Back

Cookie / Set-Cookie parser

Developer tools

Loading

Loading tool

The tool is loaded only when you open it.

All processing for this tool happens in your browser. Your input is not sent to a server.

About this tool

Choose request Cookie or response Set-Cookie mode before pasting a capture. The parser keeps repeated entries in order, preserves commas inside Expires dates, and reports malformed tokens by line and column. Results and JSON exports mask cookie and attribute values by default; the original input remains visible in the editor. Revealing or exporting raw values is an explicit choice that can expose credentials. Processing stays in this page: no requests, browser-cookie access, input history or server-side session checks.

Common uses

  • Inspect duplicate names in a copied Cookie request without turning them into a map that silently discards entries.
  • Review separate Set-Cookie lines, expiry directives and custom attributes while keeping unknown browser and origin context explicit.
  • Prepare a structured, value-masked debugging report, then review remaining names and metadata before sharing it.

How to use it

  1. 1.Choose Cookie request mode for semicolon-separated name=value pairs, or Set-Cookie response mode for one cookie and its attributes per line. Paste matching headers only; keep repeated Set-Cookie lines separate.
  2. 2.Run the parser and correct any reported line and column. Review preserved entries, attributes and conditional findings; the original origin, transport, receipt time and browser policy are not established by the pasted text.
  3. 3.Keep values masked when copying or downloading JSON. Review visible names and metadata too. Enable raw values only deliberately: raw display, clipboard content and downloaded files can contain usable credentials.

Synthetic cookie examples

Repeated request names and a simple quoted value

Cookie: session=demo-first; theme="dark"
Cookie: session=demo-second
Cookie request mode
3 cookie pairs across 2 lines, in original order
Names: session, theme, session
Cookie values: masked by default

Both session entries survive; the parser does not choose a winning value. The quoted dark value is valid because it contains only allowed cookie characters. Quotes do not make a comma, semicolon, backslash or space valid inside a cookie value.

Separate response cookies with an Expires comma

Set-Cookie: session=demo-session; Expires=Mon, 21 Oct 2030 07:28:00 GMT; Domain=example.com; Path=/; Secure; HttpOnly
Set-Cookie: theme=dark; Path=/; SameSite=Lax
Set-Cookie response mode
2 separate cookies: session, theme
First-cookie attributes: Expires, Domain, Path, Secure, HttpOnly
Cookie and attribute values: masked by default

The comma in the Expires date stays in the first cookie’s attribute. Domain and Path are parsed declarations, not proof that these cookies apply to the unknown source URL. Secure and HttpOnly are flag attributes without values.

Max-Age overrides a later Expires date

Set-Cookie: session=demo-session; Expires=Mon, 21 Oct 2030 07:28:00 GMT; Max-Age=0; Path=/; Secure; HttpOnly
Set-Cookie response mode
1 cookie with both Max-Age and Expires
Applicable Max-Age takes precedence
Stored-cookie state and login/session validity: unknown

The synthetic Max-Age=0 directive requests immediate expiry even though Expires names a later date. It does not prove that a browser received the response, deleted a matching stored cookie or ended the server-side session.

SameSite relationship and an unknown attribute

Set-Cookie: partner=demo-partner; SameSite=None; X-Trace=demo-internal
Set-Cookie response mode
1 cookie with SameSite and X-Trace attributes
SameSite/Secure relationship needs review: Secure is absent
Unknown attribute retained; values masked by default

SameSite=None needs Secure in supporting browsers. X-Trace is preserved as an unknown attribute for inspection, with its value masked in the default report; no browser behavior is inferred from that custom attribute.

Common cookie parsing mistakes

  • Choosing the wrong mode or pasting complete HTTP responses: provide only Cookie or Set-Cookie input matching the selected mode.
  • Joining multiple Set-Cookie fields with commas: keep one cookie per line, including any comma belonging to its Expires date.
  • Assuming quotes escape arbitrary characters: a quoted cookie value still cannot contain spaces, commas, semicolons, backslashes or control characters.
  • Treating duplicate names as a dictionary: review every occurrence and its location rather than silently keeping only the last value.
  • Reading expiry or security attributes as proof of an active login, accepted cookie or secure application: the relevant server, origin and browser state are unknown.
  • Sharing a raw report or assuming masking hides everything: check both the export mode and any remaining names or metadata.

Limits and notes

  • This is a bounded pasted-text inspector, not a complete browser cookie implementation. Inputs beyond the displayed size, line or item limits must be reduced before parsing; a syntax failure is not a successful partial result.
  • Cookie and Set-Cookie have separate grammars. Cookie values may use simple surrounding double quotes, but quotes do not permit spaces, control characters, non-ASCII characters, commas, semicolons or backslashes inside a value. Encode such data before capture; this tool does not repair malformed input.
  • Each Set-Cookie line describes one cookie. Expires date commas are preserved, not used as cookie separators. Repeated names and attributes, including unknown attributes, remain inspectable; their presence does not prove that a browser will accept or apply them.
  • The request URL, origin, transport and actual browser policy are unknown. The tool does not verify domain or path applicability, public-suffix eligibility, HTTPS, cookie storage, cross-site delivery or login/session validity. Expiry guidance describes directives, not whether a session still works.
  • Default masking covers cookie and attribute values in results and exports, not the original input or every identifying detail. Names, counts and locations can remain sensitive. Raw reveal/export can expose secrets; clipboard content and downloaded files remain outside this page’s control.

Frequently asked questions

Why is the request/response mode important?

Cookie carries request name=value pairs; it does not include the attributes that originally set them. Set-Cookie defines a single response cookie followed by attributes. Treating Path, Secure or SameSite as request attributes would invent information, while merging Set-Cookie lines can corrupt an Expires date.

Which wins: Max-Age or Expires?

An applicable, valid Max-Age takes precedence over Expires. Max-Age describes seconds from receipt; zero or a negative value requests immediate expiry. A pasted capture does not establish when a browser received it or what it retained, and neither directive proves that the server still accepts the session.

Does SameSite=None with Secure guarantee cross-site delivery?

No. SameSite=None requires Secure in supporting browsers, but origin, request context, browser support and privacy policy still matter. Secure is a transport restriction; HttpOnly limits script access. Neither is a complete security assessment, and this tool never tests the site.

Can I safely share the default JSON export?

The default export masks cookie and attribute values, including unknown attribute values. Review cookie names and other retained metadata before sharing; masking is not a guarantee of anonymity. Explicitly choosing raw values can disclose session credentials and other private data.

Related tools