Cookie Checker

List the cookies a website sets and check their Secure, HttpOnly and SameSite flags.

What do cookie flags mean?

Cookie flags are attributes that control how browsers handle a cookie: Secure sends it only over HTTPS, HttpOnly hides it from JavaScript, and SameSite limits when it is sent with requests from other sites.

What the checker shows

For every Set-Cookie header in the response: name, domain, expiry (session or a date), and whether Secure, HttpOnly and SameSite are set. Each cookie gets a verdict.

Recommended settings

  • Secure on every cookie of an HTTPS site.
  • HttpOnly on session and login cookies, so injected scripts cannot steal them.
  • SameSite=Lax for most cookies (protects against CSRF); SameSite=None; Secure only for cookies that must work across sites.
  • Short expiry times for authentication cookies.

Limits of this check

The checker sees cookies set by the server when the page first loads. Analytics, advertising and consent tools usually set cookies with JavaScript after the page loads; those need a browser-based scan for a full cookie audit.

Frequently asked questions

Why does SameSite=None need Secure?

Browsers reject SameSite=None cookies that are not also marked Secure.

Is a session cookie safe?

A session cookie is deleted when the browser closes. It is safe when it is Secure, HttpOnly and has a SameSite value.

Does this check cover GDPR compliance?

No. It checks technical cookie flags. GDPR compliance also requires consent for non-essential cookies, which needs a full browser scan.