Skip to content
FlexibleToolsAI
Security Toolkit · Free, Nothing Stored

Cookie Security Checker

Audit cookie security flags. Scan a URL to analyse every cookie it sets in its HTTP response, or paste Set-Cookie headers from DevTools, and get a per-cookie report on Secure, HttpOnly, SameSite, __Host-/__Secure- prefixes, Domain scope and lifetime — with extra scrutiny for session cookies.

Enter a URL (or paste Set-Cookie lines) and each cookie is parsed and checked: Secure so it's only sent over HTTPS, HttpOnly so JavaScript and XSS can't read session cookies, an explicit SameSite value for CSRF protection, valid prefixes, host-only scope, and reasonable expiry. Cookies that look like session or auth cookies are held to a stricter standard.

Instant Results

Live checks in seconds

Nothing Stored

No logs of what you check

No Sign-Up

Free, no credits or email

Suggest a Feature or Improvement for Cookie Security Checker

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use Cookie Security Checker

  1. 1Enter the URL or paste Set-Cookie headers.
  2. 2Review each cookie's report.
  3. 3Add missing flags in your server or framework config.
  4. 4Re-scan to confirm.

The flags that matter

Secure keeps cookies off plain HTTP. HttpOnly hides them from JavaScript, so an XSS bug can't steal the session. SameSite=Lax stops cookies being sent on cross-site POSTs, a strong CSRF defence; SameSite=None is required for legitimate cross-site use and must be paired with Secure.

The __Host- prefix forces Secure, Path=/ and no Domain, so subdomains can't set or overwrite the cookie — the strongest option for session cookies.

What a server-side scan can't see

Cookies set by JavaScript (analytics, consent tools) and cookies set after logging in don't appear in the first response. Copy those Set-Cookie headers from your browser's DevTools and paste them in. Document your cookies with the Cookie Policy Generator.

Frequently Asked Questions

Why does my site show no cookies?

Many sites set cookies only via JavaScript or after an action like logging in. Paste those headers instead.

Is SameSite=Lax the default?

In Chrome and Edge, cookies without SameSite are treated as Lax. Firefox and Safari differ, so set it explicitly.

What do you do with the domains and URLs I check?

Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.

Related Tools