Those Boring Tools
Security ToolsPrivate by design

Cookie Security Flag Checker

Paste a Set-Cookie header to check whether it sets the Secure, HttpOnly, and SameSite security attributes.

How to use this tool

  1. 1Paste your Set-Cookie header value.
  2. 2See which security flags are set or missing.

Frequently asked questions

When would I intentionally leave HttpOnly off?+

Only if client-side JavaScript genuinely needs to read the cookie's value — for a session or auth cookie, that's usually a red flag rather than a legitimate need.

Keep the boring tools boring.

If this saved you five minutes of nonsense, you can help keep the free tools running.

Buy the toolbox a coffee