ToolAssay

Parse Set-Cookie headers and report their attributes

Parse Set-Cookie headers and report their attributes. Names cookies with no Secure, no HttpOnly or no SameSite; SameSite=None without Secure, which browsers reject so the cookie is never set at all; an unrecognised SameSite value, where the default applies instead; a lifetime beyond a stated maximum; an unexpected Domain; and a Domain attribute at all, which widens a cookie to every subdomain. No cookie value is returned, only its length.

Answeringour last check, 2026-10-04
1 of 1checks answered this week
2653 msmedian answer time
$0.12listed price per call
$0.12price it asked us

Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.

Endpoint

POST https://api.zfinia.com/x402/v1/cookie-attribute-audit

CategoryCode and developer
Provider hostapi.zfinia.com
Networkseip155:8453
Payment schemesexact
Self-reported calls, 30 days1 from 1 payers (the provider's figure, not ours)

Our checks, last 30 days

DayResultHTTPAskedTime
2026-10-04 valid payment request 402$0.12 2653 ms

Example input (from the provider)

{
  "body": {
    "contract": {
      "expected_domain": "example.test",
      "max_age_seconds": 86400,
      "require_http_only": true,
      "require_same_site": true,
      "require_secure": true
    },
    "set_cookie": [
      "session=abc123; Path=/; HttpOnly; Secure; SameSite=Lax; Max-Age=86400",
      "analytics_id=zz; Path=/; Domain=.example.test; Max-Age=31536000",
      "embed_state=1; Path=/; SameSite=None",
      "legacy=1; Path=/; Secure; HttpOnly; SameSite=Lax; Max-Age=63072000"
    ]
  },
  "bodyType": "json",
  "method": "POST",
  "type": "http"
}

Promised output schema (from the provider)

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "input": {
      "additionalProperties": false,
      "properties": {
        "body": {
          "additionalProperties": false,
          "properties": {
            "contract": {
              "additionalProperties": false,
              "properties": {
                "expected_domain": {
                  "maxLength": 256,
                  "type": "string"
                },
                "forbid_same_site_none": {
                  "type": "boolean"
                },
                "max_age_seconds": {
                  "minimum": 0,
                  "type": "number"
                },
                "require_http_only": {
                  "type": "boolean"
                },
                "require_same_site": {
                  "type": "boolean"
                },
                "require_secure": {
                  "type": "boolean"
                }
              },
              "type": "object"
            },
            "set_cookie": {
              "items": {
                "maxLength": 8192,
                "type": "string"
              },
              "maxItems": 100,
              "minItems": 1,
              "type": "array"
            }
          },
          "required": [
            "set_cookie"
          ],
          "type": "object"
        },
        "bodyType": {
          "enum": [
            "json",
            "form-data",
            "text"
          ],
          "type": "string"
        },
        "method": {
          "enum": [
            "POST"
          ],
          "type": "string"
        },
        "type": {
          "const": "http",
          "type": "string"
        }
      },
      "required": [
        "type",
        "method",
        "bodyType",
        "body"
      ],
      "type": "object"
    },
    "output": {
      "properties": {
        "example": {
          "type": "object"
        },
        "type": {
          "type": "string"
        }
      },
      "required": [
        "type"
      ],
      "type": "object"
    }
  },
  "required": [
    "input"
  ],
  "type": "object"
}

This page as JSON