Cookie Parser
Parse Cookie and Set-Cookie headers, decode values, inspect attributes, and build Set-Cookie strings in your browser.
What is a cookie parser?
A cookie parser takes a raw HTTP Cookie or Set-Cookie string and breaks it into readable names, values, and attributes. This tool can also URL-decode values, inspect common configuration flags, parse cURL input, and build Set-Cookie headers in the browser.
Cookie vs Set-Cookie
| Header | Direction | Typical syntax |
|---|---|---|
| Cookie | Browser → server | Cookie: name=value; name2=value2 |
| Set-Cookie | Server → browser | Set-Cookie: name=value; Path=/; Secure |
Cookie is what the browser sends. Set-Cookie is what the server uses to store or update a cookie. A request Cookie header generally carries name=value pairs only — not Path, Secure, or HttpOnly.
How to use the cookie parser
- Choose Cookie Header, Set-Cookie, cURL / headers, or Auto Detect.
- Paste the raw cookie, header block, or cURL command.
- Inspect names, values, and attributes in the table, JSON, or text view.
- Enable URL decoding if values are percent-encoded. Raw values stay visible.
- Review optional configuration checks on Set-Cookie results.
- Copy or download the parsed result.
- Use the builder to create a Set-Cookie string, then parse it to confirm the attributes.
Cookie attributes explained
- Domain
- Hosts that may receive the cookie. Omitting it keeps the cookie host-only.
- Path
- URL path prefix required for the cookie to be sent.
- Expires
- Absolute expiry date. If Max-Age is also present, Max-Age wins for lifetime behavior.
- Max-Age
- Lifetime in seconds from when the cookie is stored. Zero or less expires it immediately.
- Secure
- Restricts sending to secure contexts (HTTPS), subject to browser rules.
- HttpOnly
- Hides the cookie from JavaScript APIs such as document.cookie.
- SameSite
- Controls cross-site sending: Strict, Lax, or None (None requires Secure).
- Partitioned
- Uses partitioned storage and requires Secure. It is not a general third-party-cookie replacement.
- Priority
- A non-standard hint some browsers use when evicting cookies.
Secure, HttpOnly, and SameSite
Secure limits the cookie to HTTPS connections under browser rules — it does not make a value impossible to steal. HttpOnly keeps the cookie out of document.cookie; it does not stop every XSS impact. SameSite changes when the cookie is included on cross-site requests. Missing SameSite is not automatically an exploitable finding: browsers apply their own default.
Prefix checks follow current documented rules: __Secure- needs Secure; __Host- needs Secure, Path=/, and no Domain; __Http- and __Host-Http- also need HttpOnly. These are configuration checks, not a penetration test or compliance audit.
Cookie parsing examples
- Cookie header:
sessionId=abc123; theme=dark; csrftoken=xyz789becomes three name/value rows. - Set-Cookie:
sessionId=abc123; Path=/; Secure; HttpOnly; SameSite=Laxshows attributes plus configuration status. - Encoded value:
name=John%20Doekeeps the raw value and can showJohn Doewhen decoding is on. - Builder: name
sessionId, valueabc123, Path=/, Secure, HttpOnly, SameSite=Lax generates a Set-Cookie line you can parse back. - Review case:
id=abc; SameSite=Noneis flagged because None requires Secure. - Two Set-Cookie lines become Cookie #1 and Cookie #2 — they are never merged into one cookie.
Common cookie parser mistakes
- Treating Cookie and Set-Cookie as the same header.
- Expecting HttpOnly cookies to appear in document.cookie.
- Calling missing SameSite a vulnerability by itself.
- Using SameSite=None without Secure.
- Adding Domain on a __Host- cookie, or forgetting Path=/.
- Joining multiple Set-Cookie lines into one semicolon list.
- Decoding values and discarding the raw form.
- Pasting live session tokens into a public or shared browser.
- Treating this parser as full security testing or cookie-consent law review.
Related developer tools
- JWT Decoder
Inspect a JWT-like cookie value — this page only flags the shape, it does not validate signatures.
- Base64 Encoder & Decoder
Decode a cookie value that is Base64, not a cookie header.
- URL Encoder & Decoder
Percent-encode or decode strings outside a Cookie / Set-Cookie header.
- HTTP Header Generator
Build other request or response headers, not cookie attributes.
- JSON Formatter
Pretty-print a JSON cookie value in a dedicated formatter.
- .env Parser
Parse environment files when a token lives in config instead of a cookie.
Frequently asked questions
What is a cookie parser?
It turns a raw Cookie or Set-Cookie string into names, values, and attributes you can read, copy, or export as JSON.
What is the difference between Cookie and Set-Cookie?
Cookie is the request header of name=value pairs. Set-Cookie is the response header that stores one cookie plus attributes such as Path and SameSite.
How do I parse a Cookie header?
Choose Cookie Header or Auto Detect, paste the header or document.cookie-style string, and read the name/value table.
How do I parse a Set-Cookie header?
Paste one or more Set-Cookie lines. Each line becomes its own cookie with Domain, Path, Expires, Max-Age, and flags.
Can this tool parse multiple cookies?
Yes. A Cookie header can contain many pairs. Multiple Set-Cookie lines are parsed separately and never merged.
Can this tool decode URL-encoded cookie values?
Yes, when URL-decode is enabled. The raw value stays available next to the decoded text.
Can I paste a cURL command?
Yes. The tool reads -H Cookie / Set-Cookie and --cookie values. It does not run the command or make a network request.
What does HttpOnly mean?
HttpOnly hides the cookie from JavaScript APIs such as document.cookie. It does not stop every XSS impact.
What does Secure mean on a cookie?
Secure tells supporting browsers to send the cookie only in secure contexts. It does not make the value impossible to steal.
What does SameSite mean?
SameSite controls when the cookie is sent on cross-site requests: Strict, Lax, or None.
What is SameSite=None?
None allows cross-site sending and requires the Secure attribute. This tool flags None without Secure as a review item.
What is a Partitioned cookie?
A partitioned cookie uses partitioned storage and requires Secure. It is not a drop-in replacement for all third-party cookies.
What is a __Host- cookie?
__Host- cookies must be Secure, use Path=/, and omit Domain. The parser reports those requirements when the prefix is present.
Can document.cookie include HttpOnly cookies?
No. Load document.cookie only shows cookies this page’s JavaScript can read. HttpOnly and other-site cookies are not included.
Does the parser upload cookie values to a server?
No. Parsing runs in your browser. Cookie input is not uploaded to EverydayTools.
Can I create a Set-Cookie header with this tool?
Yes. The builder outputs a Set-Cookie string and can load it back into the parser for a round-trip check.
Can the tool check cookie security settings?
It reports common configuration issues such as SameSite=None without Secure. That is not a vulnerability scan or compliance audit.
Can I export parsed cookies as JSON?
Yes. Copy or download JSON. Request cookies export name and value only; Set-Cookie objects include the attributes that were present.