Skip to content
UniKit

Cookie string converter

Convert between Cookie headers, Set-Cookie headers and JSON: parse name=value plus Path, Domain, Max-Age, Expires, SameSite, Secure and HttpOnly, with optional URL decoding.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

Only affects values when parsing a Cookie header
Result

Multi-line Set-Cookie input is parsed into an array; Expires is normalized to ISO 8601 and Secure / HttpOnly become booleans.

What this tool does

  • Debug a session problem by parsing the Cookie header you copied out of the browser and seeing the name/value pairs, including any URL encoding.
  • Check a Set-Cookie header while writing server or test code: Path, Domain, Max-Age, Expires, SameSite, Secure and HttpOnly all become structured fields to review one by one.
  • Convert between JSON and cookie strings — turn { "a": "1" } into a=1; b=2, or store a Cookie header as JSON for later.
  • Copy multiple Set-Cookie lines out of DevTools in one go; they parse into an array and Expires is normalized to ISO 8601.

Example

Input

Set-Cookie: sid=abc; Path=/; HttpOnly; Max-Age=3600

Output

{
  "name": "sid",
  "value": "abc",
  "path": "/",
  "maxAge": 3600,
  "httpOnly": true
}

Keys are emitted in a fixed order, so the same input always produces byte-identical JSON that diffs cleanly. Secure and HttpOnly are booleans and only appear when true.

Frequently asked questions

Why are there separate modes for Cookie and Set-Cookie?

They are different structures: a Cookie header is just a semicolon-separated list of name=value pairs, whereas Set-Cookie appends attributes after the first semicolon. Using the wrong mode usually shows up as Path=/ being parsed as if it were a cookie; the tool detects the format and suggests switching.

What does the URL-decode toggle change?

Only the values when parsing a Cookie header. With it on, %E4%BD%A0 becomes 你, and an invalid %XX sequence raises an error instead of leaving mojibake behind. With it off the raw string is preserved, which is safer if you plan to call decodeURIComponent yourself.

Is the leading dot on Domain kept?

No. Per RFC 6265 the leading dot is ignored, so Domain=.example.com and Domain=example.com cover the same scope; the JSON output normalizes to the form without the dot.

Why is Expires not echoed verbatim?

Date formats vary widely (GMT, UTC, with or without a comma), so it is parsed into an ISO 8601 string that is easy to compare. When generating a Set-Cookie header the tool converts it back to the standard UTC format. An unparseable date is reported as an error.

Does any of this go over the network?

No. Parsing, assembling and JSON serialization are local string handling. Cookies often carry session credentials, so the tool deliberately makes no requests and keeps no records.

Keywords:cookieset-cookiecookie 解析cookie parser请求头请求头解析sessionjson 转换

Related tools