Security ToolsPrivate by design
Cookie Security Flag Checker
Paste a Set-Cookie header to check whether it sets the Secure, HttpOnly, and SameSite security attributes.
How to use this tool
- 1Paste your Set-Cookie header value.
- 2See which security flags are set or missing.
Frequently asked questions
When would I intentionally leave HttpOnly off?+
Only if client-side JavaScript genuinely needs to read the cookie's value — for a session or auth cookie, that's usually a red flag rather than a legitimate need.
Related tools
Keep the boring tools boring.
If this saved you five minutes of nonsense, you can help keep the free tools running.
Buy the toolbox a coffee