Skip to content
BEAD

HTTP Cookie Builder & Parser

Construct or decode Set-Cookie headers with SameSite, Secure, HttpOnly, and prefix validation.

Set-Cookie header
Set-Cookie: session=abc123; Path=/; Max-Age=86400; Secure; HttpOnly; SameSite=Lax

SameSite

Lax is sent on top-level navigations only — the modern default.Strict never crosses sites, even via clicks from another origin. None allows cross-site sends but requires Secure.

Host- and Secure- prefixes

A cookie named __Host-id must set Secure, no Domain, and Path=/ — browsers reject it otherwise. __Secure- just requires Secure. Both are belt-and-braces against subdomain takeover.

You might also like