Cookie Header Explainer

Inspect separate cookie header lines with masked values and explain their stated scope, expiry and attributes.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Inspect input controls

Showing an example. Edit to see your own.

One cookie per line. Values are masked in all results. Only the documented producer syntax is supported.

name=value pairs separated by semicolons; no attributes.

Processed in your browser. Your inputs stay on this device.

How to use Cookie Header Explainer

  1. Paste one Set-Cookie line per cookie, using non-sensitive sample values when possible.
  2. Enter the response host, comparison path and explicit reference UTC time.
  3. Inspect scope and attribute observations, remembering that all result values are masked.

Example: Cookie Header Explainer

Interpret a one-hour Max-Age on a synthetic cookie.

You add
Set-Cookie: session=example; Path=/; Max-Age=3600; Secure; HttpOnly. Reference UTC: 2026-10-03T00:00:00Z; host: site.example; request path: /; request Cookie: blank.
You get
The value is masked and the stated expiry is 2026-10-03T01:00:00.000Z. The report explains the entered attributes without setting a browser cookie.

Options

Optional request Cookie header
Optional request pairs can be compared as names. Do not paste Set-Cookie attributes into this field.
Reference UTC time
Enter a supported UTC timestamp representing when the setting response is being considered. Max-Age expiry is based on that value.

Supported inputs and limits

Explains pasted syntax without setting, saving or contacting cookies or websites. Domain checks have no public-suffix database. Missing attributes and browser defaults are not guessed. A cookie’s name or flags do not establish its tracking purpose or actual acceptance. Up to 30 Set-Cookie lines or 100 request pairs and 20,000 combined characters. Explicit Expires parsing supports exact IMF-fixdate only. The relative expiry is the stated value; browser lifetime caps and eviction are not modeled. SameSite and prefix notes follow the September 2026 cookie draft, which remains work in progress.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Scope and protection flags are different checks

Path and Domain describe where a cookie may apply. Secure relates to HTTPS transport; HttpOnly limits script access rather than stopping every form of misuse. This offline explanation does not set a cookie, simulate all browser policies or establish that a session is secure. Keep application authentication and cookie interpretation separate.

Use a reference time deliberately

A relative Max-Age needs a starting time to produce a stated expiry. The reference field is not a reading from the actual setting response. If you enter an old or arbitrary time, the calculated expiry follows it. Masked values reduce accidental output disclosure, but names, hosts and paths can still reveal application details.

Questions about Cookie Header Explainer

Why paste Set-Cookie lines separately?

Expires can contain a comma. Combining headers by commas can split a valid date and change their meaning.

Which expiry wins if both are present?

A valid Max-Age takes precedence over Expires. The entered reference time is used for the stated relative expiry.

Does masking make shared input safe?

Results mask values, but pasted headers can contain sensitive names and metadata. Do not share real session credentials.

Project manager: Tony Hines · Content updated 3 October 2026 · Report a problem