Skip to cookie parser

Cookie Parser

Parse Cookie and Set-Cookie headers, decode values, inspect attributes, and build Set-Cookie strings in your browser.

Loading cookie parser…

What is a cookie parser?

A cookie parser takes a raw HTTP Cookie or Set-Cookie string and breaks it into readable names, values, and attributes. This tool can also URL-decode values, inspect common configuration flags, parse cURL input, and build Set-Cookie headers in the browser.

Cookie vs Set-Cookie

Cookie request header compared with Set-Cookie response header
HeaderDirectionTypical syntax
CookieBrowser → serverCookie: name=value; name2=value2
Set-CookieServer → browserSet-Cookie: name=value; Path=/; Secure

Cookie is what the browser sends. Set-Cookie is what the server uses to store or update a cookie. A request Cookie header generally carries name=value pairs only — not Path, Secure, or HttpOnly.

How to use the cookie parser

  1. Choose Cookie Header, Set-Cookie, cURL / headers, or Auto Detect.
  2. Paste the raw cookie, header block, or cURL command.
  3. Inspect names, values, and attributes in the table, JSON, or text view.
  4. Enable URL decoding if values are percent-encoded. Raw values stay visible.
  5. Review optional configuration checks on Set-Cookie results.
  6. Copy or download the parsed result.
  7. Use the builder to create a Set-Cookie string, then parse it to confirm the attributes.

Cookie attributes explained

Domain
Hosts that may receive the cookie. Omitting it keeps the cookie host-only.
Path
URL path prefix required for the cookie to be sent.
Expires
Absolute expiry date. If Max-Age is also present, Max-Age wins for lifetime behavior.
Max-Age
Lifetime in seconds from when the cookie is stored. Zero or less expires it immediately.
Secure
Restricts sending to secure contexts (HTTPS), subject to browser rules.
HttpOnly
Hides the cookie from JavaScript APIs such as document.cookie.
SameSite
Controls cross-site sending: Strict, Lax, or None (None requires Secure).
Partitioned
Uses partitioned storage and requires Secure. It is not a general third-party-cookie replacement.
Priority
A non-standard hint some browsers use when evicting cookies.

Secure, HttpOnly, and SameSite

Secure limits the cookie to HTTPS connections under browser rules — it does not make a value impossible to steal. HttpOnly keeps the cookie out of document.cookie; it does not stop every XSS impact. SameSite changes when the cookie is included on cross-site requests. Missing SameSite is not automatically an exploitable finding: browsers apply their own default.

Prefix checks follow current documented rules: __Secure- needs Secure; __Host- needs Secure, Path=/, and no Domain; __Http- and __Host-Http- also need HttpOnly. These are configuration checks, not a penetration test or compliance audit.

Cookie parsing examples

  • Cookie header: sessionId=abc123; theme=dark; csrftoken=xyz789 becomes three name/value rows.
  • Set-Cookie: sessionId=abc123; Path=/; Secure; HttpOnly; SameSite=Lax shows attributes plus configuration status.
  • Encoded value: name=John%20Doe keeps the raw value and can show John Doe when decoding is on.
  • Builder: name sessionId, value abc123, Path=/, Secure, HttpOnly, SameSite=Lax generates a Set-Cookie line you can parse back.
  • Review case: id=abc; SameSite=None is flagged because None requires Secure.
  • Two Set-Cookie lines become Cookie #1 and Cookie #2 — they are never merged into one cookie.

Common cookie parser mistakes

  • Treating Cookie and Set-Cookie as the same header.
  • Expecting HttpOnly cookies to appear in document.cookie.
  • Calling missing SameSite a vulnerability by itself.
  • Using SameSite=None without Secure.
  • Adding Domain on a __Host- cookie, or forgetting Path=/.
  • Joining multiple Set-Cookie lines into one semicolon list.
  • Decoding values and discarding the raw form.
  • Pasting live session tokens into a public or shared browser.
  • Treating this parser as full security testing or cookie-consent law review.

Related developer tools

Frequently asked questions

What is a cookie parser?

It turns a raw Cookie or Set-Cookie string into names, values, and attributes you can read, copy, or export as JSON.

What is the difference between Cookie and Set-Cookie?

Cookie is the request header of name=value pairs. Set-Cookie is the response header that stores one cookie plus attributes such as Path and SameSite.

How do I parse a Cookie header?

Choose Cookie Header or Auto Detect, paste the header or document.cookie-style string, and read the name/value table.

How do I parse a Set-Cookie header?

Paste one or more Set-Cookie lines. Each line becomes its own cookie with Domain, Path, Expires, Max-Age, and flags.

Can this tool parse multiple cookies?

Yes. A Cookie header can contain many pairs. Multiple Set-Cookie lines are parsed separately and never merged.

Can this tool decode URL-encoded cookie values?

Yes, when URL-decode is enabled. The raw value stays available next to the decoded text.

Can I paste a cURL command?

Yes. The tool reads -H Cookie / Set-Cookie and --cookie values. It does not run the command or make a network request.

What does HttpOnly mean?

HttpOnly hides the cookie from JavaScript APIs such as document.cookie. It does not stop every XSS impact.

What does Secure mean on a cookie?

Secure tells supporting browsers to send the cookie only in secure contexts. It does not make the value impossible to steal.

What does SameSite mean?

SameSite controls when the cookie is sent on cross-site requests: Strict, Lax, or None.

What is SameSite=None?

None allows cross-site sending and requires the Secure attribute. This tool flags None without Secure as a review item.

What is a Partitioned cookie?

A partitioned cookie uses partitioned storage and requires Secure. It is not a drop-in replacement for all third-party cookies.

What is a __Host- cookie?

__Host- cookies must be Secure, use Path=/, and omit Domain. The parser reports those requirements when the prefix is present.

Can document.cookie include HttpOnly cookies?

No. Load document.cookie only shows cookies this page’s JavaScript can read. HttpOnly and other-site cookies are not included.

Does the parser upload cookie values to a server?

No. Parsing runs in your browser. Cookie input is not uploaded to EverydayTools.

Can I create a Set-Cookie header with this tool?

Yes. The builder outputs a Set-Cookie string and can load it back into the parser for a round-trip check.

Can the tool check cookie security settings?

It reports common configuration issues such as SameSite=None without Secure. That is not a vulnerability scan or compliance audit.

Can I export parsed cookies as JSON?

Yes. Copy or download JSON. Request cookies export name and value only; Set-Cookie objects include the attributes that were present.