headers by 0x6a03448f4d
← All headers
Cookies

Cookie flags

Secure, HttpOnly, SameSite.

What it is

Attributes on Set-Cookie that decide whether a cookie is sent over HTTPS only (Secure), hidden from JavaScript (HttpOnly), and sent on cross-site requests (SameSite).

Why it matters

They protect session cookies from theft via XSS and from being used in CSRF attacks.

Risk without it

A session cookie without HttpOnly can be stolen by any XSS; without Secure it can leak over HTTP; without SameSite it can be replayed cross-site.

Recommended

Secure; HttpOnly; SameSite=Lax (or Strict). Use the __Host- prefix for session cookies.

References