Security Tools

Cookie Security Checker

Check whether your cookies are configured securely. Paste Set-Cookie headers or enter a URL, and each cookie is graded on the flags that protect it: Secure (HTTPS only), HttpOnly (no JavaScript access), SameSite (cross-site requests), the __Host- and __Secure- prefix rules, Domain scope and lifetime. Session and authentication cookies are recognised by name and held to a stricter standard. Cookie values are never shown – for URLs they are removed on the server.

  • Encrypted connection
  • No sign-up
  • Free to use

Pasted headers are analysed in your browser and never sent. For a URL our server fetches the page once; cookie values are removed before the result reaches you.

How to use Cookie Security Checker

  1. Paste Set-Cookie headers or enter a URL.
  2. Click Check cookies.
  3. Fix cookies graded D or F.
  4. Re-check after deploying.

Cookie Security Checker features

Per-cookie grade

With explained findings.

Prefix rules

__Host- and __Secure-.

Session detection

Stricter checks for auth cookies.

Values hidden

Only names and flags.

Paste mode

Analysed in your browser.

Lifetime

Session, days or expired.

When to use Cookie Security Checker

  • Securing login sessions.
  • Security reviews before launch.
  • Framework configuration checks.
  • PCI and OWASP checklists.

Cookie Security Checker FAQ

Which flags should a session cookie have?

Secure, HttpOnly, SameSite=Lax or Strict, Path=/ and ideally the __Host- prefix.

What does SameSite do?

It controls whether the cookie is sent with cross-site requests, which protects against CSRF.

Why avoid Domain=?

It sends the cookie to every subdomain, including ones that may be less secure.

How is this different from the website cookie checker?

That tool focuses on purposes and consent; this one on security flags, including pasted headers.

Small flags, big protection

Most session hijacking and CSRF attacks rely on a missing cookie flag. Setting them correctly costs nothing.

How it works: checks that need the network are made by our server through a guarded client that only connects to public addresses on the standard web ports, pins every connection to the validated address and limits time and response size. Pasted input is analysed in your browser and never sent. Nothing you check is stored, and requests are rate-limited to keep the service fair.

Every finding is rule-based and explained: the tool tells you what it saw, why it matters and what to change, instead of showing an unexplained score. Grades summarise the findings so you can compare sites and track progress after a fix, but the individual checks are what you should act on.

Only check systems you own or are authorised to assess. The probes behave like a normal browser or client – they read public responses and perform ordinary handshakes – and never try to exploit a weakness, guess passwords or overload a server.

Related tools on this site cover the rest of a security review – security header generators, CSP and CORS generators, SSL certificate and expiry checks, SPF, DKIM and DMARC record checkers, JWT tools and password generators – so you can fix what you find in the same place.

Who it is for: developers hardening a release, system administrators and DevOps teams, security and compliance reviewers preparing for audits such as PCI DSS or ISO 27001, and site owners who want to know whether their basics are right. No account or installation is needed.

Other useful tools