Skip to content
ToolSuite

Set-Cookie Generator

Build a correct Set-Cookie header with the security attributes chosen deliberately.

0 makes it a session cookie.

Processed in your browser

Your result will appear here as soon as you add some input.

How to use it

  1. 1Paste your input into the input box, or type it directly.
  2. 2Adjust the options if you need something other than the defaults.
  3. 3The result updates as you type.
  4. 4Copy the result to your clipboard or download it as a file.

About the Set-Cookie Generator

Leaving Domain blank produces a host-only cookie, which is the safer default: setting a domain shares the cookie with every subdomain, including any one an attacker manages to control.

SameSite=None is required for genuine cross-site use and forces Secure. It also removes the browser-level CSRF protection the other values give you, so a token becomes mandatory.

Questions people ask

Is your code uploaded to a server?

No. This tool runs entirely in your browser using standard web APIs, so your code never leaves your device. You can confirm it by opening your browser's network panel while the tool runs, or by disconnecting from the internet after the page has loaded.

Is it free, and do I need an account?

Yes, it is free, and there is no account, no sign-up and no watermark on the result. The project is funded by optional donations.