Cookie Policy Inspector
Inspect one Set-Cookie header and ask whether its attributes would permit storage and a later request. Enter the response URL, request URL, dates and request context to see each decision. This bounded exercise does not run a browser or discover a site's live cookies.
Key features
- Parse a single Set-Cookie header without splitting the comma in an Expires date
- Apply the last recognized duplicate attribute and Max-Age precedence over Expires
- Check host-only or Domain scope, Path segment boundaries and Secure transport
- Compare SameSite Strict, Lax, None and omitted defaults across navigation and fetch contexts
- Separate definite blocks from public-suffix, partition-key, clock-skew and third-party browser-policy review
- Download a report of decisions and codes without cookie values, names, raw URLs or paths
How to use
- Load a same-site or cross-site example, or paste one masked Set-Cookie response header.
- Enter the URL that set it, the later request URL, and UTC or offset timestamps.
- Choose the same-site relation, navigation or fetch context, method and fetch credentials.
- Inspect storage and sending results, then read individual checks and limitations.
- Download the value-free JSON or CSV report if you need to share the review.
Use cases
- Check why a cookie with Path=/docs does not accompany /docsets.
- See when Max-Age overrides a later Expires date.
- Compare a cross-site GET navigation with a POST or embedded fetch for SameSite=Lax.
- Review whether a __Host- prefix and Partitioned attribute have the required flags.
Frequently asked questions
Does an Allow result prove my browser will send the cookie?
No. Allow means the modeled checks do not block it. Browsers may reject cookies, evict them, cap lifetimes or restrict third-party storage. This tool has no live browser cookie-jar access and cannot certify delivery.
Why is Domain marked for review?
The response host must equal or be below the Domain value. A public suffix such as a registry-controlled suffix must also be considered. This tool does not ship a current Public Suffix List, so a matching Domain attribute remains a review item rather than an unqualified acceptance.
How do Expires and Max-Age differ?
A valid Max-Age takes precedence and is measured from the entered set time. Expires is an absolute HTTP date and can be affected by server/client clock skew. The exact expiry boundary is treated as expired.
Can SameSite=None force cross-site fetch cookies?
No. None requires Secure and removes the SameSite filter, but fetch credentials, third-party cookie policy, partition keys, storage access and browser settings can still prevent inclusion. Such cases remain review items.
Does HttpOnly prevent fetch requests from carrying a cookie?
No. HttpOnly prevents non-HTTP APIs such as document.cookie from reading it. HTTP requests, including fetch with suitable credentials and context, may still carry it.
Is pasting a real session cookie safe?
Prefer a masked example. Input stays in page memory and is not uploaded by this tool, but a real session value remains visible in your local textarea. The optional reports contain only lengths, flags, statuses and fixed check codes, never names or values.
Privacy
The header and URLs are processed in this browser tab only. This tool does not fetch sites, set cookies, use localStorage or upload input. JSON and CSV downloads contain fixed check codes and derived attributes, never the cookie name or value, full header, URL, Domain or Path text.
Comments & questions