Cookie Playground Documentation
Welcome to the Cookie Playground documentation! This is an educational resource for understanding how cookies work, especially in marketing and advertising contexts.
Documentation Structure
The documentation is organized into focused topics that build upon each other:
- Testing Cookie Scenarios - 🎯 START HERE Visual guide with step-by-step testing procedures and Mermaid diagrams
- Cookie Fundamentals - Learn what cookies are and how they work
- Cookie Attributes - Deep dive into cookie attributes (SameSite, Secure, HttpOnly, Domain, Path)
- First-Party vs Third-Party - Understand cookie classification
- Cross-Domain Behavior - How cookies behave across domains and subdomains
- Parent-Subdomain Cookies - Specific guide on parent domain and subdomain cookie access
- HTTP Headers - Cookie and Set-Cookie header details
- Marketing Use Cases - Pixel syncing, tracking, and advertising scenarios
- Using the Playground - How to use this infrastructure
- Manual Testing Guide - Step-by-step testing procedures
- HTTP Inspection - How to read and understand HTTP requests/responses
- Browser Behaviors - Browser-specific differences and privacy features
- Troubleshooting - Common issues and solutions
- Redirect Cookie Behavior - How cookies work with HTTP redirects
- Domain Migration for Tracker Mergers - Strategies for migrating tracking domains and preserving user identity
- Server Behavior and Cookie Scenarios - Detailed explanation of server behavior, when cookies are added, and which cookies are set
- Same-Site vs Cross-Site Requests - Terminology and behavior of same-site requests, cross-site GET requests, and cross-site POST requests
- SameSite=Lax - Comprehensive guide to SameSite=Lax: default behavior, security implications, and use cases
- SameSite Visual Guide - Visual flowcharts and decision trees for all SameSite values (None, Lax, Strict)
Quick Start
- Deploy the infrastructure using Terraform (see main README.md)
- Visit one of the playground domains:
- Main:
https://cookie-playground.pun7o.click - Subdomain A:
https://site-a.cookie-playground.pun7o.click - Subdomain B:
https://site-b.cookie-playground.pun7o.click - Redirect:
https://site-c.cookie-playground.pun7o.click(redirects to subdomain A)
- Main:
- Start with the Cookie Fundamentals guide
- Use the interactive playground pages to experiment with different cookie scenarios
Learning Path
Beginner Path:
- Cookie Fundamentals
- Cookie Attributes
- Using the Playground
- Manual Testing Guide
Intermediate Path:
- First-Party vs Third-Party
- Cross-Domain Behavior
- Parent-Subdomain Cookies
- HTTP Headers
- Same-Site vs Cross-Site Requests
- SameSite=Lax
- SameSite Visual Guide
Advanced Path:
- Marketing Use Cases
- HTTP Inspection
- Browser Behaviors
- Troubleshooting
Additional Resources
- Browser Developer Tools documentation
- HTTP/1.1 RFC 6265 (Cookie specification)
- MDN Web Docs on Cookies