Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To check a cookie’s flags, inspect the Set-Cookie response that created or refreshed it, then confirm the stored cookie in your browser’s developer tools. The response header shows what the server instructed the browser to do; the storage view shows what the browser retained. In Chrome, use DevTools’ Network and Application panels. In Firefox, use Network and Storage Inspector.
What HttpOnly and Secure mean
These are independent cookie attributes. A cookie can have one, both, or neither.
HttpOnly limits script access
When a cookie includes HttpOnly, browser JavaScript cannot read its value through APIs such as Document.cookie. The browser can still attach that cookie to JavaScript-initiated requests such as fetch() or XMLHttpRequest when the normal domain, path, same-site, and credential rules allow it. HttpOnly therefore reduces script-based theft of a cookie value; it does not stop the browser from sending the cookie.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallSecure limits transmission
A cookie with Secure is sent only over HTTPS requests. Browsers document a localhost exception, so do not assume that an HTTP localhost test behaves exactly like an HTTP production host. Secure does not prevent JavaScript from reading a cookie when HttpOnly is absent.
#1 Best Overall
Look at the other attributes too
For a meaningful review, record SameSite, Domain, Path, expiration or Max-Age, and any cookie prefix. SameSite=None requires Secure. A typical session header is:
Set-Cookie: session=...; Path=/; Secure; HttpOnly; SameSite=Lax
Attribute order is not significant. Check whether the relevant attributes are present on the relevant cookie name, rather than matching one exact string layout. Prefixes such as __Secure-, __Host-, __Http-, and __Host-Http- add naming-based restrictions in browsers that support them; verify current browser support before treating a prefix as universal.
Check the setting response in Chrome
The Network panel answers the server-side question: what did the response tell Chrome to store?
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →- Open the site in Chrome and open DevTools with
F12orCtrl+Shift+I(Cmd+Option+Ion macOS). - Select Network. Enable Preserve log if the action causes a navigation, then clear the existing requests.
- Perform the action that creates or refreshes the cookie, such as signing in, completing a consent choice, or loading a page that starts a session.
- Select the request that produced the cookie. In Headers, find Response Headers and inspect every
Set-Cookieline. For the cookie you are auditing, look for the standalone attributesHttpOnlyandSecure. - Repeat the check after redirects or token refreshes. A later response can replace a cookie with different attributes.
Do not infer that every cookie has the same flags because one response contains them. Sites commonly set separate cookies for a session, preferences, analytics, experiments, and third-party integrations.
Confirm the stored cookie in Chrome
The Application panel answers a different question: what cookie did Chrome retain for this domain and scope?
- Keep DevTools open and select Application.
- In the left sidebar, expand Storage, then Cookies, and select the site’s origin.
- Find the cookie by name. Inspect the Secure and HttpOnly columns, along with Domain, Path, SameSite, and expiration.
- Check the exact host and path. A cookie for
app.example.testor/accountis not the same stored object as one for another subdomain or path.
If the cookie is missing, return to Network and repeat the action that creates it. It may be set only after login, only on a redirect response, or only for a particular path.
Check the flags in Firefox
Network response
- Open Firefox Developer Tools with
F12orCtrl+Shift+I(Cmd+Option+Ion macOS), then choose Network. - Clear the log, perform the login or other cookie-setting action, and select the relevant request.
- In the response headers, inspect each
Set-Cookieline forHttpOnlyandSecure.
Storage Inspector
- Open the developer-tools menu and choose Storage (Storage Inspector).
- Expand Cookies and select the site or origin.
- Locate the cookie and inspect its Secure and HttpOnly properties, plus its domain, path, SameSite setting, and lifetime.
As in Chrome, inspect the response that actually set or refreshed the cookie and the stored entry that corresponds to it. A single request or cookie is not evidence about the application’s other flows.
Inspect headers from a terminal
For a quick check of a publicly reachable response, save the response headers and search for Set-Cookie:
curl -sS -D headers.txt -o /dev/null https://example.com/
grep -i '^set-cookie:' headers.txt
Use the URL that performs the setting action, not merely the home page. For a test account or a flow requiring a prior session, browser DevTools is usually more practical because it already has the authentication state. Redirects can set cookies too, so inspect each response in the chain rather than looking only at the final page.
