Cookie Security Checker
Audit cookie security flags. Scan a URL to analyse every cookie it sets in its HTTP response, or paste Set-Cookie headers from DevTools, and get a per-cookie report on Secure, HttpOnly, SameSite, __Host-/__Secure- prefixes, Domain scope and lifetime — with extra scrutiny for session cookies.
Enter a URL (or paste Set-Cookie lines) and each cookie is parsed and checked: Secure so it's only sent over HTTPS, HttpOnly so JavaScript and XSS can't read session cookies, an explicit SameSite value for CSRF protection, valid prefixes, host-only scope, and reasonable expiry. Cookies that look like session or auth cookies are held to a stricter standard.
Instant Results
Live checks in seconds
Nothing Stored
No logs of what you check
No Sign-Up
Free, no credits or email
Suggest a Feature or Improvement for Cookie Security Checker
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use Cookie Security Checker
- 1Enter the URL or paste Set-Cookie headers.
- 2Review each cookie's report.
- 3Add missing flags in your server or framework config.
- 4Re-scan to confirm.
The flags that matter
Secure keeps cookies off plain HTTP. HttpOnly hides them from JavaScript, so an XSS bug can't steal the session. SameSite=Lax stops cookies being sent on cross-site POSTs, a strong CSRF defence; SameSite=None is required for legitimate cross-site use and must be paired with Secure.
The __Host- prefix forces Secure, Path=/ and no Domain, so subdomains can't set or overwrite the cookie — the strongest option for session cookies.
What a server-side scan can't see
Cookies set by JavaScript (analytics, consent tools) and cookies set after logging in don't appear in the first response. Copy those Set-Cookie headers from your browser's DevTools and paste them in. Document your cookies with the Cookie Policy Generator.
Frequently Asked Questions
Why does my site show no cookies?
Many sites set cookies only via JavaScript or after an action like logging in. Paste those headers instead.
Is SameSite=Lax the default?
In Chrome and Edge, cookies without SameSite are treated as Lax. Firefox and Safari differ, so set it explicitly.
What do you do with the domains and URLs I check?
Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.
Related Tools
Security Headers Checker
Scan any website's HTTP security headers and get an A+ to F grade with fixes.
CSRF Token Generator
Generate secure CSRF tokens and copy correct server-side code for Node, Python, PHP, Go and Java.
Cookie Policy Generator
Generate a cookie policy with a table of the cookies your services set — Google Analytics, AdSense and more.