🍪 Cookie Inspector
View and analyze cookies set by any website to understand tracking and session data.
Which cookies this shows, and which it cannot
Type a domain and our server makes one plain request to it, then lists
every cookie the site handed back in its Set-Cookie response
headers. For each one you get the name, the value, and the
Domain, Path, Expires,
Secure and HttpOnly attributes that came with
it.
That is the server's opening move and nothing else. Cookies written later by JavaScript - most analytics, most consent managers, anything that fires after you accept a banner - never appear, because no browser runs here and no script is executed. Neither do cookies that only exist once you are logged in.
What the attributes mean
| Attribute | Effect |
|---|---|
Secure | The browser sends it over HTTPS only. Anything carrying a session should have it. |
HttpOnly | JavaScript cannot read it, which takes the cookie out of reach of a cross-site scripting bug. |
Domain | Absent, the cookie belongs to that exact host. Set to .example.com, every subdomain gets it too. |
Path | Limits it to a branch of the URL space. / means the whole site. |
Expires | A date makes it persistent and it survives a browser restart. No date at all makes it a session cookie. |
One attribute is missing from this output on purpose: cookies are read
back as parsed name-value pairs, so SameSite - which decides
whether the cookie travels on requests from other sites - is not listed.
Read the raw Set-Cookie line with the HTTP Headers tool if
you need to confirm it.
Frequently asked questions
What is the difference between a session cookie and a persistent one?
A session cookie carries no expiry date and is dropped when the browser closes, which is why logins that use one end on their own. A persistent cookie names a date and stays on disk until then, so a preference or an analytics identifier survives between visits.
Why does my browser show more cookies than this tool?
Because your browser also ran the site's JavaScript, and much of what you see under Application was written by that code, not sent in a header. This tool only fetches the page; it never executes it. The gap between the two lists is roughly the set of cookies added by scripts and tag managers.
Which of these need a consent banner?
Under the EU ePrivacy rules, cookies that are strictly necessary for a service the visitor asked for - a login session, a shopping basket, a load-balancer's routing cookie - do not need consent. Analytics, advertising and personalisation cookies do, and consent has to come before they are set. The names above rarely say which is which, so check them against what your own site actually uses.