Set-Cookie Parser
Inspect response cookie pairs, ordered attributes, empty values and syntax diagnostics
Paste one Set-Cookie field per line, then parse names, attributes and diagnostics. Expires is preserved as text without expiry calculation. Limit: 1 MiB and 2000 lines.
The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
Set-Cookie Parser inspects one response cookie field per line, with or without the Set-Cookie: prefix. It preserves the cookie pair, attribute spelling and order, repeated attributes, and the difference between Path= and a flag without an equals sign. Cookie values must use RFC 6265 cookie-octets: surrounding quotes do not make spaces, commas, semicolons or backslashes valid. Leading and trailing ASCII whitespace around pasted pairs and attributes is tolerated; this is not a byte-for-byte producer validator. Invalid lines remain visible beside extracted rows, and any syntax error prevents the batch from being reported as successful. Attribute advisories cover decimal Max-Age, recognizable SameSite values, visible Secure and cookie-prefix requirements, repeated attributes, and extension attributes. Expires is preserved as text; the tool does not calculate expiry or select a browser-effective value from duplicates. Domain matching, public suffixes, default paths, HTTPS origins, partition keys and third-party-cookie policy need the real response and browser context. Clear or editing removes the previous result. Parsing happens in the browser with no saved input, and any legacy Set-Cookie draft is removed on opening. The limit is 1 MiB and 2000 lines.
Failure Clinic (Common Pitfalls)
Expiry attributes are visible but no clock is evaluated
Cause: Max-Age=0 and negative integers request expiry. Expires is preserved as raw text, so even an invalid date can be extracted without the tool knowing a final expiry.
Fix: Check the actual response time, URL and browser cookie store. Treat decimal checks and raw attribute inspection separately from expiry calculation.
Adding Secure does not prove that a cross-site cookie works
Cause: SameSite, HTTPS, browser settings, partitioning, domain/path matching and server behavior can all affect the result. Repeated attributes also have recipient-specific handling.
Fix: Use the visible advisory to locate an attribute worth checking, then reproduce the request in the target browser. The parser never selects a browser-effective winner from duplicate attributes.
Scenario Recipes
Distinguish syntax failure from a policy advisory
Goal: Compare an invalid cookie value with a visible attribute concern.
- Parse sid="a;b"; Secure and inspect the cookie syntax error.
- Replace it with sid=ok; SameSite=None and inspect the missing-Secure advisory.
- Add Secure and inspect the attributes again, then verify actual acceptance in browser developer tools.
Result: The text syntax and visible advisory change independently; the final browser outcome is not inferred.
Production Snippets
Empty value and valueless flag are different
text
Set-Cookie: sid=; Path=; Secure; Extension=
sid: empty cookie value
Path=: hasEquals true, empty attribute value
Secure: hasEquals false, flag
Extension=: preserved extension attribute
An empty Path receives an advisory; no response URL is supplied to resolve a default path.Suggested Workflow
Fix Credentialed CORS: Check Origins, Preflight and Cookies
Trace a credentialed cross-origin request through OPTIONS and the actual response, then test allowed origins, rejected origins and cookie behavior.
SameSite=None Requires Secure: Cookie Fix Playbook
Resolve cross-site login/session failures caused by cookie attribute mismatch in modern browsers.
Cache-Control no-store with max-age: What It Means and What to Check
Interpret no-store, max-age, no-cache, private, and public with separate sensitive and public-response examples, then check the headers actually served.
Frequently Asked Questions
Can I paste the Set-Cookie: prefix?
Yes. Each non-empty line may include it. Keep each cookie on its own line; a comma-joined bundle is not a substitute.
Do empty attributes and repeated names survive?
Yes. The attribute list preserves Path= as explicitly empty and Secure as a flag. Repeated attributes stay ordered and receive an advisory.
Why is a quoted cookie containing a semicolon invalid?
RFC 6265 still restricts the content inside surrounding quotes to cookie-octets. This differs from general HTTP quoted-string grammar.
Is a negative Max-Age an error?
Not by itself. Zero or a negative integer requests expiry. A positive integer requests a lifetime; this tool does not calculate the final expiry time.
Does the tool know whether a browser accepts the cookie?
No. Warnings inspect visible attributes only. Browser version, origin, partitioning and recipient policies must be checked in context. Expires is not date-validated here.
Are cookies kept after I leave the page?
The tool does not save inputs as drafts or include their values in analytics. Opening it removes its legacy draft key. Copying or sharing a result is your own explicit action.
Keep browsing