Skip to content
Solvex Space

Cybersecurity · free, no signup

Cookie Security Auditor

Paste one or more Set-Cookie header lines to audit how each cookie is scoped and protected. Reports missing Secure, HttpOnly and SameSite protection, over-broad Domain and Path scoping, prefix violations and lifetime problems — with each cookie's own attributes quoted as the evidence behind every finding.

Authorized, defensive use only. Check assets you own or lawfully public data. This tool is educational and never provides another party's private data.

Paste one or more Set-Cookie header lines, one per line. Attributes are what get audited — scope, protection flags, prefixes and lifetime. Cookie values are never stored, and you are welcome to redact them before pasting.

One header line per cookie. Values may be redacted — only attributes are analysed.

Lets the audit reason about Domain scope and prefix rules for your actual origin.

What happens to what you enter

  • The analysis runs on Solvex servers. What is recorded afterwards is a SHA-256 hash of your input and a coarse summary of the outcome — never the input itself, and never a result you could be identified from.
  • Tools that read public sources (certificate logs, DNS, a public chain) contact those sources from our servers through a fetcher that refuses private and internal addresses.
  • An email address is stored only where a tool offers to send you a report and you choose to give one.

Limits: ten runs of this tool per minute from one address, and three signed reports per minute. Past that the tool says so and tells you when to try again.

When a free check is not enough

This tool reads what is public and reports what it can see. The Web Application Penetration Testing engagement is the authorized, specialist-led version: signed scope, findings proven by hand, a signed report, and a retest.

Explore Web Application Penetration Testing
Cookie Security Auditor — Solvex Space