🍪 Cookie Inspector

View and analyze cookies set by any website to understand tracking and session data.

💡 Tip: Enter a domain and click "Inspect Cookies" to view all cookies set by that site.
Enter a domain and click "Inspect Cookies" to view results.

Which cookies this shows, and which it cannot

Type a domain and our server makes one plain request to it, then lists every cookie the site handed back in its Set-Cookie response headers. For each one you get the name, the value, and the Domain, Path, Expires, Secure and HttpOnly attributes that came with it.

That is the server's opening move and nothing else. Cookies written later by JavaScript - most analytics, most consent managers, anything that fires after you accept a banner - never appear, because no browser runs here and no script is executed. Neither do cookies that only exist once you are logged in.

An empty result usually means the site sets its cookies from JavaScript, not that it sets none. Your browser's developer tools, under Application, show the full picture for a real visit.

What the attributes mean

AttributeEffect
SecureThe browser sends it over HTTPS only. Anything carrying a session should have it.
HttpOnlyJavaScript cannot read it, which takes the cookie out of reach of a cross-site scripting bug.
DomainAbsent, the cookie belongs to that exact host. Set to .example.com, every subdomain gets it too.
PathLimits it to a branch of the URL space. / means the whole site.
ExpiresA date makes it persistent and it survives a browser restart. No date at all makes it a session cookie.

One attribute is missing from this output on purpose: cookies are read back as parsed name-value pairs, so SameSite - which decides whether the cookie travels on requests from other sites - is not listed. Read the raw Set-Cookie line with the HTTP Headers tool if you need to confirm it.

Frequently asked questions

What is the difference between a session cookie and a persistent one?

A session cookie carries no expiry date and is dropped when the browser closes, which is why logins that use one end on their own. A persistent cookie names a date and stays on disk until then, so a preference or an analytics identifier survives between visits.

Why does my browser show more cookies than this tool?

Because your browser also ran the site's JavaScript, and much of what you see under Application was written by that code, not sent in a header. This tool only fetches the page; it never executes it. The gap between the two lists is roughly the set of cookies added by scripts and tag managers.

Which of these need a consent banner?

Under the EU ePrivacy rules, cookies that are strictly necessary for a service the visitor asked for - a login session, a shopping basket, a load-balancer's routing cookie - do not need consent. Analytics, advertising and personalisation cookies do, and consent has to come before they are set. The names above rarely say which is which, so check them against what your own site actually uses.