Cookie Lifespan Auditor
Paste the cookies your site sets and check each one against expiry guidance, Secure and SameSite flags, and the 13-month consent duration expected by European regulators.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Lifespan is the part regulators actually measure
Cookie banners get the attention, but the durations behind them are what supervisory authorities check when they look. The CNIL's guidance sets 13 months as the outer limit for a consent record and 25 months for the analytics data collected under it, and several other European authorities have adopted the same figures. A cookie set to expire in ten years is the most visible sign that nobody has reviewed the tag configuration, and it is trivially detectable from the outside.
Browsers now cap what you ask for
Setting an expiry far in the future no longer achieves what it used to. Chrome caps cookies set through document.cookie at 400 days, and Safari's Intelligent Tracking Prevention caps script-set cookies at 7 days, dropping to 24 hours where a link decoration suggests cross-site tracking. A cookie declared with a two-year expiry in your policy while the browser silently truncates it to seven days makes your policy inaccurate in a way an auditor can reproduce in a minute.
Flags are a separate failure
A session cookie carrying an authentication token without Secure, HttpOnly and a SameSite value is a security finding regardless of its duration. SameSite=None requires Secure to be set, and browsers reject the combination without it, so the cookie silently does not work. This tool checks duration and flags together because they are usually configured in the same place and fail in the same deployment.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
Where does the 13-month figure come from?
The CNIL’s guidance on cookies and trackers, which sets 13 months as the outer limit for the lifetime of a consent record and 25 months for the data gathered under it. Several other European authorities have adopted the same figures.
Do browsers really shorten my cookies?
Yes. Chrome caps cookies set through document.cookie at 400 days, and Safari caps script-set cookies at 7 days, or 24 hours where link decoration suggests cross-site tracking. Cookies set in an HTTP response header are treated differently from script-set ones.
Why does SameSite=None need Secure?
Browsers reject SameSite=None without Secure, so the cookie is simply not stored. It is a silent failure that looks like a working configuration until something depends on the cookie.
Is a session cookie exempt from consent?
Duration is not what decides that. Strictly necessary cookies are exempt regardless of lifespan, and non-essential ones need consent even if they expire when the tab closes.
Does this see my actual cookies?
No. It analyses the list you paste. It cannot read cookies from other sites, and nothing you paste is transmitted anywhere.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste your cookie list, one per line, and review the findings.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.