Cookie Parser & Decoder
Paste a Cookie header, Set-Cookie lines or cookies.txt to see decoded values, which cookies a browser keeps or rejects and why, and the next request's header.
- Runs in your browser
- Your data never leaves your browser
- Free · No Sign-Up
Scan with WeChat to share this tool
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.
Example: A Cookie Header With a Repeated Name
theme=dark; sessionid=k8Qe2Vz9LmP4tR7wX1cY3nB6; _ga=GA1.1.1234567890.1759363200; sessionid=guest; lang=en-US
The tool marks sessionid as repeated and the JSON object keeps the first value, k8Qe2Vz9LmP4tR7wX1cY3nB6. Two cookies with one name usually means one was set with Path=/ and the other with a longer path. The simulator shows the order a browser uses:
Cookie: sessionid=k8Qe2Vz9LmP4tR7wX1cY3nB6; sessionid=guest
Longer paths go first, then the cookie set earlier (RFC 6265bis §5.8.3). With Copy redacted set to “session IDs and tokens only”, both sessionid values become [redacted] while theme, _ga and lang stay readable.
Example: Set-Cookie Lines From a Login Response
These lines came back from https://www.example.com/account/login:
Set-Cookie: __Host-session=k8Qe2Vz9LmP4tR7wX1cY3nB6; Path=/; Secure; HttpOnly; SameSite=Lax
Set-Cookie: promo=spring; Domain=.example.com; Path=/; SameSite=None
Set-Cookie: __Host-csrf=Zq3Lr8Tn5Wb2Ye7Hs4; Domain=www.example.com; Path=/; Secure
Set-Cookie: cart=; Path=/; Expires=Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: lang=en; Path=/account; Max-Age=31536000
__Host-sessionis kept: Secure, Path=/, no Domain, as the__Host-prefix requires.promois rejected:SameSite=NoneneedsSecure. The leading dot in.example.comis ignored, so it would have reached every subdomain.__Host-csrfis rejected: a__Host-cookie may not have a Domain attribute, even one equal to the host.cartdeletes any existingcartcookie on path/.langis kept for 365 days (Max-Age, counted from now), only on/accountand below, and gets warnings for missing Secure, HttpOnly and SameSite.
What a Browser Does With Each Attribute
| Attribute | Rule the tool applies |
|---|---|
Expires | Read with the cookie date algorithm of RFC 6265bis §5.1.1. 2026-10-21T07:28:00Z is not a valid cookie date, so the cookie becomes a session cookie. |
Max-Age | Wins over Expires. 0 or less deletes. Lifetimes over 400 days are cut to 400 days (Chrome since 104). |
Domain | A leading dot is ignored. Without Domain the cookie is host-only; with it, every subdomain gets the cookie. A public suffix from the Public Suffix List is refused: sid=x; Domain=co.uk from https://shop.co.uk/ is rejected, and so is Domain=github.io (a private-section rule). If the Domain equals the response host, the cookie becomes host-only (RFC 6265bis §5.7 step 9). |
Path | Missing or not starting with /: the directory of the response URL. |
SameSite | Missing: Lax in Chrome 80+ and Edge 86+, not in Firefox or Safari (MDN browser data). None requires Secure. |
Partitioned | Requires Secure (CHIPS); Chrome 114+, Firefox 141+, Safari 26.2+. |
| Prefixes | __Secure- needs Secure; __Host- needs Secure, Path=/ and no Domain; __Http- and __Host-Http- also need HttpOnly (layered cookies draft, Chrome 140+, Firefox 143+). Matched without regard to case. |
| Size | Name plus value over 4096 bytes of UTF-8: the cookie is ignored. An attribute value over 1024 bytes: that attribute is ignored. |
Where Chrome Differs From the Specification
We sent each line from a local test server to Chromium 152 on 2026-10-02 and read back what it stored. Chromium followed RFC 6265bis on dates, sizes, prefixes, SameSite=None and Partitioned, and differed on these points. The tool follows the RFC and adds a note when a line hits one of them:
Max-Age=+60is ignored by the RFC; Chromium accepts it as 60 seconds.- A tab inside a value is allowed by the RFC; Chromium rejects the cookie.
