COOKIE

Cookie Header Parser

Read ordered request-cookie pairs, preserve duplicates and optionally decode percent escapes

API & HTTP
πŸ”’ 100% client-side β€” your data never leaves this page
Maintained by Evanβ€’Updated: September 30, 2026
Cookie request header

Request Cookie only; empty values and repeated names retain their order. Limit: 1 MiB. Input is not saved.

JSON

Parsed cookie JSON will appear here.

About this tool

Cookie Header Parser reads a single client request header containing semicolon-separated name=value pairs. It accepts the optional Cookie: prefix and keeps every pair in source order, including repeated names, empty values, quoted empty strings and equals signs inside a value. JSON exports contain a primary pairs array and an explicitly derived lastValueByName index; the index cannot describe duplicate scope and should not replace the ordered evidence. Names are HTTP tokens and values are checked against RFC 6265 cookie-octets. Outer quotes do not permit semicolons, commas, spaces, backslashes or control characters. ASCII whitespace around pasted pairs is tolerated, so this is not a strict producer-byte validator. Percent decoding is off by default because cookie encoding belongs to the application. If enabled, UTF-8 percent decoding adds a decodedValue without changing value; plus signs stay plus signs and malformed escapes retain the original value with a warning. A malformed segment makes the inspection invalid while valid pairs remain inspectable. JSON download is available only for a current result without syntax errors. This tool does not inspect Set-Cookie attributes, original Domain or Path, expiry or browser acceptance. Input stays in memory and is not saved. Maximum input is 1 MiB on one line.

Scenario Recipes

01

Find same-name request cookies without losing their order

Goal: Compare duplicate values before choosing an application-level interpretation.

  1. Parse Cookie: id=first; id=second; empty=; next=%2Faccount.
  2. Confirm pairs contains all four entries and lastValueByName.id contains only second.
  3. Enable percent decoding, parse again, and compare value=%2Faccount with decodedValue=/account; inspect scope in browser developer tools separately.

Result: The JSON retains both id entries and the empty value while clearly separating the decoded view.

Frequently Asked Questions

Does the JSON preserve duplicates?

Yes. pairs is an ordered array. lastValueByName is only a derived final-value lookup; use pairs to compare repeated names.

Can request cookies reveal their Domain or Path?

No. Cookie request fields carry pairs, not their original scope attributes. Inspect the browser cookie store or corresponding Set-Cookie responses.

What happens to an empty or quoted-empty value?

Both are valid empty values. rawValue and quoted preserve the distinction between a= and a="".

Why is percent decoding disabled initially?

It is an application convention, not a mandatory Cookie transformation. Enabling it adds a UTF-8 decoded view while retaining the raw value; + never becomes a space.

Can I paste a multi-line Set-Cookie response?

Use Set-Cookie Parser instead. This inspector accepts one request Cookie field and does not reinterpret attributes or join response cookies.

When is JSON download enabled?

After a current parse with no syntax errors. Editing input or the decode option clears stale output. Parsing and export are local and input is not stored.

Keep browsing