Tools
Web Security

Cookie Flag Analyzer

Review Set-Cookie headers for HttpOnly, Secure and SameSite.

Input

Output

Results appear here.

How this helps

Missing cookie flags are one of the most common and most exploitable session weaknesses.

Everything runs locally in your browser. Never paste production secrets, tokens or real credentials into any online tool.