{"uid":"cap_v4kjZl1b-OsLEW_QBcTkP","slug":"cookie-audit-4fd5413e","name":"cookie-audit","description":"Cookie audit from the Set-Cookie headers of a page load: each cookie's name, Secure, HttpOnly and SameSite flags, expiry/max-age, domain and path, with counts of cookies missing Secure or SameSite. Privacy and security hygiene without a browser. $0.01 per page.","url":"https://intel.rallylive.ca/site/cookies","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_oxydQp0cKYiBF2M9-NH7D","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits HTTP Set-Cookie headers for a given URL, reporting each cookie's security flags (Secure, HttpOnly, SameSite), expiry, domain, path, and counts of cookies missing key flags.","exampleAgentPrompt":"Can you audit the cookies set by https://example.com and tell me which ones are missing the Secure or SameSite flag?","exampleUseCases":[{"title":"Pre-launch security checklist for cookies","prompt":"Before we go live with our new site at https://shop.mystore.com, can you check all the cookies it sets and flag any that are missing Secure or SameSite — I want to make sure we're not shipping insecure cookies."},{"title":"Third-party vendor cookie compliance review","prompt":"We're onboarding a new analytics vendor at https://vendor-dashboard.example.com and I need to audit every cookie they set — give me the full list with Secure, HttpOnly, and SameSite flags plus how many are missing each."},{"title":"Privacy audit for GDPR reporting","prompt":"I need a cookie security and privacy hygiene report for https://legacyapp.corp.io — list every cookie with its expiry, domain, path, and flag whether Secure or SameSite is missing so I can include it in our compliance review."}],"resultDescription":"Returns a structured breakdown of every cookie set by the page's HTTP Set-Cookie headers, including each cookie's name, Secure flag status, HttpOnly flag status, SameSite attribute value, expiry or max-age, domain scope, and path — plus aggregate counts of cookies missing the Secure flag and the SameSite attribute.","failureModes":["URL unreachable or returns non-200 status — no cookies reported, error returned","Site sets cookies only via JavaScript (document.cookie) not Set-Cookie headers — those cookies will be missed","Redirect chains may result in cookies from intermediate pages being captured or missed depending on follow behavior","Malformed Set-Cookie headers may be partially parsed or skipped","Rate limiting or bot-blocking on target site may prevent page load"],"whenToPreferThis":"Use this endpoint when you need a fast, headless audit of a website's HTTP-level Set-Cookie headers without running a full browser. It's ideal for security reviews, compliance checks, and CI/CD pipeline hygiene scans where you want structured flag-level data (Secure, HttpOnly, SameSite) and counts of insecure cookies per URL. Prefer it over manual browser DevTools inspection when automating audits across many URLs at low cost ($0.01/call).","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T13:08:20.846Z","isFirstParty":false}