To let curl retain cookies between requests while you test a sequence, use a cookie jar:
curl -sS -c cookies.txt -D first-headers.txt -o /dev/null https://example.com/login
curl -sS -b cookies.txt -D next-headers.txt -o /dev/null https://example.com/account
This records the server’s headers and the cookies curl accepts; it does not emulate every browser policy or JavaScript step. Treat it as a repeatable HTTP check, not a replacement for verifying the browser’s stored-cookie view.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsAudit more than one request
An application audit should cover every flow that can create or replace sensitive cookies:
- Initial anonymous visit and consent response.
- Login, logout, password reset, and account recovery.
- Session renewal, refresh-token exchange, and privilege changes.
- Subdomains, embedded components, and alternate paths that set their own cookies.
- Error responses and redirects, which can set a cookie before the final page loads.
OWASP’s testing approach uses captured responses and, when useful, an intercepting proxy or traffic-capture plug-in. A proxy is helpful when you need to collect many flows or compare environments; browser tools are faster for checking one session.
How to interpret a missing flag
No HttpOnly
Scripts may be able to read that cookie. Whether this is a defect depends on the cookie’s purpose: a preference cookie might intentionally be script-readable, while a session identifier generally should not require JavaScript access. Confirm the application’s design before changing it.
No Secure
The cookie is not restricted by that attribute to HTTPS transmission. Check the actual production scheme, redirects, and cookie purpose before describing the finding’s impact. A development cookie on localhost and a production session cookie have different operational contexts.
Both flags present
This is a stronger baseline for a session cookie, but it is not a complete security verdict. HttpOnly does not prevent the browser from sending the cookie, and Secure does not stop JavaScript access. Review SameSite, domain and path scope, expiration, CSRF defenses, transport configuration, and the application’s handling of any stolen session.
Troubleshooting common checks
The cookie does not appear
Repeat the action that creates it, enable Preserve log, and inspect redirects. Check that you selected the correct origin and that the cookie was not expired, deleted, or blocked by a policy.
You see a cookie but no Set-Cookie line
You may be looking at a later request. Search the Network log for the cookie name and inspect earlier responses, including redirects and API calls.
The header and storage view disagree
Compare the exact cookie name, domain, path, and creation time. A response may overwrite an older cookie, and two cookies with the same name can coexist when their paths or domains differ.
Free tools Windows power users keep installed
One-click scans. No signup required.
A script cannot read the cookie
That is expected for an HttpOnly cookie. Test the attribute in DevTools rather than treating the failed Document.cookie read as proof of a broader security state.
HTTPS behavior differs from localhost
Secure-cookie handling has a documented localhost exception. Reproduce the check on the same HTTPS hostname and deployment configuration used in production before drawing a conclusion.
SameSite=None is rejected
Verify that the same Set-Cookie line also includes Secure. Browsers require Secure for SameSite=None.
Or skip the browser setup
ScreenshotNeo is useful when you need a visual record of a page or login step, but a screenshot cannot reveal HttpOnly or Secure flags; use DevTools or captured headers for that security check. ScreenshotNeo can still document the visible state around a test flow without configuring a headless browser. Cookie banners, newsletter popups, and chat widgets are removed before the shot; bot checks, blank pages, and failed loads are never billed; and its MCP server lets AI agents take screenshots.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
One GET request returns the image (or a PDF) and reports the result in response headers. See the ScreenshotNeo documentation for all options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
The Free plan includes 1,000 screenshots a month with no card. Paid plans start at $5 for 3,000 shots, and every plan includes the full feature set. Sign up for ScreenshotNeo free when you need repeatable page captures alongside your header-level cookie testing.
Best Value
FAQ
Can I check HttpOnly with page JavaScript?
No. The point of HttpOnly is that page JavaScript cannot read that cookie value. Use the browser’s Network and storage tools instead.
Does Secure encrypt a cookie?
No. Secure restricts transmission to HTTPS (with the documented localhost exception); it is not an encryption or confidentiality guarantee for every place the cookie may exist.
How many cookies must I inspect?
Inspect each cookie that matters to the flow you are auditing, including cookies set on redirects, subdomains, and different paths. One correctly configured cookie does not establish the settings of the rest.
Frequently Asked Questions
Can a cookie be both HttpOnly and readable by fetch()?
Yes. HttpOnly blocks script APIs from reading the value, while the browser may still attach it automatically to an eligible fetch or XMLHttpRequest.
Should every cookie use both flags?
Not necessarily. Decide based on the cookie’s purpose and required client-side access, then review SameSite, scope, lifetime, and the production transport as well.
What is the fastest check for one logged-in session?
Use DevTools Network to find the response that set or refreshed the cookie, then confirm the same entry in the browser’s cookie storage panel.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

