HttpOnly blocks direct JavaScript access to a cookie but does not prevent XSS. Secure normally restricts sending to HTTPS, with an exception for localhost. SameSite helps mitigate CSRF but is not a complete defense; None requires Secure. Domain and Path scope where a cookie applies, while Max-Age and Expires set its lifetime.
Set-Cookie responses can include attributes such as HttpOnly, Secure, and SameSite. Paste each Set-Cookie on its own line. A Cookie request header carries only name=value pairs, so missing attributes there do not mean they were never set. Inspect the original Set-Cookie response or browser storage to check those settings.
This tool parses pasted text locally. It does not connect to the website or read your browser's cookie store, and its warning rules are not a complete RFC validator or security audit. A parsed result does not prove that a browser accepts or sends the cookie. Domain, Path, request context, and browser policies still matter; check the browser's network and storage panels for actual behavior.
Common questions and answers about this topic.
Strict allows only same-site requests. Lax also allows cross-site top-level navigations with safe HTTP methods such as GET, but not cross-site fetch or POST navigations. None permits cross-site sending and requires Secure; browser policies and other cookie rules still apply. Some browsers default to a Lax-like policy when SameSite is omitted, with exceptions that differ from explicit Lax.
HttpOnly blocks direct reads through document.cookie, reducing cookie theft via XSS, but malicious scripts can still make requests. Secure normally restricts transmission to HTTPS, with an exception for localhost. They address different risks, so sensitive cookies usually set both; neither makes a site immune to XSS.
Without Max-Age or Expires, it is a session cookie; restoring a browser session may preserve it after reopening. A valid Max-Age takes precedence over Expires and measures lifetime from browser receipt, not from pasting here; 0 or less requests immediate expiry. This tool shows the configured Max-Age duration, not the original cookie's remaining life. For Expires, it estimates the interval using the time the page loaded, not a live countdown.
No. Everything is parsed entirely in your browser, and nothing you paste leaves your device.