Cookie Parser & Decoder

Paste a Cookie header, Set-Cookie lines or cookies.txt to see decoded values, which cookies a browser keeps or rejects and why, and the next request's header.

  • Runs in your browser
  • Your data never leaves your browser
  • Free · No Sign-Up
Auto recognizes header names, cookies.txt and attributes such as Path or Expires. Choose Cookie or Set-Cookie to force that format when the automatic choice does not match your input.
Options
Decode percent-encoded UTF-8 values in the table and copied JSON. Invalid escapes and non-UTF-8 bytes stay unchanged. The raw header and redacted copy keep their original encoding.
Split comma-joined Set-Cookie values, including Headers.get output, while keeping the comma in Expires dates. Turn this off to inspect the value as one Set-Cookie line.
For Cookie headers, Object keeps the first value of each name; Array keeps every cookie, including repeated names. Set-Cookie and cookies.txt exports always use arrays.
Every value is hidden by default. Session IDs and tokens only uses name and value patterns; review its output before sharing. Names and Set-Cookie attributes remain visible.

Paste a Cookie header, Set-Cookie lines or a cookies.txt file. Nothing leaves this page.

Paste Cookie or Set-Cookie headers, curl -i / -v output, Copy as cURL commands (-b or -H), or cookies.txt. Parsing runs as you type. Cookie-editor JSON exports are not supported. Nothing is saved or sent.
Parsed cookies Cookie tables show decoded values, byte counts, repeated names, known names and JWT links. Set-Cookie cards explain whether each cookie is kept, deleted or rejected. Lifetimes count from the time you parse.

Redacted copies keep cookie names and attributes. Review them before sharing.

    Build a Set-Cookie header
    Set-Cookie header Create a Set-Cookie line and a matching deletion line with the same Domain and Path. Fields update the output as you type. Enable percent-encoding when a value contains characters that cannot appear unencoded.
      Header that deletes it later
      Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.
      theme=dark; sessionid=k8Qe2Vz9LmP4tR7wX1cY3nB6; _ga=GA1.1.1234567890.1759363200; sessionid=guest; lang=en-US

      The tool marks sessionid as repeated and the JSON object keeps the first value, k8Qe2Vz9LmP4tR7wX1cY3nB6. Two cookies with one name usually means one was set with Path=/ and the other with a longer path. The simulator shows the order a browser uses:

      Cookie: sessionid=k8Qe2Vz9LmP4tR7wX1cY3nB6; sessionid=guest

      Longer paths go first, then the cookie set earlier (RFC 6265bis §5.8.3). With Copy redacted set to “session IDs and tokens only”, both sessionid values become [redacted] while theme, _ga and lang stay readable.

      These lines came back from https://www.example.com/account/login:

      Set-Cookie: __Host-session=k8Qe2Vz9LmP4tR7wX1cY3nB6; Path=/; Secure; HttpOnly; SameSite=Lax
      Set-Cookie: promo=spring; Domain=.example.com; Path=/; SameSite=None
      Set-Cookie: __Host-csrf=Zq3Lr8Tn5Wb2Ye7Hs4; Domain=www.example.com; Path=/; Secure
      Set-Cookie: cart=; Path=/; Expires=Thu, 01 Jan 1970 00:00:00 GMT
      Set-Cookie: lang=en; Path=/account; Max-Age=31536000
      • __Host-session is kept: Secure, Path=/, no Domain, as the __Host- prefix requires.
      • promo is rejected: SameSite=None needs Secure. The leading dot in .example.com is ignored, so it would have reached every subdomain.
      • __Host-csrf is rejected: a __Host- cookie may not have a Domain attribute, even one equal to the host.
      • cart deletes any existing cart cookie on path /.
      • lang is kept for 365 days (Max-Age, counted from now), only on /account and below, and gets warnings for missing Secure, HttpOnly and SameSite.

      What a Browser Does With Each Attribute

      AttributeRule the tool applies
      ExpiresRead with the cookie date algorithm of RFC 6265bis §5.1.1. 2026-10-21T07:28:00Z is not a valid cookie date, so the cookie becomes a session cookie.
      Max-AgeWins over Expires. 0 or less deletes. Lifetimes over 400 days are cut to 400 days (Chrome since 104).
      DomainA leading dot is ignored. Without Domain the cookie is host-only; with it, every subdomain gets the cookie. A public suffix from the Public Suffix List is refused: sid=x; Domain=co.uk from https://shop.co.uk/ is rejected, and so is Domain=github.io (a private-section rule). If the Domain equals the response host, the cookie becomes host-only (RFC 6265bis §5.7 step 9).
      PathMissing or not starting with /: the directory of the response URL.
      SameSiteMissing: Lax in Chrome 80+ and Edge 86+, not in Firefox or Safari (MDN browser data). None requires Secure.
      PartitionedRequires Secure (CHIPS); Chrome 114+, Firefox 141+, Safari 26.2+.
      Prefixes__Secure- needs Secure; __Host- needs Secure, Path=/ and no Domain; __Http- and __Host-Http- also need HttpOnly (layered cookies draft, Chrome 140+, Firefox 143+). Matched without regard to case.
      SizeName plus value over 4096 bytes of UTF-8: the cookie is ignored. An attribute value over 1024 bytes: that attribute is ignored.

