Network
Cookie and Set-Cookie Analyzer
Separate Cookie request pairs from Set-Cookie response instructions and review their flags.
How this tool works
Set-Cookie can declare Secure, HttpOnly, SameSite, Path, Domain, Max-Age, and Expires. The analyzer makes omissions and malformed lifetime attributes visible.
Static inspection cannot establish whether a browser accepts a cookie under its origin, TLS, and third-party policy context.
Examples
- Check SameSite=None with Secure.
- Compare request Cookie and response Set-Cookie.
- Inspect malformed Max-Age.
Common use cases
Worked synthetic example
Valid example
Set-Cookie: sid=sample; SameSite=None
Expected: Cookie attributes plus a missing Secure warning. The warning flags a browser compatibility concern; acceptance depends on context.
Failure or warning to recognize
Warning / interpretation
Set-Cookie: sid=sample; SameSite=None without Secure
Expected: SameSite=None without Secure produces a warning, not proof of whether this browser accepted the cookie.