Cookie Inspector
Parse and inspect Set-Cookie headers from HTTP responses. Visualize cookie attributes including domain, path, expiry, Secure, HttpOnly, SameSite flags. Detect potential security issues like missing Secure flag on sensitive cookies or overly broad domain scoping.
session_idsize: 126BeyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.signature✓ Secure flag set
✓ HttpOnly set (JS can't read)
✓ SameSite=Strict
ℹ Value looks like a JWT — try the JWT Decoder
csrf_tokensize: 76Ba8f5f167f44f4964e6c998dee827110c✓ Secure flag set
⚠ Missing HttpOnly — accessible via document.cookie (XSS risk)
✓ SameSite=Strict
✗ Auth-style cookie without HttpOnly — high XSS risk
tracking_idsize: 70Babc123def456✗ Missing Secure flag — cookie sent over HTTP
⚠ Missing HttpOnly — accessible via document.cookie (XSS risk)
⚠ Missing SameSite — defaults vary by browser
🔒 Cookies parsed locally. Auth cookies should always have Secure + HttpOnly + SameSite.