SCK

Set-Cookie Parser

Inspect response cookie pairs, ordered attributes, empty values and syntax diagnostics

API & HTTP
πŸ”’ 100% client-side β€” your data never leaves this page
Maintained by Evanβ€’Updated: September 30, 2026
Options
Set-Cookie Input

Paste one Set-Cookie field per line, then parse names, attributes and diagnostics. Expires is preserved as text without expiry calculation. Limit: 1 MiB and 2000 lines.

Output
Parsed result appears here
Local parsing without saved input; no expiry calculation or browser acceptance guarantee.
Page reading mode

The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.

About this tool

Set-Cookie Parser inspects one response cookie field per line, with or without the Set-Cookie: prefix. It preserves the cookie pair, attribute spelling and order, repeated attributes, and the difference between Path= and a flag without an equals sign. Cookie values must use RFC 6265 cookie-octets: surrounding quotes do not make spaces, commas, semicolons or backslashes valid. Leading and trailing ASCII whitespace around pasted pairs and attributes is tolerated; this is not a byte-for-byte producer validator. Invalid lines remain visible beside extracted rows, and any syntax error prevents the batch from being reported as successful. Attribute advisories cover decimal Max-Age, recognizable SameSite values, visible Secure and cookie-prefix requirements, repeated attributes, and extension attributes. Expires is preserved as text; the tool does not calculate expiry or select a browser-effective value from duplicates. Domain matching, public suffixes, default paths, HTTPS origins, partition keys and third-party-cookie policy need the real response and browser context. Clear or editing removes the previous result. Parsing happens in the browser with no saved input, and any legacy Set-Cookie draft is removed on opening. The limit is 1 MiB and 2000 lines.

Failure Clinic (Common Pitfalls)

Expiry attributes are visible but no clock is evaluated

Cause: Max-Age=0 and negative integers request expiry. Expires is preserved as raw text, so even an invalid date can be extracted without the tool knowing a final expiry.

Fix: Check the actual response time, URL and browser cookie store. Treat decimal checks and raw attribute inspection separately from expiry calculation.

Adding Secure does not prove that a cross-site cookie works

Cause: SameSite, HTTPS, browser settings, partitioning, domain/path matching and server behavior can all affect the result. Repeated attributes also have recipient-specific handling.

Fix: Use the visible advisory to locate an attribute worth checking, then reproduce the request in the target browser. The parser never selects a browser-effective winner from duplicate attributes.

Scenario Recipes

01

Distinguish syntax failure from a policy advisory

Goal: Compare an invalid cookie value with a visible attribute concern.

  1. Parse sid="a;b"; Secure and inspect the cookie syntax error.
  2. Replace it with sid=ok; SameSite=None and inspect the missing-Secure advisory.
  3. Add Secure and inspect the attributes again, then verify actual acceptance in browser developer tools.

Result: The text syntax and visible advisory change independently; the final browser outcome is not inferred.

Production Snippets

Empty value and valueless flag are different

text

Set-Cookie: sid=; Path=; Secure; Extension=

sid: empty cookie value
Path=: hasEquals true, empty attribute value
Secure: hasEquals false, flag
Extension=: preserved extension attribute

An empty Path receives an advisory; no response URL is supplied to resolve a default path.

Suggested Workflow

Frequently Asked Questions

Can I paste the Set-Cookie: prefix?

Yes. Each non-empty line may include it. Keep each cookie on its own line; a comma-joined bundle is not a substitute.

Do empty attributes and repeated names survive?

Yes. The attribute list preserves Path= as explicitly empty and Secure as a flag. Repeated attributes stay ordered and receive an advisory.

Why is a quoted cookie containing a semicolon invalid?

RFC 6265 still restricts the content inside surrounding quotes to cookie-octets. This differs from general HTTP quoted-string grammar.

Is a negative Max-Age an error?

Not by itself. Zero or a negative integer requests expiry. A positive integer requests a lifetime; this tool does not calculate the final expiry time.

Does the tool know whether a browser accepts the cookie?

No. Warnings inspect visible attributes only. Browser version, origin, partitioning and recipient policies must be checked in context. Expires is not date-validated here.

Are cookies kept after I leave the page?

The tool does not save inputs as drafts or include their values in analytics. Opening it removes its legacy draft key. Copying or sharing a result is your own explicit action.

Keep browsing