Security · cookies
Set-Cookie inspector.
Paste one or more Set-Cookie lines and see what a browser would read from each: name, value, Domain, Path, expiry and flags. Nothing leaves this page.
Set-Cookie lines
Result
What this checks
- Name and value split, with size in octets (name + value over 4096 is ignored by browsers)
- Expires or Max-Age converted to a date, with the 400-day lifetime cap noted
- SameSite=None without Secure
- __Secure- and __Host- prefix rules, matched case-insensitively as browsers do
- Domain, Path, HttpOnly and duplicate or unknown attributes
- Attribute values over 1024 octets, which browsers ignore
Sources and limits
Parsing follows the user-agent algorithm in draft-ietf-httpbis-rfc6265bis (sections 4.1, 5.1.1, 5.4, 5.5 and 5.6), which updates RFC 6265. The SameSite=None and Secure rule comes from MDN: Set-Cookie.
The 4096 limit is on the name and value together, in octets, as the draft states. Browsers differ in how they count attributes toward their own limits, so keep cookies well under it. A clean result means the header is well formed, not that a browser on your origin will accept or send the cookie. The draft is still a draft and may change.