All tools

HTTP Cookie Size Budget Calculator

Network

Parse a Cookie request header's name=value pairs and compute each cookie's serialized byte size and the total header size, flagging any cookie over RFC 6265's 4096-byte per-cookie guarantee and the total against a configurable budget.

Paste a Cookie header value (the name=value pairs a browser sends on every request to a domain) and see each cookie's exact byte size alongside the total header size. Every cookie is measured as the UTF-8 byte length of its name=value pair, matching how RFC 6265 defines the minimum 4096 bytes browsers must support per cookie, and the total adds the "; " separators so it reflects what actually goes over the wire. A configurable budget, 4096 bytes by default, flags when the accumulated cookies for a domain are creeping toward limits that vary by browser, server, and proxy. It checks the header text you give it, not a live request, so it won't catch cookies set by JavaScript after the page loads.

cookieheaderhttpsizebudgetbrowser

How to use HTTP Cookie Size Budget Calculator

  • 1.Paste a Cookie header value, either one you copied from browser dev tools or one you're constructing by hand.
  • 2.Optionally adjust the total byte budget; it defaults to 4096, a conservative guideline for keeping the whole header well under typical server and proxy limits.
  • 3.Review the per-cookie byte sizes and the total, and address any cookie flagged as exceeding the 4096-byte per-cookie guarantee or a total over budget.

Frequently asked questions

Does this measure a live request's actual Cookie header?
No, it only parses and measures the header text you paste. It never sends a request or reads cookies from a real browser session.
Why 4096 bytes as the default budget?
RFC 6265 requires browsers to support at least 4096 bytes per cookie, and many servers and reverse proxies cap total header line size well under typical defaults, so keeping the whole Cookie header near that figure is a common, conservative safety margin. Actual enforced limits vary by server and CDN configuration.
Does byte size include the Set-Cookie attributes like Domain or Secure?
No, it measures only the name=value pairs as they appear in the Cookie request header, since that's what a browser actually sends back on subsequent requests; attributes like Domain, Path, and Secure live only in the original Set-Cookie response and aren't resent.
What happens if a cookie's name or value contains non-ASCII characters?
The byte size is computed as the UTF-8 encoded length, which can be larger than the visible character count for non-ASCII text, exactly how it would count against a browser's byte-based cookie limits.

Use via API, SDK, or MCP

cURL# Free: 1,000 req/day · Pro: 10,000 req/day
curl -X POST https://api.utilix.tech/v1/tools/cookie-size-budget-calculator \
  -H "Authorization: Bearer utx_live_..." \
  -H "Content-Type: application/json" \
  -d '{"cookieHeader":"session=abc123; theme=dark","budgetBytes":4096}'

Get an API key from your dashboard · Full API docs →