Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To check a cookie’s flags, inspect the Set-Cookie response that created or refreshed it, then confirm the stored cookie in your browser’s developer tools. The response header shows what the server instructed the browser to do; the storage view shows what the browser retained. In Chrome, use DevTools’ Network and Application panels. In Firefox, use Network and Storage Inspector.

What HttpOnly and Secure mean

These are independent cookie attributes. A cookie can have one, both, or neither.

HttpOnly limits script access

When a cookie includes HttpOnly, browser JavaScript cannot read its value through APIs such as Document.cookie. The browser can still attach that cookie to JavaScript-initiated requests such as fetch() or XMLHttpRequest when the normal domain, path, same-site, and credential rules allow it. HttpOnly therefore reduces script-based theft of a cookie value; it does not stop the browser from sending the cookie.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Secure limits transmission

A cookie with Secure is sent only over HTTPS requests. Browsers document a localhost exception, so do not assume that an HTTP localhost test behaves exactly like an HTTP production host. Secure does not prevent JavaScript from reading a cookie when HttpOnly is absent.

#1 Best Overall

Look at the other attributes too

For a meaningful review, record SameSite, Domain, Path, expiration or Max-Age, and any cookie prefix. SameSite=None requires Secure. A typical session header is:

Set-Cookie: session=...; Path=/; Secure; HttpOnly; SameSite=Lax

Attribute order is not significant. Check whether the relevant attributes are present on the relevant cookie name, rather than matching one exact string layout. Prefixes such as __Secure-, __Host-, __Http-, and __Host-Http- add naming-based restrictions in browsers that support them; verify current browser support before treating a prefix as universal.

Check the setting response in Chrome

The Network panel answers the server-side question: what did the response tell Chrome to store?

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Open the site in Chrome and open DevTools with F12 or Ctrl+Shift+I (Cmd+Option+I on macOS).
  2. Select Network. Enable Preserve log if the action causes a navigation, then clear the existing requests.
  3. Perform the action that creates or refreshes the cookie, such as signing in, completing a consent choice, or loading a page that starts a session.
  4. Select the request that produced the cookie. In Headers, find Response Headers and inspect every Set-Cookie line. For the cookie you are auditing, look for the standalone attributes HttpOnly and Secure.
  5. Repeat the check after redirects or token refreshes. A later response can replace a cookie with different attributes.

Do not infer that every cookie has the same flags because one response contains them. Sites commonly set separate cookies for a session, preferences, analytics, experiments, and third-party integrations.

Confirm the stored cookie in Chrome

The Application panel answers a different question: what cookie did Chrome retain for this domain and scope?

  1. Keep DevTools open and select Application.
  2. In the left sidebar, expand Storage, then Cookies, and select the site’s origin.
  3. Find the cookie by name. Inspect the Secure and HttpOnly columns, along with Domain, Path, SameSite, and expiration.
  4. Check the exact host and path. A cookie for app.example.test or /account is not the same stored object as one for another subdomain or path.

If the cookie is missing, return to Network and repeat the action that creates it. It may be set only after login, only on a redirect response, or only for a particular path.

Check the flags in Firefox

Network response

  1. Open Firefox Developer Tools with F12 or Ctrl+Shift+I (Cmd+Option+I on macOS), then choose Network.
  2. Clear the log, perform the login or other cookie-setting action, and select the relevant request.
  3. In the response headers, inspect each Set-Cookie line for HttpOnly and Secure.

Storage Inspector

  1. Open the developer-tools menu and choose Storage (Storage Inspector).
  2. Expand Cookies and select the site or origin.
  3. Locate the cookie and inspect its Secure and HttpOnly properties, plus its domain, path, SameSite setting, and lifetime.

As in Chrome, inspect the response that actually set or refreshed the cookie and the stored entry that corresponds to it. A single request or cookie is not evidence about the application’s other flows.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect headers from a terminal

For a quick check of a publicly reachable response, save the response headers and search for Set-Cookie:

curl -sS -D headers.txt -o /dev/null https://example.com/
grep -i '^set-cookie:' headers.txt

Use the URL that performs the setting action, not merely the home page. For a test account or a flow requiring a prior session, browser DevTools is usually more practical because it already has the authentication state. Redirects can set cookies too, so inspect each response in the chain rather than looking only at the final page.

