Security and networkingChecked through WebDiag API

Cookie Policy Checker

Enter a URL to inspect Set-Cookie headers without browser session tracking or consent-banner analysis.

  • Secure
  • HttpOnly
  • SameSite
Online tool

Try the tool

Enter a URL: WebDiag will run a safe network check and show the result.

URL

Network check through backend

For HTTP/SEO tools, the URL is sent to the WebDiag API, where SSRF protection, DNS/IP policy, and redirect limits are applied.

Reviewed: 2026-07-17
01

How to use it

  1. 1

    Enter a public URL.

  2. 2

    Run the cookie policy check.

  3. 3

    Review Set-Cookie count, attributes, and issues.

02

What the tool can do

  • Checks Secure, HttpOnly, and SameSite.
  • Flags SameSite=None without Secure.
  • Marks persistent cookies by Max-Age/Expires.
03

Common use cases

  • Find cookies missing Secure or HttpOnly.
  • Check SameSite policy after release.
  • Prepare a baseline for security review.
04

How it works inside

The tool does not assess legal compliance of cookie banners.

Some cookies may appear only after JavaScript or login flows.

05

Questions and answers

Is this a legal cookie audit?

No. This is a technical Set-Cookie attribute check, not legal consent assessment.

Why are there no cookies?

The response may not set cookies before login, JavaScript flow, or consent choice.