Utilxodeveloper utilities
Catalog

Identity & Auth

CIBA (Decoupled Auth)
Client ID Metadata Document
DPoP Proof & Header Debugger
Dynamic Client Registration
JWT Workbench
OAuth / OIDC RP
PKCE Playground
SAML 2.0 SP
Token Exchange & Delegation Studio
WebAuthn & Passkeys

Network & APIs

Cookie & Header Inspector
CSP Evaluator & Builder
cURL to Code
HAR File Analyzer
HTTP & REST Client
iFrame Studio
SSE / EventSource Debugger
Webhook Catch & Inspect
WebSocket Tester

Crypto & Certs

Hash & Checksum Studio
HMAC Signature Workbench
JWE Encrypt / Decrypt
JWK Generator
JWKS Builder
TLS/SSL Inspector
Universal Key Converter
X.509 Cert & CSR Generator
X.509 Decoder

Formatters & Utilities

Base64 & Base64URL Encoder/Decoder
Cron Expression Studio
Diagram & Sequence Workbench
Diff Workbench
HTML Prettifier
JSON Formatter
JSON Structural Diff
Markdown Live Preview
Mock Data Generator
Regex Tester & Explainer
Schema Generator
Text Editor
Time & Epoch Studio
UUID / ULID / Snowflake Decoder
UUID & ULID Generator

Data & Markup

Protobuf Wire Inspector
SQL ↔ JSON / CSV Converter
YAML ↔ JSON ↔ TOML

AI & Prompts

AI Prompt Studio

Media & Imaging

Initials & Avatar Studio
Passport Photo Cropper
QR Code Studio

Identity & Auth

CIBA (Decoupled Auth)
Client ID Metadata Document
DPoP Proof & Header Debugger
Dynamic Client Registration
JWT Workbench
OAuth / OIDC RP
PKCE Playground
SAML 2.0 SP
Token Exchange & Delegation Studio
WebAuthn & Passkeys

Network & APIs

Cookie & Header Inspector
CSP Evaluator & Builder
cURL to Code
HAR File Analyzer
HTTP & REST Client
iFrame Studio
SSE / EventSource Debugger
Webhook Catch & Inspect
WebSocket Tester

Crypto & Certs

Hash & Checksum Studio
HMAC Signature Workbench
JWE Encrypt / Decrypt
JWK Generator
JWKS Builder
TLS/SSL Inspector
Universal Key Converter
X.509 Cert & CSR Generator
X.509 Decoder

Formatters & Utilities

Base64 & Base64URL Encoder/Decoder
Cron Expression Studio
Diagram & Sequence Workbench
Diff Workbench
HTML Prettifier
JSON Formatter
JSON Structural Diff
Markdown Live Preview
Mock Data Generator
Regex Tester & Explainer
Schema Generator
Text Editor
Time & Epoch Studio
UUID / ULID / Snowflake Decoder
UUID & ULID Generator

Data & Markup

Protobuf Wire Inspector
SQL ↔ JSON / CSV Converter
YAML ↔ JSON ↔ TOML

AI & Prompts

AI Prompt Studio

Media & Imaging

Initials & Avatar Studio
Passport Photo Cropper
QR Code Studio
HomeNetwork & APIsCookie & Header Inspector

Cookie & Header Inspector

Parse Set-Cookie headers — SameSite, Secure, HttpOnly, and CHIPS Partitioned attributes.

Privacy: 100% Client-Side. Your data never leaves this browser tab. Processing uses Web APIs and client-side libraries only.

Paste a Set-Cookie header or document.cookie snippet. Supports Partitioned (CHIPS) with Secure / SameSite checks.

session= abc123
SecureHttpOnlySameSite=Lax
path
/
domain
.example.com
httponly
true
secure
true
samesite
Lax
max-age
3600
expires in
59m 59s (2026-08-08T03:54:13.025Z)
theme= dark
SameSite=Strict
path
/
samesite
Strict
max-age
86400
expires in
23h 59m 59s (2026-08-09T02:54:13.025Z)
  • ⚠ Missing Secure flag
  • ⚠ Missing HttpOnly (readable by JS)
__Host-3p= embed42
SecureHttpOnlySameSite=NoneCHIPS · Partitioned
path
/
secure
true
httponly
true
samesite
None
partitioned (CHIPS)
true
max-age
604800
expires in
6d 23h 59m (2026-08-15T02:54:13.025Z)
  • ℹ CHIPS: Partitioned — cookie is keyed by top-level site + host (third-party opt-in).
  • ℹ CHIPS: __Host- prefix recommended — binds cookie to host (no Domain, Path=/).
legacy_3p= old
SecureSameSite=None
path
/
secure
true
samesite
None
max-age
3600
expires in
59m 59s (2026-08-08T03:54:13.025Z)
  • ℹ SameSite=None without Partitioned may be blocked as a third-party cookie — consider CHIPS (Partitioned).
  • ⚠ Missing HttpOnly (readable by JS)

Why inspect Set-Cookie headers?

Browsers enforce cookie policy through attributes like SameSite, Secure, HttpOnly, and Partitioned (CHIPS). Misconfigured cookies break SSO, CSRF protections, and third-party embeds.

This inspector parses raw Set-Cookie lines locally so you can verify attributes without sending header dumps to a server.

How to use this tool

  1. Paste one or more Set-Cookie header values into Cookie & Header Inspector.
  2. Review parsed attributes such as SameSite, Secure, HttpOnly, Path, Domain, and Partitioned.
  3. Compare the flags against what your app or IdP expects for the current browser context.

Frequently asked questions

Are cookie values uploaded?

No. Parsing runs entirely in your browser. Session cookies and secrets never leave the tab.

© 2026 utilxo.com • Built by Shachindra Tiwari • 100% Client-Side & Privacy-First

Contact•LinkedIn•Privacy Policy•