Web Security
Cookie Flag Analyzer
Review Set-Cookie headers for HttpOnly, Secure and SameSite.
Input
Output
Results appear here.How this helps
Missing cookie flags are one of the most common and most exploitable session weaknesses.
Everything runs locally in your browser. Never paste production secrets, tokens or real credentials into any online tool.