Domain=.is an empty domain (host-only) in the RFC; Chromium rejects the cookie.- When a cookie is replaced, Chromium gives it a new creation time, so it moves after cookies set before it. The RFC keeps the old time.
How Servers Read the Cookie Header
| Reader | Repeated name | "quoted" value | A space in a value |
|---|---|---|---|
Express 5 req.cookies (cookie-parser 1.4.7, cookie 0.7.2) | first wins | quotes removed | kept |
| The cookie package 1.1.1 | first wins | quotes kept | kept |
| Python 3.12 http.cookies | last wins | quotes removed | the whole header is dropped |
PHP 8.4 $_COOKIE | first wins | quotes kept | kept |
PHP also turns dots and spaces in names into underscores, so connect.sid arrives as $_COOKIE['connect_sid']. The tool notes each of these cases on the cookie row.
Compared With Other Cookie Parsers
On 2026-10-02 we pasted the same inputs into the top Bing results for “cookie parser” in four languages: ToolsForNerds, iotools.cloud, UU在线工具, Torinoa Tools and LiteDevTools. None sent the text to a server. ToolsForNerds, UU在线工具 and Torinoa read three Set-Cookie: lines as one cookie named Set-Cookie: promo, with the next line glued to its SameSite or Max-Age value. iotools.cloud and LiteDevTools (in its Set-Cookie mode) split the lines but list attributes as plain text. None of the five flagged SameSite=None without Secure or a __Host- cookie with Domain, or said that Max-Age=0 deletes the cookie. For sid=new; theme=dark; sid=old, UU在线工具’s JSON kept old, the value Express and PHP do not use.
Limits
- Public suffixes come from a fixed copy of the Public Suffix List (version 2026-10-01, both the ICANN and the private sections, with wildcard and exception rules). The list is updated often; a suffix added later is not known to the tool, and browsers ship their own copy at their own pace. The list (about 45 KB compressed) loads the first time you parse Set-Cookie lines or a cookies.txt file. Until it has loaded, or if it fails to load, a cookie with a Domain attribute is marked “Not verified”, is left out of the request simulation, and its Domain is not judged.
- The simulator assumes each Set-Cookie line came from a top-level response, with no cookies stored before. It does not model Chrome’s two-minute exception that sends new Lax-by-default cookies with cross-site POSTs.
- Lifetimes are counted from the moment you paste, not from the response time.
- JSON exports from cookie editor extensions are not read; paste a Cookie header or a cookies.txt file instead.
FAQ
Why does my Cookie header contain the same name twice?
A browser keys cookies by name, domain and path. A cookie set with Path=/ and another with the same name set with Path=/account are two cookies, and a request to /account carries both, the longer path first. Servers do not agree on which one to use: Express (the cookie package) and PHP take the first, Python's http.cookies takes the last. Delete the stale one with a Set-Cookie line that repeats its exact Domain and Path plus Max-Age=0.
Why did the browser ignore my Set-Cookie header?
The common reasons are SameSite=None without Secure, a __Host- cookie with a Domain attribute or without Path=/, a Domain that does not cover the response host, a Secure cookie set from an http:// page, and a name plus value over 4096 bytes. Paste the line here with the response URL; the card for that cookie says Rejected and gives the reason.
Which wins, Expires or Max-Age?
Max-Age. If both are present, the browser uses Max-Age and ignores Expires. Max-Age=0 or a negative number deletes the cookie, and browsers cap any lifetime at 400 days.
What happens if I leave SameSite out?
Chrome (since 80) and Edge (since 86) treat the cookie as SameSite=Lax: it is sent when the user follows a link to your site, but not with cross-site iframes, fetch calls or form POSTs. Firefox and Safari still send it cross-site. Set SameSite explicitly so all browsers behave the same.
Is the cookie data sent anywhere?
No. The page parses the text in your browser and sends no request with it, saves nothing, and does not load Google Analytics or AdSense, because cookies often hold session IDs. Copy redacted replaces values with [redacted] before you paste them into a ticket.