Developer

HTTP Cookie Parser

Parse a Cookie or Set-Cookie HTTP header into its name, value and attributes such as Path, Domain, Expires, Max-Age, Secure and SameSite.

Last reviewed by the Radiatus Cloud team

Parse a Cookie or Set-Cookie header into its name, value and attributes.

Need this built for your product?

We design, build & host secure software & APIs.

Talk to an engineer

Parse HTTP cookies

Cookies travel in HTTP headers, and their syntax packs a lot into one line. This parser breaks a cookie header into its parts so you can read it clearly. In Set-Cookie mode it extracts the cookie name and value, then lists every attribute such as Path, Domain, Expires, Max-Age, Secure, HttpOnly, SameSite and Priority. In Cookie mode it splits a request's Cookie header into each name and value pair. Any leading header name is stripped automatically, so you can paste the whole header line.

Attributes that are not part of the standard set are flagged as unknown, which helps catch typos in a Set-Cookie header.

Understanding cookie attributes

Cookie attributes control important behaviour and security. The Secure flag restricts a cookie to HTTPS, HttpOnly hides it from JavaScript to reduce cross-site scripting risk, and SameSite governs whether the cookie is sent on cross-site requests, a key defence against cross-site request forgery. Max-Age and Expires set the lifetime, while Path and Domain scope where the cookie applies.

Developers and security reviewers use this breakdown to confirm that a cookie has the right protections and scope. Seeing the attributes laid out makes it easy to spot a missing Secure flag or an overly broad Domain. All parsing happens locally in your browser.

Related tools

  • JSON Formatter — Format and beautify JSON in your browser. Pinpoints syntax errors by line and column, flags unsafe integers, and never uploads your data to a server.
  • JSON Validator — Validate JSON syntax with precise line and column errors, and check documents against a JSON Schema. Runs locally in your browser, nothing uploaded.
  • Regex Tester — Test regular expressions against sample text with live match highlighting, capture groups and flag control. Runs entirely in your browser.
  • HTML Minifier — Minify HTML by removing comments and redundant whitespace, without breaking inline elements or pre blocks. Runs entirely in your browser.

Frequently Asked Questions

What is the difference between Cookie and Set-Cookie?

Set-Cookie is sent by the server to set one cookie with attributes, while Cookie is sent by the browser and contains multiple name-value pairs with no attributes.

Which attributes does it recognise?

Path, Domain, Expires, Max-Age, Secure, HttpOnly, SameSite, Priority and Partitioned, the standard Set-Cookie attributes. Unknown ones are flagged.

What does the HttpOnly flag do?

It prevents JavaScript from reading the cookie, which reduces the risk of theft through cross-site scripting attacks.

Why does SameSite matter?

SameSite controls whether a cookie is sent on cross-site requests, which is an important protection against cross-site request forgery.

Do I need to include the header name?

No. You can paste the full header line with Set-Cookie or Cookie at the front, and the parser strips it automatically.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste a Cookie or Set-Cookie header value to break it into its parts.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.