To let curl retain cookies between requests while you test a sequence, use a cookie jar:

curl -sS -c cookies.txt -D first-headers.txt -o /dev/null https://example.com/login
curl -sS -b cookies.txt -D next-headers.txt -o /dev/null https://example.com/account

This records the server’s headers and the cookies curl accepts; it does not emulate every browser policy or JavaScript step. Treat it as a repeatable HTTP check, not a replacement for verifying the browser’s stored-cookie view.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Audit more than one request

An application audit should cover every flow that can create or replace sensitive cookies:

  • Initial anonymous visit and consent response.
  • Login, logout, password reset, and account recovery.
  • Session renewal, refresh-token exchange, and privilege changes.
  • Subdomains, embedded components, and alternate paths that set their own cookies.
  • Error responses and redirects, which can set a cookie before the final page loads.

OWASP’s testing approach uses captured responses and, when useful, an intercepting proxy or traffic-capture plug-in. A proxy is helpful when you need to collect many flows or compare environments; browser tools are faster for checking one session.

How to interpret a missing flag

No HttpOnly

Scripts may be able to read that cookie. Whether this is a defect depends on the cookie’s purpose: a preference cookie might intentionally be script-readable, while a session identifier generally should not require JavaScript access. Confirm the application’s design before changing it.

No Secure

The cookie is not restricted by that attribute to HTTPS transmission. Check the actual production scheme, redirects, and cookie purpose before describing the finding’s impact. A development cookie on localhost and a production session cookie have different operational contexts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Both flags present

This is a stronger baseline for a session cookie, but it is not a complete security verdict. HttpOnly does not prevent the browser from sending the cookie, and Secure does not stop JavaScript access. Review SameSite, domain and path scope, expiration, CSRF defenses, transport configuration, and the application’s handling of any stolen session.

Troubleshooting common checks

The cookie does not appear

Repeat the action that creates it, enable Preserve log, and inspect redirects. Check that you selected the correct origin and that the cookie was not expired, deleted, or blocked by a policy.

You see a cookie but no Set-Cookie line

You may be looking at a later request. Search the Network log for the cookie name and inspect earlier responses, including redirects and API calls.

The header and storage view disagree

Compare the exact cookie name, domain, path, and creation time. A response may overwrite an older cookie, and two cookies with the same name can coexist when their paths or domains differ.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A script cannot read the cookie

That is expected for an HttpOnly cookie. Test the attribute in DevTools rather than treating the failed Document.cookie read as proof of a broader security state.

HTTPS behavior differs from localhost

Secure-cookie handling has a documented localhost exception. Reproduce the check on the same HTTPS hostname and deployment configuration used in production before drawing a conclusion.

SameSite=None is rejected

Verify that the same Set-Cookie line also includes Secure. Browsers require Secure for SameSite=None.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

ScreenshotNeo is useful when you need a visual record of a page or login step, but a screenshot cannot reveal HttpOnly or Secure flags; use DevTools or captured headers for that security check. ScreenshotNeo can still document the visible state around a test flow without configuring a headless browser. Cookie banners, newsletter popups, and chat widgets are removed before the shot; bot checks, blank pages, and failed loads are never billed; and its MCP server lets AI agents take screenshots.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

One GET request returns the image (or a PDF) and reports the result in response headers. See the ScreenshotNeo documentation for all options.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The Free plan includes 1,000 screenshots a month with no card. Paid plans start at $5 for 3,000 shots, and every plan includes the full feature set. Sign up for ScreenshotNeo free when you need repeatable page captures alongside your header-level cookie testing.

FAQ

Can I check HttpOnly with page JavaScript?

No. The point of HttpOnly is that page JavaScript cannot read that cookie value. Use the browser’s Network and storage tools instead.

Does Secure encrypt a cookie?

No. Secure restricts transmission to HTTPS (with the documented localhost exception); it is not an encryption or confidentiality guarantee for every place the cookie may exist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How many cookies must I inspect?

Inspect each cookie that matters to the flow you are auditing, including cookies set on redirects, subdomains, and different paths. One correctly configured cookie does not establish the settings of the rest.

Frequently Asked Questions

Can a cookie be both HttpOnly and readable by fetch()?

Yes. HttpOnly blocks script APIs from reading the value, while the browser may still attach it automatically to an eligible fetch or XMLHttpRequest.

Should every cookie use both flags?

Not necessarily. Decide based on the cookie’s purpose and required client-side access, then review SameSite, scope, lifetime, and the production transport as well.

What is the fastest check for one logged-in session?

Use DevTools Network to find the response that set or refreshed the cookie, then confirm the same entry in the browser’s cookie storage panel.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.