UtilityToolsLab

© 2026 UtilityToolsLab. Built and maintained by the UtilityToolsLab Team.

Free eBooks·About·Changelog·Privacy Policy·Terms of Service·Report a bug
HomeAuth, Privacy & ValidationStorage Inspector

Related Tools

Suspicious URL Check2FA QR BuilderTOTP GeneratorCard ValidatorEmail ValidatorXSS Sanitizer

Browser Storage Inspector

See all cookies, localStorage, sessionStorage and IndexedDB this site has set in your browser. Live refresh, copy as JSON, clear storage — nothing uploaded.

You Might Also Like

All Auth, Privacy & Validation

Suspicious URL Check

Read a link before you click it: decodes punycode, spots the @ trick, mixed-script homographs and brand-in-subdomain. The link is read, never fetched.

2FA QR Builder

Build the otpauth:// URI for a TOTP or HOTP account and render it as a scannable QR code. SHA-1/256/512, 6–8 digits, 30–90s period. Nothing uploaded.

TOTP Generator

Generate time-based one-time passcodes from a Base32 secret using RFC 6238, entirely in your browser. Configure the algorithm, digit count, and refresh period.

Card Validator

Validate any card number with the Luhn algorithm. Detects Visa, Mastercard, Amex, Discover and more. Shows IIN, CVC length, and formatted display.

Every browser tab runs in a sandbox: a page can read the cookies and storage that its own origin set, and nothing from any other site you have ever visited. That constraint is what makes this tool safe to build and honest to use. Click Refresh and it reads everything utilitytoolslab.com has left in your browser right now — cookies, localStorage, sessionStorage, and IndexedDB databases.

Developers use it to confirm which keys their tools actually write, spot stale entries left by old builds, or verify that a dark-mode preference saved to localStorage came through correctly. Privacy- conscious visitors use it to see exactly what the site stores before deciding whether to clear it.

What Each Storage Type Holds

  • Cookies are name-value pairs the browser sends back with every request to the same origin. This tool shows their names and values exactly as document.cookie returns them: no HttpOnly cookies appear here, because those are intentionally invisible to JavaScript, which is the protection they exist to provide.
  • localStorage persists until explicitly cleared. This site uses it to store preferences such as your chosen dark or light theme. Each entry shows its key, a truncated value (clickmore to expand), and its size in bytes (UTF-16 pairs: each JS character counts as 2 bytes).
  • sessionStorage is tab-scoped and clears when the tab closes. Entries that survive a page reload but disappear when you re-open the URL are almost certainly sessionStorage, not localStorage.
  • IndexedDB lists database names, versions and object-store names. Firefox and older Safari do not expose indexedDB.databases(), so those browsers report none even if databases exist — the panel notes this rather than showing a misleading empty state.

Accuracy and What This Cannot Show

  • HttpOnly cookies are invisible. They are set with a flag that tells the browser to withhold them from JavaScript. Only the server sees them. A cookie used for session authentication is almost certainly HttpOnly and will not appear here.
  • Other sites are invisible. The same-origin policy prevents a page from reading any storage that a different origin set. This tool shows utilitytoolslab.com only.
  • Clear with care. The Clear localStorage button permanently removes all localStorage entries for this site. If the site writes those entries on load, a page refresh will re-create them. There is no undo.

Scope: browsers enforce same-origin isolation, so this page can only read storage that utilitytoolslab.com itself has set. It cannot read cookies or data from any other site you have visited.

Click Refresh to scan.

All reads happen inside your browser tab. No data is sent anywhere. The Clear buttons permanently delete those entries from your browser for this site; refreshing the page may re-create any that the site writes on load.