Compliance

Cookie Lifespan Auditor

Paste the cookies your site sets and check each one against expiry guidance, Secure and SameSite flags, and the 13-month consent duration expected by European regulators.

Last reviewed by the Radiatus Cloud team

Findings appear here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Lifespan is the part regulators actually measure

Cookie banners get the attention, but the durations behind them are what supervisory authorities check when they look. The CNIL's guidance sets 13 months as the outer limit for a consent record and 25 months for the analytics data collected under it, and several other European authorities have adopted the same figures. A cookie set to expire in ten years is the most visible sign that nobody has reviewed the tag configuration, and it is trivially detectable from the outside.

Browsers now cap what you ask for

Setting an expiry far in the future no longer achieves what it used to. Chrome caps cookies set through document.cookie at 400 days, and Safari's Intelligent Tracking Prevention caps script-set cookies at 7 days, dropping to 24 hours where a link decoration suggests cross-site tracking. A cookie declared with a two-year expiry in your policy while the browser silently truncates it to seven days makes your policy inaccurate in a way an auditor can reproduce in a minute.

Flags are a separate failure

A session cookie carrying an authentication token without Secure, HttpOnly and a SameSite value is a security finding regardless of its duration. SameSite=None requires Secure to be set, and browsers reject the combination without it, so the cookie silently does not work. This tool checks duration and flags together because they are usually configured in the same place and fail in the same deployment.

Related tools

Frequently Asked Questions

Where does the 13-month figure come from?

The CNIL’s guidance on cookies and trackers, which sets 13 months as the outer limit for the lifetime of a consent record and 25 months for the data gathered under it. Several other European authorities have adopted the same figures.

Do browsers really shorten my cookies?

Yes. Chrome caps cookies set through document.cookie at 400 days, and Safari caps script-set cookies at 7 days, or 24 hours where link decoration suggests cross-site tracking. Cookies set in an HTTP response header are treated differently from script-set ones.

Why does SameSite=None need Secure?

Browsers reject SameSite=None without Secure, so the cookie is simply not stored. It is a silent failure that looks like a working configuration until something depends on the cookie.

Is a session cookie exempt from consent?

Duration is not what decides that. Strictly necessary cookies are exempt regardless of lifespan, and non-essential ones need consent even if they expire when the tab closes.

Does this see my actual cookies?

No. It analyses the list you paste. It cannot read cookies from other sites, and nothing you paste is transmitted anywhere.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste your cookie list, one per line, and review the findings.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.