Feedback goes to our admin inbox.

Find another tool · Read practical guides