How to use Cookie Header Explainer
- Paste one Set-Cookie line per cookie, using non-sensitive sample values when possible.
- Enter the response host, comparison path and explicit reference UTC time.
- Inspect scope and attribute observations, remembering that all result values are masked.
Example: Cookie Header Explainer
Interpret a one-hour Max-Age on a synthetic cookie.
Options
- Optional request Cookie header
- Optional request pairs can be compared as names. Do not paste Set-Cookie attributes into this field.
- Reference UTC time
- Enter a supported UTC timestamp representing when the setting response is being considered. Max-Age expiry is based on that value.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
Scope and protection flags are different checks
Path and Domain describe where a cookie may apply. Secure relates to HTTPS transport; HttpOnly limits script access rather than stopping every form of misuse. This offline explanation does not set a cookie, simulate all browser policies or establish that a session is secure. Keep application authentication and cookie interpretation separate.
Use a reference time deliberately
A relative Max-Age needs a starting time to produce a stated expiry. The reference field is not a reading from the actual setting response. If you enter an old or arbitrary time, the calculated expiry follows it. Masked values reduce accidental output disclosure, but names, hosts and paths can still reveal application details.
Questions about Cookie Header Explainer
Why paste Set-Cookie lines separately?
Expires can contain a comma. Combining headers by commas can split a valid date and change their meaning.
Which expiry wins if both are present?
A valid Max-Age takes precedence over Expires. The entered reference time is used for the stated relative expiry.
Does masking make shared input safe?
Results mask values, but pasted headers can contain sensitive names and metadata. Do not share real session credentials.