Skip to content

HTTP Cookie Builder

Build a Set-Cookie header and matching document.cookie line with Secure, HttpOnly, SameSite, Path, Domain, Expires, Max-Age and Partitioned.

HTTP Cookie Builder

Flags

Set-Cookie header
Set-Cookie: session=abc123; Path=/; Secure; HttpOnly; SameSite=Lax
JavaScript
document.cookie = "session=abc123; path=/; secure; samesite=Lax";

Updated . Provided as is. Check the output before you rely on it in production.

Questions and answers

What is HTTP Cookie Builder?
Set-Cookie is the HTTP response header a server uses to store a cookie in the browser, with attributes that control its scope, lifetime and security. This builder assembles the header from a name, value and attributes, writes a matching document.cookie line, and warns when SameSite=None or Partitioned lacks Secure.
How do I use HTTP Cookie Builder?
Fill in the cookie name and value, configure optional attributes like Path, Domain, and Expires, then toggle flags such as Secure, HttpOnly, and SameSite. The Set-Cookie header and JavaScript snippet update instantly. Click Copy to grab either output.
Is HTTP Cookie Builder free?
Yes. Completely free with no sign-up required.
What does SameSite=None require?
Cookies with SameSite=None must also have the Secure flag set. The tool will warn you if this combination is missing, because browsers will reject cookies that violate this requirement.
What is the Partitioned attribute?
Partitioned is the Set-Cookie attribute behind CHIPS (Cookies Having Independent Partitioned State): a third-party cookie is stored in a separate jar per top-level site, so it cannot follow a user across sites. The builder adds it as a toggle and warns if Secure is not also set.

Use it as an API

HTTP Cookie Builder is also callable as a free HTTP JSON API at https://aidevhub.io/api/http-cookie-builder/ — GET with query parameters or POST with a JSON body, no authentication, CORS enabled, fair use (abusive traffic is throttled at the edge; there is no per-request quota header). Responses return { ok, tool, result, meta }.

curl -s "https://aidevhub.io/api/http-cookie-builder/?name=session&value=abc123&secure=true&same_site=Lax"

Machine-readable contract: /api/tool/http-cookie-builder.json All API endpoints: /agents/ LLM site index: /llms.txt

For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Dedicated API endpoint

Deterministic outputs, machine-safe contracts, and production-ready examples.

Dedicated API

https://aidevhub.io/api/http-cookie-builder/

OpenAPI: https://aidevhub.io/api/openapi.yaml

GET /api/http-cookie-builder/ GET http-cookie-builder
POST /api/http-cookie-builder/ POST http-cookie-builder