      Where Chrome Differs From the Specification

      We sent each line from a local test server to Chromium 152 on 2026-10-02 and read back what it stored. Chromium followed RFC 6265bis on dates, sizes, prefixes, SameSite=None and Partitioned, and differed on these points. The tool follows the RFC and adds a note when a line hits one of them:

      • Max-Age=+60 is ignored by the RFC; Chromium accepts it as 60 seconds.
      • A tab inside a value is allowed by the RFC; Chromium rejects the cookie.
      • Domain=. is an empty domain (host-only) in the RFC; Chromium rejects the cookie.
      • When a cookie is replaced, Chromium gives it a new creation time, so it moves after cookies set before it. The RFC keeps the old time.
      ReaderRepeated name"quoted" valueA space in a value
      Express 5 req.cookies (cookie-parser 1.4.7, cookie 0.7.2)first winsquotes removedkept
      The cookie package 1.1.1first winsquotes keptkept
      Python 3.12 http.cookieslast winsquotes removedthe whole header is dropped
      PHP 8.4 $_COOKIEfirst winsquotes keptkept

      PHP also turns dots and spaces in names into underscores, so connect.sid arrives as $_COOKIE['connect_sid']. The tool notes each of these cases on the cookie row.

      On 2026-10-02 we pasted the same inputs into the top Bing results for “cookie parser” in four languages: ToolsForNerds, iotools.cloud, UU在线工具, Torinoa Tools and LiteDevTools. None sent the text to a server. ToolsForNerds, UU在线工具 and Torinoa read three Set-Cookie: lines as one cookie named Set-Cookie: promo, with the next line glued to its SameSite or Max-Age value. iotools.cloud and LiteDevTools (in its Set-Cookie mode) split the lines but list attributes as plain text. None of the five flagged SameSite=None without Secure or a __Host- cookie with Domain, or said that Max-Age=0 deletes the cookie. For sid=new; theme=dark; sid=old, UU在线工具’s JSON kept old, the value Express and PHP do not use.

      Limits

      • Public suffixes come from a fixed copy of the Public Suffix List (version 2026-10-01, both the ICANN and the private sections, with wildcard and exception rules). The list is updated often; a suffix added later is not known to the tool, and browsers ship their own copy at their own pace. The list (about 45 KB compressed) loads the first time you parse Set-Cookie lines or a cookies.txt file. Until it has loaded, or if it fails to load, a cookie with a Domain attribute is marked “Not verified”, is left out of the request simulation, and its Domain is not judged.
      • The simulator assumes each Set-Cookie line came from a top-level response, with no cookies stored before. It does not model Chrome’s two-minute exception that sends new Lax-by-default cookies with cross-site POSTs.
      • Lifetimes are counted from the moment you paste, not from the response time.
      • JSON exports from cookie editor extensions are not read; paste a Cookie header or a cookies.txt file instead.

      FAQ

      Why does my Cookie header contain the same name twice?

      A browser keys cookies by name, domain and path. A cookie set with Path=/ and another with the same name set with Path=/account are two cookies, and a request to /account carries both, the longer path first. Servers do not agree on which one to use: Express (the cookie package) and PHP take the first, Python's http.cookies takes the last. Delete the stale one with a Set-Cookie line that repeats its exact Domain and Path plus Max-Age=0.

      Why did the browser ignore my Set-Cookie header?

      The common reasons are SameSite=None without Secure, a __Host- cookie with a Domain attribute or without Path=/, a Domain that does not cover the response host, a Secure cookie set from an http:// page, and a name plus value over 4096 bytes. Paste the line here with the response URL; the card for that cookie says Rejected and gives the reason.

      Which wins, Expires or Max-Age?

      Max-Age. If both are present, the browser uses Max-Age and ignores Expires. Max-Age=0 or a negative number deletes the cookie, and browsers cap any lifetime at 400 days.

      What happens if I leave SameSite out?

      Chrome (since 80) and Edge (since 86) treat the cookie as SameSite=Lax: it is sent when the user follows a link to your site, but not with cross-site iframes, fetch calls or form POSTs. Firefox and Safari still send it cross-site. Set SameSite explicitly so all browsers behave the same.

      Is the cookie data sent anywhere?

      No. The page parses the text in your browser and sends no request with it, saves nothing, and does not load Google Analytics or AdSense, because cookies often hold session IDs. Copy redacted replaces values with [redacted] before you paste them into a ticket.